Data Processing Agreement (outline)
This page is an outline of what the data processing agreement between apiRiver (processor) and the customer (controller) will cover. It is not the agreement itself: the agreement text is a separate piece of legal work that has not been prepared yet.
What the agreement will cover
- Subject matter and nature of processing. Generating and validating electronic-invoice documents from data submitted by the customer through the API.
- Duration. Processing is occasional and limited to handling a single request: the content is not stored after the request is processed. While a PDF larger than about 10 KB is validated, the validation library writes a temporary copy to a private server directory; it is deleted when processing ends or, after an abnormal stop, by a later clean-up. This is stated in the agreement outright, not left implied; see also the Privacy Notice, section 6.
- Categories of data and data subjects. For generation: names, postal addresses, VAT, tax and registration identifiers, IBAN/BIC, contact name, phone and email of the seller and buyer, invoice lines, payment terms, amounts, dates and references. For validation: whatever the submitted document contains. Data subjects: the customer's counterparties and their contact persons, and the customer where a natural person.
- Controller's instructions. The processor acts only on the controller's documented instructions (Art. 28(3)(a)); the instruction is the API call itself. The processor does not use the data for its own purposes.
- Confidentiality of the persons who have access to the data.
- Security measures (Art. 32). Content of documents is not stored after the request is processed; logs of libraries that process documents are disabled; login tokens and API-key secrets are stored only as HMAC-SHA-256 hashes with a server secret; session cookie with HttpOnly, Secure and SameSite=Lax; CSRF protection of the cabinet forms; limits on request size, structure and processing time. [AUTHOR TO PROVIDE: transport encryption (TLS) at the perimeter and the hosting measures — to be stated only once the host and the reverse proxy are chosen and set up, because a list of security measures in a contract can be checked]
- Sub-processors: the list, how changes to it are notified, and the right to object.
- Resellers. Where a customer resells or embeds the service and processes the data of its own clients through it, apiRiver acts as that customer's sub-processor for that data, and the agreement states this outright (Terms of Service, section 6).
- Assistance to the controller in answering data-subject requests and in incident notification.
- Incident notification — period and channel. [AUTHOR DECISION REQUIRED / LAWYER REQUIRED: a number]
- Audit rights and provision of information demonstrating compliance. [AUTHOR DECISION REQUIRED: in what form audits are offered — an executable form must be chosen in advance; GDPR Art. 28(3)(h) does not allow refusing audits outright]
- Handling at the end of the relationship: deletion or return of data. Since content is not stored after the request is processed, this comes down to account data.
- International transfers: standard contractual clauses or another basis, where the processor or a sub-processor is outside the EEA. [LAWYER REQUIRED]
- The right to anonymised aggregated statistics — a direct reference to section 9 of the Terms of Service, including the authenticity conditions for an aggregate. It belongs in the very first edition of the agreement, because the right arises from the contract: retrofitting it would mean re-signing with every customer already signed.
Sub-processors
- Zoho Mail — email delivery. apiRiver may change its email provider and will update this list when it does. [LAWYER REQUIRED: Zoho carries the sign-in email, that is account data for which apiRiver is the controller, not the content of documents; whether it belongs in the sub-processor list of this agreement at all]
- Hosting provider — as identified in the Privacy Notice, section 5.
- Payment-related sub-processors — none. Payment processing does not involve the content of documents processed under this agreement.