Normbeleg

Normbeleg — Data Processing Agreement (Art. 28 GDPR)

Version 1.0 · effective 10 October 2026

Between the Customer (controller) and PPFTEC S.R.L., Str. Patriarh Iustinian Marina nr. 17-19B, bl. DC12, mansardă, ap. 25, 240469 Râmnicu Vâlcea, Romania, CUI 55537142 (processor, "we"), trading as Normbeleg. This DPA forms part of the Normbeleg Terms of Service ("Terms", normbeleg.ppftec.com/terms) and is accepted with them. Contact for this DPA: privacy@ppftec.com; security incidents: security@ppftec.com.

1. Scope and roles

1.1 This DPA applies to personal data we process on the Customer's behalf to provide Normbeleg (Annex I). The Customer is the controller. If the Customer itself acts as processor for another controller, the Customer confirms it has that controller's authorisation and we are its sub-processor.

1.2 This DPA does not cover data we process as controller for our own purposes (Customer account and installation, acceptance records, our billing, support, security). Our App Privacy Notice (normbeleg.ppftec.com/app-privacy) covers that.

1.3 Stripe. Stripe is the Customer's own provider and the source system from which the App reads data with the permissions the Customer grants. Stripe is not our sub-processor and we are not Stripe's processor. Under the Stripe Apps Agreement (version of 28 April 2026, §8) neither Stripe nor we act as the other's processor or as joint controllers. Stripe processes the Customer's data under the Customer's own agreement with Stripe and in the role that agreement gives it.

1.4 Authorities and buyers. ANAF (Romanian Ministry of Finance, RO e-Factura/SPV) and, where the Poland Pack is used, the Polish Ministry of Finance (KSeF) receive invoices because the law requires the Customer to transmit them. They act as public authorities, not as our processors. Buyers and their mail providers receive invoices because the Customer instructs delivery. These are recipients on the Customer's instruction, not sub-processors.

2. Instructions

2.1 We process personal data only on the Customer's documented instructions, which are: the Terms, this DPA, and the settings the Customer makes in the App (Packs enabled, delivery options, archive option, connections to ANAF/KSeF). We process for no other purpose, unless EU or Member State law requires it; then we inform the Customer first unless that law forbids it.

2.2 We tell the Customer if we think an instruction infringes data protection law.

2.3 Archive instruction. The Customer instructs us:

  • (a) all Plans: keep Documents and their records write-protected for 12 months from generation, then delete them;
  • (b) paid Plans, once offered, if the Customer selects "Long-term archive" at setup (or later, for new Documents): keep each Document generated while the option is active, write-protected, until 31 December of the 8th year after its issue year, including after cancellation, uninstallation of the App or termination of the Terms, solely for storage, integrity checks and export to the Customer. The Customer confirms that it needs this retention to meet its own legal retention duties;
  • (c) after the applicable period we delete, unless the Customer placed a legal hold (Terms 10.6).

3. Confidentiality

Only persons authorised by us who are bound by confidentiality may access the data. At version 1.0 that is PPFTEC's administrator only.

4. Security

We implement the measures in Annex II (Art. 32 GDPR). We may improve them; we will not lower the overall level of protection.

5. Sub-processors

5.1 The Customer gives general authorisation for the sub-processors in Annex III.

5.2 We give at least 30 days' notice of any intended addition or replacement by e-mail to the account owner and by updating Annex III on normbeleg.ppftec.com/dpa. The Customer may object on reasonable data-protection grounds within that period by writing to privacy@ppftec.com. If we cannot address the objection, the Customer may terminate the affected service and receives a refund of any unused prepaid fees.

5.3 We impose on each sub-processor data-protection obligations that are in substance the same as in this DPA, and we remain liable to the Customer for their performance.

6. International transfers

Storage of Customer data is in the EU (Annex II, measure 1). Cloudflare, Inc. is a US company and Workers code runs on Cloudflare's global network, so personal data may be processed transiently outside the EEA. Such transfers rely on Cloudflare's certification under the EU-U.S. Data Privacy Framework (adequacy decision (EU) 2023/1795) and, as fallback, the Standard Contractual Clauses in Cloudflare's Data Processing Addendum. Personal data that the Customer sends us by e-mail may be processed by Google outside the EEA under the transfer terms of the Google Cloud Data Processing Addendum (Annex III). We make no other transfer outside the EEA without the Customer's prior instruction.

7. Assistance

7.1 Data-subject requests. We forward to the Customer without undue delay any request we receive from a data subject about Customer data and do not answer it ourselves unless instructed. On the Customer's request we help find and export all Documents for a buyer.

7.2 Erasure versus retention. Where an invoice must be kept by law (Art. 17(3)(b) GDPR), the Customer may instruct us to restrict the buyer's Documents instead of deleting them; we keep them only for archive and export, and delete them at the end of the retention period.

7.3 We assist the Customer, taking into account the nature of processing and the information available to us, with Arts. 32–36 GDPR (security, breach notification, impact assessment, prior consultation).

8. Personal data breaches

8.1 We notify the Customer without undue delay and in any case within 48 hours after becoming aware of a personal data breach affecting Customer data, at the account owner's verified e-mail and in the App.

8.2 The notice describes, as far as known: what happened, categories and approximate numbers of data subjects and records, likely consequences, measures taken or proposed, and a contact. We provide further information as it becomes available.

8.3 If ANAF or KSeF Credentials may be compromised, we also delete them at once, tell the Customer to revoke them, and report the token to ANAF for blocking where ANAF's procedure provides for it.

9. End of processing: return and deletion

9.1 At the end of the Terms, the Customer can export all Customer data (Terms section 11). After the Data Act retrieval period (at least 30 days after the transition period), we delete all Customer data except:

  • write-protected archive copies under 2.3(a) and 2.3(b), kept and deleted as instructed there;
  • data we must keep by law.

9.2 Credentials are deleted immediately on disconnect, uninstall or termination.

9.3 Database point-in-time history (Cloudflare D1 Time Travel) rolls off within 30 days of deletion. Write-protected archive objects cannot be deleted before their lock date; this is why the Customer chooses the archive option knowingly.

9.4 On request we confirm deletion in writing.

10. Demonstrating compliance with Art. 28 and audits

10.1 We make available the information needed to demonstrate that we meet our obligations under Art. 28 GDPR: this DPA, Annex II, our records of processing (processor part), and the certifications and audit reports that Cloudflare and Google publish.

10.2 The Customer may send one written questionnaire per year free of charge to privacy@ppftec.com. If that is insufficient, or a supervisory authority requires it, the Customer (or an independent auditor bound by confidentiality) may audit, with 30 days' notice, during business hours, without access to other customers' data, at the Customer's cost. Audits of our sub-processors take place through their own reports.

11. Liability and term

11.1 Liability between the parties follows the Terms (section 14). Data subjects' rights under Art. 82 GDPR are not affected.

11.2 This DPA runs as long as we process Customer data, including any archive period.

11.3 Romanian law; courts as in the Terms. Supervisory authority for PPFTEC: ANSPDCP (Romania).


Annex I — Description of the processing

Annex I — Description of the processing
ItemDescription
Subject matterGenerating, validating, delivering or submitting and archiving the Customer's e-invoices and e-credit notes from Stripe data
DurationTerm of the Terms + the archive period (12 months, or 8 years after the issue year with Long-term archive) + exit retrieval period
Nature of processingReading (via Stripe API, read-only permissions), mapping, generating XML/PDF, validating (our validator container), uploading to ANAF SPV (Romania); in test mode also sending by e-mail (Germany) and sending to KSeF test systems (Poland); polling status and downloading Authority responses, storing write-protected copies, hashing, export, restriction, deletion
PurposeFulfil the Customer's invoicing obligations as instructed (Terms section 3)
Data subjects(1) Customer's buyers who are natural persons (sole traders, freelancers, PFA; consumers where the Customer's Stripe invoices are addressed to them); (2) contact persons of business buyers; (3) the Customer itself where it is a natural person; (4) Customer's staff: Stripe Dashboard users (by Stripe user ID), reply-to and test-recipient e-mail owners, persons whose certificate authorised ANAF or KSeF access
Categories of dataNames; postal addresses; e-mail addresses; VAT IDs and national tax numbers (CUI/CIF, Steuernummer, NIP); invoice content (number, dates, lines, quantities, prices, tax, totals, payment terms, notes); seller bank details (IBAN/BIC/holder); Stripe object and user IDs; delivery records (masked recipient, provider message ID, timestamps, hashes); Authority records (upload index, ANAF signed response, KSeF number, UPO); Credentials (ANAF OAuth tokens; KSeF tokens; KSeF company certificates and private keys) and their metadata (CUI/NIP, serial or fingerprint, expiry)
Special categoriesNone intended. The Customer must not put special-category data in Stripe fields we read (Terms 7). Free-text line descriptions are copied as entered.
Not collectedCard or other payment-method data; buyer date of birth; personal identity numbers (CNP, PESEL, Steuer-ID) unless the Customer's invoice legally requires them; buyer IP addresses; buyer phone numbers
Retention of operational dataStripe event records and raw event copies 30 days; one-time download links 1 day; unverified e-mail recipients 90 days; Credentials until disconnect or uninstall; document index rows as long as the Document; D1 point-in-time history 30 days; Worker logs contain IDs only
LocationStorage: Cloudflare D1 and R2 with EU jurisdiction; validator container on Cloudflare. Compute: Cloudflare global network (transient)

Annex II — Technical and organisational measures (Art. 32)

Annex II — Technical and organisational measures (Art. 32)
#AreaMeasure
1Data locationDatabase (D1) and archive and event storage (R2) created with EU jurisdiction; no invoice content in queues or logs
2EncryptionTLS for all traffic; Cloudflare storage encryption at rest; Credentials additionally encrypted with AES-256-GCM using a key held only as a Worker secret, bound to the tenant, with key versioning
3Credential handlingNo API route returns Credential material; KSeF key password used once and never stored; Credentials deleted at once on disconnect or uninstall; natural-person KSeF certificates refused; KSeF tokens refused after 31 Dec 2026
4Least privilege at StripeRead-only permissions only (events, invoices, credit notes, customers, tax rates, connected account), each with a written purpose
5Authentication of inputsStripe webhook signatures verified on the raw body (fail-closed); event de-duplication; tenant resolved only from the verified account; App requests verified with Stripe's app signature; ANAF OAuth state bound and single-use
6Tenant isolationEvery table carries the tenant ID; all database access through one data-access module taking the tenant first; isolation tests; storage keys built only from server IDs; download links single-use and short-lived
7IntegrityIdempotent issuance per Stripe object and version; state machine with compare-and-set transitions; at-most-once automatic upload, ambiguous results never retried automatically; validation before upload
8ArchiveWrite-protected storage locks per retention class; SHA-256 of every stored file in a manifest; hash-chained, insert-only audit log
9LoggingStructured logs with IDs only; redaction tests over the pipeline; validator messages stored only in the tenant's report
10Test-mode separationEnvironment taken from the receiving endpoint; test Documents watermarked, never sent to Authorities' production systems, sent only to verified addresses
11Live safeguardsLive processing only after acceptance of the current Terms; live switch that refuses all live processing unless enabled; live mode limited to the Romania Pack
12Secrets and accessSecrets only in Worker and CI secret stores; per-Worker least privilege; access to production limited to PPFTEC's administrator
13Supply chainValidator artefacts pinned and verified by SHA-256; lockfile installs; CI uses synthetic fixtures and test keys only
14Validator isolationValidators in a container without a public route; XML parsers with DTDs and external entities disabled
15Availability and recoveryDead-letter handling for failed events; D1 point-in-time recovery (30 days); per-Document download at any time
16OrganisationConfidentiality of authorised persons; incident procedure (Customer notice within 48 hours, ANAF token blocking, KSeF revocation advice); annual review of this annex
17Data minimisationFields not needed for the invoice are not collected (Annex I); masked recipients in the UI and logs; operational retention limits (Annex I)

Annex III — Sub-processors and other parties

Sub-processors (general authorisation)

Sub-processors (general authorisation)
Sub-processorService usedDataLocation / safeguard
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (and the Cloudflare affiliates in its sub-processor list)Workers (compute), Queues, D1 (database, EU jurisdiction), R2 (archive and event storage, EU jurisdiction), Containers (validators), Email Service and Email Routing (notices; e-mail delivery in the Germany Pack)All Annex I dataStorage in the EU; transient processing on the global network; Cloudflare Data Processing Addendum with Standard Contractual Clauses; EU-U.S. Data Privacy Framework
Google (provider of Google Workspace to PPFTEC)PPFTEC company mailbox behind support@ppftec.com, privacy@ppftec.com and security@ppftec.comOnly what the Customer or its staff send us by e-mail, or include in the contact form, about a support or privacy requestGoogle Cloud Data Processing Addendum (last modified 8 June 2026), under which Google acts as processor; transfers outside the EEA under the transfer terms of that addendum

No other sub-processor is used at version 1.0.

Not sub-processors (stated for transparency)

Not sub-processors (stated for transparency)
PartyRoleWhy not a sub-processor
StripeThe Customer's own provider and our data source; separately, our payment provider for paid Plans once offeredEngaged by the Customer under its own Stripe agreement; Stripe Apps Agreement §8 says neither party is the other's processor. The App's UI runs inside the Stripe Dashboard; we store no personal data in Stripe-hosted app storage.
ANAF / Ministerul Finanțelor (Romania): RO e-Factura, SPVPublic authority receiving invoices by lawRecipient on the Customer's instruction and legal obligation
Ministerstwo Finansów (Poland): KSeFPublic authority receiving invoices by law (Poland Pack, test mode only at version 1.0)Same
Buyers and their e-mail providersRecipients of DocumentsDelivery on the Customer's instruction
GitHub, Inc.Source code and CIProcesses synthetic test data only; no Customer data

Version 1.0. SHA-256 of the text of this version, as recorded when you accept it in the app: eb53156d64e05cfda7f7716a7cd8833d5341fb86a32ed1d0d0f69c2a63c26713