Last updated: September 22, 2026 · Version: 2026-09-22
This Data Processing Agreement (the "DPA") forms an integral part of the Cofactu terms of service and governs the processing of personal data that Codificado SL (the "Processor") carries out on the Customer's behalf (the "Controller") in the course of providing the Service, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
This DPA is particularly relevant where the Customer is an accounting firm or business that processes third-party data (its own clients, employees or suppliers) through Cofactu. In that case, the Customer acts as Controller (or Processor, vis-à-vis its end clients) and Cofactu as Processor (or Sub-processor).
1. Subject matter and duration
The Processor will process personal data on the Controller's behalf solely to provide the contracted Service. The duration of the processing matches the term of the contractual relationship; upon its end, clause 9 applies.
2. Nature and purpose of processing
Processing operations: collection, recording, structuring, storage, retrieval, use, disclosure (to the Spanish Tax Agency and other recipients necessary for the Service) and erasure. Purpose: providing the electronic invoicing, accounting, tax-management and transport-documentation platform (DeCA, e-CMR and proof of delivery) and associated features.
3. Types of data and categories of data subjects
- Types of data: identification and contact data (name, tax ID, address, email, phone), financial and billing data, tax and accounting data; where the Controller uses Logistics, transport data, signers' identity and representation, technical signing evidence, recipient name and signature, delivery photographs and geolocation; and, where it uses payroll and staff management, employment and pay data, working time and absences.
- Special categories (Art. 9 GDPR): the Service is not designed to process them generally, but the employment modules may incorporate them when the Controller enters them: absences for temporary incapacity, maternity or paternity leave reveal health data, and certain payroll items may reveal trade union membership. A handwritten POD signature is processed as an image of acknowledgement: its dynamics are not extracted and no biometric template is created. The Controller determines what data it enters and warrants that it has a legal basis.
- Categories of data subjects: the Controller's clients, suppliers, employees and contacts, end clients of accounting firms and, where Logistics is used, transport parties and signers, drivers and goods recipients.
4. Controller's obligations and instructions
The Controller determines the purposes and means of processing and warrants that it has a legal basis to provide the data to the Processor. The Processor will process the data only on the Controller's documented instructions, including those arising from use of the Service, unless required by law (in which case it will inform the Controller, where legally permitted).
5. Processor's obligations
- Confidentiality: personnel authorised to process the data are bound by a duty of confidentiality.
- Security (Art. 32 GDPR): the Processor applies appropriate technical and organisational measures: encryption in transit and at rest, role-based access control, multi-tenant isolation, audit logging, backups and hosting within the European Union. Details at cofactu.com/seguridad.
- Assistance: the Processor assists the Controller, as far as possible, in responding to data subject rights requests (access, rectification, erasure, portability, etc.) and in complying with the obligations of Articles 32 to 36 (security, breach notification, impact assessments and prior consultations).
- Breach notification: the Processor will notify the Controller without undue delay of any personal data breach it becomes aware of, with the information needed for the Controller to meet its notification obligations (Articles 33 and 34 GDPR).
- Warning about unlawful instructions: the Processor will immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions (Art. 28.3, last paragraph, GDPR).
6. Sub-processors
The Controller generally authorises the Processor to engage the sub-processors listed below to provide the Service. The Processor requires sufficient guarantees from each sub-processor under Art. 28.4 GDPR so as to flow down data protection obligations equivalent to those in this DPA, and remains liable to the Controller for its sub-processors' compliance with their data protection obligations.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting, CDN, file storage and abuse protection. Since August 2026 it also operates the service that transmits invoicing records to the AEAT, and therefore processes the invoice content and, where applicable, the digital certificate during submission | EU |
| Neon | PostgreSQL database | EU (eu-central-1, Frankfurt) |
| Stripe | Payment processing | EU / US (SCC) |
| Resend | Transactional email | US (SCC) |
| Twilio | SMS and WhatsApp delivery (only if the Controller enables the feature) | EU (Ireland) |
| Sentry | Error monitoring | US (SCC) |
| PostHog | Product analytics (consent only) | EU |
| Google (Gemini API) | Language model for the assistant and automatic document reading | US (SCC / DPF) |
| Voyage AI | Indexing of the tax knowledge base; receives only the text of the query | US (SCC) |
| Google Wallet | Issuance of digital loyalty cards (only if the Controller offers them) | US (SCC / DPF) |
The Processor will inform the Controller of any intended addition or replacement of sub-processors, giving it the opportunity to object on reasonable grounds before the new sub-processor processes data on the Controller's behalf (Art. 28.2 GDPR). The current version of this list is published on this page.
7. Data processed by the artificial intelligence providers
The assistant and automatic document reading (OCR) transmit to the AI provider the information needed to resolve each request: the text of the query, the results of the searches the assistant runs against the Controller's data (names and tax IDs of clients and suppliers, amounts, due dates, balances), the content of documents uploaded or received in the expense inbox and, in the payroll module, the payslip data, including the employee's name, tax ID and amounts.
These sub-processors process the data solely to return the result of the request and, under their terms for paid API customers, do not use it to train their models. These are optional features: if the Controller does not use them, no information is transmitted to these sub-processors.
8. International transfers
The primary hosting and database are located within the European Union. Where a sub-processor processes data outside the European Economic Area, that transfer relies on an adequacy decision or on the Standard Contractual Clauses (SCC) approved by the European Commission, together with any appropriate supplementary measures.
Third-country governmental access (Articles 28 and 32 of Regulation (EU) 2023/2854, the "Data Act"): the Processor takes reasonable technical, organisational and contractual measures to prevent access to, or transfer of, non-personal data held in the Union where that would conflict with Union or Member State law. If a third-country authority requests access, the Processor will verify the legal basis of the request, challenge it where appropriate, limit any disclosure to the minimum permissible, and inform the Controller before granting access unless expressly prohibited by law.
9. Return or deletion on termination
On termination of the Service, the Processor will, at the Controller's choice, return or delete the personal data, except data whose retention is required by Union or Spanish law (in particular, tax retention of invoices and VeriFactu records for the legal periods). The Controller can export its data from the Service at any time (invoicing export + per-module exports) and request a complete copy at privacidad@cofactu.com. After the transition period in the Terms, the Processor will maintain an additional minimum 30-calendar-day retrieval period and will then erase or block the data in accordance with the Controller's instruction and applicable statutory duties.
Transport control documents (DeCA). On the Controller's instruction and in compliance with the Resolution of the Spanish Directorate-General for Road Transport of 5 June 2026, the Processor generates the PDF containing the data listed in article 6 of Order FOM/2861/2012 and makes it available through a direct download link without authentication, protected by a random identifier. The file is retained for the Processor's custody period — twelve months from the later of the issue of the last version and the effective end of the transport, on top of the one-year statutory minimum in Art. 9 of the Order —, including after termination of this agreement, because it contains data of the other party to the transport contract and both parties must be able to produce it to the inspection authorities; within that period, certain data may be retained even if an erasure request is received, to the extent the processing remains necessary for that legal obligation (Art. 17(3)(b) GDPR). Availability of the link is independent of retention: the Processor may disable or replace it seven days after the service ends or for security or compliance reasons. Public access logs record only the date, the document and its version. The IP address is processed temporarily and solely for security — preventing automated bulk downloading — and kept for at most ten minutes from the last request.
10. Audit
The Processor will make available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and will allow and contribute to audits, including inspections, conducted by the Controller or a mandated auditor, with reasonable notice and without compromising the security or confidentiality of other customers (Art. 28.3.h GDPR).
11. Liability
The parties' liability for breach of data protection obligations is governed by Article 82 of the GDPR and by the terms of service.
12. Execution
This DPA is deemed accepted upon contracting the Service. Controllers requiring a signed DPA (with handwritten or electronic signature) may request one at privacidad@cofactu.com, stating the company name and tax ID.
Questions about this DPA: privacidad@cofactu.com (privacy contact at Codificado SL).