Legal

Data Processing Agreement

Last updated: September 5, 2026

Version 1.0 — effective September 5, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies automatically to every customer account. No signature is needed. A countersigned copy of the current version is available on request from privacy@spaceinvoices.com. The English text governs.

Parties and scope

Provider is the company you contract with under the Terms. For customers outside the United States, Provider is Studio 404 d.o.o., Gradišče 15c, 1360 Vrhnika, Slovenia. For United States customers, Provider is Space Invoices Inc., 8 The Green, Suite B, Dover, Delaware 19901, United States. Space Invoices Inc. owns the platform intellectual property and licenses it to Studio 404 d.o.o.

Customer is the account holder.

This DPA applies to the extent Provider processes Personal Data on Customer's behalf that is subject to the GDPR, the UK GDPR, or Swiss data-protection law (together, the "Data Protection Laws"). Terms such as Personal Data, controller, processor, and Personal Data Breach have the meanings given in those laws. The invoicing service Provider offers under the Terms is the "Service".

1. Roles

Customer is the controller of the Personal Data it enters into the Service, such as invoice recipients and contacts. Provider processes that Personal Data as Customer's processor.

Where Customer itself acts as a processor for its own clients (for example, a platform issuing invoices on behalf of its customers), Provider acts as Customer's sub-processor. In that case this DPA contains the Article 28(3) terms Customer passes through to Provider. Customer warrants that it has the authority to appoint Provider and to give the instructions in this DPA.

For Customer's own account data (login, billing, support), Provider is a controller as described in the Privacy Policy. This DPA does not cover that data.

2. Precedence

This DPA supplements the Terms. It prevails over the Terms only for personal-data processing obligations. It does not change commercial terms and does not create liability beyond the Terms.

3. Instructions

Provider processes Personal Data only on Customer's documented instructions, except where required by applicable law. The Terms, the Service documentation, Customer's configuration of the Service, and the API requests Customer makes are the documented instructions.

Under those instructions, Provider processes Personal Data as needed to create, manage, deliver, export, and support invoicing, including security and maintenance of the Service.

Provider will inform Customer if, in Provider's opinion, an instruction infringes the Data Protection Laws.

4. Confidentiality and security

Provider ensures that persons authorised to process Personal Data are bound by confidentiality obligations. Provider implements the technical and organisational measures in Annex C. Provider may update those measures over time, provided the overall level of protection is not reduced.

5. Sub-processors

Customer gives general written authorisation for the sub-processors listed at spaceinvoices.com/sub-processors. Provider imposes materially equivalent data-protection obligations on each sub-processor and remains responsible for their processing.

Provider gives at least 30 days' notice of an intended addition or replacement by updating the sub-processor list and emailing account owners. If Customer objects on reasonable data-protection grounds and the parties cannot resolve the objection, Customer may stop using the affected feature or terminate the affected account without penalty.

Feature-dependent sub-processors are engaged only when Customer enables the feature.

6. Assistance and incidents

Taking into account the nature of the processing and the information available to it, Provider provides reasonable assistance with data-subject requests and with Customer's obligations under Articles 32 to 36 of the GDPR. Assistance beyond the standard Service is provided at reasonable cost.

Provider notifies Customer without undue delay after Provider confirms a Personal Data Breach affecting Customer's Personal Data, and provides further information in phases as it becomes available.

7. Information and audit

Provider makes available the written information reasonably necessary to demonstrate compliance with this DPA, including any third-party certifications or reports Provider holds.

Provider allows and contributes to audits, including inspections, where required by the Data Protection Laws or a supervisory authority, or where the written information is demonstrably insufficient. Audits are conducted remotely where possible, on 30 days' written notice, no more than once per year, during business hours, at Customer's cost, under confidentiality, and without access to other customers' data.

8. Retention and end of service

Issued fiscal documents, their audit trail, and statutory exports (for example SAF-T) are retained for the statutory retention period. This retention is a legal obligation and continues after the Service ends. Those records remain exportable during that period.

Other Personal Data is available for export for 30 days after termination, as stated in the Terms, and is deleted within 90 days after that period unless Customer requests its return in writing first. Backups are overwritten on their normal rotation.

9. International transfers and remote access

Personal Data is hosted in the EU; the sub-processor list records the providers that process outside the EEA and the safeguard for each. Provider transfers Personal Data outside the EEA (and outside the United Kingdom or Switzerland, where those laws apply) only under an adequacy decision or the EU Standard Contractual Clauses, with the UK Addendum or Swiss amendments where they apply, as recorded in the sub-processor list.

Provider's authorised personnel may access Personal Data remotely, occasionally from outside the EEA, over authenticated and logged connections under the measures in Annex C.

10. Acceptance and changes

Customer accepts this DPA by creating an account or by continuing to use the Service after the effective date.

Provider may publish a new version of this DPA. For material changes, Provider gives at least 30 days' notice by updating this page and emailing account owners. The version in force is the one published at spaceinvoices.com/dpa. A version history is kept at the bottom of this page.

A countersigned copy of the current version is available on request from privacy@spaceinvoices.com.

Annex A — Processing particulars

  • Subject matter: hosted invoicing service.
  • Duration: the service term, plus statutory retention of fiscal records.
  • Nature and purpose: creating, managing, delivering, exporting, and supporting invoices and related fiscal documents on documented instructions.
  • Data subjects: Customer's personnel; Customer's clients, invoice recipients, and their contacts; where Customer is a processor, its clients' end customers.
  • Categories of Personal Data: account and contact data; business data; invoice content, including name, tax number, address, bank details, and line descriptions as they appear on documents and exports.
  • Special-category data: not intended. Where invoice line descriptions reveal health or other special-category information (for example, medical services), Customer is responsible for the lawful basis and for informing data subjects. Provider processes such data only as invoice content.

Annex B — Sub-processors and transfers

The authoritative list of sub-processors, their locations, and the transfer mechanism for each is published at spaceinvoices.com/sub-processors. That page is part of this DPA.

Annex C — Technical and organisational measures

Provider maintains measures appropriate to the risk of the processing, including:

  • access controls, multi-factor authentication, and least-privilege access for authorised personnel;
  • encryption in transit and, where supported by the relevant service, at rest;
  • logical tenant separation and controlled change management;
  • backup, recovery, and service-resilience controls;
  • removal of personal data from error reporting and reduction of personal data in usage analytics, and proportionate logging with redaction;
  • incident detection, assessment, and response procedures;
  • retention and deletion controls; and
  • sub-processor due diligence and change management.

Version history

  • 1.0 — 2026-09-05 — first published version.