Skip to main content
LEGAL · DPA

Data Processing Agreement (DPA)

Data-processing agreement between you (controller) and Freya (processor) under GDPR art. 28.

§ 01

Roles of the parties

This document covers the relationship that arises when you enter third-party personal data into Freya (for example, your clients' details on invoices: name, NIP, address, email).

  • Data controller (Administrator): you — the Freya user, a JDG or a legal entity that decides whose data to enter and for what purpose.
  • Processor (Procesor / podmiot przetwarzający): Freya — processes the data solely on your instructions and within the platform's functionality.
  • Freya is NOT the controller of your clients' data. Freya is the controller only of its own users (you) — see the separate Privacy Policy.
§ 02

Subject, duration and nature of processing

Processing is carried out by automated means, within the following limits:

  • Subject: storage, computation, generation of documents (invoices, JPK, PIT) and their delivery to the relevant state registers on your behalf.
  • Duration: the entire period of an active subscription. After account deletion, personal data is anonymized immediately, while data subject to tax obligations is retained for 5 years from the end of the calendar year in which the tax payment deadline passed (art. 70 § 1 of the Ordynacja podatkowa) — in practice ca. 66 months from account deletion — and then permanently deleted.
  • Nature: computational and reference processing of structured data; no profiling within the meaning of GDPR art. 22 is performed.
  • Purpose: performance of the Freya service contract only (GDPR art. 6(1)(b)) — not for marketing and not for training models.
  • Documented instructions (GDPR art. 28(3)(a)): the controller's instructions are deemed to be: (i) this DPA, (ii) the Freya Terms of Service, (iii) the in-app account configuration, and (iv) written communications to shaposhnik.mcd@gmail.com. Any processing outside these instructions is performed only where required by EU/Polish law — and we notify you in advance unless that law prohibits such notice.
  • Personnel confidentiality (GDPR art. 28(3)(b)): every person with access to your data on Freya's side — employees and contractors — is bound by a written confidentiality undertaking for the duration of access plus 5 years, with disciplinary and civil-law consequences for breach.
§ 03

Categories of data and data subjects

The types of data that flow into Freya from you or through you:

  • Client contact details: name/company name, NIP/REGON, address, email, phone number (if entered).
  • Payment details: the bank account number on the invoice, BIC/SWIFT (optional). Stored encrypted.
  • Transactional data: invoice numbers and amounts, payment dates, bank statements (if uploaded).
§ 04

Technical and organisational measures (GDPR art. 32)

Security measures are described in full in the Trust Center and summarised here:

  • Encryption of sensitive fields with AES-256-GCM at application level before being written to the database.
  • TLS 1.2+ for all network traffic, HSTS, SameSite=Lax cookies.
  • Append-only audit log (Postgres trigger), MFA via Clerk, EU-only hosting (Frankfurt, Vercel fra1 + Neon eu-central-1).
  • Independent penetration test: first round scheduled for Q4 2026; summary report shared under NDA on request to shaposhnik.mcd@gmail.com. In the interim — daily SAST via GitHub CodeQL + npm audit on every commit.
§ 05

Sub-processors

Freya engages qualified sub-processors under the general authorisation regime (GDPR art. 28(2)). The full, up-to-date list with jurisdictions and data categories — at Privacy §6; the categorised overview below:

  • EU-hosted infrastructure: Vercel (hosting, fra1 Frankfurt), Neon (Postgres database, Frankfurt), Vercel Blob (object storage for PDF/JPK files, fra1). Processing and storage take place within the European Economic Area.
  • Providers with US transfers under SCC 2021/914: Clerk (authentication), Resend (transactional email), Inngest (background jobs and crons), Sentry (error monitoring with PII redaction), Anthropic (AI assistant, receipt recognition and parsing of uploaded PDFs — bank statements and supplier invoices), Telegram (optional, only if you connect the Freya bot). For each of these, Module 3 SCC (processor-to-processor) applies as the appropriate transfer mechanism under GDPR art. 46.
  • Payments: Stripe Payments Europe Ltd (Dublin, IE) is the principal counterparty for EU-user payments; Stripe Inc. (US) may access limited transaction metadata as a sub-processor under Stripe's own DPA + SCC 2021/914.
  • OAuth providers (optional): Google — only during «Sign in with Google» (via Clerk); we receive the profile email and name, nothing more. Without using OAuth sign-in, Google is not engaged.
  • Flow-down obligations + TIA (GDPR art. 28(3)(d) + (4)): every sub-processor is bound by a written agreement at a protection level no lower than this DPA. For US transfers Freya has performed a Transfer Impact Assessment per EDPB Recommendations 01/2020 (last reviewed 2026-05-28) and confirms supplementary measures: encryption in transit (TLS 1.2+) and at rest (AES-256), contractual confidentiality, no clear-text PII in logs.

We will give written notice (email + in-app banner) of any new or changed sub-processor at least 14 days in advance. You may object — we will then propose an alternative or terminate the affected service without penalty.

§ 06

Data-subject requests (DSAR)

If your client has made a request under GDPR art. 15-22 (access, rectification, erasure, portability, restriction, objection), you respond as the controller. We provide the tools:

  1. Export: the button in Settings → Export returns a JSON containing all data for the selected client (or for all clients).
  2. Erasure: delete the client's card in the Biuro section — a soft-delete with a 30-day grace period during which the card can be restored. After the grace period the erasure is irreversible: contact details and access credentials are removed immediately, while data covered by the tax-law retention duty (invoices, filings) is kept for 5 years from the end of the year in which the tax payment deadline passed (in practice about 66 months from deletion) and then permanently deleted.
  3. Rectification: all fields can be edited directly in the app; the change history lives in the audit log.
  4. If a DSAR comes directly to Freya (for example, your client writes to us), we forward it to you within 5 working days and assist with the technical response.
§ 07

Incident notification

In the event of a confirmed breach of data you entrusted to us:

  • We notify you at your main account email within 72 hours of detection (GDPR art. 33(2)).
  • The notification contains: the nature of the incident, the categories and volume of data, likely consequences, and response measures.
  • You, as the controller, are responsible for notifying UODO (72h under art. 33(1)) and your clients (art. 34) — we provide technical assistance.
  • The term «personal data breach» follows GDPR art. 4(12): a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Mere suspicion without confirmation does not start the 72-hour clock — only the moment the incident is confirmed as a breach.
  • Assistance with DPIA and consultations (GDPR art. 35-36): if your processing using Freya requires a data protection impact assessment or prior consultation with UODO — on written request we provide technical documentation (processing description, security measures, sub-processor list, risk assessment) within 10 working days.
§ 08

Audit

The right to audit is implemented as follows:

  • First level — the public Trust Center + this DPA + Privacy Policy + a security questionnaire (sent on request to shaposhnik.mcd@gmail.com, reply within 5 working days).
  • Second level — a joint on-site audit with 30 days' notice and a mutually agreed auditor; reasonable costs are borne by the party requesting the audit, save in the event of a confirmed breach on our side.
§ 09

End of processing

After the contract ends you choose one of:

  • Export + erasure: we export everything as JSON; personal data is anonymized immediately upon the account-deletion request. Data subject to a mandatory statutory retention period (tax law) is permanently deleted once that period lapses — in practice ca. 66 months from account deletion; until then access to it stays locked. Audit logs (append-only, no personal data after anonymization) remain a permanent evidentiary record.
  • Erasure without export: the same, without the export.
  • Export without erasure: kept in a read-only archive for a further 30 days under a separate arrangement.
§ 10

Contact

Questions, a request for a signed version, or incident notifications — the contact page or directly at shaposhnik.mcd@gmail.com.

§ 11

Entry into force and final provisions

Legal framework of the agreement:

  • Entry into force: clicking «Accept agreement» (or exchanging qualified electronic signatures for B2B) converts this DPA into a binding agreement between both parties supplementing the Freya Terms of Service. We retain the date, IP and user-agent as evidence of consent (GDPR art. 7(1)).
  • Order of precedence: in case of conflict between this DPA and the Terms of Service in matters of personal-data processing — this DPA prevails. All other matters remain governed by the Terms.
  • Governing law and jurisdiction: Polish law applies, with direct application of the GDPR. Disputes that cannot be resolved through negotiation will be heard by the court competent for Freya's seat (Kraków); this clause does not deprive a consumer-controller of the mandatory procedural rights of their place of residence.
  • Sub-processor list by reference: the current sub-processor list including jurisdictions, data categories and legal basis for transfer is published at freyatax.com/privacy §6 and forms an integral part of this DPA. Changes are communicated as set out in §05 (14 days).
  • Amendments to the DPA: we may update the DPA with 30 days notice to your account email plus an in-app banner. If the change materially restricts your rights — we will request a fresh acceptance (with a new date-IP-agent). Until the new version is accepted, the previous one remains in force.

Last updated · July 17, 2026