Skip to content
C
Citofact

Data Processing Agreement

Last updated: June 25, 2026

Draft template. Before launching publicly, have this reviewed by qualified Latvian counsel.

This agreement governs Citofact's processing of personal data on your behalf and supplements our Terms of Service. It applies to the data you enter about your own customers; for your account data Citofact is the controller and the Privacy Policy applies instead.

1. Roles and subject matter

You are the controller and Citofact is the processor. Citofact processes personal data only to provide the invoicing service described in the Terms, and only on your documented instructions — which include your configuration and use of the service.

2. Duration

This agreement runs for as long as Citofact processes personal data on your behalf, i.e. for the term of your account.

3. Data subjects and categories of data

Data subjects: your customers and invoice recipients.Categories of data: contact details (name, email, address), tax identifiers such as VAT IDs, and invoice contents (line items, amounts, dates, payment status). No special categories of data are intended to be processed.

4. Our obligations (Art. 28(3) GDPR)

  • process personal data only on your documented instructions, including for transfers;
  • ensure that persons authorised to process the data are bound to confidentiality;
  • implement appropriate technical and organisational security measures (see section 6);
  • engage sub-processors only under the conditions in section 5;
  • assist you, as far as possible, in responding to data-subject requests;
  • assist you with your obligations on security, breach notification and data-protection impact assessments (Art. 32–36 GDPR);
  • delete or return personal data at the end of the service (see section 8);
  • make available the information needed to demonstrate compliance and allow audits (section 9).

5. Sub-processors

You authorise Citofact to engage the following sub-processors: Supabase (database and authentication), Stripe (payments), Resend (transactional email), Cloudflare (DNS and edge hosting), and Render (API hosting). Each is bound by data-protection obligations no less protective than this agreement. We will give advance notice of any intended change to this list and you may object on reasonable data-protection grounds.

6. Security (Art. 32 GDPR)

We maintain appropriate technical and organisational measures, including encryption in transit, access controls and tenant isolation, authentication via established identity providers, and backups. Payment card data never reaches Citofact — it is handled by Stripe directly.

7. International transfers

Where sub-processors process data outside the EEA, transfers rely on the EU–US Data Privacy Framework where the recipient is certified, otherwise on Standard Contractual Clauses; for Swiss data, on the Swiss–US Data Privacy Framework or recognised Standard Contractual Clauses.

8. Deletion and return

On termination, we export your data on request and delete it within 30 days, except where law requires continued retention.

9. Audits

We will provide the information reasonably necessary to demonstrate compliance with this agreement and will support audits, which may be satisfied by relevant third-party certifications or reports where available.

10. Switzerland (FADP)

Where the Swiss FADP applies, this agreement is read to meet the processor requirements of Art. 9 FADP, references to the GDPR apply correspondingly, and the competent authority is the Federal Data Protection and Information Commissioner (FDPIC).

11. How this agreement is concluded

[Acceptance mechanism — e.g. this agreement is deemed accepted when you accept the Terms of Service; a signed copy is available on request at legal@citofact.com.]