This is a courtesy translation. The legally binding text is the Spanish version, at factuza.com/legal/encargo-tratamiento. Where this translation differs from it, the Spanish version prevails.
This matters more here than on the other pages: this is a contract, and the acceptance recorded in your account is acceptance of the Spanish text.
This text is not yet in force. It is the proposed wording, pending legal review, published so that you can read it in advance —particularly if you are an accountancy practice and need to assess it before signing up.
It will come into force on 1 September 2026. Until then its acceptance is not requested and processing is governed by what is described in the privacy policy. If anything changes during the review, this page will reflect it before that date.
Contents
1. Parties and purpose
Of the one part, the Client, whose identifying details appear in their Factuza account, in their capacity as data controller.
Of the other, Eduardo Ortega Busutil, tax number 50744036X, of Avenida del Talgo 86, 1.º B, 28023 Madrid, owner of the Factuza service, in his capacity as data processor.
The purpose is to authorise the Processor to process, on the Client's behalf, the personal data necessary to provide the Factuza invoicing service.
The Client owns their data. Their clients' data, their suppliers' data and their invoices are theirs: they decide what is done with them, and the Processor only processes them on their instructions.
2. Duration
For as long as the contractual relationship lasts. On termination, clause 8 applies.
3. Nature, purpose and scope
The Processor will process the data solely in order to:
- Issue, correct and void invoices on the Client's behalf, with the hash chaining required by Royal Decree 1007/2023.
- File the invoicing records with the Spanish Tax Agency (VERI*FACTU).
- Email invoices to the recipients the Client specifies, and record whether that email was delivered and opened.
- Automatically read (OCR) the expense invoices the Client uploads.
- Calculate draft tax returns from the Client's data.
- Retain the Client's history and make it available to them.
- Handle the support requests the Client sends.
Categories of data: identifying (name or company name, tax number, address), contact (email, telephone), financial and billing data, and whatever the Client themselves puts into their invoice descriptions.
Categories of data subjects: the Client's clients and suppliers, and the people in their organisation who use Factuza.
4. The processor's obligations
In accordance with article 28.3 GDPR, the Processor undertakes to:
- Process the data only on documented instructions from the Client, including those arising from normal use of the service. If the Processor considers an instruction to breach the rules, it will say so.
- Confidentiality. Anyone accessing the data will be bound by a duty of secrecy which survives the end of the relationship.
- Security. Apply the article 32 measures described in Annex II.
- Sub-processors. Only those in Annex I, on the terms of clause 5.
- Assist the Client in handling data subjects' rights of access, rectification, erasure, objection, restriction and portability. The service includes a full export of the Client's data, which in practice resolves portability without intervention.
- Assist the Client in complying with articles 32 to 36: security, breach notification and impact assessments.
- Notify any security breach affecting the Client's data without undue delay and, in any event, within 24 hours of becoming aware of it, with the information required by article 33.3.
- Make available to the Client the information needed to demonstrate compliance, and allow audits on reasonable notice.
5. Sub-processors
The Client gives general authorisation for the Processor to use the sub-processors listed in Annex I. The Processor imposes on them by contract the same obligations it assumes here, and is answerable for their conduct.
Any addition or change will be notified at least 30 days in advance. During that period the Client may object; if they do and there is no reasonable alternative, either party may terminate the contract without penalty.
6. International transfers
Processing takes place in the European Union, with primary hosting in the Azure region in Spain. If any sub-processor were to process data outside the European Economic Area, it would be under the safeguards of Chapter V GDPR, as stated in Annex I.
7. The client's instructions
The Client undertakes to:
- Have informed the data subjects and to have a lawful basis for the processing they instruct.
- Not to include in their invoice descriptions special categories of data (health, political opinions, trade union membership and the rest of article 9). The service is not designed to process them.
- Keep their contact details up to date, because that is the channel through which breaches and sub-processor changes are notified.
8. On termination: what is returned and what cannot be deleted
On termination, the Client may export all their data, and the Processor will delete it except for data the law requires to be retained.
And here there are two things that cannot be deleted even if asked for:
- Invoicing records are unalterable by design. The VERI*FACTU hash chain links each invoice to the previous one: deleting one breaks the chain for all those that follow, and that is exactly what the rules forbid. An issued invoice is corrected or voided —leaving a record— but it does not disappear.
- There is a legal retention obligation. Invoices and their records must be kept for the periods laid down by tax law.
Accordingly, the right to erasure does not extend to an invoice already issued, neither as against the Client nor as against a data subject who asks. It does extend to everything else: the client address book, drafts, settings and account data.
Once the legal retention periods have expired, the above is deleted as well.
9. Liability
Each party is answerable for the breaches attributable to it, in accordance with article 82 GDPR.
Annex I · Sub-processors
| Sub-processor | What for | Where |
|---|---|---|
| Microsoft Azure | Hosting of the application, database and backups | Spain (spaincentral) |
| Azure Communication Services | Sending email: invoices, notices and the newsletter | European Union |
| Azure Document Intelligence | Reading (OCR) the expense invoices | European Union |
| Azure OpenAI | Drafting the support centre's replies from the content of the message received. Microsoft does not use this data to train its models | European Union |
| Microsoft Entra External ID | Registration and login | European Union |
| Stripe | Collecting the licence fee. Card details are handled entirely within their environment; Factuza does not store them | EU / USA with appropriate safeguards |
The Spanish Tax Agency is not a sub-processor. It is the recipient of the invoicing records by legal mandate: a disclosure imposed by law, not a processing arrangement.
Annex II · Security measures
- Encryption in transit (HTTPS) and at rest.
- Authentication through an identity provider; no passwords are stored.
- Role-based access control, checked on the server and not only on screen.
- Isolation between clients: each request resolves which issuer it belongs to from who you are, never from what you ask for.
- Unalterable invoicing records, in a ledger table with cryptographic verification and periodic publication of digests.
- Automatic backups with retention.
- Secrets in a managed key store, never in configuration or in code.
- Access logging and application traces.
Annex III · Contact
For any matter concerning this agreement: soporte@factuza.com.