Data Processing Agreement
Last updated: 2026-06-27
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and Fluidlabs OÜ (“Processor”, “Quittance”) for use of the Service, and governs Quittance’s processing of personal data on the Controller’s behalf under the EU/UK GDPR. This is a public reference copy; a signable version (with the parties’ details and signatures) is available on request or with the order form.
1. Roles & scope
The Controller determines the purposes and means of processing the Customer Data; Quittance processes it only as a Processor to provide the Service.
2. Details of processing (Art. 28(3))
- Subject matter: provision of the Quittance invoice-reconciliation Service.
- Duration: for the term of the agreement and until deletion/return of the data.
- Nature & purpose: ingestion, parsing, validation against the Controller’s agreements, flagging, and posting of drafts.
- Types of personal data: names and business-contact details of vendor staff, approvers and signatories appearing in invoices and agreements.
- Categories of data subjects: the Controller’s personnel, and vendor/supplier contacts.
3. Processor obligations
- Documented instructions. We process Customer Data only on the Controller’s documented instructions (including for transfers), unless required by law, in which case we will inform the Controller where legally permitted. We will inform the Controller if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law.
- Confidentiality. Personnel authorised to process the data are bound by confidentiality.
- Security. We implement appropriate technical and organisational measures under Art. 32 (encryption in transit and at rest, access controls, etc.); Quittance is operated by an ISO/IEC 27001:2022-certified organisation (Fluidlabs OÜ). A technical-and-organisational-measures (TOMs) schedule is provided with the signable version of this DPA.
- Data-subject rights. We assist the Controller, by appropriate technical and organisational measures and insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR.
- Assistance. We assist the Controller, taking into account the nature of processing and the information available to us, with obligations under Arts. 32-36 (security, breach notification, DPIAs, prior consultation).
- Breach notification. We notify the Controller without undue delay after becoming aware of a personal-data breach, and in any event within 72 hours of becoming aware, to help the Controller meet its own notification obligations.
- Deletion or return. On termination, we delete or return Customer Data at the Controller’s choice within 30 days, and delete existing copies unless retention is required by law.
- Audits. We make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, or provision of third-party audit reports / certifications. Audits may be carried out once per 12-month period (and after a personal-data breach) on 30 days’ prior written notice.
4. Sub-processors
The Controller provides general authorisation for Quittance to engage the sub-processors listed on our Subprocessorspage. We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain responsible for their performance. We will give at least 30 days’ advance notice of new sub-processors and a reasonable opportunity to object. If the Controller reasonably objects to a new sub-processor, the parties will work together in good faith to address the concern; if it cannot be resolved, the Controller may suspend or terminate the affected part of the Service.
5. International transfers
Personal data may be processed in the United States. Where personal data is transferred outside the EEA/UK, we rely on the EU Standard Contractual Clauses (Module 2, controller-to-processor) as accepted in each sub-processor’s data processing agreement, supplemented by encryption in transit and at rest as additional safeguards; where a sub-processor is certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), we rely on that framework additionally. The applicable Standard Contractual Clauses are incorporated into this DPA by reference. We do not offer EU-only data residency.
6. General
- Precedence & governing law. In case of conflict with the main agreement on data-protection matters, this DPA prevails. It is governed by the laws of the Republic of Estonia, and the parties submit to the exclusive jurisdiction of the Estonian courts. The Standard Contractual Clauses and a technical-and-organisational-measures (TOMs) schedule are attached as annexes to the signable version.
- Liability. Each party’s liability under this DPA is subject to the exclusions and limitations of liability set out in the main agreement / Terms (see the “Limitation of liability” section of the Terms).
- US / CCPA. For US customers, Quittance acts as a “service provider” and processes personal information only to provide the Service; we do not sell or share it, and do not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the Service.