Data Processing Agreement (DPA)
Last updated: 2026-07-21
This Data Processing Agreement ("DPA") supplements the Terms of Service between InvoiceAlert, Sofia, Bulgaria ("Processor") and the Customer ("Controller") and applies to personal data the Controller uploads to InvoiceAlert about the Controller's own clients. It is intended to satisfy Article 28 GDPR.
1. Roles
The Controller determines the purposes and means of processing its clients' personal data. The Processor processes that data solely on the Controller's documented instructions, as set out in this DPA and the Terms of Service.
2. Subject matter, duration, nature and purpose
- Subject matter: provision of the InvoiceAlert invoice-tracking and payment-reminder service.
- Duration: for the duration of the Controller's subscription, plus the data-retention period stated in the Privacy Policy.
- Nature of processing: storage, retrieval, transmission (email), and deletion of the data described below.
- Purpose: to track invoices and send automated payment reminders on the Controller's behalf.
3. Categories of data and data subjects
- Data subjects: the Controller's own clients (individuals or company contacts).
- Categories of data: name, email address(es), nationality/company identifiers, invoice numbers, amounts, due dates, payment status, and any free-text notes the Controller enters.
4. Processor obligations
- Process personal data only on the Controller's documented instructions (including regarding international transfers), unless required otherwise by EU/member-state law.
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Art. 32 GDPR) — see Privacy Policy §6 for current measures.
- Assist the Controller, insofar as reasonably possible, in responding to data-subject rights requests and in complying with Art. 32–36 GDPR obligations (security, breach notification, DPIAs).
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.
- At the Controller's choice, delete or return all personal data after the end of the subscription, and delete existing copies unless EU/member-state law requires storage.
- Make available information necessary to demonstrate compliance with this Article and allow for audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice.
5. Sub-processors
The Controller authorizes the Processor to engage the following categories of sub-processor, each bound by written terms providing equivalent data-protection obligations:
- Cloud hosting provider (EU-based server infrastructure).
- Outbound email relay (used only when the Controller's own configured SMTP provider cannot be reached directly, solely to complete message delivery).
- Offsite backup storage provider (only if the Controller has enabled offsite backup in account settings).
A current, named sub-processor list is available on request. The Processor will notify the Controller of any intended change concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data-protection grounds.
6. International transfers
Where a sub-processor is located outside the EU/EEA, the Processor relies on Standard Contractual Clauses as adopted by the European Commission to ensure an adequate level of protection.
7. Liability
Liability under this DPA mirrors the structure in the Terms of Service: each party is liable for damage caused by its own breach of the GDPR obligations set out in this DPA.
8. Contact
Privacy / DPO email: [email protected]
InvoiceAlert, Sofia, Bulgaria