Data Processing Agreement (DPA) - English
# Data Processing Agreement under Article 28 GDPR
**Version 2026-07-30 · Effective text dated 30 July 2026**
between the **customer identified in the acceptance record** (“Controller”) and **Tom Trögler, trading as RechneX**, Schutterstr. 36/5, 77743 Neuried, Germany, privacy contact: datenschutz@rechnex.de (“Processor”).
The German version is legally authoritative. This English translation is provided for information.
## 1. Formation, scope and precedence
1. This DPA is concluded electronically for the standard RechneX service by a separate, unticked declaration in the user account. RechneX records the contracting party, account, email address, DPA version, document hash, exact declaration, time, language and completion channel. No handwritten signature is required.
2. This DPA applies only where RechneX processes personal data on the Controller’s behalf. Account and contract administration, billing and payments, abuse and security prevention, general support and sales are RechneX’s own-controller activities and are covered by the privacy notice.
3. Individual Enterprise or API services are covered only if expressly agreed in the applicable offer or individual DPA. An individual Enterprise DPA prevails for enabled Enterprise processing.
4. In case of conflict, mandatory data protection law prevails, followed by this DPA and its annexes, and then the main agreement and Terms. Liability terms in the Terms apply additionally where permitted by mandatory law and Section 12.
## 2. Subject matter and duration
The processing covers the technical provision of the selected standard functions for conversion, generation, viewing and validation of electronic invoices and the temporary processing required for them. It lasts for the main agreement or until completion of the individual operation, subject to statutory record-retention duties.
## 3. Nature and purpose
Processing is limited to receiving PDF, XML or embedded invoice files; OCR and AI-assisted field extraction; temporary display and editing; generating XRechnung or ZUGFeRD; technical validation using KoSIT and Mustang rules; providing output files and reports; and necessary job, security and usage metadata without planned storage of invoice content.
Customer Data is not used for advertising or for training RechneX’s or a third party’s general-purpose AI models.
## 4. Data and data subjects
Data may include invoice, supply and service information; names, addresses and business contact details; customer, supplier, order, contract and invoice identifiers; tax, payment and bank details; text and attachments submitted by the Controller; and technical job, format, validation, security and usage metadata.
Data subjects may include the Controller’s customers, suppliers and business partners; their staff, contacts and agents; and other persons whose data appears in an invoice or attachment.
The standard service is not intended for special categories of personal data under Article 9 GDPR or criminal conviction and offence data under Article 10 GDPR. The Controller must not submit such data to the standard service. Any such processing requires a prior express written Enterprise agreement and defined additional safeguards.
## 5. Instructions and Controller obligations
1. RechneX processes personal data only on documented instructions. The main agreement, this DPA, the selected function and documented settings form the initial instructions.
2. Additional instructions must be in text form, lawful, reasonable and within scope. Out-of-scope effort may be charged after prior coordination.
3. If RechneX considers an instruction unlawful, it will notify the Controller without undue delay and may suspend it pending clarification.
4. The Controller is responsible for lawfulness, notices to data subjects, accuracy, data-subject rights and lawful instructions.
5. The Controller submits only necessary data, verifies AI-extracted and generated results before use, and downloads outputs it needs within the availability period.
## 6. Processor obligations
RechneX will process data only on documented instructions unless legally required otherwise; ensure authorised persons are bound by confidentiality; maintain appropriate Article 32 measures; reasonably assist with data-subject requests, DPIAs, prior consultations and Articles 32–36 obligations; forward relevant data-subject requests; notify the Controller without undue delay after becoming aware of a personal data breach affecting entrusted data; and provide compliance information under Section 11.
## 7. Security
The measures in Annex 2 apply at conclusion. RechneX may update them with technical progress provided the agreed protection level is not reduced. Measures are reviewed and adjusted on a risk basis.
## 8. Sub-processors
1. The Controller grants general authorisation for the sub-processors in Annex 1 and others required for the service.
2. RechneX will normally notify intended additions or replacements by email or in the account at least 14 days in advance. Urgent security or continuity changes may occur sooner, with notice without undue delay.
3. The Controller may object within the notice period on objectively substantiated data-protection grounds. The parties will seek a reasonable solution. If none is available, RechneX may discontinue, or either party may terminate, the affected service part.
4. RechneX imposes materially equivalent data-protection duties on sub-processors and remains responsible to the Controller for their performance.
## 9. International transfers
For processing outside the EEA, RechneX ensures a lawful Chapter V mechanism, such as an adequacy decision, valid EU-US Data Privacy Framework certification or EU Standard Contractual Clauses with necessary supplementary measures. Primary content processing in Oracle Cloud Infrastructure and Supabase is directed to the documented Frankfurt regions; provider edge, support or security processing may occur elsewhere.
## 10. Return and deletion
1. Original PDFs are not planned for persistent storage by RechneX. AI processing uses stateless Mistral endpoints enabled for Zero Data Retention. Validator and viewer uploads are discarded after the request.
2. Access to outputs and reports in download storage ends no later than 24 hours after creation. Technical cleanup then runs in short regular intervals.
3. Voluntarily saved account or template data remains until changed, deleted or the account ends, subject to legal duties and legitimate evidence needs.
4. At the end of processing, RechneX deletes or returns entrusted data at the Controller’s choice unless retention is legally required. Backups are overwritten through the scheduled technical rotation. If restored, intervening deletions are reapplied.
5. The Controller can download outputs during availability. Special return, restoration or migration outside the standard function may be charged.
## 11. Evidence and audits
RechneX provides information required by Article 28. Reviews are remote-first using documentation, suitable reports, questionnaires and video calls. On-site audits are available where remote evidence is insufficient, normally once per calendar year, with 14 days’ notice, during business hours and by qualified independent non-competitors. Incident-driven or authority-mandated audits remain unaffected. Audits must protect operations, other customers, secrets and security. The Controller bears its audit costs and reasonable additional RechneX effort unless the audit confirms a material breach attributable to RechneX or is ordered due to a circumstance attributable to RechneX.
## 12. Liability and claims
Mandatory data-subject rights and Article 82 liability remain unaffected. Between the parties, losses and costs are allocated according to each party’s responsibility and causation, subject to Article 82(5). The parties notify each other promptly of claims, cooperate reasonably, avoid settlements burdening the other party without prior coordination, and mitigate loss. Otherwise, the main agreement’s liability limits apply where lawful. No strict or responsibility-independent indemnity is created.
## 13. Final terms
Non-public processing information is confidential. Changes require text form. RechneX does not overwrite concluded versions; a new version requires renewed express acceptance unless a change is purely editorial, legally mandatory without adverse effect, or exclusively beneficial to the Controller. Invalid provisions do not affect the remainder. German law applies where lawful. The German text controls.
# Annex 1 – Approved sub-processors
| Sub-processor | Location | Service | Processing / safeguards |
|---|---|---|---|
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | global edge locations | delivery, routing, DDoS protection, WAF | content and technical metadata as required; DPA, EU SCCs and Chapter V safeguards |
| Mistral AI SAS, 15 rue des Halles, 75001 Paris, France | European Union | OCR and AI extraction | Scale Plan API, Zero Data Retention enabled, stateless endpoints, no API-content model training; Mistral DPA |
| ORACLE Deutschland B.V. & Co. KG, Riesstraße 25, 80992 Munich, Germany | Oracle Cloud eu-frankfurt-1 | KoSIT and Mustang validator services | temporary XML/PDF and technical metadata processing; Oracle data-protection terms and EU region |
| Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 | primary Frankfurt project region (eu-central-1); support/sub-processor locations may vary | authentication, database, storage and job functions | DPA, documented project region and Chapter V safeguards |
Payment services, optional external login, general support and transactional contract email are used by RechneX for its own contract and business purposes and are therefore not listed as sub-processors of this narrow processing instruction.
# Annex 2 – Technical and organisational measures
- TLS encryption in transit; least-privilege role-based access; server-side secret management; logical tenant separation, row-level database policies and separate storage paths; confidentiality obligations.
- Input, size and format controls; controlled deployment and version control; authentication and authorisation checks; immutable versioned acceptance evidence with SHA-256 document hash.
- Edge protection, rate limits, DDoS protection and WAF; managed infrastructure monitoring; provider backup and recovery procedures within the subscribed service; documented incident response.
- Purpose-separated data flows; no planned persistent original-PDF storage; Zero Data Retention on the stateless Mistral endpoints; Oracle validators and primary Supabase project in Frankfurt; time-limited downloads and regular cleanup; no planned invoice content in ordinary application logs.
- Periodic review of relevant permissions, dependencies and safeguards, with risk-based corrective action.