Data processing agreement
This is an English translation for convenience. The Spanish version prevails if there is any discrepancy.
1. Parties and object
The client identified in the service agreement is the Controller and TAX FACTORY, S.L. is the Processor where services require processing on the client’s behalf. Processor contact: guillem@taxfactory.es.
The Processor will process data only for documented services and lawful Controller instructions.
2. Processing description
| Element | Description |
|---|---|
| Purpose | Contracted tax, accounting, employment, corporate and administrative work |
| Operations | Collection, access, organization, storage, preparation, authorized disclosure, return or deletion |
| Data subjects | Workers, directors, shareholders, customers, suppliers and other persons linked to the Controller |
| Data | Identity, contact, economic, banking, tax, employment, Social Security and strictly necessary special-category data |
| Duration | Service duration and applicable retention periods |
The Controller warrants a legal basis and lawful instructions.
3. Instructions and confidentiality
The Processor acts only on documented instructions, including instructions for disclosures and transfers. It will notify the Controller if an instruction appears to breach data-protection law and may suspend it while clarification is obtained. Authorized personnel are bound by confidentiality and need-to-know access.
4. Security
Risk-based Article 32 GDPR measures include access control, authentication, segregation, backup, encryption where appropriate, logging, continuity, vulnerability management and provider review.
5. Subprocessors
The Controller grants general authorization for necessary subprocessors. Current or planned categories include Cloudflare, Stripe where it acts for the Controller, Holded, Microsoft 365, e-Signature.eu after approval and professional collaborators such as Gabinete Gestor, S.L. (MLT Asesores).
TaxFactory will notify relevant additions or replacements, allow a reasoned objection within a reasonable period, impose equivalent duties and retain the responsibility required by Article 28 GDPR.
6. Assistance and incidents
The Processor will assist with data-subject rights and, within the nature of processing, security, impact assessments and consultations. A request received directly will be forwarded unless a different instruction or legal duty applies.
A known personal-data breach will be reported to the Controller without undue delay with available details on nature, categories, consequences and measures. The parties will cooperate to meet legal deadlines.
7. Transfers
International transfers require an instruction, documented necessity or legal duty and a valid safeguard. Adequacy decisions, the applicable framework, standard contractual clauses and supplementary measures will be used where required.
8. Return, deletion and audit
At termination, the Controller may choose return or deletion unless law requires retention. Retained copies remain restricted. The Processor will provide information needed to demonstrate compliance and allow reasonable coordinated audits that protect other clients and system security.
9. Responsibility, duration and law
Each party is responsible for its attributable breach under the GDPR. This agreement lasts while processing on the Controller’s behalf continues. The GDPR, LOPDGDD and Spanish law apply; B2B disputes are submitted to Barcelona unless a mandatory rule states otherwise.