Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller", "Customer") and Tobias Satzger, operating as Beliq ("Processor", "we", "us"). This DPA applies when we process personal data on your behalf in the course of providing the Beliq service ("Service").
This DPA is established in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Definitions
Unless otherwise defined, terms used in this DPA have the same meaning as in the GDPR and the Terms of Service.
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by us on your behalf through the Service.
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, adaptation, retrieval, use, disclosure, or erasure.
- "Sub-Processor" means any third party engaged by us to assist in processing Personal Data on behalf of the Controller.
2. Scope and Applicability
This DPA applies when you, as the Controller, submit content containing Personal Data to the Service for invoice processing (for example, JSON, XML, or PDF containing customer names, addresses, VAT identifiers, or other personal information in invoices). You determine the purposes and means of processing; we process the data solely on your instructions and for the purpose of providing the Service.
This DPA does not apply to data we process as an independent controller (for example, your account data and billing information), which is covered by our Privacy Policy.
3. Subject Matter and Duration
3.1 Subject Matter
The subject matter of this DPA is the processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of e-invoice generation, validation, parsing, and conversion services via the Beliq API.
3.2 Duration
This DPA remains in effect for the duration of the Controller's use of the Service. Upon termination, the provisions of this DPA continue to apply to any Personal Data still in the Processor's possession until it is deleted.
4. Nature and Purpose of Processing
The Processor processes Personal Data for the following purposes:
- Generating e-invoices from structured JSON data submitted by the Controller (including party names, addresses, and financial details)
- Validating e-invoice XML or PDF documents against EN 16931 and CIUS rules
- Parsing e-invoice documents into normalized JSON for the Controller
- Converting e-invoices between supported formats for the Controller
- Delivering processing results to the Controller via API response or webhook
5. Types of Personal Data
The types of Personal Data processed depend on the content the Controller submits. This may include but is not limited to:
- Names and contact details (addresses, email, phone numbers)
- Business and financial data (invoice amounts, account numbers, IBAN, VAT identifiers)
- Any other Personal Data contained in the invoice data submitted by the Controller
6. Categories of Data Subjects
Data Subjects may include the Controller's customers, employees, suppliers, partners, or any other individuals whose Personal Data is contained in the invoice content submitted for processing.
7. Processor Obligations
In accordance with Art. 28(3) GDPR, the Processor shall:
- Documented instructions: Process Personal Data only on documented instructions from the Controller. The Controller's instructions are defined by the API request parameters.
- Confidentiality: Ensure that persons authorized to process Personal Data have committed themselves to confidentiality.
- Security measures: Implement appropriate technical and organizational measures as described in Section 10.
- Sub-processors: Not engage another processor without prior general written authorization from the Controller, as described in Section 8.
- Data Subject rights: Assist the Controller in responding to Data Subject requests.
- Security and breach assistance: Assist the Controller, taking into account the nature of processing and the information available, with its obligations under Art. 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation).
- Deletion: At the Controller's choice, delete or return all Personal Data after the end of the provision of services.
- Audits: Make available all information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits.
8. Sub-Processors
8.1 General Authorization
The Controller grants general written authorization for the Processor to engage Sub-Processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors, giving the Controller the opportunity to object within 14 days. If the Controller objects on reasonable data-protection grounds, the Controller may terminate the affected part of the Service. The Processor imposes on each Sub-Processor, by contract, data-protection obligations equivalent to those in this DPA (Art. 28(4) GDPR).
8.2 Current Sub-Processors
The following Sub-Processor may process Personal Data submitted via the API (invoice content). Invoice content is processed in memory and is not persistently stored:
| Sub-Processor | Purpose | Location | Data Processed |
|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure (servers, Kubernetes, database) | Germany (EU) | Invoice content transiting our infrastructure (in memory only, not stored) |
The following services process the Controller's account, support, or operational data but do not process invoice content (the Personal Data submitted via the API):
| Service | Purpose | Location |
|---|---|---|
| Scaleway SAS | Transactional email, static-site object storage, and encrypted off-site backup copy | France (EU) |
| OVH SAS | Hosting for our self-managed logs and metrics monitoring (operational metadata only). Error tracking is self-hosted on Hetzner (EU). | France (EU) |
| BunnyWay d.o.o. | Content delivery network for static sites (website request metadata only; invoice data does not transit the CDN) | Slovenia (EU) |
| Mistral AI SAS | AI assistant in our self-hosted support chat (drafts replies from support messages; no invoice content) | France (EU) |
| Armitage Labs OÜ (Creem) | Subscription checkout, customer billing portal, payment processing, and subscription webhooks (account and billing data only) | Estonia (EU) |
9. International Transfers
All processing of invoice content occurs within the European Union. The Processor does not transfer Personal Data submitted via the API to countries outside the EU/EEA.
10. Technical and Organizational Measures
The Processor implements the following technical and organizational measures (TOMs) in accordance with Art. 32 GDPR:
10.1 Encryption
- All data in transit is encrypted using TLS 1.3 / HTTPS
- Sensitive fields at rest (email addresses, secrets, invoice templates) are encrypted using AES-256-GCM
- Database backups are stored in encrypted object storage, held on-site (EU) and off-site (France)
10.2 Access Controls
- Row-level security in the database, isolating each organization's data
- Least-privilege database roles; the application role does not own the schema
- Network policies in Kubernetes for strict service isolation
- Signed, short-lived session tokens with immediate revocation on password change or account lock
10.3 Data Minimization
- Invoice content is processed in memory and not persistently stored
- Personal data submitted via the API is not included in job metadata or logs
- Temporary files used during document processing are deleted after each request
10.4 Availability and Resilience
- Kubernetes-based infrastructure across two data centers with auto-scaling
- Regular automated database backups, on-site and off-site (both in the EU)
- Rate limiting and abuse protection to preserve availability
10.5 Monitoring
- Self-managed error tracking (self-hosted in the EU), plus logging and metrics (self-hosted in France); this telemetry excludes invoice content and secrets. Client-side error reports from the interactive tools on our public website also exclude the content entered into the invoice form.
11. Data Breach Notification
The Processor shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Personal Data processed on behalf of the Controller. The notification shall include a description of the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences, and the measures taken to address the breach.
12. Return and Deletion of Data
Invoice content is processed in memory and not persistently stored. After each API request, the content is discarded. The job metadata we retain (described in our Privacy Policy) contains no invoice content and none of the personal data submitted via the API.
Upon termination of the Service agreement, the Processor shall delete all Personal Data processed on behalf of the Controller (to the extent it is still in the Processor's possession), unless EU or member state law requires storage.
13. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR. Audits shall be conducted with reasonable prior notice (at least 30 days), limited to once per year, conducted during normal business hours, and at the Controller's expense.
14. Governing Law
This DPA is governed by the laws of the Federal Republic of Germany. The provisions of the GDPR apply directly.
15. Contact
For questions about this Data Processing Agreement or to exercise audit rights, please contact us at:
Email: hello@beliq.eu