Accordix
Prihlásiť sa

Verzia: 1.2 Účinné od: 2026-07-12 Naposledy aktualizované: 2026-07-12

Data Processing Agreement

1. Applicability

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer and Anton Desiatnykov ("Accordix"). It applies where Accordix processes Customer Personal Data on the Customer's behalf. If this DPA conflicts with the Terms on personal-data processing, this DPA prevails.

2. Definitions

GDPR terms have the meanings given in Regulation (EU) 2016/679. "Customer Personal Data" means personal data within Customer Content processed by Accordix on the Customer's behalf. "Subprocessor" means a third party engaged by Accordix to process Customer Personal Data.

3. Roles

For Customer Personal Data, the Customer is the controller or a processor acting for another controller, and Accordix is the processor or subprocessor as applicable. Accordix acts as an independent controller for limited account, authentication, security, contractual, support and business-administration data described in the Privacy Policy.

Where the Customer acts as a processor for its own client, the Customer confirms that it is authorised to appoint Accordix as a subprocessor and to issue the instructions described in this DPA.

4. Subject matter and duration

The subject matter is the provision of Accordix's document-collection, shared-inbox, workflow, communication, extraction and optional AI-assisted features. Processing continues for the Customer's use of the Service and the deletion or return period described below.

5. Nature and purposes of processing

Accordix may collect, receive, store, organise, structure, extract, display, transmit, retrieve, export, restrict and delete Customer Personal Data to provide the Service. Depending on Customer configuration and use, this includes:

  • web upload, storage, review and workflow tracking;
  • inbound and outbound email needed for document collection and reminders;
  • inbound WhatsApp messages and attachments through the WhatsApp Business Platform;
  • local text extraction and classification;
  • AI-assisted invoice extraction through Google Cloud Vertex AI;
  • AI-assisted bank-statement and transaction extraction through Google Cloud Vertex AI;
  • AI-assisted suggestions of potentially missing linked documents through Google Cloud Vertex AI;
  • assisted export, support, security investigation and deletion.

AI output is assistive and must be reviewed by an authorised person. Accordix does not use it to make decisions producing legal or similarly significant effects about a data subject.

6. Data subjects

Data subjects may include Customer users, accountants, Customer clients, client representatives, employees, contractors, suppliers, customers, payers, payees and other individuals identified in accounting or business documents and communications.

7. Personal-data categories

Data may include names, email addresses, telephone numbers, addresses, usernames, company and tax identifiers, bank account numbers and IBANs, invoice and receipt data, payment and transaction information, document contents, message content and metadata, workflow status, timestamps, technical identifiers and support communications.

8. Sensitive data

Accordix is not designed for the intentional collection of special-category data, biometric data for identification, criminal-offence data, medical records or similarly high-risk material unless agreed in writing. The Customer must not use Accordix for such data without an appropriate legal basis, documented risk assessment and any required agreement with Accordix.

9. Instructions

The Terms, this DPA, the Customer's workspace configuration, use of an intake channel, initiation of AI analysis, support requests and other written directions constitute documented instructions. Enabling or initiating an AI feature instructs Accordix to transmit the selected document to Google Cloud Vertex AI for the stated purpose. Using an enabled WhatsApp channel instructs Accordix to receive and process the resulting WhatsApp messages and attachments.

Accordix will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law, unless prohibited by law. The Customer is responsible for the lawfulness, accuracy, transparency, minimisation and retention of Customer Personal Data and for providing required notices to its clients and other data subjects.

10. Processor obligations

Accordix will process Customer Personal Data only on documented instructions; ensure authorised persons are subject to confidentiality; implement measures appropriate to risk; assist with data-subject requests, security, breach obligations and DPIAs; maintain required processor records; and delete or return data as described in this DPA.

11. Security

Accordix's current measures include HTTPS/TLS, bcrypt password hashing, signed HttpOnly authentication cookies, permission checks, role-based access, logical organisation separation, secrets in environment configuration, login throttling, provider-managed infrastructure controls and limited operational logging. Current limitations are disclosed on the Security page, including no MFA, no application-managed field or file encryption at rest, and no complete end-user audit trail.

12. Subprocessors

The Customer gives general authorisation for subprocessors listed on the Subprocessors page. Accordix will impose applicable data-protection obligations and remains responsible for its own obligations under this DPA.

Accordix will provide at least 30 days' advance notice by email or another durable method where reasonably practicable before a new subprocessor begins materially processing Customer Personal Data. The Customer may object during that period on reasonable data-protection grounds. If the objection cannot reasonably be resolved, the Customer may terminate the affected part of the Service before that subprocessor begins processing.

13. International transfers

The primary application deployment is intended for the EU. Where Customer Personal Data is transferred outside the EU/EEA, Accordix will rely on an applicable adequacy decision, the European Commission Standard Contractual Clauses, or another lawful safeguard. EU data residency does not necessarily exclude all global support, security, telemetry or corporate access by a provider.

The Customer authorises Accordix to enter into appropriate Standard Contractual Clauses with subprocessors as necessary for the processing covered by this DPA.

14. Data-subject requests

Taking account of the nature of processing, Accordix will provide reasonable assistance to help the Customer respond to requests for access, rectification, erasure, restriction, portability and objection. If a data subject contacts Accordix about Customer Personal Data, Accordix will normally refer the request to the Customer unless legally required to respond directly.

15. Security assistance and breaches

Accordix will provide reasonable assistance with security obligations, breach assessment and notification, DPIAs and prior consultation, taking account of the processing and information available.

Accordix will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. Where reasonably possible, the notice will describe the nature of the breach, affected data and people, likely consequences, mitigation and available contact information. Initial information may be provided in phases.

16. Return and deletion

During the Service, the Customer may request an assisted export of Customer Content in original and reasonably available structured formats.

Following termination, Accordix normally permits an export request for up to 30 days and then deletes or anonymises active Customer data, unless the Customer requests earlier deletion, a different period is agreed, or retention is required by law. Deletion is currently an assisted operational process rather than a guaranteed self-service workflow.

Residual copies may remain in provider-managed backups until expiry or overwrite under the provider's then-current lifecycle. Accordix does not guarantee that all backup copies are removed within a fixed 35-day period. Backups are not ordinarily restored to recover individual deleted records and remain protected while retained.

The Customer remains responsible for keeping copies required by accounting, tax, payroll or other record-retention laws before requesting deletion.

17. Audits and information

Accordix will make information reasonably necessary to demonstrate compliance available to the Customer and will allow reasonable audits subject to confidentiality, security, scope and notice requirements. Audits are normally limited to once per 12 months unless required by a supervisory authority, a material breach has occurred, or another compelling compliance reason exists.

18. Liability and precedence

Liability is subject to the Terms except where mandatory law provides otherwise. Nothing limits data-subject rights or liability that cannot lawfully be limited. This DPA prevails over conflicting Terms provisions on Customer Personal Data.


Annex 1 - Processing details

Item Detail
Subject matter Accordix document collection, shared inbox, workflow, communications, extraction, AI assistance, hosting, support, export and deletion
Duration Service term plus the applicable export, deletion and backup-expiry period
Nature Collection, receipt, storage, organisation, extraction, transmission, display, retrieval, export, restriction and deletion
Purposes Collecting and reviewing accounting-support documents; managing requests and reminders; receiving email and WhatsApp intake; extracting invoice and bank-statement data; suggesting missing linked documents; operating and securing the Service
Data subjects As described in section 6
Personal data As described in section 7, including complete document files submitted for AI processing
Frequency Continuous for hosting and workflow; event-driven for intake, export and AI analysis
AI subprocessors Google Cloud Vertex AI in the eu multi-region for invoice extraction, bank-statement extraction and linked-document suggestions where instructed
Communication subprocessors CloudMailin for email and Meta/WhatsApp Business Platform for WhatsApp intake where used

Annex 2 - Technical and organisational measures

  • HTTPS/TLS for network transport.
  • Salted bcrypt password hashes.
  • Signed HttpOnly authentication cookie and production Secure-cookie configuration.
  • Login throttling and verification-email throttling.
  • Role and permission checks with logical organisation separation.
  • Secrets stored in managed environment configuration rather than source files.
  • Path and upload-size validation in the application.
  • Restricted inline previews for supported formats.
  • Provider-managed infrastructure protections and backup processes.
  • Confidentiality and need-to-know production access.
  • Incident-response and breach-notification process.
  • Current limitations disclosed publicly: no MFA, no self-service password reset, no complete end-user audit trail, no application-level encryption at rest, and no signed or time-limited download URLs.

Annex 3 - Subprocessors

The current Subprocessors page, including provider purpose, data categories, location and safeguards, is incorporated into this DPA by reference.

Accordix

Accordix je priestor na zber dokladov. Neposkytuje účtovné, daňové ani právne poradenstvo.

Postupy zohľadňujúce GDPR

Právne informácie Zásady ochrany osobných údajov Podmienky používania Zmluva o spracúvaní údajov Subsprostredkovatelia Zásady používania súborov cookie
Dôvera Bezpečnosť Export a vymazanie údajov

© 2026 Accordix

Prihlásiť sa