Data Processing Agreement

Effective from: 6th of May, 2025

  • 1. Parties, scope and document priority

    1.1 This Data Processing Agreement (“DPA”) is between Stark Codes, s. r. o. (“Processor”) and the Lucanto Business User that determines purposes and means for personal data in its content (“Controller”). It takes effect when accepted at order, signed with an order, or otherwise demonstrably accepted.

    1.2 It applies only to **Customer Personal Data** processed by Processor on Controller’s behalf in providing Lucanto. It does not apply to a private Consumer or to account, billing, payment, security, own business communication and compliance data for which Stark Codes acts as controller. The Privacy Notice governs those activities.

    1.3 “GDPR” means Regulation (EU) 2016/679. “Customer Personal Data”, “processing”, “data subject”, “personal data breach” and related terms have their GDPR meanings. “**Subprocessor**” is another processor engaged by Processor for Customer Personal Data.

    1.4 For Customer Personal Data protection, this DPA prevails over general Terms. Standard Contractual Clauses prevail within their subject matter.

    2. Instructions and legal compliance

    2.1 Processor processes Customer Personal Data only on Controller’s documented instructions, including for third-country transfers, and only as needed to provide, secure, support and terminate the Service under the contract, settings and authorised requests.

    2.2 The contract, DPA, feature use, workspace configuration and proper support requests constitute documented instructions. An additional instruction beyond the Service may require agreement on cost and technical feasibility.

    2.3 If EU or Member State law requires processing beyond instructions, Processor informs Controller of the legal requirement before processing unless law prohibits notice for important public-interest reasons.

    2.4 Processor promptly informs Controller if it believes an instruction violates GDPR or other Union or Member State data-protection law. It may suspend the affected instruction until confirmed or amended.

    2.5 Controller is responsible for lawful instructions, data-subject information, legal basis, minimisation and Service configuration. It must avoid data not needed for the agreed purpose.

    3. Confidentiality and authorised personnel

    Processor ensures persons authorised to process Customer Personal Data are under contractual or statutory confidentiality, have need-based access, and receive appropriate privacy and security training.

    4. Security

    4.1 Processor maintains appropriate Article 32 GDPR technical and organisational measures, considering state of the art, cost, nature, scope, context, purposes and risks. The current minimum description is in Annex 2.

    4.2 Processor may change measures without materially decreasing overall protection. On request, it supplies information reasonably needed for assessment without exposing other customers’ data or undermining security.

    5. Subprocessors

    5.1 Controller gives general written authorisation for Annex 3 Subprocessors.

    5.2 At least **30 days** before adding or replacing a Subprocessor that will process Customer Personal Data, Processor notifies the workspace administrator by email and/or persistent in-Service notice of its name, country, purpose, data categories and relevant transfer mechanism. The current list always forms part of Annex 3 to this DPA; a separate Subprocessor page is not required. The administrator is responsible for keeping the notice address current in the account and may also notify a change at [hello@lucanto.eu](mailto:hello@lucanto.eu).

    5.3 Controller may object within that period for reasonable, documented data-protection grounds. The parties will seek a reasonable solution in good faith, such as a configuration avoiding the provider where technically and commercially feasible. If no solution is possible and the objection is justified, Controller may terminate the affected Service portion without penalty before the new Subprocessor starts; we refund the proportionate prepaid price for the unprovided part.

    5.4 Processor contracts with each Subprocessor on substantially equivalent data-protection duties and remains liable to Controller for its performance to the extent required by GDPR and the contract.

    5.5 In an urgent security or continuity case a provider may be engaged sooner, but Processor notifies without undue delay, explains why, and preserves a meaningful objection right.

    6. Data-subject rights

    6.1 If Processor receives a request concerning Customer Personal Data, it does not substantively respond without instruction except to acknowledge and direct the person to Controller, and promptly forwards it where law allows.

    6.2 Taking account of processing nature, Processor helps Controller by appropriate technical and organisational measures with Articles 12–22 GDPR. Standard self-service functions are included; unusual or extensive help may be charged at a reasonable pre-agreed price unless Processor caused the need.

    7. Personal data breach

    7.1 After becoming aware of a Customer Personal Data breach, Processor notifies Controller without undue delay.

    7.2 Based on available information, notice describes the nature, categories and approximate number of affected persons and records, likely consequences, measures taken or proposed, and contact point. Missing information follows in phases without undue further delay.

    7.3 Processor reasonably contains and remediates the incident and gives information needed for Controller’s Articles 33–34 obligations. Notice is not an admission of fault.

    8. DPIAs, consultations and compliance

    Taking account of processing nature and available information, Processor reasonably assists with data-protection impact assessments, prior supervisory consultation and Articles 32–36 GDPR duties.

    9. Audits and information

    9.1 Processor provides information necessary to demonstrate Article 28 compliance, prioritising current security documents, questionnaires, independent reports or certifications where available.

    9.2 If those are reasonably insufficient, Controller may audit itself or through an independent confidential auditor no more than once per 12 months and with 30 days’ notice. Frequency and notice limits do not apply after a serious incident, reasonable suspected breach or supervisory-authority request.

    9.3 Audit occurs during business hours, does not unreasonably disrupt operations, compromise security or expose other customers. Controller bears its and our reasonable costs unless the audit finds Processor’s material DPA breach.

    10. Transfers outside the EEA

    10.1 Processor does not transfer Customer Personal Data outside the EEA without a GDPR Chapter V mechanism and imposes the same duty on Subprocessors.

    10.2 Where no adequacy decision applies, relevant parties execute current European Commission Standard Contractual Clauses with the correct module. Processor conducts an appropriate transfer assessment and supplementary measures and supplies safeguard information on request with lawful redactions.

    10.3 Where SCCs apply directly between Controller as exporter and Stark Codes as importer, they are incorporated and completed using this DPA and annex information. SCCs prevail on conflict.

    11. Return and deletion

    11.1 At Service end, Processor at Controller’s choice enables reasonable export and then returns or erases Customer Personal Data and deletes copies, unless law requires storage.

    11.2 If Controller does not choose, Processor erases. Erasure from active systems and backups is completed within **45 days** after effective account deletion or affected Service termination. Backups remain isolated and protected against ordinary processing until then.

    11.3 This does not cover data Stark Codes must retain as controller for accounting, tax, legal or security obligations; it is not used to continue customer Service.

    12. Duration, liability and changes

    12.1 The DPA continues while Processor handles Customer Personal Data. Confidentiality, deletion and audit of past processing survive as appropriate.

    12.2 Liability follows GDPR and the agreed Terms. No contractual cap restricts data-subject rights or supervisory powers or applies where mandatory law prohibits it.

    12.3 We give at least 30 days’ notice of a material DPA change. If existing legal grounds or Subprocessor authorisation do not validly cover a replacement DPA or OpenAI, the workspace administrator must demonstrably accept it before AI processing continues. AI extraction for that workspace is paused until acceptance.

  • Annex 1 — Processing details

Controller

Description

Controller

Business customer and contact details shown in the order, account or signed contract

Subject

Lucanto cloud service including document records, team collaboration, integrations, support and optional AI extraction

Duration

Contract term plus no more than 45 days for erasure, except legal retention

Operations

receipt, recording, organisation, structuring, storage, viewing, retrieval, automated extraction, correction, instructed transmission, support, export, restriction and erasure

Purpose

provide Controller-selected features and support, protect the Service and carry out documented instructions

Data subjects

Controller’s customers, suppliers, counterparties, contacts, employees, contractors, Team Members and other persons in its documents

Data

identity/contact, business identifiers, billing and bank/transaction data, OAuth identifiers, items, amounts, dates, bank details, document content, bug-report and AI-extraction metadata, work notes, audit, network and technical data

Special data

not intentionally required; may incidentally appear. Controller must minimise it and ensure a legal basis

Frequency

continuously according to use and Controller’s instructions

  • Annex 2 — Technical and organisational measures

    These are Processor's minimum commitments:

    1. Governance: assigned security responsibilities, recurring risk review, system/provider inventory, joiner and leaver process.

    2. Access: individual accounts, least privilege, roles, recurring privileged-access review, and MFA for privileged/admin systems.

    3. Encryption: TLS in transit; appropriate encryption at rest and key management.

    4. Separation: logical workspace and environment separation; no production data in test without necessity and appropriate safeguards.

    5. Development: change and code review, secret management, dependency control, testing and risk-based vulnerability remediation.

    6. Logging/monitoring: access-restricted audit, application and security logs; incident detection and appropriate alerts; passwords, tokens, cookies, full payment details and document content are filtered from logs and error events. The Better Stack browser tag, including frontend monitoring and session replay, is activated only after the relevant consent; sensitive inputs and documents are masked or excluded, and unnecessary analytics, autocapture and fingerprinting remain disabled.

    7. Availability: backups, tested recovery, continuity planning and reasonable loss/corruption protection.

    8. Incidents: documented identification, containment, investigation, remediation and breach-notification process.

    9. Minimisation/retention: export and deletion functions, 45-day post-deletion completion, limited log periods and recurring cleanup.

    10. People/providers: confidentiality, training, due diligence, DPAs and Subprocessor oversight.

    11. Physical security: appropriate data-centre controls and restricted physical access.

    12. Testing: recurring effectiveness review and risk-prioritised remediation.

  • Príloha 3 — Sub-sprostredkovatelia

Subprocessor

Country / processing

Service and scope

Transfer mechanism

OpenAI Ireland Ltd. and approved subprocessors

Ireland; possible processing outside EEA

document AI extraction, prompt, output and technical metadata; under standard settings, abuse-monitoring logs for up to 30 days, and longer only where required by law or reasonably necessary to protect OpenAI's services or third parties from harm

adequacy decision or SCCs under the OpenAI DPA

Cloudflare, Inc. and approved subprocessors

global network; possible non-EEA processing

reverse proxy/CDN, DDoS and Turnstile; IP, TLS fingerprint, user-agent, URL/headers and customer data transmitted through `app.lucanto.eu`

DPF where applicable, otherwise SCCs under Cloudflare DPA

Render Services, Inc.

EEA, USA and countries of Render suppliers

reverse proxy/CDN, DDoS and Turnstile; IP, TLS fingerprint, user-agent, URL/headers and customer data transmitted through `app.lucanto.eu`

DPF where applicable, otherwise SCCs under Cloudflare DPA

Hetzner Online GmbH

Germany or Finland |

Object Storage for all attachments, including invoices, receipts and contracts

processing in the EEA

Better Stack, Inc.

EEA and USA

server-side logs including IP address, backend errors, stack trace, path without query string and minimised internal identifiers; browser tag, frontend monitoring and session replay only after consent, with sensitive inputs and documents masked or excluded

adequacy decision where applicable, otherwise SCCs under the Better Stack DPA

Linear Orbit, Inc.

USA

bug report: reporter name/email, workspace legal name/company ID and failed-AI-extraction metadata; a document is sent only on the User's separate instruction

DPF where applicable, otherwise SCCs under Linear DPA

Plus Five Five, Inc. (Resend)

USA

transactional/service email, name, email, language, account/plan state and minimised message content

SCCs under Resend DPA |

Simple Casual, LLC (Logo.dev)

USA

counterparty name/domain, IP, time and technical logo-request data

SCC Modules 2/3 under Logo.dev DPA

Not Subprocessors for Customer Personal Data:** Loops handles Stark Codes marketing; Stripe and Tatra banka act as independent controllers for regulated activities and otherwise handle account/payment data for which Stark Codes is controller; Google and Apple provide optional sign-in. Google Tag Manager, Google Fonts, jsDelivr and UNPKG are used for Stark Codes' own controller processing and are listed in the Privacy Notice. If a purpose or data flow changes so that one begins processing Customer Personal Data on Stark Codes' behalf, it will be added to this Annex under Article 5 before that change.