Login
Open navigation menu

Data Processing Agreement (DPA)

Agreement on the processing of personal data

1. Parties

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between:

  • Controller: The customer using the Facturium platform
  • Processor: Facturium, the provider of the software-as-a-service platform

For the purposes of applicable data protection laws, including Regulation (EU) 2016/679 ("GDPR"), the Controller and the Processor agree as follows.

2. Subject Matter and Duration

The subject matter of this DPA is the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the Facturium services.

Processing shall continue for the duration of the service agreement unless otherwise agreed in writing.

3. Nature and Purpose of Processing

The Processor processes personal data solely for the purpose of:

  • Providing invoicing, administrative, and fiscal management functionalities
  • Storing, generating, exporting, and transmitting invoices and related records
  • Complying with technical requirements applicable to invoicing systems

The Processor shall not process personal data for any purpose other than those instructed by the Controller.

4. Categories of Data and Data Subjects

4.1 Data Subjects

  • Customers, suppliers, and business contacts of the Controller
  • Natural persons appearing on invoices or fiscal records

4.2 Categories of Personal Data

  • Identification data (name, tax identification number, address)
  • Contact data (email address)
  • Fiscal and invoicing data (invoice numbers, dates, amounts, tax details)
  • Any other data voluntarily entered by the Controller into the platform

5. Processor Obligations

The Processor shall:

  1. Process personal data only on documented instructions from the Controller
  2. Ensure that persons authorized to process the data are bound by confidentiality
  3. Implement appropriate technical and organizational measures to protect personal data
  4. Assist the Controller in responding to data subject rights requests
  5. Assist the Controller in complying with obligations relating to security, breach notification, and impact assessments
  6. Not disclose personal data to third parties unless legally required or instructed by the Controller

6. Security Measures

The Processor shall implement appropriate technical and organizational measures, including but not limited to:

  • Encrypted communications (HTTPS/TLS)
  • Logical access controls and authentication mechanisms
  • Regular backups and data integrity controls
  • Measures to prevent unauthorized access, alteration, or loss of data

These measures may evolve over time in accordance with industry standards.

7. Subprocessors

The Controller authorizes the Processor to engage subprocessors necessary for the provision of the service, including but not limited to:

  • Hosting and infrastructure providers
  • Backup and storage services
  • Email or notification services

The Processor shall ensure that any subprocessor is subject to data protection obligations no less protective than those set out in this DPA.

An up-to-date list of subprocessors may be made available upon request.

8. Data Subject Rights

Taking into account the nature of the processing, the Processor shall assist the Controller, where reasonably possible, in fulfilling requests from data subjects to exercise their rights under GDPR.

The Processor shall not respond directly to data subject requests unless instructed by the Controller or legally required.

9. Personal Data Breach

In the event of a personal data breach, the Processor shall notify the Controller without undue delay after becoming aware of the breach and provide available information to assist the Controller in meeting its notification obligations.

10. Data Deletion or Return

Upon termination of the service, and at the choice of the Controller, the Processor shall:

  • Delete personal data, or
  • Return personal data to the Controller

unless retention is required by applicable law.

11. Audits

The Controller may verify compliance with this DPA through reasonable requests for information or documentation.

On-site audits shall only be permitted where legally required and subject to reasonable notice and confidentiality obligations.

12. Liability

Each party shall be liable for damages caused by processing activities for which it is responsible under applicable data protection laws.

Nothing in this DPA increases the Processor's liability beyond what is set out in the Terms and Conditions.

13. Governing Law

This DPA shall be governed by and construed in accordance with the laws of Spain.

14. Precedence

In the event of a conflict between this DPA and the Terms and Conditions, this DPA shall prevail with respect to data protection matters.

15. Acceptance

This DPA is accepted electronically upon the Controller's acceptance of the Terms and Conditions of the Facturium platform.

Annex I – Tax Authority Submissions (VeriFactu)

The Controller acknowledges that, as part of the service, the Processor may transmit invoicing records and related information to the Spanish Tax Agency (Agencia Estatal de Administración Tributaria – AEAT), when such transmission is enabled or required by applicable law.

Such transmissions are performed:

  • On behalf of the Controller
  • In accordance with the technical specifications published by the AEAT
  • Based on the data provided and configuration selected by the Controller

The Processor does not verify the material accuracy or legal correctness of the transmitted data and does not act as the tax representative of the Controller before the tax authorities.

Electronic invoicing software for freelancers, SMEs, and firms that need a solid foundation to operate in Spain.

+34 900 815 523