Data Processing Agreement
This Agreement supplements the Privacy Policy and Terms of Service and applies whenever you enter YOUR OWN CLIENTS' personal data into Paperwork — in that case, under the GDPR (Regulation (EU) 2016/679), you act as the data controller and Paperwork acts as the data processor.
Last updated: September 2, 2026 (2026-09-02)
1. Subject, Parties and Roles
When you use the client records, document, or invoicing features, you (the "Controller") decide WHICH personal data of your clients (data subjects) to enter and for what purpose. Kęstutis Skrebė (the "Processor" or "Paperwork") processes this data EXCLUSIVELY on your behalf and on your instructions, acting as a data processor under GDPR Art. 4(8) and Art. 28. This Agreement applies automatically to every User from the moment registration is confirmed — no separate paper signature is required.
2. Subject Matter, Nature, Purpose and Duration of Processing
The Processor processes data subjects' personal data ONLY for the purpose of providing the Service — following the Controller's instructions as expressed through the system's features (filling in client records, creating and sending estimates/contracts/invoices for signature, accounting data). Nature of processing: automated storage, display, document generation and delivery. Processing continues for the full duration of Service use and ends as set out in Section 8.
3. Categories of Data Subjects and Data
This Agreement covers:
- Data subjects: the Controller's clients, with whom estimates, contracts or invoices are created.
- Data categories: name, surname or company name, email address, phone number, address, VAT/company registration code (for corporate clients), and data related to services provided (order, invoice and contract content).
- The system is not designed to process special categories of data (GDPR Art. 9 — health, religion, political opinions, etc.); the Controller undertakes not to enter such data into the system.
4. Processor's Obligations
The Processor undertakes to:
- Process data ONLY on the Controller's instructions, within the bounds of the system's functionality, and never for its own or third parties' purposes.
- Ensure that employees or contractors with access to the data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures (see Section 6).
- Engage another processor (sub-processor) only in accordance with Section 5.
- Assist the Controller in responding to data subject requests and in reporting personal data breaches (see Section 7).
- Upon termination of Service use, act in accordance with Section 8 and, upon reasonable request, provide the Controller with information necessary to demonstrate compliance with this Agreement.
5. Sub-processors
The Controller agrees that the Processor may engage the sub-processors listed in Section 5 of the Privacy Policy, as necessary to provide the Service. BEFORE actually transferring data subjects' data to a new sub-processor, or to one not yet active in the production environment, the Processor undertakes to put in place a written agreement compliant with GDPR Art. 28, ensuring a level of data protection no lower than set out in this Agreement. Current status: the infrastructure and payment sub-processors operate in production under standing commercial terms; the qualified signature provider (Dokobit) is used TODAY ONLY in a sandbox/test environment and does not receive any real data subjects' data until a separate production agreement is signed; the AI language model provider (OpenAI) operates under its own published standard data processing terms, and the status of an individual GDPR Art. 28 agreement with it is currently being verified. The Controller is notified in advance (by email or an in-app notice) of any new sub-processor, its activation in production, or any change; if the Controller does not raise a reasoned objection in writing within 14 days of notice, the change is deemed accepted. Privacy Policy
6. Security Measures
The Processor applies industry-standard technical and organizational measures: data in transit is encrypted (TLS/HTTPS), access to the production environment is restricted and logged, passwords are stored only as cryptographic hashes, software is kept up to date, and regular data backups are performed. Further details on the security measures applied are provided to the Controller upon reasonable request.
7. Assistance with Data Subject Rights and Breach Notification
Upon receiving a data subject request directly related to data processed on the Controller's behalf, the Processor promptly forwards it to the Controller and, to the extent technically possible, assists in fulfilling it through the system's features (viewing, editing, deletion, export). Upon becoming aware of a personal data breach affecting data processed on the Controller's behalf, the Processor notifies the Controller without undue delay, and no later than 48 hours after becoming aware of it, providing the information available on the nature, likely impact, and measures taken.
8. End of Processing
Today, closing one's own account (via the "Close account" option on the profile page) removes that individual user's own access and anonymizes their own account data (name, email, contact details); the Controller's clients (data subjects) and other organization-level data that is not part of an accounting document are NOT anonymized by this action. Data subjects' data already recorded in accounting documents (invoices, contracts) continues to be retained for the period required by law (up to 10 years in Lithuania, see Section 4 of the Privacy Policy) REGARDLESS of the termination of this Agreement — the basis for this retention is a legal obligation binding on the Processor (GDPR Art. 6(1)(c)), not this Agreement. A full organization closure flow that would anonymize the Controller's remaining client data not held in accounting documents is NOT YET IMPLEMENTED — it depends on a reliable ownership (organization-level) model currently being developed. Until it exists, such removal can be requested directly by contacting the Processor at the email address given in Section 1. Before ending use of the Service, the Controller may at any time obtain a copy of all data processed on their behalf using the data export feature on the profile page.
9. Controller's Responsibility
The Controller is responsible for ensuring that their clients' personal data entered into the system is collected and processed on a lawful basis (e.g., contract performance or legitimate interest), and that data subjects are properly informed about the processing of their data. The Processor is not responsible for the lawfulness, accuracy, or circumstances of collection of data supplied by the Controller — the Processor only technologically processes the data on the Controller's instructions.