Data processing agreement
Effective from 2 Nov 2026
Until this version takes effect, the version of 2 October 2026 applies.
Operator
Contact and the points of contact under the Digital Services Act
1. Parties and subject
This agreement is made between the person or business that owns an account in the service (the controller) and the operator named above (the processor). It is part of the terms of service and is concluded by accepting them when the account is created.
The processor processes the personal data that the controller or the people it invites enter into the account, only to provide the service to the controller.
2. Nature and purpose
Storing and showing data, issuing documents and their formats, sending e-mail, checks in public registers, recording payments, webhooks and the API, export and backups, and reading the details of received documents by AI as the controller sets it up or requests it in the account.
3. Data and data subjects
The controller's business partners (customers and suppliers) and their contact people: identification data, addresses, contact details, billing and payment data, the content of documents and correspondence about them. The people named in the records the controller files (contracts, authorities' letters, filings and internal documents): the data those records hold. The service needs no special categories of data, and the controller does not enter any; records are business documents.
4. Duration
The agreement lasts as long as the account exists. The controller can download an export of all data at any time. After the account is closed, its owners can still request and download it for 30 days; then the processor deletes all of the account's data. If the owner chooses the archive instead of closing, the processor keeps the data read-only with export for the period section 35 of the Czech VAT act sets for the account's latest issued document or expense, ten years from the end of the year it was issued or received, and then deletes it.
5. The processor's obligations
- It processes data only on the controller's documented instructions, which are this agreement and the controller's actions in the service.
- It binds everyone with access to the data to confidentiality.
- It protects the data by the technical and organisational measures the security policy annexed to this agreement describes: encrypted connections, accounts separated in the database itself, roles and two-step sign-in, an audit log, continuous backups restorable over 7 days.
- It looks into an account only with support access the account's owner grants, for 7 days at most and read-only, and every look is written to the audit log.
- It helps the controller answer data subjects' requests, above all by export and erasure, and assists with impact assessments and consultations with the supervisory authority.
- It notifies the controller of a personal data breach without undue delay, at the latest within 48 hours of discovering it.
Annex: the technical and organisational measures are on the page Security policy.
6. Sub-processors
The controller gives general authorisation to engage sub-processors. The processor binds them by contracts with the same obligations. It announces a change of the list by e-mail at least 14 days ahead; the controller may object before then and close the account.
| Processor | What it provides | Where |
|---|---|---|
| Microsoft Ireland Operations Limited (Microsoft Azure) | Running the application, database, file storage, backups, monitoring and sending e-mail (Azure Communication Services) | EU, the Netherlands (West Europe), backups Ireland (North Europe) |
| Microsoft Ireland Operations Limited (Microsoft Entra External ID) | Sign-up and sign-in of users | EU |
| Google Ireland Limited (Google Analytics) | Measuring visits to the public pages and the steps of the application's getting-started guide, only with your consent | EU, with a possible transfer to the USA |
| Anthropic Ireland, Limited, with its sub-processor Anthropic, PBC (USA) | AI extraction of documents, from the date the notice announces | Ireland and the USA |
We check companies and taxpayers in public registers: ARES (Czech Ministry of Finance), the Register of Legal Entities (Statistical Office of the Slovak Republic), VIES (European Commission) and the register of unreliable VAT payers (Czech Financial Administration). Exchange rates come from the Czech National Bank and the European Central Bank. These institutions are not our processors; we send them only the identification numbers we ask about.
Anthropic Ireland, Limited processes documents only to extract them and, under its commercial terms, does not use them to train its models. It keeps them only for the time its commercial terms allow. Anthropic may keep them for its safety reviews.
7. Transfers outside the EU
The data and its backups are stored in Microsoft Azure, region West Europe (the Netherlands); geo-redundant backups in North Europe (Ireland). A transfer outside the EU happens only with appropriate safeguards under Chapter V GDPR.
Anthropic Ireland, Limited passes documents for extraction to its sub-processor Anthropic, PBC in the USA on the safeguards agreed between the two companies.
8. Audit
The processor gives the controller the information needed to show compliance with this agreement and allows audits after reasonable prior notice, at the controller's cost.