Acordo de Tratamento de Dados (esboço)
O texto deste documento está disponível apenas em inglês.
This page is an outline of what the data processing agreement between apiRiver (processor) and the customer (controller) will cover. It is not the agreement itself: the agreement text is a separate piece of legal work that has not been prepared yet.
What the agreement will cover
- Subject matter and nature of processing. Generating and validating electronic-invoice documents from data submitted by the customer through the API.
- Duration. Processing is occasional and limited to handling a single request: the content is not stored after the request is processed. While a PDF larger than about 10 KB is validated, the validation library writes a temporary copy to a private server directory; it is deleted when processing ends or, after an abnormal stop, by a later clean-up. This is stated in the agreement outright, not left implied; see also the Privacy Notice, section 6.
- Categories of data and data subjects. For generation: names, postal addresses, VAT, tax and registration identifiers, IBAN/BIC, contact name, phone and email of the seller and buyer, invoice lines, payment terms, amounts, dates and references. For validation: whatever the submitted document contains. Data subjects: the customer's counterparties and their contact persons, and the customer where a natural person.
- Controller's instructions. The processor acts only on the controller's documented instructions (Art. 28(3)(a)); the instruction is the API call itself. The processor does not use the data for its own purposes.
- Confidentiality of the persons who have access to the data.
- Security measures (Art. 32). Content of documents is not stored after the request is processed; logs of libraries that process documents are disabled; login tokens and API-key secrets are stored only as HMAC-SHA-256 hashes with a server secret; session cookie with HttpOnly, Secure and SameSite=Lax; CSRF protection of the cabinet forms; limits on request size, structure and processing time. [AUTHOR TO PROVIDE: transport encryption (TLS) at the perimeter and the hosting measures — to be stated only once the host and the reverse proxy are chosen and set up, because a list of security measures in a contract can be checked]
- Sub-processors: the list, how changes to it are notified, and the right to object.
- Resellers. Where a customer resells or embeds the service and processes the data of its own clients through it, apiRiver acts as that customer's sub-processor for that data, and the agreement states this outright (Terms of Service, section 6).
- Assistance to the controller in answering data-subject requests and in incident notification.
- Incident notification — period and channel. [AUTHOR DECISION REQUIRED / LAWYER REQUIRED: a number]
- Audit rights and provision of information demonstrating compliance. [AUTHOR DECISION REQUIRED: in what form audits are offered — an executable form must be chosen in advance; GDPR Art. 28(3)(h) does not allow refusing audits outright]
- Handling at the end of the relationship: deletion or return of data. Since content is not stored after the request is processed, this comes down to account data.
- International transfers: standard contractual clauses or another basis, where the processor or a sub-processor is outside the EEA. [LAWYER REQUIRED]
- The right to anonymised aggregated statistics — a direct reference to section 9 of the Terms of Service, including the authenticity conditions for an aggregate. It belongs in the very first edition of the agreement, because the right arises from the contract: retrofitting it would mean re-signing with every customer already signed.
Sub-processors
- Zoho Mail — email delivery. apiRiver may change its email provider and will update this list when it does. [LAWYER REQUIRED: Zoho carries the sign-in email, that is account data for which apiRiver is the controller, not the content of documents; whether it belongs in the sub-processor list of this agreement at all]
- Hosting provider — as identified in the Privacy Notice, section 5.
- Payment-related sub-processors — none. Payment processing does not involve the content of documents processed under this agreement.