Skip to main content

Data Processing Addendum

Template — incorporated by reference into the Terms of Service.

1. Roles

Customer is the Controller. FawtaraX is the Processor.

2. Subject matter

Processing of invoice and customer master data necessary to deliver the e-invoicing service and meet OTA requirements.

3. Duration

For the term of the subscription plus the 10-year retention period.

4. Nature & purpose

Storage, transformation (UBL, hash chain, QR), transmission to OTA, archival, retrieval.

5. Categories of data subjects

Customer employees, end customers (buyers), suppliers.

6. Categories of data

Identifiers, contact data, tax identifiers, invoice line items.

7. Sub-processors

Listed in the Privacy Policy. We notify in advance of changes.

8. Security measures

See /security. Includes RLS isolation, encryption in transit (TLS 1.2+) and at rest, role-based access, audit logging, HMAC-verified webhooks.

9. Sub-processor obligations

All sub-processors are bound by equivalent confidentiality and security obligations.

10. Data subject rights

We assist Customer in fulfilling access, rectification, deletion and portability requests within 30 days.

11. Breach notification

We notify Customer of a confirmed personal-data breach without undue delay and within 72 hours.

12. Return & deletion

On termination, Customer may export all data. We delete copies after the OTA retention period, except where legally required to retain.

13. Audit

Customer may request audit reports (e.g. SOC 2 from sub-processors) once per year. On-site audits subject to mutual agreement.

Signed copy available on request: legal@fawtara.daftari.app