DPA (Art. 28 GDPR)
pursuant to Art. 28 GDPR
Processor: TK ENTERPRISES LTD, Griva Digeni 51, Athinaion Court, Flat/Office 202, 8047 Paphos, Cyprus
Controller: Any natural or legal person who accepts the Terms of Service of Invoboard.
Effective date: Date of acceptance of the Terms of Service.
This DPA is incorporated by reference into the Terms of Service. By accepting the Terms of Service – whether by completing the registration process or otherwise using the Services – the Controller agrees to this DPA. No separate signature is required (Art. 28(9) GDPR). In the event of conflict, this DPA prevails in data protection matters.
1. Subject Matter and Duration
The Processor operates the Invoboard SaaS platform on behalf of the Controller for invoicing, accounting, time tracking, and document management. Processing commences upon acceptance of the Terms of Service and ends upon termination of the service relationship.
2. Description of Processing
Purpose: Provision of the contracted SaaS platform features.
Nature: Storage, retrieval, processing, and transmission of business data; user authentication; backups; logging; system monitoring; support.
Categories of personal data: Customer and supplier master data (name, address, email, phone, VAT ID); invoice and payment data; bank details (IBAN, BIC, payment references); document contents (invoices, receipts, bank statements); email delivery logs; platform user data (login timestamps, hashed IP addresses).
Categories of data subjects: The Controller’s customers, suppliers, employees, and business contacts; the Controller themselves if a natural person.
3. Processor’s Obligations
(a) Instructions. The Processor shall process personal data only on documented instructions from the Controller. The Controller’s use of the platform constitutes documented instructions with respect to platform features. If the Processor is required by law to process data beyond those instructions, it shall inform the Controller before doing so unless prohibited by law.
(b) Confidentiality. The Processor shall ensure that all persons authorized to access personal data are bound by confidentiality obligations.
(c) Technical and organizational measures. The Processor shall implement and maintain appropriate technical and organizational measures pursuant to Art. 32 GDPR as set out in Annex 2.
(d) Sub-processors. The Processor may engage sub-processors as listed in Annex 1. The Processor shall notify the Controller of any intended changes at least 30 days in advance via email or notice within the platform. The Controller may object within that period; if the change cannot be avoided, the Controller may terminate the agreement for cause. The Processor shall impose equivalent data protection obligations on all sub-processors and remains liable for their compliance.
(e) Data subject rights. The Processor shall not respond to data subject requests directly. If a data subject contacts the Processor directly, the Processor shall forward the request to the Controller without delay. The Processor shall assist the Controller in fulfilling obligations under Arts. 15–22 GDPR by appropriate technical and organizational means.
(f) Security assistance. The Processor shall assist the Controller in ensuring compliance with Arts. 32–36 GDPR, including security measures, breach notification, and data protection impact assessments.
(g) Security incidents. The Processor shall notify the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach, to the email address registered in the Controller’s account. Notification shall include the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. Where full information is not yet available, initial notification shall be made promptly with further details to follow.
(h) Supervisory authorities. The Processor shall promptly inform the Controller of any investigation or measure by a supervisory authority insofar as legally permissible.
(i) Deletion and return. Upon termination of the service relationship, the Processor shall delete all personal data within 30 days. The Controller may request a full data export via the self-service export function before termination. Deletion does not apply where Union or Member State law requires continued storage.
(j) Audit rights. The Processor shall provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA. On-site audits are permitted with at least 30 days’ prior written notice, during normal business hours, and subject to reimbursement of reasonable costs. Audits may be conducted by qualified independent third parties subject to prior confidentiality obligations.
(k) Records. The Processor shall maintain records of processing activities pursuant to Art. 30(2) GDPR and make them available to supervisory authorities upon request.
4. Controller’s Obligations
The Controller is solely responsible for the lawfulness of the personal data it submits to the platform, including obtaining any required consents from its own end customers, maintaining its own records of processing activities, and fulfilling its information obligations under Arts. 13–14 GDPR toward its own data subjects.
5. International Transfers
Personal data is processed within the EU/EEA. The Processor’s infrastructure is hosted on own servers in Germany, operated by TK ENTERPRISES LTD (Cyprus). All third-country transfers are subject to appropriate safeguards as indicated in Annex 1 (adequacy decision, Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914, and/or EU-US Data Privacy Framework certification).
6. Liability
Each party’s liability is governed by Art. 82 GDPR. As between the parties, liability is further subject to the limitations set out in the Terms of Service to the maximum extent permitted by law.
7. Governing Law
This DPA is governed by the laws of the Republic of Cyprus.
8. Amendments
The Processor may update this DPA to reflect changes in law or the Services. Material changes will be notified at least 30 days before taking effect by email or notice within the platform. Continued use of the Services after the effective date constitutes acceptance. If the Controller objects, it may terminate the agreement in accordance with the Terms of Service.
Annex 1 – Sub-processors
| Provider | Service | Location / Transfer basis |
|---|---|---|
| TK ENTERPRISES LTD | Hosting, database, storage, application infrastructure | Cyprus (EU) – servers located in germany. No third-country transfer. |
| Stripe Payments Europe Ltd. | Subscription billing, payment processing | Ireland (EU). DPA in place. |
| Anthropic PBC | AI features (user opt-in only) | USA. EU-US Data Privacy Framework (adequacy decision of 10.07.2023). |
Changes are notified at least 30 days before taking effect.
Annex 2 – Technical and Organizational Measures (Art. 32 GDPR)
Access control. Role-based access control; Row-Level Security on all relevant database tables; service role keys restricted to server-side use only; MFA available.
Encryption. Data at rest: standard database-level encryption; application-level encryption (AES-256-GCM) for sensitive fields only (SMTP credentials, stripe credentials). Data in transit: TLS 1.2 minimum, HSTS with preload.
Integrity. Append-only audit log; immutability of finalized invoices enforced at database level; dependency vulnerability scanning (Dependabot, npm audit).
Availability. Daily automated backups with 7-day point-in-time recovery; encrypted off-site backup; multi-availability-zone hosting.
Incident response. Documented incident response plan; regular drills; PII scrubbing in error monitoring.
Review. Annual internal security and data protection review.