Data processing agreement (DPA)

Translation provided for convenience. The German version is legally binding.

Agreement on processing on behalf under Art. 28 GDPR. Version of 8 October 2026.

Parties

Controller: the customer, as named in the account or in the individual contract.

Processor: Dmytro Yalanskyi, NormAPI Ladoz'ka street 19-126, Zaporizhzhia 69121 Ukraine Email: kontakt@normapi.de · Data protection: datenschutz@normapi.de

§ 1 Subject matter and duration

(1) The processor processes personal data on behalf of the controller where the controller uses the NormAPI services to validate or generate electronic invoices. The basis is the main contract: the NormAPI terms of service or a separate individual contract.

(2) This agreement runs for as long as the main contract.

(3) This agreement forms part of the terms of service and is concluded when they are accepted. The controller may also accept it in text form, for example by email to kontakt@normapi.de, or sign it together with an individual contract. The controller receives a copy signed by the processor on request.

§ 2 Nature, purpose and scope of processing

(1) The purpose is validating electronic invoices against the official KoSIT ruleset and generating electronic invoices (XRechnung, ZUGFeRD) from structured data, each at the controller's request through the API or the website.

(2) Processing consists of receiving, reading and validating or generating in memory, returning the result to the controller, and then discarding the data. Invoice content is not stored.

(3) Types of personal data, insofar as the invoice data contains them:

  • Names, addresses and contact details of seller, buyer and contact persons
  • Tax and registration details (tax number, VAT ID, Leitweg-ID)
  • Payment details (IBAN, BIC, account holder, payment terms)
  • Invoice and delivery details (invoice number, date, lines, quantities, prices, delivery and order references)

(4) Data subjects are the controller's customers, suppliers and other business partners where they are natural persons (such as sole traders), and the contact persons and employees of either side named in invoices.

(5) Processing takes place in data centres in the European Union (EU West region, Amsterdam, Netherlands). The processor is based in Ukraine and accesses the systems from there; see § 9.

§ 3 Instructions

(1) The processor processes the data only on documented instructions from the controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law. In that case the processor informs the controller of that legal requirement before processing, unless that law prohibits it.

(2) The instructions are set out in this agreement. Submitting a document or invoice data through the API or the website instructs the processor to validate it or to generate an invoice from it. Further instructions are given in text form.

(3) If the processor considers an instruction to infringe data protection law, it informs the controller without undue delay.

§ 4 Obligations of the processor

(1) The processor processes the data personally. Anyone it authorises to process data in future will first be committed to confidentiality, unless already under a statutory obligation of confidentiality.

(2) It implements the technical and organisational measures under Art. 32 GDPR described in annex 1. It may develop them further as long as the level of protection does not fall.

(3) Taking into account the nature of the processing, it assists the controller in responding to requests from data subjects (Art. 12 to 22 GDPR) and with the obligations under Art. 32 to 36 GDPR. If a data subject contacts it directly, it forwards the request to the controller without undue delay.

(4) It informs the controller of a personal data breach without undue delay, and no later than 48 hours after becoming aware of it, and provides the information under Art. 33(3) GDPR insofar as it is available.

(5) It makes available to the controller all information necessary to demonstrate compliance with Art. 28 GDPR (§ 7).

§ 5 Sub-processors

(1) The controller gives general authorisation to engage further processors. The sub-processors engaged when this agreement is concluded are listed in annex 2 and are deemed authorised.

(2) The processor announces any intended change, meaning adding or replacing a sub-processor, at least 30 days in advance in text form. Within that period the controller may object on substantial data protection grounds. If the parties cannot agree, the controller may terminate the main contract as of the date of the change.

(3) The processor imposes on every sub-processor by contract the same data protection obligations as this agreement sets out. It remains liable to the controller for the sub-processor meeting them (Art. 28(4) GDPR).

(4) Ancillary services without access to the controller's personal data, such as telecommunications or availability monitoring, are not sub-processing.

§ 6 Obligations of the controller

(1) The controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects.

(2) If it finds errors or irregularities with regard to data protection provisions, it informs the processor without undue delay.

§ 7 Evidence and audits

(1) The processor demonstrates compliance with this agreement primarily through information, these documents and current evidence from its sub-processors, such as their certifications.

(2) Where that is not sufficient in an individual case, the controller may, after giving reasonable notice of usually 30 days, carry out audits including inspections, or have them carried out by an auditor bound to confidentiality who is not a competitor of the processor. As the processor runs no data centres of its own, inspections cover its procedures; for the data centres, the sub-processors' evidence applies.

(3) The controller bears the costs of an audit unless it reveals a material breach by the processor.

§ 8 Deletion and return

(1) Invoice content is discarded after each processing operation. It is not stored at the processor, so there is nothing to return.

(2) When the main contract ends, the processor deletes any other data processed on behalf of the controller unless there is a statutory retention obligation. Request logs are deleted after seven days in any case. The controller can delete its account itself at any time and export its data beforehand.

§ 9 Transfers to third countries

(1) The processor is based in Ukraine. There is no adequacy decision of the European Commission for Ukraine. When the processor accesses personal data from there, this is a transfer to a third country.

(2) For these transfers the parties agree the Standard Contractual Clauses of the European Commission under Implementing Decision (EU) 2021/914, Module 2 (transfer controller to processor). They are incorporated into this agreement by reference, with the following choices: Clause 7 (docking clause) applies; in Clause 9, Option 2 (general written authorisation) applies with a period of 30 days; the optional wording in Clause 11 does not apply; the competent supervisory authority under Clause 13 is the controller's; under Clause 17, the law of the Federal Republic of Germany applies; under Clause 18, the courts of Germany have jurisdiction. Annex I of the clauses follows from the details of the parties and from §§ 1 and 2, Annex II from annex 1 and Annex III from annex 2.

(3) The processor engages sub-processors in third countries only where the conditions of Art. 44 et seq. GDPR are met; the safeguard for each is listed in annex 2.

(4) In case of conflict between this agreement and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

§ 10 Liability

Liability is governed by Art. 82 GDPR. Otherwise the liability provisions of the main contract apply.

§ 11 Final provisions

(1) Amendments and additions to this agreement require text form.

(2) In case of conflict between this agreement and the main contract, this agreement prevails on matters of data protection.

(3) German law applies. The place of jurisdiction is, as far as legally permitted, the controller's registered seat.

(4) Should a provision be invalid, the rest of the agreement remains valid.

Annex 1: Technical and organisational measures

Measures under Art. 32 GDPR, as of this version. A plain-language overview is on the security page.

Physical access control

  • NormAPI runs no servers or data centres of its own. Website, API and database run at the hosting provider Railway in the EU West region (Amsterdam, Netherlands); physical security of the data centres lies with the provider and its data centre operators.

System access control

  • Only the operator has administrative access to hosting, the source repository, the payment provider and the mailbox; these accounts are protected by two-factor authentication.
  • The database has no public network address and can only be reached from the hosting provider's private network.
  • The API's internal administration interface requires a separate token known only to our own frontend server; it is compared in constant time. Without a token set, the interface is switched off.
  • Customers sign in with a one-time link that is valid for 24 hours and consumed on first use, or with GitHub. Sessions use strictly necessary cookies.

Data access control

  • API keys are generated randomly on the server (192 bits), shown exactly once and stored only as a SHA-256 hash.
  • Customers can revoke keys themselves at any time. Every request checks the key against the database directly, with no cache in between — a revoked key is refused from that moment on.
  • Each account sees only its own keys, usage counters and request log.

Separation control

  • Account data is logically separated per account; every query is bound to the account making it.
  • Invoice content is not stored and therefore cannot be mixed between customers.
  • Development and testing run in a separate environment with synthetic data; production data is not used for them.

Data minimisation and pseudonymisation

  • Submitted invoices and invoice data are processed in memory only and discarded once the response has been delivered — stored neither in the database nor in log files.
  • Of a request, only metadata is logged: time, key name, endpoint, status code and duration. These entries are deleted after seven days.
  • Statistics on triggered rules are kept as anonymous daily counts per rule code, with no link to a document or an account.
  • IP addresses are discarded in the website's usage analytics.

Transfer control

  • All connections to normapi.de, normapi.com and api.normapi.de are encrypted with TLS; unencrypted requests are redirected to HTTPS.
  • Browsers are instructed by HSTS to connect only over encryption for a year, including all subdomains.
  • API and database are connected over the hosting provider's private, WireGuard-encrypted network.
  • Invoice content is not passed on to third parties.

Input control

  • Every request made with an API key is logged with time, key, endpoint, status code and duration (kept seven days); daily usage counters per key serve billing and abuse control.
  • Changes to the system are versioned in source control and fully traceable.

Availability and resilience

  • Availability is monitored externally (UptimeRobot) and shown on a public status page.
  • Failed services are restarted automatically.
  • Rate limits per key or client and caps on concurrent validations and PDF renderings protect against overload; under load the API answers quickly with 503 and Retry-After instead of timing out.
  • Uploaded documents are limited to 5 MB.

Recoverability

  • Every deployed version is built from versioned source code and can be replaced by an earlier one within minutes if needed.

Regular testing and evaluation

  • Every change passes automated tests before it is deployed, including checks against the official KoSIT ruleset; nothing is deployed unless all tests pass.
  • Every generated invoice is validated against the ruleset before it is returned.
  • These measures are reviewed and updated at least once a year and whenever something significant changes.

Control of processing on instructions

  • Data is processed only on the controller’s instructions: what gets validated or generated is what the controller submits through the API or the website.
  • Sub-processors are bound by contract under Art. 28 GDPR; the current list is in annex 2.

Incident response

  • Security incidents and vulnerabilities can be reported at any time to kontakt@normapi.de.
  • In the event of a personal data breach, the processor informs the controller without undue delay, and no later than 48 hours after becoming aware of it.

Annex 2: Sub-processors

Engaged when this agreement is concluded and authorised under § 5(1):

  • Railway Corporation

    548 Market St PMB 68956, San Francisco, CA 94104, USA

    Purpose
    Hosting of the website, the API and the database. Invoices are processed there in memory and not stored.
    Location
    EU West region (Amsterdam, Netherlands)
    Safeguards
    Data processing agreement under Art. 28 GDPR; EU Standard Contractual Clauses, as the provider is based in the USA
  • Zoho Corporation B.V.

    Utrecht, Netherlands

    Purpose
    Mailbox for support and correspondence — involves your data only if you send us some by email.
    Location
    Data centres in the EU
    Safeguards
    Data processing agreement under Art. 28 GDPR; processing in the EU