Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the SimplNorm Terms of Service and applies where Mark Kucler s.p. processes personal data on behalf of a user as processor under the GDPR.
1. Parties And Roles
The user or organization using SimplNorm for its business records is normally the controller of personal data entered about its own clients, customers, suppliers, collaborators, invoice recipients, and other third parties.
Mark Kucler s.p. is the processor for that data. For data we process for our own purposes, such as account data, security logs, support, waitlist, and service administration, we act as controller as described in the Privacy Policy.
2. Subject Matter And Duration
The subject matter of the processing is the provision, security, support, and lawful operation of SimplNorm as an online invoicing and related business-records service.
The processing lasts for as long as you use SimplNorm and for as long as we are required or permitted to keep data under the Terms of Service, Privacy Policy, your instructions, legal obligations, or the establishment, exercise, or defense of legal claims.
3. Nature And Purpose
Processing may include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission, disclosure to subprocessors, export, restriction, deletion, and destruction of personal data.
The purpose is to enable use of SimplNorm, including workspaces, clients, invoices, invoice PDFs, exports, reports, templates, imports, support, security, agents/API, and related features.
4. Types Of Personal Data And Categories Of Data Subjects
Types of personal data may include names, legal names, addresses, countries, tax numbers, VAT IDs, registration numbers, email addresses, phone numbers, bank details, invoice data, line items, amounts, dates, payment statuses, notes, files, PDFs, imports, exports, and usage metadata.
Categories of data subjects may include SimplNorm users, workspace members, clients, customers, suppliers, collaborators, contact persons, invoice recipients, and other people whose data the user enters into SimplNorm.
5. User Instructions
We process personal data only on documented user instructions, including the Terms of Service, this DPA, product settings, and actions taken by authorized users or agents.
If we believe an instruction infringes the GDPR or other EU or Member State data-protection law, we will inform the user unless legally prohibited from doing so.
6. Confidentiality
We will ensure that persons authorized to process personal data are under an appropriate confidentiality obligation or statutory duty of confidentiality.
7. Security Measures
We use reasonable technical and organizational measures appropriate to the nature, scope, context, and purposes of processing. The current measures are described in more detail in Annex 1 to this DPA.
The user is responsible for managing its users, access rights, devices, passwords, agents, API tokens, and for limiting the data entered into SimplNorm.
8. Subprocessors
The user grants us general written authorization to use subprocessors needed to provide, secure, support, and improve SimplNorm.
Current subprocessors are listed in the Subprocessor List. We will notify active users directly by email or in the application before adding or replacing a subprocessor where the change materially affects personal data processed on the user’s behalf. Where practicable, we will provide at least 15 days’ notice.
The user may object within that period on reasonable data-protection grounds by contacting info@simplnorm.com. We will consider the objection in good faith and try to offer a reasonable change, alternative, or instructions for stopping the affected feature. If no reasonable solution is available, the user may stop using the affected service and request export and deletion under this DPA before the disputed processing begins.
We enter into appropriate data-protection obligations with subprocessors. If a subprocessor fails to meet its data-protection obligations, we remain responsible for the performance of the subprocessor’s obligations to the extent required by the GDPR.
9. International Transfers
Where processing involves a transfer of personal data outside the EU/EEA, we will use appropriate safeguards required by the GDPR, such as adequacy decisions, EU Standard Contractual Clauses, data processing agreements, and supplementary safeguards where needed.
10. Assistance To The User
Taking into account the nature of processing and the information available to us, we will reasonably assist the user with:
- responding to data-subject rights requests;
- ensuring security of processing;
- handling personal-data breaches;
- data protection impact assessments and prior consultations where required.
If a request goes beyond ordinary support or requires disproportionate effort, we may agree reasonable fees unless the law requires otherwise.
11. Personal-Data Breaches
If we become aware of a personal-data breach affecting personal data that we process as processor, we will notify the user without undue delay.
The notice will, to the extent reasonably known, describe the nature of the breach, affected data and data-subject categories, likely consequences, measures taken or proposed, and a contact point for further communication.
12. Deletion Or Return
After the end of the service, we will, at the user’s choice, delete personal data processed as processor or return it in a reasonably accessible form and then delete remaining copies. The user must request return and use available export features before the deletion period expires. If the user does not request return, deletion under the product’s account-deletion process is the default choice.
Copies may be retained only where EU or Member State law applicable to SimplNorm requires storage. In that case, we will inform the user of the legal requirement where permitted, isolate the data, and not process it for another purpose unless that law requires it. Shared-workspace data that another controller continues to use lawfully is not a retained copy of the departing user’s data.
13. Demonstrating Compliance And Audits
Upon request, we will make reasonably available the information necessary to demonstrate compliance with this DPA and GDPR Article 28, taking into account confidentiality, security, trade secrets, and the rights of other users.
Audits or inspections must be reasonably noticed, limited to the scope necessary to verify compliance, conducted in a way that does not compromise SimplNorm security or operations, and must not expose other users’ data.
14. Order Of Precedence
If this DPA conflicts with the Terms of Service regarding processing of personal data as processor, this DPA controls for that processing.
15. Contact
Questions about this DPA can be sent to:
Annex 1: Technical And Organizational Measures
We regularly review these measures and adapt them to risk, the state of the art, and service development. Current measures include:
- Access control: authenticated user sessions, separated administrative privileges, restricted production-system access, and session or token revocation.
- Authentication and credentials: password hashing, email verification, time-limited reset links, user-controlled account linking, and secrets managed outside source code.
- Data separation: server-side access checks tied to organization membership. Agent tokens use explicit, limited permission scopes.
- Transport and storage security: encrypted HTTPS/TLS transport and use of the security and access controls provided by Neon, Cloudflare R2, and Hetzner.
- Application security: input validation, rate limiting on sensitive paths, authorization checks, and guarded agent workflows for issuing invoices.
- Monitoring and response: limited operational logging, Sentry error monitoring, and a documented process for incident triage, containment, notification, and remediation.
- Minimization and deletion: diagnostic-data minimization, an expiring browser query cache, and procedures for export, scheduled deletion, and permanent erasure of account data.
- Recovery and continuity: managed infrastructure providers and documented service-recovery procedures. A separate SimplNorm-managed backup system is not yet active, so the service does not promise restoration from such a copy.
