Data Processing Addendum
Parties and status
This Data processing addendum (“DPA”) forms part of the agreement between the Client as controller and Negative Epsilon SL, NIF B02850360, as processor (“FiscalRail”) for the FiscalRail service. It applies when FiscalRail processes personal data in Client Data on the Client’s behalf.
The Client enters this DPA for itself and, where authorised, for its relevant affiliates. Capitalised terms not defined here have the meaning in the Terms or GDPR. If this DPA conflicts with the Terms on personal-data processing, this DPA controls.
Roles and instructions
The Client determines the purposes and essential means of processing Client Personal Data and is the controller. FiscalRail processes that data only on documented Client instructions, including the agreement, configured product actions, API requests, support instructions and applicable law.
If we believe an instruction infringes GDPR or other applicable data-protection law, we will inform the Client unless prohibited and may pause the affected processing. If law requires processing beyond the Client’s instruction, we will notify the Client before processing unless law prohibits notice.
FiscalRail is an independent controller for user account administration, billing, fraud and abuse prevention, service security and its own legal obligations. That processing is covered by the Privacy policy, not this DPA.
Processing details
- Subject matter: hosting, validating, calculating, numbering, rendering, transmitting, retrieving and supporting invoices, customer records, fiscal records, events, webhooks and related artifacts through FiscalRail.
- Duration: for the agreement and any period needed to return or delete data, subject to documented Client instructions and legal retention duties.
- Nature and purpose: storage, organisation, consultation, calculation, transformation, disclosure to Client-configured recipients and supported authorities, restriction, export and deletion required to provide and secure the service.
- Data subjects: the Client’s customers and suppliers; sole traders; invoice recipients and contacts; Client personnel, representatives and users; payers and payees; and other people identified in Client-submitted invoice or fiscal data.
- Personal-data categories: names, business and trade names where they identify a person, tax and VAT identifiers, postal addresses, email addresses, phone numbers, transaction and invoice details, goods or service descriptions, payment instructions, financial account references, authority responses, identifiers, timestamps, event and webhook payloads, and technical metadata.
- Sensitive data: FiscalRail is not designed for special-category data under GDPR Article 9 or criminal-offence data under Article 10. The Client must not intentionally submit it without a separate written agreement.
Client obligations
The Client will:
- comply with applicable data-protection law and give lawful, fair and transparent instructions;
- have a valid legal basis for Client Personal Data and all authority submissions, validations, webhooks and connected integrations;
- provide required privacy information and handle data-subject requests and objections;
- limit data to what is adequate, relevant and necessary and avoid sensitive data;
- configure access, retention, exports, webhook recipients and credentials securely; and
- assess whether FiscalRail and the documented security measures are appropriate for its processing risks.
Confidentiality and personnel
FiscalRail will ensure that people authorised to process Client Personal Data are bound by confidentiality and receive appropriate data-protection and security instructions. Access will be limited to personnel who need it to provide, secure or support the service.
Security
Taking account of the state of the art, implementation costs and processing risk, FiscalRail will maintain appropriate technical and organisational measures under GDPR Article 32. Current measures include:
- TLS encryption for public service interfaces and transactional email transport where supported;
- account-scoped authorisation and separation between Client accounts;
- short-lived passwordless sign-in tokens and protected API and webhook credentials;
- parameter filtering intended to keep credentials and common personal fields out of application logs;
- immutable application controls for issued invoices, fiscal records, events and billing records;
- restricted production and vendor access, dependency maintenance and security monitoring;
- resilience, backups and recovery procedures appropriate to the service; and
- processes to investigate incidents and restore availability.
FiscalRail may update measures without materially reducing overall protection.
Subprocessors
The Client gives general written authorisation for subprocessors on the Subprocessors page. FiscalRail will impose data-protection obligations that provide substantially equivalent protection for the relevant processing and remains responsible for each subprocessor’s performance as required by GDPR.
FiscalRail will give at least 15 days’ notice before a new subprocessor begins processing Client Personal Data. The Client may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a reasonable solution. If none is available, the Client may terminate only the affected service before the subprocessor begins processing; this is the Client’s sole remedy for the objection.
International transfers
FiscalRail will not transfer Client Personal Data outside the EEA except on documented instructions or using a lawful GDPR Chapter V mechanism. Where required, FiscalRail will use an adequacy decision, applicable European Commission Standard Contractual Clauses and supplementary measures, or another lawful safeguard and will provide relevant information on request.
If the Client’s use of the service constitutes a restricted transfer from the Client to FiscalRail, the parties will cooperate to implement the required transfer mechanism. Client-configured webhook recipients and integrations are Client transfers.
Data-subject requests
If FiscalRail receives a request concerning Client Personal Data, it will notify the Client and will not respond on the merits except on Client instructions or where legally required. Taking account of the nature of processing, FiscalRail will provide reasonable technical and organisational assistance so the Client can respond. The Client remains responsible for the response and identity verification.
Assistance and compliance
Taking account of the processing and information available, FiscalRail will reasonably assist the Client with security, personal-data-breach duties, data-protection impact assessments and prior consultation under GDPR Articles 32 to 36.
FiscalRail will make information reasonably necessary to demonstrate compliance with GDPR Article 28 available to the Client. No more than once per year, unless a breach or regulator reasonably requires more, the Client may request an audit. Audits must use independent qualified auditors, protect other clients and confidential information, avoid unreasonable disruption and be at the Client’s cost unless they identify a material FiscalRail breach.
Personal-data breaches
FiscalRail will notify the Client without undue delay after becoming aware of a personal-data breach affecting Client Personal Data. As information becomes available, notice will describe the nature of the breach, likely consequences, measures taken or proposed and a contact point. FiscalRail’s notice is not an admission of fault. The Client is responsible for notifications to authorities and data subjects unless law assigns that duty to FiscalRail.
Return, deletion and legal retention
During the term, the Client may retrieve Client Personal Data through the documented API, including free read operations. The Client must complete any required export before closing the account. Account closure through the dashboard is the Client’s documented instruction to delete Client Personal Data and is irreversible. FiscalRail deletes the Live account, its Test account and active Client Personal Data and has no obligation to retain or restore it for the Client.
Data already present in isolated backups is put beyond ordinary use and deleted through the normal backup expiry cycle unless Union or Member State law requires longer retention. FiscalRail may separately retain payment records as an independent controller for its own legal, tax and accounting duties; those records are not retained on the Client’s behalf under this DPA.
Government and authority requests
FiscalRail will direct a requesting authority to the Client where lawful and appropriate. If compelled to disclose Client Personal Data, FiscalRail will notify the Client before disclosure unless prohibited, review the request’s validity and disclose only what is legally required. Client-directed submissions to AEAT, VIES or another supported official service are service instructions, not government-access requests under this section.
Liability and term
The liability provisions in the Terms apply to this DPA to the extent permitted by law. This DPA starts when the Client accepts it through the account-creation checkbox or a signed order form, and ends after FiscalRail has completed its deletion obligations.
Contact and governing law
Data-protection notices under this DPA must be sent to contact@negativeepsilon.com. The governing law and courts in the Terms apply, without reducing mandatory data-subject or supervisory-authority rights.