Legal · GDPR

Data Processing Agreement (DPA)

Governs the processing of personal data that Codificado SL carries out on the Customer's behalf, under Article 28 of the GDPR.

Last updated: July 23, 2026

This Data Processing Agreement (the "DPA") forms an integral part of the Cofactu terms of service and governs the processing of personal data that Codificado SL (the "Processor") carries out on the Customer's behalf (the "Controller") in the course of providing the Service, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

This DPA is particularly relevant where the Customer is an accounting firm or business that processes third-party data (its own clients, employees or suppliers) through Cofactu. In that case, the Customer acts as Controller (or Processor, vis-à-vis its end clients) and Cofactu as Processor (or Sub-processor).

1. Subject matter and duration

The Processor will process personal data on the Controller's behalf solely to provide the contracted Service. The duration of the processing matches the term of the contractual relationship; upon its end, clause 8 applies.

2. Nature and purpose of processing

Processing operations: collection, recording, structuring, storage, retrieval, use, disclosure (to the Spanish Tax Agency and other recipients necessary for the Service) and erasure. Purpose: providing the electronic invoicing, accounting and tax-management platform and associated features.

3. Types of data and categories of data subjects

  • Types of data: identification and contact data (name, tax ID, address, email, phone), financial and billing data, tax and accounting data. No special categories of data (Art. 9 GDPR) are processed by design.
  • Categories of data subjects: the Controller's clients, suppliers, employees and contacts, as well as the end clients of accounting firms.

4. Controller's obligations and instructions

The Controller determines the purposes and means of processing and warrants that it has a legal basis to provide the data to the Processor. The Processor will process the data only on the Controller's documented instructions, including those arising from use of the Service, unless required by law (in which case it will inform the Controller, where legally permitted).

5. Processor's obligations

  • Confidentiality: personnel authorised to process the data are bound by a duty of confidentiality.
  • Security (Art. 32 GDPR): the Processor applies appropriate technical and organisational measures: encryption in transit and at rest, role-based access control, multi-tenant isolation, audit logging, backups and hosting within the European Union. Details at cofactu.com/seguridad.
  • Assistance: the Processor assists the Controller, as far as possible, in responding to data subject rights requests (access, rectification, erasure, portability, etc.) and in complying with the obligations of Articles 32 to 36 (security, breach notification, impact assessments and prior consultations).
  • Breach notification: the Processor will notify the Controller without undue delay of any personal data breach it becomes aware of, with the information needed for the Controller to meet its notification obligations (Articles 33 and 34 GDPR).
  • Records of processing: the Processor maintains the record of processing activities required by Art. 30.2 GDPR.

6. Sub-processors

The Controller generally authorises the Processor to engage the sub-processors listed below to provide the Service. All of them are bound by data protection obligations equivalent to those in this DPA.

Sub-processorPurposeLocation
CloudflareHosting and CDNEU
NeonPostgreSQL databaseEU (eu-central-1, Frankfurt)
StripePayment processingEU / US (SCC)
ResendTransactional emailUS (SCC)
SentryError monitoringUS (SCC)
PostHogProduct analytics (consent only)EU
AnthropicAI assistantUS (SCC)

The Processor will inform the Controller of any intended addition or replacement of sub-processors, giving it the opportunity to object on reasonable grounds before the new sub-processor processes data on the Controller's behalf (Art. 28.2 GDPR). The current version of this list is published on this page.

7. International transfers

The primary hosting and database are located within the European Union. Where a sub-processor processes data outside the European Economic Area, that transfer relies on an adequacy decision or on the Standard Contractual Clauses (SCC) approved by the European Commission, together with any appropriate supplementary measures. For the AI assistant (Anthropic), no identifying data of the Controller's end clients is transmitted with queries.

8. Return or deletion on termination

On termination of the Service, the Processor will, at the Controller's choice, return or delete the personal data, except data whose retention is required by Union or Spanish law (in particular, tax retention of invoices and VeriFactu records for the legal periods). The Controller can export its data from the Service at any time (invoicing export + per-module exports) and request a complete copy at privacidad@cofactu.com.

9. Audit

The Processor will make available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and will allow and contribute to audits, including inspections, conducted by the Controller or a mandated auditor, with reasonable notice and without compromising the security or confidentiality of other customers (Art. 28.3.h GDPR).

10. Liability

The parties' liability for breach of data protection obligations is governed by Article 82 of the GDPR and by the terms of service.

11. Execution

This DPA is deemed accepted upon contracting the Service. Controllers requiring a signed DPA (with handwritten or electronic signature) may request one at privacidad@cofactu.com, stating the company name and tax ID.

Questions about this DPA: privacidad@cofactu.com · Data protection contact at Codificado SL.

Ready to invoice without the headaches?

Start free or browse the plans. Your first VeriFactu invoice in under 10 minutes.

No card requiredCancel in 1 clickExport anytime