Normbeleg — Data Processing Agreement (Art. 28 GDPR)
Version 1.0 · effective 10 October 2026
Between the Customer (controller) and PPFTEC S.R.L., Str. Patriarh Iustinian Marina nr. 17-19B, bl. DC12, mansardă, ap. 25, 240469 Râmnicu Vâlcea, Romania, CUI 55537142 (processor, "we"), trading as Normbeleg. This DPA forms part of the Normbeleg Terms of Service ("Terms", normbeleg.ppftec.com/terms) and is accepted with them. Contact for this DPA: privacy@ppftec.com; security incidents: security@ppftec.com.
1. Scope and roles
1.1 This DPA applies to personal data we process on the Customer's behalf to provide Normbeleg (Annex I). The Customer is the controller. If the Customer itself acts as processor for another controller, the Customer confirms it has that controller's authorisation and we are its sub-processor.
1.2 This DPA does not cover data we process as controller for our own purposes (Customer account and installation, acceptance records, our billing, support, security). Our App Privacy Notice (normbeleg.ppftec.com/app-privacy) covers that.
1.3 Stripe. Stripe is the Customer's own provider and the source system from which the App reads data with the permissions the Customer grants. Stripe is not our sub-processor and we are not Stripe's processor. Under the Stripe Apps Agreement (version of 28 April 2026, §8) neither Stripe nor we act as the other's processor or as joint controllers. Stripe processes the Customer's data under the Customer's own agreement with Stripe and in the role that agreement gives it.
1.4 Authorities and buyers. ANAF (Romanian Ministry of Finance, RO e-Factura/SPV) and, where the Poland Pack is used, the Polish Ministry of Finance (KSeF) receive invoices because the law requires the Customer to transmit them. They act as public authorities, not as our processors. Buyers and their mail providers receive invoices because the Customer instructs delivery. These are recipients on the Customer's instruction, not sub-processors.
2. Instructions
2.1 We process personal data only on the Customer's documented instructions, which are: the Terms, this DPA, and the settings the Customer makes in the App (Packs enabled, delivery options, archive option, connections to ANAF/KSeF). We process for no other purpose, unless EU or Member State law requires it; then we inform the Customer first unless that law forbids it.
2.2 We tell the Customer if we think an instruction infringes data protection law.
2.3 Archive instruction. The Customer instructs us:
- (a) all Plans: keep Documents and their records write-protected for 12 months from generation, then delete them;
- (b) paid Plans, once offered, if the Customer selects "Long-term archive" at setup (or later, for new Documents): keep each Document generated while the option is active, write-protected, until 31 December of the 8th year after its issue year, including after cancellation, uninstallation of the App or termination of the Terms, solely for storage, integrity checks and export to the Customer. The Customer confirms that it needs this retention to meet its own legal retention duties;
- (c) after the applicable period we delete, unless the Customer placed a legal hold (Terms 10.6).
3. Confidentiality
Only persons authorised by us who are bound by confidentiality may access the data. At version 1.0 that is PPFTEC's administrator only.
4. Security
We implement the measures in Annex II (Art. 32 GDPR). We may improve them; we will not lower the overall level of protection.
5. Sub-processors
5.1 The Customer gives general authorisation for the sub-processors in Annex III.
5.2 We give at least 30 days' notice of any intended addition or replacement by e-mail to the account owner and by updating Annex III on normbeleg.ppftec.com/dpa. The Customer may object on reasonable data-protection grounds within that period by writing to privacy@ppftec.com. If we cannot address the objection, the Customer may terminate the affected service and receives a refund of any unused prepaid fees.
5.3 We impose on each sub-processor data-protection obligations that are in substance the same as in this DPA, and we remain liable to the Customer for their performance.
6. International transfers
Storage of Customer data is in the EU (Annex II, measure 1). Cloudflare, Inc. is a US company and Workers code runs on Cloudflare's global network, so personal data may be processed transiently outside the EEA. Such transfers rely on Cloudflare's certification under the EU-U.S. Data Privacy Framework (adequacy decision (EU) 2023/1795) and, as fallback, the Standard Contractual Clauses in Cloudflare's Data Processing Addendum. Personal data that the Customer sends us by e-mail may be processed by Google outside the EEA under the transfer terms of the Google Cloud Data Processing Addendum (Annex III). We make no other transfer outside the EEA without the Customer's prior instruction.
7. Assistance
7.1 Data-subject requests. We forward to the Customer without undue delay any request we receive from a data subject about Customer data and do not answer it ourselves unless instructed. On the Customer's request we help find and export all Documents for a buyer.
7.2 Erasure versus retention. Where an invoice must be kept by law (Art. 17(3)(b) GDPR), the Customer may instruct us to restrict the buyer's Documents instead of deleting them; we keep them only for archive and export, and delete them at the end of the retention period.
7.3 We assist the Customer, taking into account the nature of processing and the information available to us, with Arts. 32–36 GDPR (security, breach notification, impact assessment, prior consultation).
8. Personal data breaches
8.1 We notify the Customer without undue delay and in any case within 48 hours after becoming aware of a personal data breach affecting Customer data, at the account owner's verified e-mail and in the App.
8.2 The notice describes, as far as known: what happened, categories and approximate numbers of data subjects and records, likely consequences, measures taken or proposed, and a contact. We provide further information as it becomes available.
8.3 If ANAF or KSeF Credentials may be compromised, we also delete them at once, tell the Customer to revoke them, and report the token to ANAF for blocking where ANAF's procedure provides for it.
9. End of processing: return and deletion
9.1 At the end of the Terms, the Customer can export all Customer data (Terms section 11). After the Data Act retrieval period (at least 30 days after the transition period), we delete all Customer data except:
- write-protected archive copies under 2.3(a) and 2.3(b), kept and deleted as instructed there;
- data we must keep by law.
9.2 Credentials are deleted immediately on disconnect, uninstall or termination.
9.3 Database point-in-time history (Cloudflare D1 Time Travel) rolls off within 30 days of deletion. Write-protected archive objects cannot be deleted before their lock date; this is why the Customer chooses the archive option knowingly.
9.4 On request we confirm deletion in writing.
10. Demonstrating compliance with Art. 28 and audits
10.1 We make available the information needed to demonstrate that we meet our obligations under Art. 28 GDPR: this DPA, Annex II, our records of processing (processor part), and the certifications and audit reports that Cloudflare and Google publish.
10.2 The Customer may send one written questionnaire per year free of charge to privacy@ppftec.com. If that is insufficient, or a supervisory authority requires it, the Customer (or an independent auditor bound by confidentiality) may audit, with 30 days' notice, during business hours, without access to other customers' data, at the Customer's cost. Audits of our sub-processors take place through their own reports.
11. Liability and term
11.1 Liability between the parties follows the Terms (section 14). Data subjects' rights under Art. 82 GDPR are not affected.
11.2 This DPA runs as long as we process Customer data, including any archive period.
11.3 Romanian law; courts as in the Terms. Supervisory authority for PPFTEC: ANSPDCP (Romania).
Annex I — Description of the processing
| Item | Description |
|---|---|
| Subject matter | Generating, validating, delivering or submitting and archiving the Customer's e-invoices and e-credit notes from Stripe data |
| Duration | Term of the Terms + the archive period (12 months, or 8 years after the issue year with Long-term archive) + exit retrieval period |
| Nature of processing | Reading (via Stripe API, read-only permissions), mapping, generating XML/PDF, validating (our validator container), uploading to ANAF SPV (Romania); in test mode also sending by e-mail (Germany) and sending to KSeF test systems (Poland); polling status and downloading Authority responses, storing write-protected copies, hashing, export, restriction, deletion |
| Purpose | Fulfil the Customer's invoicing obligations as instructed (Terms section 3) |
| Data subjects | (1) Customer's buyers who are natural persons (sole traders, freelancers, PFA; consumers where the Customer's Stripe invoices are addressed to them); (2) contact persons of business buyers; (3) the Customer itself where it is a natural person; (4) Customer's staff: Stripe Dashboard users (by Stripe user ID), reply-to and test-recipient e-mail owners, persons whose certificate authorised ANAF or KSeF access |
| Categories of data | Names; postal addresses; e-mail addresses; VAT IDs and national tax numbers (CUI/CIF, Steuernummer, NIP); invoice content (number, dates, lines, quantities, prices, tax, totals, payment terms, notes); seller bank details (IBAN/BIC/holder); Stripe object and user IDs; delivery records (masked recipient, provider message ID, timestamps, hashes); Authority records (upload index, ANAF signed response, KSeF number, UPO); Credentials (ANAF OAuth tokens; KSeF tokens; KSeF company certificates and private keys) and their metadata (CUI/NIP, serial or fingerprint, expiry) |
| Special categories | None intended. The Customer must not put special-category data in Stripe fields we read (Terms 7). Free-text line descriptions are copied as entered. |
| Not collected | Card or other payment-method data; buyer date of birth; personal identity numbers (CNP, PESEL, Steuer-ID) unless the Customer's invoice legally requires them; buyer IP addresses; buyer phone numbers |
| Retention of operational data | Stripe event records and raw event copies 30 days; one-time download links 1 day; unverified e-mail recipients 90 days; Credentials until disconnect or uninstall; document index rows as long as the Document; D1 point-in-time history 30 days; Worker logs contain IDs only |
| Location | Storage: Cloudflare D1 and R2 with EU jurisdiction; validator container on Cloudflare. Compute: Cloudflare global network (transient) |
Annex II — Technical and organisational measures (Art. 32)
| # | Area | Measure |
|---|---|---|
| 1 | Data location | Database (D1) and archive and event storage (R2) created with EU jurisdiction; no invoice content in queues or logs |
| 2 | Encryption | TLS for all traffic; Cloudflare storage encryption at rest; Credentials additionally encrypted with AES-256-GCM using a key held only as a Worker secret, bound to the tenant, with key versioning |
| 3 | Credential handling | No API route returns Credential material; KSeF key password used once and never stored; Credentials deleted at once on disconnect or uninstall; natural-person KSeF certificates refused; KSeF tokens refused after 31 Dec 2026 |
| 4 | Least privilege at Stripe | Read-only permissions only (events, invoices, credit notes, customers, tax rates, connected account), each with a written purpose |
| 5 | Authentication of inputs | Stripe webhook signatures verified on the raw body (fail-closed); event de-duplication; tenant resolved only from the verified account; App requests verified with Stripe's app signature; ANAF OAuth state bound and single-use |
| 6 | Tenant isolation | Every table carries the tenant ID; all database access through one data-access module taking the tenant first; isolation tests; storage keys built only from server IDs; download links single-use and short-lived |
| 7 | Integrity | Idempotent issuance per Stripe object and version; state machine with compare-and-set transitions; at-most-once automatic upload, ambiguous results never retried automatically; validation before upload |
| 8 | Archive | Write-protected storage locks per retention class; SHA-256 of every stored file in a manifest; hash-chained, insert-only audit log |
| 9 | Logging | Structured logs with IDs only; redaction tests over the pipeline; validator messages stored only in the tenant's report |
| 10 | Test-mode separation | Environment taken from the receiving endpoint; test Documents watermarked, never sent to Authorities' production systems, sent only to verified addresses |
| 11 | Live safeguards | Live processing only after acceptance of the current Terms; live switch that refuses all live processing unless enabled; live mode limited to the Romania Pack |
| 12 | Secrets and access | Secrets only in Worker and CI secret stores; per-Worker least privilege; access to production limited to PPFTEC's administrator |
| 13 | Supply chain | Validator artefacts pinned and verified by SHA-256; lockfile installs; CI uses synthetic fixtures and test keys only |
| 14 | Validator isolation | Validators in a container without a public route; XML parsers with DTDs and external entities disabled |
| 15 | Availability and recovery | Dead-letter handling for failed events; D1 point-in-time recovery (30 days); per-Document download at any time |
| 16 | Organisation | Confidentiality of authorised persons; incident procedure (Customer notice within 48 hours, ANAF token blocking, KSeF revocation advice); annual review of this annex |
| 17 | Data minimisation | Fields not needed for the invoice are not collected (Annex I); masked recipients in the UI and logs; operational retention limits (Annex I) |
Annex III — Sub-processors and other parties
Sub-processors (general authorisation)
| Sub-processor | Service used | Data | Location / safeguard |
|---|---|---|---|
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (and the Cloudflare affiliates in its sub-processor list) | Workers (compute), Queues, D1 (database, EU jurisdiction), R2 (archive and event storage, EU jurisdiction), Containers (validators), Email Service and Email Routing (notices; e-mail delivery in the Germany Pack) | All Annex I data | Storage in the EU; transient processing on the global network; Cloudflare Data Processing Addendum with Standard Contractual Clauses; EU-U.S. Data Privacy Framework |
| Google (provider of Google Workspace to PPFTEC) | PPFTEC company mailbox behind support@ppftec.com, privacy@ppftec.com and security@ppftec.com | Only what the Customer or its staff send us by e-mail, or include in the contact form, about a support or privacy request | Google Cloud Data Processing Addendum (last modified 8 June 2026), under which Google acts as processor; transfers outside the EEA under the transfer terms of that addendum |
No other sub-processor is used at version 1.0.
Not sub-processors (stated for transparency)
| Party | Role | Why not a sub-processor |
|---|---|---|
| Stripe | The Customer's own provider and our data source; separately, our payment provider for paid Plans once offered | Engaged by the Customer under its own Stripe agreement; Stripe Apps Agreement §8 says neither party is the other's processor. The App's UI runs inside the Stripe Dashboard; we store no personal data in Stripe-hosted app storage. |
| ANAF / Ministerul Finanțelor (Romania): RO e-Factura, SPV | Public authority receiving invoices by law | Recipient on the Customer's instruction and legal obligation |
| Ministerstwo Finansów (Poland): KSeF | Public authority receiving invoices by law (Poland Pack, test mode only at version 1.0) | Same |
| Buyers and their e-mail providers | Recipients of Documents | Delivery on the Customer's instruction |
| GitHub, Inc. | Source code and CI | Processes synthetic test data only; no Customer data |
Version 1.0. SHA-256 of the text of this version, as recorded when you accept it in the app: eb53156d64e05cfda7f7716a7cd8833d5341fb86a32ed1d0d0f69c2a63c26713