Data Processing Agreement
Last updated: 2 September 2026
This Data Processing Agreement (the "DPA") is concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 (GDPR) between you, the customer of E-Rechnung Pro (the "Controller"), and CHERNOVA LILIIA PETRIVNA, Private entrepreneur under the law of Ukraine, Masyv Raiduzhnyi 24, 67804 Lymanka, Odesa district, Odesa region, Ukraine (the "Processor").
This DPA forms an integral part of our Terms of Use and applies automatically to every customer from the moment the Terms of Use are accepted. No separate signature is required. On request we will provide and sign a separate counterpart bearing your company details.
1. Subject matter, nature and purpose
The Processor provides the E-Rechnung Pro service, which creates, converts and validates electronic invoices. In doing so the Processor processes personal data contained in the invoices and related documents supplied by the Controller, exclusively for the purpose of providing that service.
The duration of the processing corresponds to the term of the main contract between the parties.
2. Categories of data subjects and types of personal data
Categories of data subjects: the Controller's customers and business partners, and the Controller's own employees named in documents.
Types of personal data: names and company names, postal addresses, contact details, tax and VAT identification numbers, bank details, invoice numbers and dates, descriptions and values of goods or services supplied, payment terms, and any further data the Controller chooses to include in a document.
The Processor does not require special categories of data within the meaning of Article 9 GDPR and the Controller shall not upload such data.
3. Instructions
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by law applicable to the Processor. In that case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
Use of the Service by the Controller, in particular the uploading, creation, conversion, validation, storage, downloading and deletion of documents, constitutes the Controller's documented instruction. Further instructions shall be given in text form to zugferd@randomstar.org.
The Processor shall inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions, and may suspend execution of that instruction until it is confirmed or amended.
4. Confidentiality
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to production systems is restricted to the Processor personally.
5. Security of processing
The Processor implements the technical and organisational measures required by Article 32 GDPR, in particular:
- encryption of all data in transit by means of TLS;
- storage of authentication credentials exclusively as bcrypt hashes;
- logical separation of customer accounts, so that documents are accessible only to the account which created them;
- authenticated individual access to production systems, with no shared administrative credentials;
- regular backups and prompt installation of security updates;
- physical security, redundancy of power and network, and access control at the data centre, provided by the hosting provider named in section 6;
- server log records enabling detection and investigation of unauthorised access.
The Processor may modify these measures provided the level of protection is not reduced.
6. Sub-processors
The Controller grants the Processor general authorisation to engage sub-processors. The Processor shall inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, and the Controller may object on reasonable data protection grounds; in that case either party may terminate the main contract with effect from the date on which the change takes effect.
The following sub-processors are engaged at the date of this DPA:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — provision of servers, storage and email delivery. Processing location: Falkenstein, Germany.
Payment processing is carried out through Stripe Payments Europe, Limited (Ireland). Stripe receives only the data required to collect the fees due under the main contract and never receives personal data processed on behalf of the Controller; it is therefore not a sub-processor within the meaning of Article 28 GDPR. Details are set out in the privacy notice.
The validation and rendering components at validator.randomstar.org and render.randomstar.org are operated by the Processor itself on the same infrastructure and are not third parties.
The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those set out in this DPA, and remains fully liable to the Controller for their performance.
7. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests to exercise data subject rights under Chapter III GDPR.
Where a data subject addresses such a request directly to the Processor, the Processor shall not act on it itself but shall forward it to the Controller without undue delay.
8. Assistance with the Controller's further obligations
The Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Processor, in particular as regards the security of processing, notification of personal data breaches, and data protection impact assessments.
9. Personal data breaches
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller. The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
10. Deletion or return of data
On termination of the main contract the Controller may download its documents for a period of 30 days. After the expiry of that period the Processor shall delete all personal data processed on behalf of the Controller, unless the law applicable to the Processor requires further storage. Payment and accounting records are retained in accordance with the retention period stated in the privacy notice.
Backups are overwritten in the ordinary backup cycle; personal data contained in them is protected by the measures set out in section 5 until it is overwritten.
11. Audits and evidence of compliance
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
Audits shall be announced at least 14 days in advance, shall take place during normal business hours, shall not unreasonably disrupt operations, and shall be limited to one audit per calendar year unless there is a specific cause. The auditor must not be a competitor of the Processor and must be bound by confidentiality. In the first instance, the Processor may discharge this obligation by providing written information and, where available, certificates or audit reports of its sub-processors.
12. Processing location and international transfers
All personal data processed on behalf of the Controller is stored exclusively on servers located in Falkenstein, Germany, within the European Union.
The Processor is established in Germany. All processing of personal data on behalf of the Controller, including every access by the Processor, takes place within the European Union. No personal data is transferred to a third country, and safeguards under Chapter V GDPR are therefore not required. Should the Processor intend to process personal data outside the European Economic Area in future, it will inform the Controller in advance in accordance with section 6 and put appropriate safeguards under Chapter V GDPR in place beforehand.
13. Liability and final provisions
Liability under this DPA is governed by Article 82 GDPR. The limitations of liability agreed in the Terms of Use apply in addition, to the extent permitted by law, save that they do not limit either party's liability towards data subjects or supervisory authorities.
Should any provision of this DPA be invalid, the validity of the remaining provisions is unaffected. In the event of a conflict between this DPA and the Terms of Use, this DPA prevails in matters of data protection. In the event of a conflict between this DPA and the standard contractual clauses, those clauses prevail.