Last updated: July 23, 2026
This Data Processing Agreement (the "DPA") forms an integral part of the Cofactu terms of service and governs the processing of personal data that Codificado SL (the "Processor") carries out on the Customer's behalf (the "Controller") in the course of providing the Service, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
This DPA is particularly relevant where the Customer is an accounting firm or business that processes third-party data (its own clients, employees or suppliers) through Cofactu. In that case, the Customer acts as Controller (or Processor, vis-à-vis its end clients) and Cofactu as Processor (or Sub-processor).
1. Subject matter and duration
The Processor will process personal data on the Controller's behalf solely to provide the contracted Service. The duration of the processing matches the term of the contractual relationship; upon its end, clause 8 applies.
2. Nature and purpose of processing
Processing operations: collection, recording, structuring, storage, retrieval, use, disclosure (to the Spanish Tax Agency and other recipients necessary for the Service) and erasure. Purpose: providing the electronic invoicing, accounting and tax-management platform and associated features.
3. Types of data and categories of data subjects
- Types of data: identification and contact data (name, tax ID, address, email, phone), financial and billing data, tax and accounting data. No special categories of data (Art. 9 GDPR) are processed by design.
- Categories of data subjects: the Controller's clients, suppliers, employees and contacts, as well as the end clients of accounting firms.
4. Controller's obligations and instructions
The Controller determines the purposes and means of processing and warrants that it has a legal basis to provide the data to the Processor. The Processor will process the data only on the Controller's documented instructions, including those arising from use of the Service, unless required by law (in which case it will inform the Controller, where legally permitted).
5. Processor's obligations
- Confidentiality: personnel authorised to process the data are bound by a duty of confidentiality.
- Security (Art. 32 GDPR): the Processor applies appropriate technical and organisational measures: encryption in transit and at rest, role-based access control, multi-tenant isolation, audit logging, backups and hosting within the European Union. Details at cofactu.com/seguridad.
- Assistance: the Processor assists the Controller, as far as possible, in responding to data subject rights requests (access, rectification, erasure, portability, etc.) and in complying with the obligations of Articles 32 to 36 (security, breach notification, impact assessments and prior consultations).
- Breach notification: the Processor will notify the Controller without undue delay of any personal data breach it becomes aware of, with the information needed for the Controller to meet its notification obligations (Articles 33 and 34 GDPR).
- Records of processing: the Processor maintains the record of processing activities required by Art. 30.2 GDPR.
6. Sub-processors
The Controller generally authorises the Processor to engage the sub-processors listed below to provide the Service. All of them are bound by data protection obligations equivalent to those in this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting and CDN | EU |
| Neon | PostgreSQL database | EU (eu-central-1, Frankfurt) |
| Stripe | Payment processing | EU / US (SCC) |
| Resend | Transactional email | US (SCC) |
| Sentry | Error monitoring | US (SCC) |
| PostHog | Product analytics (consent only) | EU |
| Anthropic | AI assistant | US (SCC) |
The Processor will inform the Controller of any intended addition or replacement of sub-processors, giving it the opportunity to object on reasonable grounds before the new sub-processor processes data on the Controller's behalf (Art. 28.2 GDPR). The current version of this list is published on this page.
7. International transfers
The primary hosting and database are located within the European Union. Where a sub-processor processes data outside the European Economic Area, that transfer relies on an adequacy decision or on the Standard Contractual Clauses (SCC) approved by the European Commission, together with any appropriate supplementary measures. For the AI assistant (Anthropic), no identifying data of the Controller's end clients is transmitted with queries.
8. Return or deletion on termination
On termination of the Service, the Processor will, at the Controller's choice, return or delete the personal data, except data whose retention is required by Union or Spanish law (in particular, tax retention of invoices and VeriFactu records for the legal periods). The Controller can export its data from the Service at any time (invoicing export + per-module exports) and request a complete copy at privacidad@cofactu.com.
9. Audit
The Processor will make available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and will allow and contribute to audits, including inspections, conducted by the Controller or a mandated auditor, with reasonable notice and without compromising the security or confidentiality of other customers (Art. 28.3.h GDPR).
10. Liability
The parties' liability for breach of data protection obligations is governed by Article 82 of the GDPR and by the terms of service.
11. Execution
This DPA is deemed accepted upon contracting the Service. Controllers requiring a signed DPA (with handwritten or electronic signature) may request one at privacidad@cofactu.com, stating the company name and tax ID.
Questions about this DPA: privacidad@cofactu.com · Data protection contact at Codificado SL.