Data processing agreement
The Article 28 GDPR contract for the personal data you put into our applications. You are the controller, we are the processor, and this is what binds us.
In force since
Who you are contracting with
- Company
- IRUKA DIGITAL spółka z ograniczoną odpowiedzialnością
- Registered office
- ul. Szczęsna 26, 02-454 Warszawa, Poland
- Registry court
- Sąd Rejonowy dla m.st. Warszawy w Warszawie, Wydział Gospodarczy Krajowego Rejestru Sądowego
- KRS
- 0000980870
- NIP
- 5223230254
- REGON
- 522516722
- EU VAT
- PL5223230254
- Share capital
- 5 000,00 PLN
- [email protected]
- Phone
- +48 690 164 776
0. Why you already have this
If you upload an invoice, a bank statement, a trial balance, a customs declaration or a customer record, you are handing us personal data about people who are not our customers — your suppliers, your clients, their staff. For that data you are the controller and we are the processor, and Article 28(3) GDPR says that relationship must be governed by a contract that binds us in writing.
So here it is, in force without anybody chasing a signature. This agreement is incorporated into the terms of service and applies automatically from the moment you first submit content to one of our applications. It is written to be the whole Article 28 contract, not a summary of one.
If your procurement process needs a signed counterpart — or your own DPA template, or the EU standard contractual clauses as a separate instrument — write to [email protected] and we will sign. We do not charge for that and we do not make you escalate to get it.
Definitions. “Controller”, “processor”, “processing”, “personal data”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in Article 4 GDPR. “GDPR” means Regulation (EU) 2016/679. “Customer Personal Data” means personal data contained in content you submit to, or generate in, the applications. “You” means the customer named on the account; “we” means IRUKA DIGITAL sp. z o.o.
1. Roles, and where the boundary sits
You are the controller. You decide what personal data goes into the applications, why, and what happens to it. You are responsible for having a lawful basis for putting it there, for the transparency obligations towards those people, and for the accuracy of what you upload.
We are the processor. We process Customer Personal Data only to deliver the service to you, and only as this agreement and your instructions allow.
Where we are the controller instead, and this agreement does not apply: your own account and contact data, your billing and payment records, our support correspondence with you, our security logs, and our site statistics. That processing is ours to decide and answer for, and the privacy policy governs it. Two documents, one boundary, no gap between them.
2. Your instructions
We process Customer Personal Data only on your documented instructions — Article 28(3)(a) GDPR. Your instructions are:
- this agreement and the terms of service;
- the settings and choices you make in the product, including retention settings and which features you enable;
- any further written instruction you give us, which we will follow if it is lawful and technically feasible; where it goes beyond the agreed service we may ask you to cover the reasonable cost, after telling you what that is.
We will not process Customer Personal Data for our own purposes. In particular we will not use it to train AI models, to build datasets or products, to profile your customers, or for our own marketing.
If an instruction of yours appears to breach the GDPR or other EU or Member State data protection law, we will tell you immediately and may suspend that processing until it is resolved — Article 28(3) second paragraph.
3. Confidentiality of the people who touch it
Access to Customer Personal Data is limited to those of our personnel who need it to deliver the service or to support you. Everyone with access is bound by a written confidentiality obligation that survives their engagement, is instructed on how the data may be handled, and has an individual account so that access can be attributed to a person — Articles 28(3)(b) and 29.
We do not grant standing production access “just in case”. Elevated access is granted for a purpose and withdrawn afterwards.
4. Security
We implement and maintain the technical and organisational measures required by Article 32 GDPR. They are set out in Annex 2 and are a contractual commitment, not a description of aspiration.
We may change a measure, provided the change does not materially reduce the overall level of protection.
5. Sub-processors
You give general written authorisation for us to engage sub-processors — Article 28(2) GDPR. The current list is Annex 3 at the foot of this page, and it is the same register the sub-processors page publishes.
The conditions we hold ourselves to:
- every sub-processor is engaged under a written contract imposing the same data protection obligations as this agreement, including the security measures and the transfer safeguards — Article 28(4);
- we remain fully liable to you for a sub-processor’s performance;
- before adding or replacing one, we will give you at least 30 days notice by email to your account address, or in the product;
- you may object on reasonable data protection grounds within those 30 days. We will then work with you to find an alternative; if we cannot, you may terminate the affected subscription without penalty and receive a refund of the unused prepaid period. An objection is not a breach and we will not treat it as one.
You can subscribe to notifications of changes to the register by writing to [email protected].
6. International transfers
Some sub-processors are established in, or transfer data to, third countries — see Annex 3. Where they do, we rely on Article 46(2)(c) GDPR: the European Commission’s Standard Contractual Clauses, concluded with each such sub-processor, supported by a transfer impact assessment and the technical measures in Annex 2. Where a provider also holds an EU–US Data Privacy Framework certification, that adequacy decision applies in addition; we do not rely on it as the sole safeguard.
You instruct and authorise us to make those transfers, and to conclude the Standard Contractual Clauses on your behalf where the module for a controller-to-processor onward transfer requires it. If a transfer tool we rely on is invalidated, we will tell you and put an alternative in place, or stop the transfer.
7. Helping you answer data subjects
The people in your documents will sometimes exercise their rights. Those requests are yours to answer, and Article 28(3)(e) requires us to help you do it.
- We will not respond to a data subject directly about Customer Personal Data. If a request reaches us, we will tell you without undue delay and point the person to you.
- We will give you the technical means to fulfil a request yourself where the product allows it — search, export, correction, deletion.
- Where the product does not allow it, we will act on your written instruction and do so within 5 business days, which leaves you the rest of your one-month deadline under Article 12(3).
- This assistance is included in what you pay. We do not meter it.
8. Helping you with assessments and incidents
We will assist you, taking into account the nature of the processing and the information available to us, in complying with Articles 32 to 36 GDPR — Article 28(3)(f). That means:
- information for your records — the description of processing you need for your Article 30 record, and the technical detail you need for a data protection impact assessment under Article 35;
- breach notification — if a personal data breach affecting Customer Personal Data occurs, we will notify you without undue delay and in any event within 48 hours of becoming aware of it. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once, we will send what we have and follow up.
We will not decide for you whether a breach is notifiable. Article 33 is your assessment as controller, and you cannot make it if we sit on the information. So we tell you what happened even where our own view is that the threshold is not met.
We will not notify a supervisory authority or data subjects about Customer Personal Data on your behalf unless you ask us to or the law requires it of us.
9. Deletion and return
On the end of the contract, or earlier if you ask, we will delete Customer Personal Data or return it to you, and delete existing copies — Article 28(3)(g).
- You have at least 30 days after termination to export it; section 11 of the terms describes how.
- After that window we delete it from production, and backups age out within a further 30 days.
- The only exception is data EU or Member State law requires us to keep — invoices and accounting records, principally. Those are ours as controller, they are listed in the privacy policy, and they are not kept for any other purpose.
- We will confirm the deletion in writing if you ask.
10. Audit and information
We will make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections — Article 28(3)(h).
In practice, and in this order:
- we answer your security questionnaire and give you our documentation, at no charge, once per year and whenever there has been a material change or an incident;
- where that is genuinely insufficient for your obligations, you may audit us, or appoint an independent auditor who is not our competitor and who signs a confidentiality undertaking;
- an audit happens on at least 30 days notice, in business hours, no more than once a year unless a supervisory authority requires otherwise or there has been a breach, and without access to other customers’ data or to anything that would compromise our security;
- you bear the cost of your own audit, unless it finds a material breach of this agreement, in which case we bear it.
11. Liability
Each side is liable under Article 82 GDPR and under the general rules of Polish law. The liability provisions in section 14 of the terms apply to claims under this agreement, except that they do not limit either side’s liability towards a data subject, or any liability that the GDPR or Polish law does not permit to be limited.
If we pay compensation or a fine for damage caused by processing in which you also participated, the apportionment follows Article 82(5).
12. Duration and precedence
This agreement takes effect when you first submit content to an application and lasts as long as we process Customer Personal Data for you. Provisions that need to survive termination — confidentiality, deletion, audit, liability — do.
For Customer Personal Data, this agreement prevails over anything inconsistent in the terms of service. If you and we sign a separate, negotiated DPA, that one prevails over this page.
Annex 1 — Details of the processing
Required by Article 28(3) and useful for your Article 30 record.
Subject matter: provision of the software-as-a-service applications you subscribe to. Duration: the term of your subscription, plus the retrieval and deletion periods in section 9. Nature of the processing: collection, recording, organisation, structuring, storage, retrieval, consultation, use, automated analysis, matching, transmission, erasure. Hosting and, where you enable an AI feature, submission to the model provider in Annex 3. Purpose: delivering the functionality of the product to you, supporting you, and keeping the service secure and available. Nothing else. Special categories: we do not ask for them and the products are not designed for them. If your documents contain them, that is your decision as controller and your lawful basis to establish.
| Product | Typical categories of personal data | Typical data subjects | Retention specific to the product |
|---|---|---|---|
| InvoiceMatch (RozliczTo in Poland) | Names and addresses on invoices and bank statements, bank account numbers, contact details, transaction amounts, dates, references, tax identifiers | Your suppliers and customers, their staff, your own employees who appear on the records | Uploaded source documents are deleted 30 minutes after processing. Match results and metadata persist per your settings |
| e-Sprawozdanie | Names, roles and signatures of board members and signatories, identifiers appearing in financial statements, notes and resolutions | Board members, proxies and signatories of the filing entity | Per your settings; filing packages are kept while you may need to re-file |
| AduanaLink | Names, addresses and identifiers of importers, exporters, consignees and brokers, declaration and transport data, tax identifiers | Parties to a customs operation, your staff and your clients’ staff | Per your settings and the retention periods your customs obligations impose |
| CarPanel | Customer names, phone numbers including WhatsApp, vehicle registration plates, visit and service history, preferences, prices paid | Your car-wash customers, who are usually consumers, and your staff | Per your settings. Because these are consumer records, keep your retention setting deliberate rather than default |
Frequency: continuous, for as long as you use the product. Transfers: as set out in section 6 and Annex 3.
Annex 2 — Technical and organisational measures
The measures we maintain under Article 32 GDPR. They are proportionate to the risk and to the fact that we are a small team running our own infrastructure — which is a constraint, and also the reason there are few places for data to leak.
Encryption and pseudonymisation. TLS for all data in transit, including internally between services. Encryption at rest for databases, object storage and backups. Passwords stored only as salted hashes, never recoverable. Secrets held in a managed secret store, never in the repository or in a configuration file in version control.
Access control. Individual named accounts; no shared credentials. Multi-factor authentication mandatory for administrative access. Least privilege by default, reviewed when a role changes and revoked on departure. Row-level authorisation in the database that denies by default, so a query without an established identity returns nothing rather than everything. Administrative interfaces restricted to an explicit allowlist of staff.
Separation. Production is separate from development and testing. We do not copy production personal data into a development or test environment. Customer data is logically separated per customer and access is scoped to a single customer’s records.
Availability and resilience. Managed, redundant hosting. Automated backups with a defined retention, restore tested rather than assumed. Deletion propagates to backups within 30 days.
Integrity and monitoring. Application and access logging with attribution to an account. Error and anomaly monitoring with alerting. Rate limiting and abuse protection at the edge. Webhook and inbound integration signatures verified, and processing made idempotent so a replay cannot duplicate or corrupt records.
Data minimisation by design. We collect the fields the feature needs and no more. Where a document is only needed to produce a result, it is deleted once the result exists — InvoiceMatch’s 30-minute deletion is this principle in code rather than in prose.
Vendor governance. A written data processing agreement with every sub-processor, incorporating the Standard Contractual Clauses where the transfer requires them, and a contractual prohibition on the model provider using your inputs or outputs for training.
People. Confidentiality undertakings for everyone with access. Data protection and security instruction appropriate to the role. A documented internal procedure for handling a suspected breach, including the 48-hour notification in section 8.
Testing and review. Dependency and vulnerability monitoring with prompt patching. Review of these measures at least annually, and after any incident.
Annex 3 — Authorised sub-processors
The general authorisation in section 5 covers the providers below. Changes are notified 30 days in advance and you may object as described there. Rows marked as a separate controller are recipients of personal data but are not our sub-processors — Tpay is the example, because it decides for itself what it must do to execute a payment and to satisfy its obligations as a supervised payment institution.
| Provider | What it does for us | Where | Role |
|---|---|---|---|
| Cloudflare Cloudflare, Inc. / Cloudflare Ltd. | Hosting, CDN, DNS, WAF and edge compute for the websites and applications | EU edge locations; United States * | Processor |
| Supabase Supabase, Inc. | Managed PostgreSQL database and account authentication | Per product: Paris (eu-west-3) and Stockholm (eu-north-1) in the EU; London (eu-west-2) in the UK, under the adequacy decision of 19 December 2025; and — for CarPanel only — N. Virginia (us-east-1) in the United States. Company established in the United States. * | Processor |
| Anthropic (Claude) Anthropic PBC | The AI features described in the privacy policy — document analysis, matching and drafting. Inputs are not used to train the provider's models. | United States * | Processor |
| Resend Resend, Inc. | Delivery of transactional and service email (receipts, alerts, account notices) | United States * | Processor |
| Google Analytics 4 Google Ireland Ltd. / Google LLC | Audience measurement on the marketing site. Loaded only after consent; never on the product applications. | Ireland; United States * | Processor |
| Tpay Krajowy Integrator Płatności S.A., plac Władysława Andersa 3, 61-894 Poznań, KRS 0000412357 | Execution, settlement and security of payments; statutory payment-services, AML, accounting and chargeback obligations. Tpay decides these purposes itself and is a separate controller, not our sub-processor. | Poland (EEA) | Separate controller |
| Mailbox hosting (MySecureCloudHost) WHG Hosting Services Ltd, Norwich, United Kingdom (company no. 14644356) | Hosts the [email protected] mailbox — support correspondence, complaints, withdrawal notices and data subject requests | Servers in Frankfurt, Germany (EEA); provider established in the United Kingdom, covered by the Commission's adequacy decision of 19 December 2025 | Processor |
* Transfer outside the EEA on the Commission's Standard Contractual Clauses (art. 46(2)(c) GDPR)