Data processing agreement

The terms on which we process your customers’ personal data on your behalf, under article 28 of the GDPR.

In force from

This Agreement forms part of the Terms of Service and applies automatically, without separate signature, from the moment you enter data about your customers into FiskalMe.

The controller is the Customer — your sole trade or company. The processor is PERFECT LIGHT, obrt, vl. Filip Curkić, Zagreb, Croatia, OIB 40797811615.

This Agreement governs only the data you enter about your customers. For your own data as a user we are the controller, and that is described in the Privacy Policy.

1. Subject matter, duration, nature and purpose

Subject matter: processing of personal data contained in the invoices, quotes, books and other documents the Customer creates in FiskalMe.

Duration: the term of the service agreement, extended by the retention periods in clause 8.

Nature and purpose: storing, formatting and displaying documents; computing tax and accounting values; signing and submitting fiscal messages to the tax authority on the Customer’s behalf; sending documents to recipients the Customer designates.

Types of data: name or business name, tax number, address, e-mail and telephone, invoice and line-item data, amounts and payment records.

Categories of data subjects: the Customer’s own customers and their contact persons and, where applicable, the operators the Customer names on an invoice.

Special categories of data under art. 9 are not contemplated and the Customer must not enter them into the application.

2. Processing only on documented instructions (art. 28(3)(a))

We process the data only on the Customer’s documented instructions. Use of the application — entering data, issuing, sending, exporting, deleting — is itself such an instruction.

We do not transfer data to a third country or international organisation unless required to by EU or Member State law; in that case we inform the Customer before processing, unless that notice is prohibited.

If we consider an instruction to infringe the GDPR or other data protection law, we will tell the Customer without delay.

3. Confidentiality (art. 28(3)(b))

Only people who need it to perform the agreement have access. All of them are bound to confidentiality, by contract or statute, and that duty survives the end of their engagement.

4. Security of processing (art. 28(3)(c) and art. 32)

We implement technical and organisational measures appropriate to the risk, including:

  • encryption in transit (HTTPS) and at rest with the infrastructure provider,
  • access control enforced by the database rather than by the interface alone — every business sees only its own data,
  • separation of roles inside the Customer’s organisation (owner, admin, operator, viewer),
  • certificates and passphrases held in a dedicated secret store, separate from application data,
  • actions on fiscal documents written to an append-only audit record,
  • regular backups with restore testing,
  • automated testing of the security rules on every change to the code.

5. Sub-processors (art. 28(2) and 28(4))

The Customer gives general written authorisation for engaging sub-processors. The list of those we use is published in the Privacy Policy, clause 4.

We will give the Customer at least 30 days’ notice, by e-mail or in the application, before adding or replacing a sub-processor. The Customer may object within that period. If we cannot reasonably address the objection, the Customer may terminate the service agreement without notice and without charge.

We impose data protection obligations equivalent to these on every sub-processor, and we remain liable for their performance as for our own.

6. Assistance with data subject rights (art. 28(3)(e))

The application is built so the Customer can satisfy most requests unaided: a customer record can be viewed, corrected, exported and deleted without our involvement.

If we receive a data subject request directly, we will not answer it ourselves — we will pass it to the Customer without delay, because the Customer is the controller.

Where a request exceeds what the interface can do, we will assist by appropriate technical measures.

7. Assistance with security and breaches (art. 28(3)(f) and art. 33)

We will notify the Customer of a personal data breach without undue delay after becoming aware of it, and before the deadline by which the Customer must notify the supervisory authority — in practice within 24 hours of becoming aware.

The notice will describe the nature of the breach, the approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose.

Notification to the supervisory authority and to data subjects is made by the Customer as controller; we provide all the information we hold for that purpose.

We will also assist with a data protection impact assessment and prior consultation with the supervisory authority, should the Customer need them.

8. Deletion or return of data (art. 28(3)(g))

On the end of the service agreement the Customer chooses whether to export the data or to have it deleted. Data remains available for export for 60 days, after which we delete it.

The exception is records we are ourselves required by law to keep — chiefly the fiscal archive of messages sent and received, and our accounting records. We retain those until the statutory period expires, process them for no other purpose, and delete them when it does.

9. Demonstrating compliance and audits (art. 28(3)(h))

On request we make available to the Customer the information necessary to demonstrate compliance with this Agreement.

The Customer may audit, including by inspection, once a year, on 30 days’ notice and during business hours, in a way that does not disrupt the service or endanger other customers’ data. More frequent audits are permitted after a personal data breach or where a supervisory authority requires one.

The Customer bears the cost of an audit, unless it establishes material non-compliance on our part.

10. Relationship to the Terms of Service

Where this Agreement and the Terms of Service conflict, this Agreement prevails on matters of personal data protection.

Everything else is governed by the Terms of Service, including governing law and jurisdiction.