Background and scope
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Nephworx Ltd., EIK 207138187, VAT BG207138187, with registered seat at 51 Cherni Vrah Blvd., Hladilnika Industrial Zone, Lozenets District, 1407 Sofia, Bulgaria (“Processor”), and the customer subscribing to the Service (“Controller” or “Customer”).
It applies to the extent the Processor processes personal data on behalf of the Controller in connection with the Service, and is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).
By subscribing to the Service or accepting the Terms, Customer is deemed to have entered into this DPA. A signed counterpart can be requested by emailing contact@smetni.app.
Definitions
Capitalised terms not defined here have the meaning given in the Terms of Service or the GDPR. In particular:
- GDPR: Regulation (EU) 2016/679 of 27 April 2016, as amended.
- Customer Data: personal data uploaded to or generated through the Service that the Processor processes on the Controller’s behalf.
- Data Subject: an identified or identifiable natural person to whom Customer Data relates.
- Sub-processor: any third party engaged by the Processor to process Customer Data, listed on the sub-processors page.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data.
Subject matter and duration
The Processor processes Customer Data solely to provide and support the Service for the duration of the Customer’s Subscription, and for any period afterwards required by applicable law or by the Terms.
The nature, purpose and types of personal data processed are described in Annex A.
Roles of the parties
Customer is the data controller of Customer Data and determines the purposes and means of processing.
Processor processes Customer Data on Customer’s behalf as a data processor under Article 28 GDPR.
Each party complies with its respective obligations under applicable data protection law.
Customer’s instructions
Processor processes Customer Data only on Customer’s documented instructions, including with regard to international transfers, except where Processor is required to process by EU or Member State law (in which case Processor will inform Customer unless prohibited by that law).
The Terms, this DPA and Customer’s configuration of the Service constitute Customer’s complete and final instructions at the time of signing.
Processor will inform Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
Confidentiality of personnel
Processor ensures that personnel authorised to process Customer Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and have received training on their data-protection responsibilities.
Access to Customer Data is granted on a need-to-know basis and reviewed periodically.
Security measures
Processor implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, in line with Article 32 GDPR.
An overview of these measures is set out in Annex B, and updated information is published on the security page.
Sub-processors
Customer grants Processor a general authorisation to engage Sub-processors to provide the Service. The current list of authorised Sub-processors is published on the sub-processors page.
Processor will give Customer at least 30 days’ notice before engaging a new Sub-processor or replacing an existing one. Customer may object on reasonable data-protection grounds; if no acceptable resolution is reached, Customer may terminate the affected portion of the Subscription with a pro-rated refund.
Processor enters into written contracts with each Sub-processor that impose data-protection obligations no less protective than those in this DPA.
Processor remains liable to Customer for the performance of any Sub-processor’s obligations.
Assistance with data subject requests
Taking into account the nature of the processing, Processor assists Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer’s obligation to respond to requests from Data Subjects to exercise their rights under Chapter III GDPR.
If Processor receives a request directly from a Data Subject in respect of Customer Data, it will not respond except on Customer’s instructions or as legally required, and will promptly forward the request to Customer.
Personal Data Breach notification
Processor will notify Customer without undue delay, and in any case no later than 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data, so that Customer can meet its own notification obligations under Articles 33-34 GDPR.
The notification will, to the extent then known, include:
- a description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- the name and contact details of the Processor’s contact point for further information;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and mitigate its possible adverse effects.
DPIA and prior-consultation assistance
Processor provides reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Articles 35-36 GDPR, taking into account the nature of the processing and information available to Processor.
International transfers
To the extent that processing involves a transfer of Customer Data outside the European Economic Area, Processor ensures that an appropriate transfer mechanism under Chapter V GDPR is in place, including the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses with supplementary technical and organisational measures where required.
Where the EU SCCs apply, the parties are deemed to have entered into Module Two (Controller to Processor) of the SCCs published on 4 June 2021 and that module is incorporated into this DPA by reference.
Audits
Processor makes available to Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR.
Customer may, no more than once per calendar year (and additionally following a confirmed Personal Data Breach), conduct an audit by reviewing relevant policies, certifications and reports made available by Processor. On-site audits will be agreed in writing in advance, conducted at Customer’s expense and subject to reasonable security and confidentiality measures.
Processor may demonstrate compliance through independent third-party certifications or audit reports (e.g. ISO 27001, SOC 2) where available.
Return or deletion of Customer Data
On termination or expiry of the Subscription, Processor will, at Customer’s choice, return or delete Customer Data within 30 days, except to the extent applicable law requires retention. On Customer’s request, Processor provides written confirmation of the deletion.
Backups will be deleted in the ordinary course in accordance with Processor’s retention schedule. Customer Data retained for legal reasons remains subject to the security obligations of this DPA.
Liability
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
Governing law
This DPA is governed by the laws of the Republic of Bulgaria. Any dispute is subject to the exclusive jurisdiction of the competent courts of Sofia, Bulgaria, save for mandatory jurisdiction rules of EU data protection law.
Annex A: Details of processing
Subject matter
Provision of the smetni.app cloud invoicing platform to Customer.
Duration
For the term of the Subscription and for as long after termination as required to comply with applicable law or this DPA.
Nature of the processing
Storage, hosting, transmission, structuring, retrieval, display, adaptation, erasure and other operations necessary to deliver the Service.
Purpose
To enable Customer to create, send and manage invoices and related accounting documents, manage clients and produce reports for tax-compliance purposes.
Categories of data subjects
Customer Data may relate to the following categories of data subjects:
- Customer’s representatives, employees, contractors and other Users of the Service;
- Customer’s clients (recipients of invoices) and their contact persons;
- any other natural persons whose data Customer chooses to enter into the Service.
Categories of personal data
Customer Data typically includes:
- identity and contact data: name, email, phone, address;
- business identification data: EIK, VAT number, company name and address;
- financial data: invoice line items, amounts, payment status, bank details where Customer provides them;
- any free-form text or attachments Customer adds to invoices, notes or other records.
Customer is responsible for ensuring it does not enter “special categories” of personal data (Article 9 GDPR) unless strictly necessary, in which case it acknowledges that the Service is not specifically designed for such data.
Annex B: Security measures
Processor maintains the following technical and organisational measures:
- Encryption: TLS 1.2+ in transit, AES-256 at rest for the production database and backups.
- Access control: role-based access, least-privilege principle, periodic review of administrative access.
- Authentication: centralised identity via WorkOS, support for SSO, mandatory multi-factor authentication for administrators.
- Network security: production runs in a private VPC; ingress is restricted; CDN/WAF in front of public endpoints.
- Backups and recovery: automated daily backups with point-in-time recovery; documented restore procedure tested periodically.
- Logging and monitoring: application and infrastructure logs centralised; alerting on security-relevant events; observability via Grafana Cloud.
- Secure development: code review, automated testing, dependency scanning and infrastructure-as-code with versioned deploys.
- Incident response: documented incident-response process with defined roles, communication paths and breach-notification timelines.
- Vendor management: sub-processors are screened, contractually bound to equivalent obligations and listed publicly on the sub-processors page.
Up-to-date details are also published on the security page.