1. Parties, scope and document priority
1.1 This Data Processing Agreement (“DPA”) is between Stark Codes, s. r. o. (“Processor”) and the Lucanto Business User that determines purposes and means for personal data in its content (“Controller”). It takes effect when accepted at order, signed with an order, or otherwise demonstrably accepted.
1.2 It applies only to **Customer Personal Data** processed by Processor on Controller’s behalf in providing Lucanto. It does not apply to a private Consumer or to account, billing, payment, security, own business communication and compliance data for which Stark Codes acts as controller. The Privacy Notice governs those activities.
1.3 “GDPR” means Regulation (EU) 2016/679. “Customer Personal Data”, “processing”, “data subject”, “personal data breach” and related terms have their GDPR meanings. “**Subprocessor**” is another processor engaged by Processor for Customer Personal Data.
1.4 For Customer Personal Data protection, this DPA prevails over general Terms. Standard Contractual Clauses prevail within their subject matter.
2. Instructions and legal compliance
2.1 Processor processes Customer Personal Data only on Controller’s documented instructions, including for third-country transfers, and only as needed to provide, secure, support and terminate the Service under the contract, settings and authorised requests.
2.2 The contract, DPA, feature use, workspace configuration and proper support requests constitute documented instructions. An additional instruction beyond the Service may require agreement on cost and technical feasibility.
2.3 If EU or Member State law requires processing beyond instructions, Processor informs Controller of the legal requirement before processing unless law prohibits notice for important public-interest reasons.
2.4 Processor promptly informs Controller if it believes an instruction violates GDPR or other Union or Member State data-protection law. It may suspend the affected instruction until confirmed or amended.
2.5 Controller is responsible for lawful instructions, data-subject information, legal basis, minimisation and Service configuration. It must avoid data not needed for the agreed purpose.
3. Confidentiality and authorised personnel
Processor ensures persons authorised to process Customer Personal Data are under contractual or statutory confidentiality, have need-based access, and receive appropriate privacy and security training.
4. Security
4.1 Processor maintains appropriate Article 32 GDPR technical and organisational measures, considering state of the art, cost, nature, scope, context, purposes and risks. The current minimum description is in Annex 2.
4.2 Processor may change measures without materially decreasing overall protection. On request, it supplies information reasonably needed for assessment without exposing other customers’ data or undermining security.
5. Subprocessors
5.1 Controller gives general written authorisation for Annex 3 Subprocessors.
5.2 At least **30 days** before adding or replacing a Subprocessor that will process Customer Personal Data, Processor notifies the workspace administrator by email and/or persistent in-Service notice of its name, country, purpose, data categories and relevant transfer mechanism. The current list always forms part of Annex 3 to this DPA; a separate Subprocessor page is not required. The administrator is responsible for keeping the notice address current in the account and may also notify a change at [hello@lucanto.eu](mailto:hello@lucanto.eu).
5.3 Controller may object within that period for reasonable, documented data-protection grounds. The parties will seek a reasonable solution in good faith, such as a configuration avoiding the provider where technically and commercially feasible. If no solution is possible and the objection is justified, Controller may terminate the affected Service portion without penalty before the new Subprocessor starts; we refund the proportionate prepaid price for the unprovided part.
5.4 Processor contracts with each Subprocessor on substantially equivalent data-protection duties and remains liable to Controller for its performance to the extent required by GDPR and the contract.
5.5 In an urgent security or continuity case a provider may be engaged sooner, but Processor notifies without undue delay, explains why, and preserves a meaningful objection right.
6. Data-subject rights
6.1 If Processor receives a request concerning Customer Personal Data, it does not substantively respond without instruction except to acknowledge and direct the person to Controller, and promptly forwards it where law allows.
6.2 Taking account of processing nature, Processor helps Controller by appropriate technical and organisational measures with Articles 12–22 GDPR. Standard self-service functions are included; unusual or extensive help may be charged at a reasonable pre-agreed price unless Processor caused the need.
7. Personal data breach
7.1 After becoming aware of a Customer Personal Data breach, Processor notifies Controller without undue delay.
7.2 Based on available information, notice describes the nature, categories and approximate number of affected persons and records, likely consequences, measures taken or proposed, and contact point. Missing information follows in phases without undue further delay.
7.3 Processor reasonably contains and remediates the incident and gives information needed for Controller’s Articles 33–34 obligations. Notice is not an admission of fault.
8. DPIAs, consultations and compliance
Taking account of processing nature and available information, Processor reasonably assists with data-protection impact assessments, prior supervisory consultation and Articles 32–36 GDPR duties.
9. Audits and information
9.1 Processor provides information necessary to demonstrate Article 28 compliance, prioritising current security documents, questionnaires, independent reports or certifications where available.
9.2 If those are reasonably insufficient, Controller may audit itself or through an independent confidential auditor no more than once per 12 months and with 30 days’ notice. Frequency and notice limits do not apply after a serious incident, reasonable suspected breach or supervisory-authority request.
9.3 Audit occurs during business hours, does not unreasonably disrupt operations, compromise security or expose other customers. Controller bears its and our reasonable costs unless the audit finds Processor’s material DPA breach.
10. Transfers outside the EEA
10.1 Processor does not transfer Customer Personal Data outside the EEA without a GDPR Chapter V mechanism and imposes the same duty on Subprocessors.
10.2 Where no adequacy decision applies, relevant parties execute current European Commission Standard Contractual Clauses with the correct module. Processor conducts an appropriate transfer assessment and supplementary measures and supplies safeguard information on request with lawful redactions.
10.3 Where SCCs apply directly between Controller as exporter and Stark Codes as importer, they are incorporated and completed using this DPA and annex information. SCCs prevail on conflict.
11. Return and deletion
11.1 At Service end, Processor at Controller’s choice enables reasonable export and then returns or erases Customer Personal Data and deletes copies, unless law requires storage.
11.2 If Controller does not choose, Processor erases. Erasure from active systems and backups is completed within **45 days** after effective account deletion or affected Service termination. Backups remain isolated and protected against ordinary processing until then.
11.3 This does not cover data Stark Codes must retain as controller for accounting, tax, legal or security obligations; it is not used to continue customer Service.
12. Duration, liability and changes
12.1 The DPA continues while Processor handles Customer Personal Data. Confidentiality, deletion and audit of past processing survive as appropriate.
12.2 Liability follows GDPR and the agreed Terms. No contractual cap restricts data-subject rights or supervisory powers or applies where mandatory law prohibits it.
12.3 We give at least 30 days’ notice of a material DPA change. If existing legal grounds or Subprocessor authorisation do not validly cover a replacement DPA or OpenAI, the workspace administrator must demonstrably accept it before AI processing continues. AI extraction for that workspace is paused until acceptance.
Annex 1 — Processing details
Controller
Description
Controller
Business customer and contact details shown in the order, account or signed contract
Subject
Lucanto cloud service including document records, team collaboration, integrations, support and optional AI extraction
Duration
Contract term plus no more than 45 days for erasure, except legal retention
Operations
receipt, recording, organisation, structuring, storage, viewing, retrieval, automated extraction, correction, instructed transmission, support, export, restriction and erasure
Purpose
provide Controller-selected features and support, protect the Service and carry out documented instructions
Data subjects
Controller’s customers, suppliers, counterparties, contacts, employees, contractors, Team Members and other persons in its documents
Data
identity/contact, business identifiers, billing and bank/transaction data, OAuth identifiers, items, amounts, dates, bank details, document content, bug-report and AI-extraction metadata, work notes, audit, network and technical data
Special data
not intentionally required; may incidentally appear. Controller must minimise it and ensure a legal basis
Frequency
continuously according to use and Controller’s instructions
Annex 2 — Technical and organisational measures
These are Processor's minimum commitments:
1. Governance: assigned security responsibilities, recurring risk review, system/provider inventory, joiner and leaver process.2. Access: individual accounts, least privilege, roles, recurring privileged-access review, and MFA for privileged/admin systems.
3. Encryption: TLS in transit; appropriate encryption at rest and key management.
4. Separation: logical workspace and environment separation; no production data in test without necessity and appropriate safeguards.
5. Development: change and code review, secret management, dependency control, testing and risk-based vulnerability remediation.
6. Logging/monitoring: access-restricted audit, application and security logs; incident detection and appropriate alerts; passwords, tokens, cookies, full payment details and document content are filtered from logs and error events. The Better Stack browser tag, including frontend monitoring and session replay, is activated only after the relevant consent; sensitive inputs and documents are masked or excluded, and unnecessary analytics, autocapture and fingerprinting remain disabled.
7. Availability: backups, tested recovery, continuity planning and reasonable loss/corruption protection.
8. Incidents: documented identification, containment, investigation, remediation and breach-notification process.
9. Minimisation/retention: export and deletion functions, 45-day post-deletion completion, limited log periods and recurring cleanup.
10. People/providers: confidentiality, training, due diligence, DPAs and Subprocessor oversight.
11. Physical security: appropriate data-centre controls and restricted physical access.
12. Testing: recurring effectiveness review and risk-prioritised remediation.
Príloha 3 — Sub-sprostredkovatelia
Subprocessor
Country / processing
Service and scope
Transfer mechanism
OpenAI Ireland Ltd. and approved subprocessors
Ireland; possible processing outside EEA
document AI extraction, prompt, output and technical metadata; under standard settings, abuse-monitoring logs for up to 30 days, and longer only where required by law or reasonably necessary to protect OpenAI's services or third parties from harm
adequacy decision or SCCs under the OpenAI DPA
Cloudflare, Inc. and approved subprocessors
global network; possible non-EEA processing
reverse proxy/CDN, DDoS and Turnstile; IP, TLS fingerprint, user-agent, URL/headers and customer data transmitted through `app.lucanto.eu`
DPF where applicable, otherwise SCCs under Cloudflare DPA
Render Services, Inc.
EEA, USA and countries of Render suppliers
reverse proxy/CDN, DDoS and Turnstile; IP, TLS fingerprint, user-agent, URL/headers and customer data transmitted through `app.lucanto.eu`
DPF where applicable, otherwise SCCs under Cloudflare DPA
Hetzner Online GmbH
Germany or Finland |
Object Storage for all attachments, including invoices, receipts and contracts
processing in the EEA
Better Stack, Inc.
EEA and USA
server-side logs including IP address, backend errors, stack trace, path without query string and minimised internal identifiers; browser tag, frontend monitoring and session replay only after consent, with sensitive inputs and documents masked or excluded
adequacy decision where applicable, otherwise SCCs under the Better Stack DPA
Linear Orbit, Inc.
USA
bug report: reporter name/email, workspace legal name/company ID and failed-AI-extraction metadata; a document is sent only on the User's separate instruction
DPF where applicable, otherwise SCCs under Linear DPA
Plus Five Five, Inc. (Resend)
USA
transactional/service email, name, email, language, account/plan state and minimised message content
SCCs under Resend DPA |
Simple Casual, LLC (Logo.dev)
USA
counterparty name/domain, IP, time and technical logo-request data
SCC Modules 2/3 under Logo.dev DPA
Not Subprocessors for Customer Personal Data:** Loops handles Stark Codes marketing; Stripe and Tatra banka act as independent controllers for regulated activities and otherwise handle account/payment data for which Stark Codes is controller; Google and Apple provide optional sign-in. Google Tag Manager, Google Fonts, jsDelivr and UNPKG are used for Stark Codes' own controller processing and are listed in the Privacy Notice. If a purpose or data flow changes so that one begins processing Customer Personal Data on Stark Codes' behalf, it will be added to this Annex under Article 5 before that change.