Data Processing Agreement (DPA)

under Art. 28 of Regulation (EU) 2016/679 (GDPR) and § 34 of Act No. 18/2018 Coll.

Version: 1.0 · Effective date: 21 June 2026

This agreement forms an integral part of the Terms of Service for the Faktio Service and is concluded between:

  • Controller: the Customer (the Faktio service customer) who enters personal data into the Service or transfers it via connectors. Where the Customer processes data on behalf of its own clients, it acts as a processor and the Provider as a sub-processor; the provisions apply accordingly.
  • Processor: VisionEdge s. r. o., 29. augusta 1503/1A, 958 01 Partizánske, Company ID (IČO): 51962161, registered in the Commercial Register of the District Court Trenčín, Section Sro, Insert No. 37109/R.

1. Subject matter and duration

1.1 The Processor processes personal data on behalf of the Controller solely for the purpose of providing the Faktio service under the Terms — in particular for converting, validating, sending and receiving invoices over the Peppol network, storing them and — once available — reporting data to IS EFA.

1.2 Processing lasts for the duration of the agreement on provision of the Service. After its termination, Art. 7 applies.

2. Nature and purpose of processing

2.1 Nature: collection, storage, structuring, conversion, validation, display, transfer (including delivery over the Peppol network via an Access Point), backup and deletion of personal data, carried out by automated means within the Service.

2.2 Purpose: providing electronic invoicing functionality for the Controller.

2.3 Categories of data subjects and data: see Annex 1.

3. Controller's instructions

3.1 The Processor processes personal data only on the basis of the Controller's documented instructions; the use of the Service and these Terms/DPA are also deemed instructions.

3.2 If the Processor is required to process data under EU or Slovak law, it informs the Controller, unless the law prohibits this.

3.3 If the Processor considers that an instruction infringes data protection regulations, it notifies the Controller without delay.

4. Processor's obligations

4.1 Confidentiality: persons authorised to process the data are bound by confidentiality.

4.2 Security (Art. 32 GDPR): the Processor implements the measures under Annex 3.

4.3 Assistance to the Controller: the Processor assists, to a reasonable extent, in responding to data subject requests (Art. 12 to 23 GDPR) and in fulfilling obligations under Art. 32 to 36 GDPR.

4.4 Personal data breach: the Processor notifies the Controller of any personal data breach without delay, and no later than within 48 hours of becoming aware of it, and provides cooperation.

4.5 Audit: the Processor makes available the information necessary to demonstrate compliance with Art. 28 GDPR and allows for an audit by prior arrangement while maintaining the confidentiality of other customers.

5. Sub-processors

5.1 The Controller grants general authorisation to engage the sub-processors listed in Annex 2.

5.2 The Processor imposes equivalent data protection obligations on sub-processors.

5.3 The Processor informs the Controller in advance of any intended change to the list of sub-processors and allows the Controller to object.

6. Transfers to third countries

6.1 Transfers outside the EEA take place only where appropriate safeguards under the GDPR exist, in particular standard contractual clauses (SCC). Current sub-processors and their locations are listed in Annex 2.

7. Deletion or return of data

7.1 Upon termination of the provision of the Service, the Processor, at the Controller's choice, returns or deletes the personal data and existing copies, unless EU or Slovak law requires further retention. The period is aligned with the Terms (Art. 11.4): export is available for 30 days after termination.

8. Liability and final provisions

8.1 The liability of the parties is governed by the GDPR and the Terms. In the event of a conflict on matters of personal data processing, this DPA prevails over the Terms. This DPA is governed by the law of the Slovak Republic.


Annex 1: Categories of data subjects and personal data

Categories of data subjects:

  • customers and suppliers listed on invoices, including natural persons (e.g. sole traders),
  • contact persons and representatives of business partners,
  • users to whom the Controller has granted access,
  • other persons whose data appears in invoices or the Customer Content.

Categories of personal data:

  • identification and contact data (name, address, email, telephone, role),
  • business and tax identifiers (business name, Company ID, Tax ID, VAT ID, Peppol ID),
  • invoice data (invoice numbers and dates, line items, amounts, VAT data, payment data, any notes),
  • operational data (logs, audit records, identifiers).

Special categories of data (Art. 9 GDPR) are not to be entered into the Service beyond what is necessary for the invoice content.

Annex 2: List of sub-processors

Sub-processorPurposeLocationTransfer safeguard
Storecove B.V.delivery of invoices over Peppol (Access Point)EU (NL)within the EEA
Hetzner Online GmbHhosting of server infrastructureEUwithin the EEA
Clerk, Inc.authentication and user identity managementUSAstandard contractual clauses (SCC)
Resend, Inc.sending transactional emailsUSAstandard contractual clauses (SCC)

The storage of invoices and documents (MinIO) is operated within our own infrastructure on servers in the EU. Connectors to accounting/ERP systems (Pohoda mServer, KROS Onix) are activated and controlled by the Controller and are not sub-processors of the Processor.

Annex 3: Technical and organisational measures (Art. 32 GDPR)

  • Transmission encryption: communication via HTTPS/TLS; security HTTP headers (HSTS); delivery over the Peppol network via secure protocols (TLS/AS4) at the Access Point.
  • Data isolation: logical row-level isolation of individual customers' data (RLS).
  • Access management: authentication via an identity provider, role and permission management, employee access only to the extent necessary.
  • Audit log: logging of actions for evidentiary and security purposes.
  • Backup and recovery: regular encrypted backups with a defined retention; tested recovery.
  • Availability and monitoring: operational monitoring and access logging.
  • Change management: a controlled process for deploying changes.

The measures are reviewed on an ongoing basis according to the state of the art.