Data Processing Agreement (DPA)
Version 1.1, 2026-06-24. This DPA is incorporated into the terms accepted by installing the Faktwise app and is concluded between the merchant (controller) and Emanuel José Vargas Luís, sole trader, Portugal, operating Faktwise (processor), per Art. 28 GDPR.
1. Subject matter and duration
Processing of order and customer data solely to generate, store, deliver and export invoices and credit notes on the controller's documented instruction (given through app configuration), for the duration of the app installation plus statutory retention periods.
2. Nature and purpose
Generation of legally required invoices (PDF, ZUGFeRD/Factur-X, XRechnung), archiving (10 years), email delivery to end customers when enabled, VAT ID validation via VIES, reporting exports.
3. Categories of data and data subjects
Data subjects: the controller's customers. Data: name, billing/shipping address, email, country, VAT ID, purchased items and amounts. No special categories (Art. 9) are processed.
4. Processing on instructions only
We process personal data only on the controller's documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which we are subject; in such a case we inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).
5. Confidentiality
All persons authorised to process the personal data, including the sole trader operating Faktwise, are bound to confidentiality and process the personal data only on the controller's documented instructions (Art. 28(3)(b), Art. 29 GDPR). Confidentiality obligations continue after the end of the processing activity.
6. Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| alwaysdata SAS | Hosting, database, email delivery (SMTP) | Paris, France (EU) |
The controller grants general authorization for these subprocessors. We will inform merchants of intended additions or replacements at least 30 days in advance (in-app or by email); the merchant may object on reasonable data-protection grounds, in which case the merchant may terminate by uninstalling the app before the change takes effect.
Where we engage a subprocessor to carry out specific processing activities on behalf of the controller, we impose on that subprocessor, by written contract, the same data-protection obligations as set out in this DPA (in particular providing sufficient guarantees to implement appropriate technical and organisational measures). Where the subprocessor fails to fulfil its data-protection obligations, we remain fully liable to the controller for the performance of that subprocessor's obligations (Art. 28(4) GDPR).
Note: VAT IDs are validated against VIES, a service of the European Commission. VIES is a public authority service acting as a separate controller, not our subprocessor. Shopify, as your commerce platform, likewise acts under its own agreement with you.
7. Security measures (Art. 32)
- TLS for all transport; personal data encrypted at rest with AES-256-GCM (customer name/address/email snapshots on invoices, invoice PDF and XML artifacts, job payloads, and OAuth/session tokens)
- Per-tenant data isolation enforced at the data layer
- EU-only hosting; dedicated database user; daily backups
- Append-only invoice storage with an audit log (GoBD)
8. Assistance to the controller
Taking into account the nature of the processing, we assist the controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the controller's obligation to respond to requests for exercising the data subject's rights (Art. 28(3)(e) GDPR). We implement Shopify's GDPR webhooks: data-subject requests are surfaced to the controller.
Taking into account the nature of processing and the information available to us, we assist the controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR, that is, security of processing, notification of a personal-data breach, communication of a breach to the data subject, data-protection impact assessment, and prior consultation (Art. 28(3)(f) GDPR).
We notify the controller without undue delay after becoming aware of a personal-data breach affecting the processed data, and we provide the controller with the information reasonably necessary to enable the controller to meet its own notification obligations under Art. 33 and 34 GDPR (Art. 33(2) GDPR).
9. Return and deletion on termination
On termination of the provision of services (uninstallation of the app), the controller may, at its choice, obtain the return or an export of the personal data before deletion. We provide invoice and document exports in standard formats on request. After the return or export, or if the controller does not request return or export, we delete all copies of the personal data, save where storage of the personal data is required by Union or Member State law to which we are subject (Art. 28(3)(g) GDPR).
In practice: on uninstallation, operational data is deleted within 48 hours, while invoice archives are retained for the statutory period (Art. 17(3)(b) GDPR, 10 years), after which they are deleted.
10. Audit and inspection
We make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and this DPA. We further allow for and contribute to audits, including on-site inspections, conducted by the controller or another auditor mandated by the controller (Art. 28(3)(h) GDPR). Audits and inspections are carried out under reasonable prior notice, during normal business hours, no more than once per year save where required by a supervisory authority or following a personal-data breach, and subject to confidentiality so as not to compromise the security of other controllers' data.
11. Governing law and venue
This DPA is governed by German law. For merchants who are entrepreneurs (B2B), the place of jurisdiction is the provider's registered seat in Lisbon, Portugal, to the extent legally permissible. This DPA is a data-protection agreement only; it is software, not tax advice.