Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") is entered into pursuant to Art. 28 of Regulation (EU) 2016/679 ("GDPR") between the User of the Fattura Smart service ("Controller") and Fraway S.r.l. a socio unico, with registered office at Via Fiume Giallo, 275 - 00144, Rome ("Processor"), and forms an integral part of the Terms and Conditions of the Service. Acceptance of the Terms and Conditions entails acceptance of this DPA. Terms not defined in this DPA (such as "personal data", "processing", "data subject", "personal data breach") have the meaning given to them in Art. 4 GDPR.
1. Background and Roles of the Parties
- 1.1. When using the Service, the User enters personal data relating to third parties (client records, invoice recipients, bank transaction counterparties and, for healthcare professionals, patients), of which the User is and remains the data controller.
- 1.2. Fraway S.r.l. processes such data on the User's behalf, as data processor pursuant to Art. 28 GDPR, exclusively to provide the Service.
- 1.3. For the User's own personal data (account, billing data, contact details), Fraway S.r.l. instead acts as an independent data controller, as described in the Privacy Policy.
2. Subject Matter, Duration, Nature and Purpose of Processing
- 2.1. Subject matter: processing of personal data entered into the Service by the User and relating to third parties.
- 2.2. Duration: the duration of the contractual relationship, plus the 90-day period following termination provided for in the Terms and Conditions (art. 13-bis.4) and, for the Tax Archive only, the retention period set out in section 10.
- 2.3. Nature and purpose: collection, recording, storage, consultation, processing, transmission and erasure of data, to the extent necessary for: creating, sending and receiving electronic invoices through SDI; transmitting healthcare expense data to Sistema Tessera Sanitaria; managing client records, deadlines and payments; reconciling the bank transactions in statements uploaded by the User; estimating and computing VAT (VAT liquidation), including the automatic classification of expense documents for deductibility purposes; assigning documents to cost and revenue centres and related analyses; automatic reading of data from documents uploaded by the User; retention of the Tax Archive under section 10; generating documents and exports; support features and, where used, artificial-intelligence-based features.
3. Categories of Data Subjects and Personal Data
- 3.1. Data subjects: the User's clients and invoice recipients (natural persons); for healthcare-professional Users, patients; where the User uses the bank reconciliation feature, the counterparties of the transactions contained in the uploaded bank statements (which may include third parties other than the User's clients).
- 3.2. Categories of data: identification and contact data, tax code (codice fiscale) and VAT number, billing and payment data; where the User uses the bank reconciliation feature, data relating to the bank transactions in the uploaded statements (date, amount, counterparty and description).
- 3.3. Special categories of data: for healthcare-professional Users, expense documents may reveal data concerning the health of patients within the meaning of Art. 9 GDPR. The Processor applies enhanced protection measures to such data and excludes any form of dissemination, in accordance with Art. 2-septies of Legislative Decree 196/2003. Documents relating to healthcare services, i.e. those linked to a transmission to Sistema Tessera Sanitaria, are never sent to artificial-intelligence-based features (point 7.3).
4. Documented Instructions of the Controller
- 4.1. The Processor processes data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by Union or Member State law to which it is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The following constitute documented instructions: the Terms and Conditions, this DPA and the use of the Service's features by the Controller and its authorized users. Further instructions may be given in writing to the address set out in section 13.
- 4.2. Support requests submitted by the Controller or its authorized collaborators (via email, chat, WhatsApp or other support channels) constitute an instruction and authorization for the Processor's authorized personnel to access the data strictly necessary to handle the request. Such access is limited to the scope of the request and logged.
- 4.3. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
- 4.4. The Processor does not process the data for its own purposes and does not determine purposes or means of processing other than those set by the Controller; Art. 28(10) GDPR remains unaffected.
- 4.5. The Controller warrants the lawfulness of the data entered into the Service and of the instructions given, including the existence of an appropriate legal basis (also under Art. 9 GDPR for special categories of data) and the provision of privacy notices to data subjects under Arts. 13 and 14 GDPR, including, where it uses bank reconciliation, to transaction counterparties. The Controller is responsible for correctly handling patients' objections to the transmission of their data to Sistema Tessera Sanitaria and refrains from entering into the Service data not necessary for the purposes set out in section 2.
5. Confidentiality of Authorized Personnel
The Processor ensures that persons authorized to process the data (Art. 29 GDPR and Art. 2-quaterdecies of Legislative Decree 196/2003) have committed themselves to confidentiality, have received adequate training and operate under written instructions, with access limited on a need-to-know basis.
6. Security Measures
The Processor implements the technical and organizational measures referred to in Art. 32 GDPR, including: encryption of data in transit (TLS), field-level AES-256 encryption, in the database, of specific higher-risk data (tax codes in client records; names and tax codes of document parties; line descriptions of documents transmitted to Sistema Tessera Sanitaria; Sistema Tessera Sanitaria access credentials; counterparty names and descriptions of bank transactions; employees' tax codes, IBANs and sick-leave certificate protocol numbers), role-based access control, staff authentication, append-only access and export logging, automatic database backups (the last 7 full backups are kept) encrypted before transfer to the hosting provider's storage in Germany, safety copies taken before Service updates encrypted and deleted after 7 days, no copies of production data on developer workstations, recovery procedures, environment segregation and periodic assessment of the effectiveness of the measures. The Processor may update these measures in line with technological developments, provided that the overall level of security is not reduced.
7. Sub-processors
- 7.1. The Controller grants a general authorization for the engagement of the sub-processors listed below, pursuant to Art. 28(2) GDPR. The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those of this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures (Art. 28(4) GDPR), and remains fully liable to the Controller for the performance of the sub-processors' obligations.
- 7.2. The Processor shall inform the Controller, with at least 15 days' notice by email, of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Controller the opportunity to object on reasonable data protection grounds within the same period. In case of objection, the parties shall seek a solution in good faith; failing that, the Controller may terminate the agreement, before the change takes effect, as provided for in the Terms and Conditions.
- 7.3. Requests sent through OpenRouter are routed exclusively to model-hosting providers selected by the Processor that neither retain the data nor use it for training (zero data retention); if no compliant provider is available, the request is not executed. For the other artificial intelligence service providers, under the contractual terms applicable to the services used by the Processor, the data is not used to train models and is retained only for the time needed for processing and, where those terms so provide, for a limited period for security and abuse-prevention purposes. Documents relating to healthcare services, i.e. those linked to a transmission to Sistema Tessera Sanitaria, are never sent to artificial-intelligence-based features and are excluded, in particular, from assignment to cost and revenue centres and from the example centres suggested during set-up; for those examples, the most frequent line descriptions of the other documents are sent, discarding those that appear to contain personal data. Payslips and other payroll data are never sent to artificial intelligence service providers. Only the data strictly necessary for the requested feature is sent to the providers: for bank reconciliation, counterparty names and transaction descriptions are pseudonymised by replacement with opaque tokens before being sent to the provider, which receives only amounts, dates, internal identifiers and tokens; for VAT deductibility classification, document line descriptions are sent in minimized form, after removal of identifying data such as tax codes, VAT numbers, IBANs, email addresses and telephone numbers; for assignment to cost and revenue centres, the provider receives only the names of counterparties that are not natural persons, line descriptions and amounts, with documents relating to healthcare services excluded; for the automatic reading of documents uploaded by the User (tax code card, expense receipts, the invoice uploaded from the mobile app for the initial profile set-up), the provider receives the document or its image for the sole purpose of extracting the requested data; the invoice for the initial set-up is read only after the Terms and Conditions and this DPA have been accepted. Some of these flows may incidentally contain data concerning health: the invoice uploaded for the initial set-up, which is sent in full and for which the app warns not to use an invoice issued to a patient and the Controller undertakes not to do so; photos of expense receipts (for example from a pharmacy); the line descriptions of received documents used for VAT deductibility classification, stripped of identifying data as described above. The outputs of the artificial intelligence features are proposals that the User can review and change and do not involve decisions based solely on automated processing producing legal effects concerning data subjects within the meaning of Art. 22 GDPR.
| Sub-processor | Purpose | Location / non-EEA transfer | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, database, object storage (documents, payslips, receipts) and backups | Germany (EEA) | Processing within the EEA — no non-EEA transfer |
| Meta Platforms Ireland Ltd. (WhatsApp Business) | Customer support channel | Ireland / USA | EU-US Data Privacy Framework / standard contractual clauses |
| Google LLC (Gemini) | Artificial-intelligence-based features | USA | EU-US Data Privacy Framework |
| Google LLC / Google Ireland Ltd. (Firebase Cloud Messaging) | Delivery of push notifications on the mobile applications | USA | EU-US Data Privacy Framework |
| Anthropic PBC (Claude) | Artificial-intelligence-based features | USA | Standard contractual clauses (provider's DPA) |
| OpenRouter, Inc. | Artificial-intelligence-based features (bank reconciliation, VAT deductibility classification, cost and revenue centres, automatic document reading) — routing exclusively to model-hosting providers with zero data retention (DeepInfra, Fireworks AI, Together AI, Baseten, Parasail) | USA | Standard contractual clauses (countersigned DPA) |
| Amazon Web Services EMEA SARL (Amazon SES) | Sending transactional emails, including emails sent to the User's clients (document delivery, payment reminders) | EU (Ireland) | Processing within the EEA |
| Functional Software, Inc. (Sentry) | Error and performance monitoring of the server and the web application: error reports, traces of a sample of requests and, for the web application, session recordings only on errors (with text, input fields and media masked). Request content, cookies, URL parameters, user identifiers and the profile name are not sent; error messages and technical metadata may be sent | EU (Germany), the provider's EU data region | Processing within the EEA; for any access from third countries, EU-US Data Privacy Framework (certified provider) and standard contractual clauses (provider's DPA) |
| Mapbox, Inc. | Autocompletion of entered addresses | USA | EU-US Data Privacy Framework (certified provider) and standard contractual clauses (provider's DPA) |
| Openapi S.p.A. Unipersonale (company subject to the direction and coordination of Open Holding S.r.l.) | Lookup of company data in public registers when entering client records | Italy (EEA) | Processing within the EEA |
- 7.4. Non-EEA transfers: by accepting this DPA, the Controller instructs the Processor to carry out the transfers of data to third countries indicated in the table above. Such transfers take place solely in compliance with Chapter V GDPR, on the basis of the adequacy decision on the EU-US Data Privacy Framework for certified recipients or, failing that, of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, in the relevant module, supplemented where necessary by additional measures (such as the pseudonymisation and minimization described in point 7.3) on the basis of a documented transfer assessment. Should an adequacy decision cease to apply, the Processor shall without undue delay adopt an alternative safeguard under Art. 46 GDPR or suspend the transfer. On request, the Processor provides the Controller with information on the safeguards in place.
- 7.5. Institutional recipients and recipients designated by the Controller: the Italian Revenue Agency (Agenzia delle Entrate), as operator of the Exchange System (SDI), and Sistema Tessera Sanitaria, to which data is transmitted on the Controller's instructions and in fulfilment of the Controller's legal obligations, process the data as independent controllers and are not sub-processors of the Processor. The same applies to the persons to whom the Controller grants access to the Service (collaborators, accountant) or to whom it asks for data to be transmitted (section A.6 of Annex A), who act under the Controller's responsibility.
8. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures: in fulfilling requests to exercise data subjects' rights (Arts. 15-22 GDPR), including through the consultation, rectification, export and deletion features available in the Service; and in complying with the obligations under Arts. 32-36 GDPR (security, breach notification, impact assessments), taking into account the information available to the Processor. The Processor forwards to the Controller, without undue delay and without acting on them independently, any requests to exercise data-subject rights received directly from data subjects whose data is processed on the Controller's behalf.
9. Personal Data Breach
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed on the Controller's behalf, at the email address associated with the account, providing the information necessary to enable the Controller to comply with its notification and communication obligations under Arts. 33 and 34 GDPR and, in particular, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the contact point at the Processor, the likely consequences and the measures taken or proposed to address the breach and mitigate its effects. Information not immediately available is provided in phases without further undue delay. The Processor documents the breach, promptly takes the containment measures within its remit and does not notify the supervisory authority or communicate with data subjects on the Controller's behalf, unless instructed to do so or required by law.
10. Deletion, Return and Retention of Data
- 10.1. Return: upon termination of the contractual relationship, for whatever reason, the Controller may obtain the return of its data by exporting it, in commonly used electronic formats, through the Service's features during the 90-day period provided for in art. 13-bis.4 of the Terms and Conditions.
- 10.2. Deletion: after that period, or earlier if the Controller requests deletion of the account, the Processor permanently deletes the data processed on the Controller's behalf and existing copies, except for the Tax Archive under point 10.3 and unless retention is required by Union or Member State law to which the Processor is subject. Copies in backups are deleted when the backup containing them leaves the rotation of the last 7 full backups, and those in safety copies taken before Service updates within 7 days; until then they remain encrypted and are not otherwise processed. On request, the Processor confirms the deletion in writing.
- 10.3. Retention of the Tax Archive: by accepting this DPA, the Controller instructs the Processor, pursuant to Art. 28(3)(a) and (g) GDPR, to retain after termination of the relationship or deletion of the account, for a maximum of 10 years, the electronic invoices issued and received through the SDI with their XML files and transmission receipts, the documents transmitted to Sistema Tessera Sanitaria with their outcomes and the accounting entries linked to those documents, including the counterparties' personal data contained in them (the "Tax Archive"). The retention is provided free of charge and its sole purpose is to enable the Controller to comply with its obligations to keep accounting and tax records and documents (Art. 2220 of the Italian Civil Code, Art. 22 of Presidential Decree 600/1973, Art. 39 of Presidential Decree 633/1972) and to produce them in audits, assessments or disputes.
- 10.4. Arrangements: during the retention period the Tax Archive is not processed for purposes other than those in point 10.3, is separated from the terminated account and stripped of profile data that is not needed, is accessible only to the Processor's authorized personnel and is protected by the measures in section 6. The Controller may request in writing, at the address in section 13 and subject to verification of its identity, access to or export of the Tax Archive, or its early deletion; in the latter case the Controller discharges its retention obligations on its own. The Processor acts on the request within 30 days of receipt. At the end of the retention period the Processor permanently deletes the Tax Archive.
- 10.5. Exclusions: retention of the Tax Archive does not constitute legally compliant digital preservation (conservazione a norma) of electronic documents under Legislative Decree 82/2005 and the related AgID guidelines, as specified in art. 3-bis.2 of the Terms and Conditions, and does not relieve the Controller of its statutory retention obligations, including those concerning employment records, which the Controller also discharges by exporting the data before the period in point 10.1 expires.
- 10.6. During the contractual relationship, the Service's default retention periods (for employee data, Annex A.7) constitute documented instructions pursuant to Art. 28(3)(a) GDPR; the Service offers no configurable periods or legal holds, and a Controller that needs to keep data beyond those periods does so by exporting it before they expire.
11. Audits
The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller and bound by confidentiality, subject to reasonable prior written notice and to the security of the Service and the confidentiality of its other users. The Processor maintains the record of categories of processing activities carried out on the Controller's behalf referred to in Art. 30(2) GDPR and cooperates, on request, with the supervisory authority.
12. Final Provisions
- 12.1. For anything not provided for in this DPA, the Terms and Conditions of the Service apply.
- 12.2. This DPA is governed by Italian law; the Court of Rome shall have exclusive jurisdiction over any dispute.
- 12.3. In the event of conflict between this DPA and the Terms and Conditions, this DPA prevails with regard to the processing of personal data carried out on the Controller's behalf.
- 12.4. Each party's liability towards data subjects under Art. 82 GDPR remains unaffected. The limitations of liability in the Terms and Conditions do not apply in case of wilful misconduct or gross negligence, pursuant to Art. 1229 of the Italian Civil Code.
- 12.5. Amendments to this DPA are communicated to the Controller in the manner and with the notice provided for in the Terms and Conditions for their amendments, unless imposed by law or by orders of the competent authorities. Changes to the list of sub-processors are governed by point 7.2.
- 12.6. This DPA is drawn up in Italian and English; in the event of any discrepancy, the Italian version prevails.
13. Contact
For any request relating to this DPA: info@fatturasmart.com
Annex A — Employee Management Module
This Annex supplements the DPA and applies to Users who activate the employee management module. It takes effect from the moment of the acceptance recorded by the User upon activation of the module and forms an integral part of the DPA.
A.1. Data subjects
The User's employees and collaborators.
A.2. Categories of data
Identification and contact data, tax code (codice fiscale), IBAN, contractual and employment-classification data (contract type, working hours), attendance and clock-in/out events (including the geofence check outcome; location coordinates are not stored), holidays, leave, absences and supporting documents, payslips, expense reports and related receipts, push notification tokens, access logs.
A.3. Special categories of data
Processing may involve special categories of employee data within the meaning of Art. 9 GDPR: data concerning health (sick leave, limited to the certificate protocol number, with any diagnostic data excluded; leave under Italian Law 104/1992), data that may reveal trade-union membership (payslip deductions) and data relating to protected categories. The Processor applies enhanced measures to such data (encryption, need-to-know access, prohibition of dissemination pursuant to Art. 2-septies of Legislative Decree 196/2003).
A.4. Purposes
Management of attendance, absences and supporting documents, distribution of payslips, management of expense reports (including automatic data extraction from receipts), sending of push notifications, periodic export to the consultant designated by the User. Payslips are never sent to artificial intelligence service providers: each page is matched to the employee locally on the basis of the tax code and surname, and unmatched pages are held for manual assignment by the User. Photos of expense-report receipts are sent to the artificial intelligence provider for the sole purpose of extracting the expense data and may incidentally contain data concerning health (for example pharmacy receipts) (point 7.3 of the DPA).
A.5. Punch-time geolocation
Location capture is disabled by default and may be enabled only by the User, subject to an attestation — recorded by the Service — that the prerequisites of Art. 4 of Italian Law 300/1970 are met. Location is captured exclusively at the moment of clocking in or out and is used solely for the geofence check: coordinates are never stored; only the outcome of the check (inside/outside the area) is recorded, and it is not used for purposes other than attendance validation.
A.6. Transmission to the consultant
On the Controller's documented instruction, expressed by configuring the relevant address in the Service, the Processor periodically transmits attendance data and supporting documents to the consultant designated by the Controller. The recipient acts as a processor or independent controller designated by the Controller, not as a sub-processor of Fraway S.r.l.; the Controller warrants the accuracy of the configured address and the recipient's entitlement.
A.7. Retention
Employee data is kept in the Service for 5 years from the end-of- employment date recorded by the Controller; once that period has elapsed the Service anonymises it automatically. The Controller may delete or anonymise an employee's data earlier through the Service's functions and must export, before the period expires, any data it intends to keep longer (for example for pending litigation): the Service offers neither configurable retention periods nor legal holds. That period constitutes documented instructions pursuant to Art. 28(3)(a) GDPR. Access logs relating to employee data are retained for 5 years. Section 10 of the DPA remains unaffected.
A.8. Privacy notice to employees
Providing employees with the privacy notice pursuant to Arts. 13-14 GDPR — in any event within one month of the entry of their data into the Service — is the exclusive obligation of the Controller. The Service records the employee's acknowledgment of the notice at first login, as evidence of delivery; such record does not constitute consent.
A.9. Specific measures
In addition to the measures under section 6 of the DPA: minimized push notification content (no indication of the nature of absences or of amounts), deletion of notification tokens within 60 days of the employee's offboarding (during which the employee has read-only access to their own data), need-to-know data visibility according to the roles configured by the Controller, no storage of location coordinates.
Last updated: 24 September 2026