Data Processing Agreement

GDPR Data Processing Agreement

Last Modified: 28 September 2026

This DPA applies to new customers from 28 September 2026 and to existing customers from 1 November 2026.

This GDPR Data Processing Agreement (DPA) forms part of the Terms of Service available at https://www.datamolino.com/legal/terms-of-service/ or such other location as the Terms of Service may be posted from time to time, entered into by and between the Customer and Datamolino s.r.o. (Datamolino), pursuant to which Customer has accessed Datamolino’s Services as defined in the applicable Terms of Service. The purpose of this DPA is to reflect the parties’ agreement with regard to the processing of personal data in accordance with the requirements of Data Protection Legislation as defined below.

If the Customer entity entering into this DPA is not party to the Terms of Service, this DPA is not valid and is not legally binding. Such entity should request that the Customer entity that is a party to the Agreement executes this DPA.

This DPA shall not replace or supersede any agreement or addendum relating to processing of personal data negotiated by Customer and referenced in the Terms of Service, and any such individually negotiated agreement or addendum shall apply instead of this DPA.

In the course of providing the Services to Customer pursuant to the Terms of Service, Datamolino may process personal data on behalf of Customer. Datamolino agrees to comply with the following provisions with respect to any personal data submitted by or for Customer to the Services or collected and processed by or for Customer through the Services. Any capitalized but undefined terms herein shall have the meaning set forth in the Terms of Service.

Data Processing Terms

In this DPA, “Data Protection Legislation” means the General Data Protection Regulation (Regulation (EU) 2016/679), the UK GDPR and the UK Data Protection Act 2018, and all other applicable laws relating to processing of personal data and privacy that may exist in any relevant jurisdiction.

“data controller”, “data processor”, “data subject”, “personal data”, “processing”, and “appropriate technical and organisational measures” shall be interpreted in accordance with applicable Data Protection Legislation;

The parties agree that Customer is the data controller and that Datamolino is its data processor in relation to personal data that is processed in the course of providing the Services. Where Customer processes the personal data on behalf of its own clients, Customer is a processor and Datamolino is its subprocessor, and Customer confirms that the relevant controller has authorised Datamolino’s engagement. Customer shall comply at all times with Data Protection Legislation in respect of all personal data it provided to Datamolino pursuant to the Terms of Service.

The subject-matter of the data processing covered by this DPA is the Services ordered by Customer through Datamolino’s website and provided by Datamolino to Customer via www.datamolino.com or app.datamolino.com, or as additionally described in the Terms of Service or the DPA. The processing will be carried out until the term of Customer’s ordering of the Services ceases. Further details of the data processing are set out in Annex 1 hereto.

In respect of personal data processed in the course of providing the Services, Datamolino:

  1. shall process the personal data only in accordance with the documented instructions from Customer (as set out in this DPA or the Terms of Service or as otherwise notified by Customer to Datamolino (from time to time). If Datamolino is required to process the personal data for any other purpose provided by applicable law to which it is subject, Datamolino will inform Customer of such requirement prior to the processing unless that law prohibits this on important grounds of public interest;
  2. shall notify Customer without undue delay if, in Datamolino’s opinion, an instruction for the processing of personal data given by Customer infringes applicable Data Protection Legislation;
  3. shall implement and maintain appropriate technical and organisational measures designed to protect the personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage, theft, alteration or disclosure. These measures shall be appropriate to the harm which might result from any unauthorised or unlawful processing, accidental loss, destruction, damage or theft of the personal data and having regard to the nature of the personal data which is to be protected;
  4. may hire other companies to provide limited services on its behalf, provided that Datamolino complies with the provisions of this Clause. Any such subcontractors will be permitted to process personal data only to deliver the services Datamolino has retained them to provide, and they shall be prohibited from using personal data for any other purpose, except as described under Service improvement below. Datamolino remains responsible for its subcontractors’ compliance with the obligations of this DPA. Any subcontractors to whom Datamolino transfers personal data will have entered into written agreements with Datamolino requiring that the subcontractor abide by terms substantially similar to this DPA. A list of subcontractors is available to the Customer’s account owners in the Datamolino app, and Datamolino sends it by email on request to support@datamolino.com. Datamolino will inform the Customer of any intended addition or replacement of a subcontractor by updating that list and notifying the account owner by email at least 14 days before the change takes effect. The Customer may object before the change takes effect by writing to support@datamolino.com, giving reasons related to data protection. If the Customer does not object within that period, it accepts the change. If the Customer objects, its remedy is to cancel its account and export its data before the change takes effect.
  5. shall ensure that all Datamolino personnel required to access the personal data are informed of the confidential nature of the personal data and comply with the obligations sets out in this Clause;
  6. at the Customer’s request and cost (and insofar as is possible), shall assist the Customer by implementing appropriate and reasonable technical and organisational measures to assist with the Customer’s obligation to respond to requests from data subjects under Data Protection Legislation (including requests for information relating to the processing, and requests relating to access, rectification, erasure or portability of the personal data) provided that Datamolino reserves the right to reimbursement from Customer for the reasonable cost of any time, expenditures or fees incurred in connection with such assistance;
  7. shall take reasonable steps at the Customer’s request and cost to assist Customer in meeting Customer’s obligations under Article 32 to 36 of that regulation taking into account the nature of the processing under this DPA, provided that Datamolino reserves the right to reimbursement from Customer for the reasonable cost of any time, expenditures or fees incurred in connection with such assistance;
  8. at the end of the applicable term of the Services, shall delete or return the personal data, at Customer’s choice, as described in the Terms of Service, unless applicable law requires Datamolino to keep it;
  9. may transfer personal data outside the EEA or the UK, provided that the transfer is covered by an adequacy decision, by standard contractual clauses approved by the European Commission (with the UK addendum for data from the UK), or by another transfer mechanism permitted by Data Protection Legislation;
  10. shall allow Customer and its respective auditors or authorized agents to conduct audits or inspections during the term of the Terms of Service, which shall include providing reasonable access to the premises, resources and personnel used by Datamolino in connection with the provision of the Services, and provide all reasonable assistance in order to assist Customer in exercising its audit rights under this Clause. The purposes of an audit pursuant to this Clause include to verify that Datamolino is processing personal data in accordance with its obligations under the DPA and applicable Data Protection Legislation. Notwithstanding the foregoing, such audit shall in the first instance consist of: (i) the provision by Datamolino of written information (including, without limitation, questionnaires and information about security policies) that may include information relating to subcontractors; and (ii) interviews with Datamolino’s IT personnel. Such audit may be carried out by Customer or an inspection body composed of independent members and in possession of the required professional qualifications bound by a duty of confidentiality. An inspection of premises or systems may take place only if that information is not sufficient to demonstrate compliance or a supervisory authority requires it, with at least 30 days’ written notice, no more than once in any 12 months, during business hours, at Customer’s cost (including Datamolino’s reasonable costs), and without access to other customers’ data or to anything that would compromise Datamolino’s security. The auditor must not be a competitor of Datamolino and must sign a confidentiality agreement. Datamolino may comment on the draft audit report and decides, within a reasonable time, how to address any findings;
  11. If Datamolino becomes aware of any accidental, unauthorised or unlawful destruction, loss, alteration, or disclosure of, or access to the personal data that is processed by Datamolino in the course of providing the Services (an “Incident”) under the Terms of Service it shall without undue delay notify Customer and provide Customer (as soon as possible) with a description of the Incident as well as periodic updates to information about the Incident, including its impact on Customer content. Datamolino shall additionally take action to investigate the Incident and reasonably prevent or mitigate the effects of the Incident;
  12. Datamolino shall provide information requested by Customer to demonstrate compliance with the obligations set out in this DPA.

Service improvement

The Services process documents automatically. Datamolino personnel access them only when needed for customer support, correcting errors, or setting up and testing the Services, including data capture settings.

Datamolino may use the documents submitted to the Services, and the data extracted from them, to improve how the Services read documents, including to train the models and test the prompts and settings that read documents. This does not include account details, the Customer’s communications with Datamolino, or data Datamolino receives from accounting software the Customer connects, such as contacts, chart of accounts or tax rates. Because documents may contain personal data of the people named on them, such as suppliers’ contact persons, Datamolino acts for this purpose as an independent controller on the basis of its legitimate interest (Article 6(1)(f) GDPR). It uses only what it needs, does not make the data available to anyone for their own purposes, and protects it in the same way as the Services. If the Customer does not agree with this use, it may cancel its account.

Some subcontractors that read documents may use the documents they process to improve their own services, under their own terms, as is common for such services. The list of subcontractors shows which. The Customer authorises this. Datamolino uses general-purpose AI models under business or API terms that do not allow the provider to train its models on the data.

Messages and files sent to Datamolino’s customer support, by chat or email, are handled by its support tool, whose provider may use them to improve its AI assistant. The Customer should not send documents for processing through customer support.

Datamolino may also create anonymised or aggregated data from documents, results and use of the Services, including corrections users make to extracted data, and use it for statistics, research and to improve the Services. Such data does not identify the Customer or any person, and it belongs to Datamolino.

Liability

The limitations of liability in the Terms of Service, or in the Datamolino for Business Agreement where it applies, also apply to this DPA. The Customer will compensate Datamolino for fines, damages and reasonable costs that result from the Customer’s breach of Data Protection Legislation.

Annex 1

Details of the Data Processing

Datamolino shall process information to provide the Services pursuant to the Terms of Service. Datamolino shall process information sent by Customer’s end users identified through Customer’s implementation of the Services.  As an example, in a standard programmatic implementation, to utilize the Services, Customer may allow the following information to be sent by default as “default properties:”

Types of Personal Data

When it comes to users of our Service:

  • name
  • phone number
  • email

When it comes to the files that users of our Service submit to us, we process the following data, some of which may be considered as personal data:

  • IP address used during login to our Service
  • Invoice Supplier and Customer data in the extent of: name, supplier id, tax id, vat id, bank account details, street, city, postal code, country.
  • Invoice contents in the extent of: full invoice text, invoice description, invoice line items, invoice number, SEPA reference, variable symbol, specific symbol, issue date, tax date, due date. currency, currency rate, invoice quantities, sums and applicable taxes.
  • Bank statement data in the extent of: counterparties, amounts, dates and references.
  • Metadata connected to file uploads in the extent of: who uploaded the file, what file was uploaded, which channel was used to upload the file (web, email, api, mobile app), email address of the user that uploaded files to our service.

Additional detail regarding what information Customer may send to Datamolino can be found in the Terms of Service.

Categories of Data Subjects

Users of the Customer’s account, and the Customer’s suppliers, customers, employees and other persons whose personal data appears in documents submitted to the Services.

Processing Activities

The provision of Services by Datamolino to Customer, and customer support.

Annex 2

The current list of Datamolino’s subcontractors and subprocessors, with their purpose and location, is available to the Customer’s account owners in the Datamolino app. Datamolino sends it by email on request to support@datamolino.com.