Data Processing Addendum
Template — incorporated by reference into the Terms of Service.
1. Roles
Customer is the Controller. FawtaraX is the Processor.
2. Subject matter
Processing of invoice and customer master data necessary to deliver the e-invoicing service and meet OTA requirements.
3. Duration
For the term of the subscription plus the 10-year retention period.
4. Nature & purpose
Storage, transformation (UBL, hash chain, QR), transmission to OTA, archival, retrieval.
5. Categories of data subjects
Customer employees, end customers (buyers), suppliers.
6. Categories of data
Identifiers, contact data, tax identifiers, invoice line items.
7. Sub-processors
Listed in the Privacy Policy. We notify in advance of changes.
8. Security measures
See /security. Includes RLS isolation, encryption in transit (TLS 1.2+) and at rest, role-based access, audit logging, HMAC-verified webhooks.
9. Sub-processor obligations
All sub-processors are bound by equivalent confidentiality and security obligations.
10. Data subject rights
We assist Customer in fulfilling access, rectification, deletion and portability requests within 30 days.
11. Breach notification
We notify Customer of a confirmed personal-data breach without undue delay and within 72 hours.
12. Return & deletion
On termination, Customer may export all data. We delete copies after the OTA retention period, except where legally required to retain.
13. Audit
Customer may request audit reports (e.g. SOC 2 from sub-processors) once per year. On-site audits subject to mutual agreement.
Signed copy available on request: legal@fawtara.daftari.app