This agreement governs the processing of personal data when using the invoiceverify.eu e-invoice validation tool. The German version is legally authoritative; this translation is provided for convenience.
1. Parties
Processor: netzmal GmbH, Robert-Koch-Straße 48, 25813 Husum, Germany, represented by managing director Tim David Saxen, email: info@netzmal.de.
Controller: the natural or legal person initiating the upload and electronically accepting this agreement before upload. The uploader confirms authority to conclude the agreement and transmit the data.
2. Processing
The service receives, temporarily stores, extracts, parses and validates PDF/XML e-invoices and displays results in the browser. Processing starts with upload and ends with deletion of all uploaded and generated working files, no later than 24 hours after upload. The Processor does not use invoice content for its own purposes.
3. Data and data subjects
Data may relate to employees, contacts, customers, suppliers and other persons named in invoices. It may include identification, contact, address, invoice, service, order, tax, payment and bank data. Special-category data under Article 9 GDPR is not intended and must not be uploaded.
4. Instructions
The Processor acts only on documented instructions. Upload, selected analysis functions and deletion rules constitute the initial instruction. Further instructions may be sent to info@netzmal.de. The Processor will notify the Controller if an instruction appears to infringe data protection law. No third-country transfer takes place unless expressly agreed or legally required.
5. Confidentiality and security
Access is limited to authorised persons bound by confidentiality. Measures under Article 32 GDPR include TLS transport encryption, restrictive access permissions, isolated temporary upload directories, minimised logging, security updates and automated deletion.
6. Assistance and incidents
Taking account of the nature of processing, the Processor assists with data-subject requests and obligations under Articles 32 to 36 GDPR. Personal data breaches in the Processor’s area are reported without undue delay with the information available.
7. Deletion and return
Personal data and working files are deleted after the service, no later than 24 hours after upload, unless law requires retention. Return is not intended for this short-lived automated processing; the Controller retains the original. Backups are overwritten according to defined cycles.
8. Information and audits
The Processor provides information necessary to demonstrate compliance and permits proportionate audits on reasonable notice, subject to confidentiality and security. Suitable certifications, audit reports and documentation may be used first.
9. Sub-processors
The Controller grants general authorisation for the listed sub-processor. Planned changes will be announced with an opportunity to object on reasonable grounds. Equivalent obligations apply and the Processor remains responsible.
Industriestraße 25, 91710 Gunzenhausen, Germany
Server and data-centre infrastructure within the EU/EEA
10. Controller obligations
The Controller remains responsible for lawfulness, transparency and data-subject rights and uploads only necessary, lawfully obtained data.
11. Liability and final terms
Statutory liability, including Article 82 GDPR, remains unaffected. Amendments require text form. German law applies; where permitted, Husum is the place of jurisdiction.
12. Electronic conclusion
The agreement is concluded before the first upload by expressly selecting the unchecked DPA checkbox. Time, version, language and pseudonymised technical evidence are logged. The full text is available before acceptance.