# Data Processing Agreement (DPA)

URL: https://postman.slovakodata.com/help/en/pravne/dpa/
Updated: 2026-08-18

Clause under Article 28(3) GDPR — standing of the parties, scope and purpose of processing, and the processor's obligations.

**Version 1.0 · effective from 18 August 2026**

This is an informative translation. In the event of any discrepancy, the Slovak
wording of this document prevails.

This document forms **Annex 1** to the Terms of Service for the "Digital Postman"
services. It is concluded under Article 28(3) of Regulation (EU) 2016/679 of the
European Parliament and of the Council (GDPR).

By giving consent during registration, this clause becomes legally binding on
both parties. We record the consent together with the date, time, document
version and the IP address it was given from.

### 1. Standing of the parties

The **Customer** acts as the **Controller** of personal data.

**SLOVAKODATA, a.s.** acts as the **Processor**. Full identification details are
on the [Contact details](/help/en/pravne/kontakt/) page.

### 2. Subject matter and purpose of processing

The Processor processes personal data **solely for the purpose of providing the
Services** under the Terms of Service — that is, to carry out the transmission,
transformation and delivery of electronic invoices.

### 3. Categories of data subjects and scope of data

**Data subjects** are employees, customers or suppliers of the Customer who are
natural persons.

**The scope of data** covers ordinary personal data stated on invoices and
accompanying documents:

- first name and surname,
- address,
- company ID and tax ID for a natural person,
- e-mail address,
- telephone number,
- bank account number,
- the invoiced amount.

Special categories of personal data under Article 9 GDPR are not processed in
the course of providing the Services.

### 4. Duration of processing

Personal data is processed **for the duration of the contractual relationship**
established by the Terms of Service, and thereafter for the period required by
specific legislation — in particular the Archives and Registries Act and tax
legislation.

### 5. Obligations of the Processor

The Processor undertakes to:

1. **Process personal data only on documented instructions** from the Customer.
2. **Ensure confidentiality** — persons authorised to process personal data will
   commit to secrecy.
3. **Implement appropriate technical and organisational measures** to secure the
   data under Article 32 GDPR.
4. **On termination of the Services**, at the Customer's decision, delete or
   return all personal data, unless specific legislation requires its retention.
5. **Assist the Customer** in fulfilling its obligation to respond to data
   subject requests and in ensuring compliance under Articles 32 to 36 GDPR.

### 6. Sub-processors

The Customer hereby gives the Processor **general written authorisation** to engage
sub-processors under Article 28(2) GDPR.

- The **current list** of sub-processors, including their role and place of
  processing, is published at [List of sub-processors](/help/en/pravne/subdodavatelia/)
  and forms an integral part of this clause.
- The Processor will notify the Customer by e-mail **at least 30 days before** any
  intended addition or replacement of a sub-processor takes effect.
- Within that period the Customer may **object on reasoned grounds**. If the
  objection cannot be resolved by agreement, the Customer may terminate the
  Agreement as of the effective date of the change without penalty; until then the
  sub-processor concerned will not be engaged in processing the Customer's data.
- The Processor will impose on every sub-processor **the same data protection
  obligations** as those set out in this clause and **remains fully liable to the
  Customer** for the performance of that sub-processor's obligations
  (Article 28(4) GDPR).
- Where a sub-processor carries out processing **outside the European Economic
  Area**, it is safeguarded by one of the instruments in Chapter V GDPR — an
  adequacy decision or standard contractual clauses. The specific transfer basis
  for each sub-processor is stated on the
  [List of sub-processors](/help/en/pravne/subdodavatelia/) page.

### 7. Demonstrating compliance and audits

Under Article 28(3)(h) GDPR the Processor undertakes to:

- **make available to the Customer all information** necessary to demonstrate
  compliance with the obligations laid down in Article 28 GDPR;
- **allow for and contribute to audits, including inspections**, conducted by the
  Customer or an auditor mandated by the Customer.

An audit takes place on written request delivered at least 30 days in advance,
as a rule once per calendar year, during business hours and in a manner that does
not unreasonably disrupt the Processor's operations. Persons carrying out the audit
are bound by confidentiality. If the audit reveals a breach of the Processor's
obligations, the Processor bears its cost; otherwise the Customer does.

Instead of its own audit, the Customer may accept a current independent auditor's
report or a certification, provided it demonstrates compliance with the same
obligations.

### 8. Notification of unlawful instructions

If the Processor considers that an instruction from the Customer **infringes GDPR
or other data protection provisions**, it will inform the Customer without undue
delay (Article 28(3), final subparagraph, GDPR). Pending clarification of such an
instruction, the Processor is entitled to suspend its execution.

### 9. Changes to this document

The Processor will notify the Customer of any change to this clause by e-mail at
least 15 days before it takes effect. The document version is stated in its
header and changes whenever the content changes.

Send questions about the processing of personal data to
[podpora@postman.slovakodata.com](mailto:podpora@postman.slovakodata.com).
