Data Processing Agreement
Art. 28 GDPR (Auftragsverarbeitungsvertrag) between you as controller and the operator as processor.
1. Parties and roles
This agreement applies wherever the operator processes personal data on your behalf.
Controller: you, the account holder (the business using the Service).
Processor: (aPunkt) Peter & Boluwatife · o.emmanuel@apunkt.ai · t.peter@apunkt.ai.
2. Subject-matter, nature, purpose and duration
The processor stores and processes your customer and invoice data to provide the invoicing Service you have signed up for. Processing lasts for the duration of your account and, for issued invoices, for the statutory retention period that follows it (see clause 8). The processor processes the data only to provide the Service — never for its own purposes.
3. Categories of data subjects and personal data
Data subjects: your customers and their contacts.
Personal data: customer name, postal address, email address and VAT identification number; invoice content (line items, amounts, dates); and the copy of the customer’s name, address and VAT ID frozen onto each issued invoice.
4. Controller instructions
The processor processes personal data only on your documented instructions. Your use of the Service’s features constitutes those instructions; any other instruction must be given in text form. The processor informs you if, in its view, an instruction infringes data-protection law — though it is not obliged to give legal advice.
5. Confidentiality
The processor ensures that persons authorised to process the personal data are bound to confidentiality and are processing it only under this agreement.
6. Security of processing (Art. 32) — Annex 2
The processor implements appropriate technical and organisational measures. As the Service is built, these are:
- Passwords are stored only as a memory-hard scrypt hash — never in a recoverable form. Email verification and password-reset links are stored hashed, expire, and can be used once.
- Tenant isolation: every record carries an organisation identifier, every query is scoped to it, and that identifier is taken from the authenticated session — never from user input — so one tenant cannot read another’s data.
- Only strictly necessary cookies (a session cookie and a CSRF cookie). No analytics, tracking, advertising identifiers or profiling.
- No third-party requests from the visitor’s browser: fonts are self-hosted at build time, and there are no external scripts, maps or embeds.
- Data is held in a SQLite database on the operator’s own infrastructure. Backups, encryption at rest and access control at the hosting layer are the operator’s responsibility and depend on the deployment (see Annex 1).
7. Sub-processors — Annex 3
You give general authorisation for the processor to engage sub-processors. The processor informs you of any intended change and gives you the opportunity to object. The current sub-processors are:
- Hosting provider — whoever hosts the deployment. To be named by the operator, with its own Art. 28 agreement in place.
- Resend (email delivery) — only when email is configured. Handles account verification and password-reset messages and, when you email an invoice, the invoice PDF — so emailing an invoice transmits that invoice’s content (both parties’ names and addresses) to Resend and to the recipient you name. Resend is a US company; the operator must select its EU data region and record the Chapter V transfer basis (EU–US Data Privacy Framework certification or Standard Contractual Clauses). Where email is not configured, no message data leaves the operator’s server.
8. Assistance, deletion and return of data
The processor assists you, so far as the Service’s features allow, in responding to data-subject requests (Art. 12–23) and in meeting your Art. 32–36 obligations. It forwards to you any data-subject request it receives directly.
On termination, personal data is deleted or returned at your choice — except where Union or Member-State law requires continued storage. Issued invoices and the details frozen onto them are retained for ten years from the end of their year of issue (§ 147 AO, § 14b UStG) and cannot be deleted before then; this is the split the account-closure procedure performs. Retained records can be produced for you as a machine-readable export for a tax audit.
9. Breach notification and audits
The processor notifies you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own Art. 33/34 duties. On request, the processor makes available the information needed to demonstrate compliance with Art. 28 and allows for and contributes to audits.

