OFFITIA - Plataforma Inteligente de Facturación, Gestión Administrativa y Cumplimiento Veri*Factu para Autónomos y PYMEs

OFFITIA és la plataforma tecnològica de facturació homologada Veri*Factu (RD 1007/2023) i gestió de pressupostos per a autònoms i pimes a Catalunya i Espanya. Permet emetre factures oficials amb codi QR de l'AEAT, pressupostos amb firma digital eIDAS, xat en viu i escàner de tiquets amb Intel·ligència Artificial.

Data Processing Agreement (DPA)

Data Processor Contract (Art. 28 GDPR)

Last updated: August 2026

1. Parties and Purpose

This Data Processing Agreement (DPA) forms an integral part of the OFFITIA Terms of Service and governs the processing of personal data carried out by OFFITIA (the data processor) on behalf of the customer (the data controller) in providing the SaaS invoicing and professional management platform.

2. Scope of Application

This DPA applies to the processing of personal data of end clients of OFFITIA users, pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

3. Processing Description and Data Export Tools

OFFITIA processes personal data entered by the customer exclusively to deliver the contracted services: creation and management of quotes, invoices, delivery notes, and professional documents. Data is retained during account active status and for a 30-day statutory portability period following cancellation, during which the customer may export their data via integrated platform utilities.

Customers may download and port their data at any time in the following formats:

  • Official Documentation in PDF: Single or batch downloads of all invoices, quotes, delivery notes, and expense receipts in PDF format.
  • Structured Data in Excel (.XLSX) and CSV: Spreadsheet exports of the complete customer directory, materials/products catalog, invoice logs, and expense ledgers.
  • Compressed ZIP Packages (Fiscal Year-End Closing): One-click bulk download of ZIP archives bundling all issued invoice PDFs, accounting spreadsheets, and attached receipts in an organized structure.

4. Processor Obligations (OFFITIA)

OFFITIA undertakes to:

  • Process personal data exclusively for the purposes detailed in our Privacy Policy and under documented customer instructions
  • Implement appropriate technical and organizational measures to ensure data security and confidentiality
  • Notify the controller without undue delay upon becoming aware of any personal data breach
  • Assist the controller in meeting regulatory compliance and responding to data subject rights requests
  • Refrain from communicating data to third parties without authorization, except under statutory obligation or sub-processing authorized in Annex I
  • Delete or return data upon termination of services, except records required to be retained under statutory legal data blocking

5. Authorized Sub-Processors

The customer expressly authorizes engagement of the sub-processors listed in Annex I of this agreement for cloud infrastructure, payment gateways, artificial intelligence, and Veri*Factu statutory reporting. OFFITIA will notify any modification with 14 days prior notice.

6. Security Measures and Proactive Accountability

In accordance with Articles 24, 28, and 32 of the GDPR and Article 28 of Spanish LOPDGDD, OFFITIA applies appropriate technical and organizational measures to ensure a level of security proportional to the risk:

  • Advanced Encryption: TLS 1.3 encryption in transit and AES-256 encryption at rest across databases and cloud servers (Frankfurt, EU).
  • Access Control & Authentication: Strict user data segregation (Row Level Security), bcrypt password hashing, and secure authentication via Supabase Auth.
  • Periodic Risk Assessment: Contractual commitment to conduct a formal Risk Assessment at least annually or following significant technical updates, evaluating threats and defense efficacy.
  • Continuous Verification: Regular resilience testing and automated daily redundant backups.
  • Audit Documentation: Maintaining documentation evidencing these evaluations available to the Customer upon request.

7. Security Breach Notification Protocol (48-Hour Guarantee)

If OFFITIA becomes aware of a personal data breach (incident causing accidental or unlawful destruction, loss, alteration, or unauthorized access):

  1. 48-Hour Notification Window: OFFITIA will notify the Customer without undue delay and within a maximum of 48 hours of becoming aware of the breach, enabling the Customer to fulfill their statutory reporting duty to the supervisory authority within the 72-hour legal window (Art. 33 GDPR).
  2. Notification Content: The notice will detail the nature of the breach, affected categories and records, contact details of the security point of contact (support@offitia.io), likely consequences, and remediation measures implemented immediately.
  3. Collaboration: OFFITIA will actively cooperate with the Customer in investigating the incident and preparing necessary supervisory documentation.

8. Audit Rights and Compliance Verification

Pursuant to Article 28.3.h of the GDPR, OFFITIA makes available to the Customer all information necessary to demonstrate compliance with this DPA:

  • Executive Risk Summary: OFFITIA will provide the Customer, upon reasonable written request, an executive summary report of its latest Risk Assessment and technical security audits.
  • Independent Audits: The Customer may conduct an audit either directly or through an accredited independent auditor with a minimum prior notice of 30 business days, at most once per calendar year (unless there are substantiated indications of non-compliance or prior personal data breach). Costs are borne by the Customer (except in cases of material breach by OFFITIA), and the auditor must execute a strict confidentiality agreement protecting other customers and trade secrets.

9. Data Residency and International Transfers

Personal data is stored and processed primarily in European Union data centers (Spain and Frankfurt/Germany). Where US-based auxiliary providers are engaged (e.g. OpenAI or Stripe), international transfers operate under the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCC) approved by the European Commission. Regarding OpenAI, OFFITIA guarantees via Enterprise agreements that customer data is never used to train third-party AI models.

10. Duration, Termination, and Legal Data Blocking

This DPA remains in force while the customer holds an active account. Upon termination:

  1. Phase 1 (Portability): The account remains in read-only mode for 30 calendar days to enable complete export of data and invoices (SAN 706:2025).
  2. Phase 2 (Legal Data Blocking): Following the 30-day window, login access is disabled and tax/invoice records are placed in a blocked state pursuant to Art. 32 LOPDGDD and Spanish General Tax Law, retained encrypted for 5 years exclusively for AEAT and judicial authorities.
  3. Permanent Purge: Upon expiration of the 5-year statutory period, all data is permanently and irreversibly destroyed.

Annex I — List of Authorized Sub-Processors

Sub-ProcessorProcessing PurposeLocation / Guarantee
Vercel Inc. / Vercel EuropeWeb hosting and serverless API executionFrankfurt, Germany (EU)
Supabase Inc. / Supabase EUSQL Database and encrypted storage vaultFrankfurt, Germany (EU)
Stripe Payments Europe Ltd.Payment processing and subscription managementIreland (EU) / DPF (USA)
VeriFacti.com (Verifacti SL)Veri*Factu records generation and AEAT electronic gatewaySpain (EU)
OpenAI LLCReceipt OCR processing (Zero customer data model training)USA (Data Privacy Framework)
Google Ireland Ltd. / Microsoft Ireland Ltd.OAuth authentication and email integrationIreland (EU)

Annex II — Authorization for Submission of Records to the AEAT

Within the framework of the Pro and Business plans, the User (Data Controller) expressly authorizes OFFITIA (Data Processor) to carry out the automatic electronic submission of billing records and tax data to the Spanish Tax Agency (AEAT). This communication is performed in strict compliance with the legal obligation established in the Twenty-first Additional Provision of Law 56/2007 and Royal Decree 1007/2023. The User guarantees having informed the invoice recipients about such data processing in accordance with Article 13 of the GDPR.