Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") is entered into pursuant to Art. 28 of Regulation (EU) 2016/679 ("GDPR") between the User of the Fattura Smart service ("Controller") and Fraway S.r.l. a socio unico, with registered office at Via Fiume Giallo, 275 - 00144, Rome ("Processor"), and forms an integral part of the Terms and Conditions of the Service. Acceptance of the Terms and Conditions entails acceptance of this DPA. Terms not defined in this DPA (such as "personal data", "processing", "data subject", "personal data breach") have the meaning given to them in Art. 4 GDPR.


1. Background and Roles of the Parties

2. Subject Matter, Duration, Nature and Purpose of Processing

3. Categories of Data Subjects and Personal Data

4. Documented Instructions of the Controller

5. Confidentiality of Authorized Personnel

The Processor ensures that persons authorized to process the data (Art. 29 GDPR and Art. 2-quaterdecies of Legislative Decree 196/2003) have committed themselves to confidentiality, have received adequate training and operate under written instructions, with access limited on a need-to-know basis.

6. Security Measures

The Processor implements the technical and organizational measures referred to in Art. 32 GDPR, including: encryption of data in transit (TLS), field-level AES-256 encryption, in the database, of specific higher-risk data (tax codes in client records; names and tax codes of document parties; line descriptions of documents transmitted to Sistema Tessera Sanitaria; Sistema Tessera Sanitaria access credentials; counterparty names and descriptions of bank transactions; employees' tax codes, IBANs and sick-leave certificate protocol numbers), role-based access control, staff authentication, append-only access and export logging, automatic database backups (the last 7 full backups are kept) encrypted before transfer to the hosting provider's storage in Germany, safety copies taken before Service updates encrypted and deleted after 7 days, no copies of production data on developer workstations, recovery procedures, environment segregation and periodic assessment of the effectiveness of the measures. The Processor may update these measures in line with technological developments, provided that the overall level of security is not reduced.

7. Sub-processors

Sub-processor Purpose Location / non-EEA transfer Safeguards
Hetzner Online GmbH Hosting, database, object storage (documents, payslips, receipts) and backups Germany (EEA) Processing within the EEA — no non-EEA transfer
Meta Platforms Ireland Ltd. (WhatsApp Business) Customer support channel Ireland / USA EU-US Data Privacy Framework / standard contractual clauses
Google LLC (Gemini) Artificial-intelligence-based features USA EU-US Data Privacy Framework
Google LLC / Google Ireland Ltd. (Firebase Cloud Messaging) Delivery of push notifications on the mobile applications USA EU-US Data Privacy Framework
Anthropic PBC (Claude) Artificial-intelligence-based features USA Standard contractual clauses (provider's DPA)
OpenRouter, Inc. Artificial-intelligence-based features (bank reconciliation, VAT deductibility classification, cost and revenue centres, automatic document reading) — routing exclusively to model-hosting providers with zero data retention (DeepInfra, Fireworks AI, Together AI, Baseten, Parasail) USA Standard contractual clauses (countersigned DPA)
Amazon Web Services EMEA SARL (Amazon SES) Sending transactional emails, including emails sent to the User's clients (document delivery, payment reminders) EU (Ireland) Processing within the EEA
Functional Software, Inc. (Sentry) Error and performance monitoring of the server and the web application: error reports, traces of a sample of requests and, for the web application, session recordings only on errors (with text, input fields and media masked). Request content, cookies, URL parameters, user identifiers and the profile name are not sent; error messages and technical metadata may be sent EU (Germany), the provider's EU data region Processing within the EEA; for any access from third countries, EU-US Data Privacy Framework (certified provider) and standard contractual clauses (provider's DPA)
Mapbox, Inc. Autocompletion of entered addresses USA EU-US Data Privacy Framework (certified provider) and standard contractual clauses (provider's DPA)
Openapi S.p.A. Unipersonale (company subject to the direction and coordination of Open Holding S.r.l.) Lookup of company data in public registers when entering client records Italy (EEA) Processing within the EEA

8. Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures: in fulfilling requests to exercise data subjects' rights (Arts. 15-22 GDPR), including through the consultation, rectification, export and deletion features available in the Service; and in complying with the obligations under Arts. 32-36 GDPR (security, breach notification, impact assessments), taking into account the information available to the Processor. The Processor forwards to the Controller, without undue delay and without acting on them independently, any requests to exercise data-subject rights received directly from data subjects whose data is processed on the Controller's behalf.

9. Personal Data Breach

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed on the Controller's behalf, at the email address associated with the account, providing the information necessary to enable the Controller to comply with its notification and communication obligations under Arts. 33 and 34 GDPR and, in particular, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the contact point at the Processor, the likely consequences and the measures taken or proposed to address the breach and mitigate its effects. Information not immediately available is provided in phases without further undue delay. The Processor documents the breach, promptly takes the containment measures within its remit and does not notify the supervisory authority or communicate with data subjects on the Controller's behalf, unless instructed to do so or required by law.

10. Deletion, Return and Retention of Data

11. Audits

The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller and bound by confidentiality, subject to reasonable prior written notice and to the security of the Service and the confidentiality of its other users. The Processor maintains the record of categories of processing activities carried out on the Controller's behalf referred to in Art. 30(2) GDPR and cooperates, on request, with the supervisory authority.

12. Final Provisions

13. Contact

For any request relating to this DPA: info@fatturasmart.com


Annex A — Employee Management Module

This Annex supplements the DPA and applies to Users who activate the employee management module. It takes effect from the moment of the acceptance recorded by the User upon activation of the module and forms an integral part of the DPA.

A.1. Data subjects

The User's employees and collaborators.

A.2. Categories of data

Identification and contact data, tax code (codice fiscale), IBAN, contractual and employment-classification data (contract type, working hours), attendance and clock-in/out events (including the geofence check outcome; location coordinates are not stored), holidays, leave, absences and supporting documents, payslips, expense reports and related receipts, push notification tokens, access logs.

A.3. Special categories of data

Processing may involve special categories of employee data within the meaning of Art. 9 GDPR: data concerning health (sick leave, limited to the certificate protocol number, with any diagnostic data excluded; leave under Italian Law 104/1992), data that may reveal trade-union membership (payslip deductions) and data relating to protected categories. The Processor applies enhanced measures to such data (encryption, need-to-know access, prohibition of dissemination pursuant to Art. 2-septies of Legislative Decree 196/2003).

A.4. Purposes

Management of attendance, absences and supporting documents, distribution of payslips, management of expense reports (including automatic data extraction from receipts), sending of push notifications, periodic export to the consultant designated by the User. Payslips are never sent to artificial intelligence service providers: each page is matched to the employee locally on the basis of the tax code and surname, and unmatched pages are held for manual assignment by the User. Photos of expense-report receipts are sent to the artificial intelligence provider for the sole purpose of extracting the expense data and may incidentally contain data concerning health (for example pharmacy receipts) (point 7.3 of the DPA).

A.5. Punch-time geolocation

Location capture is disabled by default and may be enabled only by the User, subject to an attestation — recorded by the Service — that the prerequisites of Art. 4 of Italian Law 300/1970 are met. Location is captured exclusively at the moment of clocking in or out and is used solely for the geofence check: coordinates are never stored; only the outcome of the check (inside/outside the area) is recorded, and it is not used for purposes other than attendance validation.

A.6. Transmission to the consultant

On the Controller's documented instruction, expressed by configuring the relevant address in the Service, the Processor periodically transmits attendance data and supporting documents to the consultant designated by the Controller. The recipient acts as a processor or independent controller designated by the Controller, not as a sub-processor of Fraway S.r.l.; the Controller warrants the accuracy of the configured address and the recipient's entitlement.

A.7. Retention

Employee data is kept in the Service for 5 years from the end-of- employment date recorded by the Controller; once that period has elapsed the Service anonymises it automatically. The Controller may delete or anonymise an employee's data earlier through the Service's functions and must export, before the period expires, any data it intends to keep longer (for example for pending litigation): the Service offers neither configurable retention periods nor legal holds. That period constitutes documented instructions pursuant to Art. 28(3)(a) GDPR. Access logs relating to employee data are retained for 5 years. Section 10 of the DPA remains unaffected.

A.8. Privacy notice to employees

Providing employees with the privacy notice pursuant to Arts. 13-14 GDPR — in any event within one month of the entry of their data into the Service — is the exclusive obligation of the Controller. The Service records the employee's acknowledgment of the notice at first login, as evidence of delivery; such record does not constitute consent.

A.9. Specific measures

In addition to the measures under section 6 of the DPA: minimized push notification content (no indication of the nature of absences or of amounts), deletion of notification tokens within 60 days of the employee's offboarding (during which the employee has read-only access to their own data), need-to-know data visibility according to the roles configured by the Controller, no storage of location coordinates.


Last updated: 24 September 2026