ePostman docs
Console

Data Processing Agreement (DPA)

Clause under Article 28(3) GDPR — standing of the parties, scope and purpose of processing, and the processor's obligations.

4 min read
  • #dpa
  • #gdpr
  • #personal data
  • #processor
  • #controller
  • #article 28
  • #processing

Version 1.0 · effective from 18 August 2026

This document forms Annex 1 to the Terms of Service for the “Digital Postman” services. It is concluded under Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

By giving consent during registration, this clause becomes legally binding on both parties. We record the consent together with the date, time, document version and the IP address it was given from.

1. Standing of the parties

The Customer acts as the Controller of personal data.

SLOVAKODATA, a.s. acts as the Processor. Full identification details are on the Contact details page.

2. Subject matter and purpose of processing

The Processor processes personal data solely for the purpose of providing the Services under the Terms of Service — that is, to carry out the transmission, transformation and delivery of electronic invoices.

3. Categories of data subjects and scope of data

Data subjects are employees, customers or suppliers of the Customer who are natural persons.

The scope of data covers ordinary personal data stated on invoices and accompanying documents:

  • first name and surname,
  • address,
  • company ID and tax ID for a natural person,
  • e-mail address,
  • telephone number,
  • bank account number,
  • the invoiced amount.

4. Duration of processing

Personal data is processed for the duration of the contractual relationship established by the Terms of Service, and thereafter for the period required by specific legislation — in particular the Archives and Registries Act and tax legislation.

5. Obligations of the Processor

The Processor undertakes to:

  1. Process personal data only on documented instructions from the Customer.
  2. Ensure confidentiality — persons authorised to process personal data will commit to secrecy.
  3. Implement appropriate technical and organisational measures to secure the data under Article 32 GDPR.
  4. On termination of the Services, at the Customer’s decision, delete or return all personal data, unless specific legislation requires its retention.
  5. Assist the Customer in fulfilling its obligation to respond to data subject requests and in ensuring compliance under Articles 32 to 36 GDPR.

6. Sub-processors

The Customer hereby gives the Processor general written authorisation to engage sub-processors under Article 28(2) GDPR.

  • The current list of sub-processors, including their role and place of processing, is published at List of sub-processors and forms an integral part of this clause.
  • The Processor will notify the Customer by e-mail at least 30 days before any intended addition or replacement of a sub-processor takes effect.
  • Within that period the Customer may object on reasoned grounds. If the objection cannot be resolved by agreement, the Customer may terminate the Agreement as of the effective date of the change without penalty; until then the sub-processor concerned will not be engaged in processing the Customer’s data.
  • The Processor will impose on every sub-processor the same data protection obligations as those set out in this clause and remains fully liable to the Customer for the performance of that sub-processor’s obligations (Article 28(4) GDPR).
  • Where a sub-processor carries out processing outside the European Economic Area, it is safeguarded by one of the instruments in Chapter V GDPR — an adequacy decision or standard contractual clauses. The specific transfer basis for each sub-processor is stated on the List of sub-processors page.

7. Demonstrating compliance and audits

Under Article 28(3)(h) GDPR the Processor undertakes to:

  • make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR;
  • allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

An audit takes place on written request delivered at least 30 days in advance, as a rule once per calendar year, during business hours and in a manner that does not unreasonably disrupt the Processor’s operations. Persons carrying out the audit are bound by confidentiality. If the audit reveals a breach of the Processor’s obligations, the Processor bears its cost; otherwise the Customer does.

8. Notification of unlawful instructions

If the Processor considers that an instruction from the Customer infringes GDPR or other data protection provisions, it will inform the Customer without undue delay (Article 28(3), final subparagraph, GDPR). Pending clarification of such an instruction, the Processor is entitled to suspend its execution.

9. Changes to this document

The Processor will notify the Customer of any change to this clause by e-mail at least 15 days before it takes effect. The document version is stated in its header and changes whenever the content changes.