Background and scope
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Nephworx Ltd (Нефуъркс ЕООД), UIC 207138187, VAT BG207138187, with registered seat at 51 Cherni Vrah Blvd, Hladilnika Industrial Zone, Lozenets, Sofia 1407, Bulgaria (“Processor”), and the customer subscribing to the Service (“Controller” or “Customer”).
It applies to the extent the Processor processes personal data on behalf of the Controller in connection with the Service, and is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).
By creating an account or accepting the Terms, Customer enters into this DPA. A countersigned counterpart for enterprise customers can be requested by emailing info@smetni.app.
Definitions
Capitalised terms not defined here have the meaning given in the Terms of Service or the GDPR. In particular:
- GDPR: Regulation (EU) 2016/679 of 27 April 2016, as amended.
- Customer Data: personal data uploaded to or generated through the Service that the Processor processes on the Controller's behalf.
- Data Subject: an identified or identifiable natural person to whom Customer Data relates.
- Sub-processor: any third party engaged by the Processor to process Customer Data, listed in Annex C of this DPA.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data.
Subject matter and duration
The Processor processes Customer Data solely to provide and support the Service for the duration of the Customer's Subscription and account, and for any period afterwards required by applicable law or by the Terms.
The nature, purpose and types of personal data processed are described in Annex A.
Roles of the parties
Customer is the data controller of Customer Data and determines the purposes and means of processing.
Processor processes Customer Data on Customer's behalf as a data processor under Article 28 GDPR.
Each party complies with its respective obligations under applicable data protection law.
Customer's instructions
Processor processes Customer Data only on Customer's documented instructions, including with regard to international transfers, except where Processor is required to process by EU or Member State law (in which case Processor will inform Customer unless prohibited by that law).
The Terms, this DPA and Customer's configuration and use of the Service constitute Customer's complete and final documented instructions. This includes, in particular, the recipient addresses Customer enters when dispatching documents, the rules and schedules Customer configures for automated issuance, and Customer's choice to use AI-assisted features.
Additional or altered instructions require Processor's prior written agreement. Processor will inform Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
Confidentiality of personnel
Processor ensures that personnel authorised to process Customer Data are bound by appropriate confidentiality obligations (whether contractual or statutory).
Access to Customer Data is granted on a need-to-know basis and reviewed periodically.
Security measures
Processor implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, in line with Article 32 GDPR.
An overview of these measures is set out in Annex B. Processor may update the measures from time to time, provided the overall level of protection is not reduced.
Customer is responsible for the security of the systems and credentials it uses to access the Service, for assigning and revoking User access, and for any technical and organisational measures on its side, including the decision whether to enable optional security features.
Sub-processors
Customer grants Processor a general written authorisation to engage Sub-processors to provide the Service. The current list of authorised Sub-processors is set out in Annex C.
Processor gives notice of a new Sub-processor, or the replacement of an existing one, by updating Annex C and the effective date of this DPA before the new Sub-processor starts processing Customer Data. Customer may object on reasonable data-protection grounds before the new Sub-processor starts processing Customer Data; if no acceptable resolution is reached, Customer may terminate the affected portion of the Subscription with a pro-rated refund of prepaid Fees.
Processor enters into written contracts with each Sub-processor that impose data-protection obligations no less protective than those in this DPA.
Processor remains liable to Customer for the performance of any Sub-processor's obligations.
If no acceptable resolution is reached, Processor may alternatively choose not to appoint the Sub-processor or to terminate the affected portion of the Subscription on written notice.
Assistance with data subject requests
Taking into account the nature of the processing, Processor assists Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR. The Service's export, editing and deletion functions are the primary means of such assistance; Customer handles such requests itself where it can do so through the Service.
Processor does not respond to Data Subjects directly on Customer's behalf and refers them to Customer. For assistance beyond the Service's standard functionality, Processor may charge a reasonable fee to the extent permitted by law.
Personal Data Breach notification
Processor notifies Customer of a Personal Data Breach affecting Customer Data in accordance with Article 33(2) GDPR, so that Customer can meet its own obligations under Articles 33-34 GDPR. Information may be provided in phases as it becomes available.
Notification is not an acknowledgement of fault or liability by Processor. Customer is responsible for its own notifications to supervisory authorities and Data Subjects.
DPIA and prior-consultation assistance
Processor provides reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Articles 35-36 GDPR, taking into account the nature of the processing and the information available to Processor. Processor may charge a reasonable fee for such assistance to the extent permitted by law.
International transfers
To the extent that processing involves a transfer of Customer Data outside the European Economic Area, Processor ensures that an appropriate transfer mechanism under Chapter V GDPR is in place, including the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses with supplementary technical and organisational measures where required.
Where the EU SCCs apply, the parties are deemed to have entered into Module Two (Controller to Processor) of the SCCs published on 4 June 2021, and that module is incorporated into this DPA by reference. The transfer mechanism for each Sub-processor is listed in Annex C.
Audits
Processor makes available to Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer, as required by Article 28(3)(h) GDPR. Processor meets this obligation primarily by providing documentation (this DPA, Annex B and any available third-party certifications or reports).
Any further audit requires reasonable prior written notice, takes place no more than once per year, at Customer's expense and during business hours, is limited to what is necessary to verify compliance with this DPA, must not endanger the security or confidentiality of other customers' data, and is subject to reasonable security and confidentiality conditions. Processor may charge a reasonable fee for time spent on audits beyond providing documentation, to the extent permitted by law.
Return or deletion of Customer Data
After the Subscription ends, the account remains in read-only mode and Customer can view and export Customer Data for as long as the account exists and the Service is operated, as described in the Terms.
On Customer's written request, Processor deletes Customer Data, except to the extent applicable law requires retention (for example accounting records). On request, Processor provides written confirmation of the deletion.
Backups are deleted in the ordinary course in accordance with Processor's retention schedule. Customer Data retained for legal reasons remains subject to the security obligations of this DPA.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
Governing law
This DPA is governed by the laws of the Republic of Bulgaria. Any dispute is subject to the exclusive jurisdiction of the competent courts of Sofia, Bulgaria, save for mandatory jurisdiction rules of EU data protection law.
Annex A: Details of processing
Subject matter
Provision of the smetni.app cloud invoicing platform to Customer.
Duration
For the term of the Subscription and account, and for as long after termination as required to comply with applicable law or this DPA.
Nature of the processing
Storage, hosting, transmission, structuring, retrieval, display, adaptation, erasure and other operations necessary to deliver the Service, including dispatch of documents by email to recipients designated by Customer and, where Customer uses AI-assisted features, automated extraction of structured data from uploaded documents.
Purpose
To enable Customer to create, send and manage invoices and related accounting documents, manage clients and produce reports for tax-compliance purposes.
Categories of data subjects
Customer Data may relate to the following categories of data subjects:
- Customer's representatives, employees, contractors and other Users of the Service;
- Customer's clients (recipients of invoices) and their contact persons;
- any other natural persons whose data Customer chooses to enter into the Service.
Categories of personal data
Customer Data typically includes:
- identity and contact data: name, email, phone, address;
- business identification data: EIK, VAT number, company name and address;
- financial data: invoice line items, amounts, payment status, bank details where Customer provides them;
- any free-form text or attachments Customer adds to invoices, expenses, notes or other records.
Customer is responsible for ensuring it does not enter “special categories” of personal data (Article 9 GDPR) unless strictly necessary, in which case it acknowledges that the Service is not specifically designed for such data.
Annex B: Security measures
Processor maintains the following technical and organisational measures:
- Encryption: TLS 1.2+ in transit, AES-256 at rest for the production database and backups.
- Access control: role-based access, least-privilege principle, periodic review of administrative access.
- Authentication: centralised identity via WorkOS, support for SSO and multi-factor authentication.
- Network security: production runs in a private network; ingress is restricted; a CDN with edge protections sits in front of public endpoints.
- Backups and recovery: automated daily backups with point-in-time recovery.
- Logging and monitoring: application and infrastructure logs centralised; alerting on security-relevant events.
- Secure development: code review, automated testing, dependency scanning and infrastructure-as-code with versioned deploys.
Annex C: Authorised Sub-processors
The following Sub-processors process Customer Data on Processor's behalf:
| Provider | Purpose | Processing location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, database and backups | EU (Frankfurt, eu-central-1) | EU: no Article 44 transfer |
| Plus Five Five, Inc. (Resend) | Transactional email dispatch (documents and notifications sent from the Service) | United States | EU-U.S. Data Privacy Framework; SCCs |
| Google LLC (Gemini API) | AI extraction of structured data from uploaded documents, only when Customer uses AI-assisted features | United States | EU-U.S. Data Privacy Framework |
| WorkOS, Inc. | Authentication and identity of Users (sign-in, SSO) | United States | EU-U.S. Data Privacy Framework |
Providers that process personal data for Processor's own purposes as an independent controller or processor of Processor (for example payment processing for Subscription Fees, or consent-based analytics and telemetry) are not Sub-processors of Customer Data and are disclosed in the Privacy Policy.
Changes to this list are announced by updating this Annex and the effective date of this DPA in advance, as described in the Sub-processors section.