This Data Processing Addendum ("DPA") is entered into between {{controller_name}}, {{controller_address}} ("Controller"), and TaxRouter UG (haftungsbeschränkt), Lange Reihe 14, 20099 Hamburg, Germany ("Processor"). It forms part of the agreement under which Processor provides TaxRouter services to Controller (the "Main Agreement").
1. Scope and order of precedence
This DPA applies where Processor processes personal data on behalf of Controller within the meaning of Article 28 GDPR. If this DPA conflicts with the Main Agreement on processing personal data, this DPA prevails. Mandatory data-protection law prevails over both.
Controller remains responsible for determining the purposes and essential means of processing and for the lawfulness, transparency, accuracy, and data-subject communications relating to its processing.
2. Details of processing
The subject matter, duration, nature, purpose, data categories, and data subjects are described in Annex 1. Processing continues for the term of the Main Agreement and any period required to return or delete data, unless law requires further processing.
3. Documented instructions
Processor will process personal data only on Controller's documented instructions, including instructions in the Main Agreement, this DPA, Controller's use and configuration of the service, and authorized support requests. Processor will inform Controller if it believes an instruction infringes applicable data-protection law, unless prohibited by law, and may suspend the affected processing pending clarification.
If Union or Member State law requires processing outside Controller's instructions, Processor will inform Controller before processing unless the law prohibits that information for important public-interest reasons.
4. Confidentiality and personnel
Processor ensures that persons authorized to process personal data are bound by confidentiality or an appropriate statutory duty and receive access only to the extent needed for their duties. Processor maintains proportionate privacy and security awareness measures for relevant personnel.
5. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of processing, Processor will implement and maintain appropriate technical and organizational measures under Article 32 GDPR. The applicable measures are described in the Technical and Organizational Measures document incorporated as Annex 2.
Processor may update individual measures where the overall level of protection is not materially reduced. Material reductions require Controller's prior agreement where required by law.
6. Subprocessors
Controller grants Processor general written authorization to engage subprocessors listed in the current Subprocessor List. Processor will impose data-protection obligations on subprocessors that provide substantially equivalent protection for the relevant processing and remains responsible for their performance as required by Article 28 GDPR.
Processor will give notice of an intended addition or replacement at least 30 calendar days before the change. Controller may object on reasonable data-protection grounds within 14 calendar days after receipt of the notice. The parties will attempt in good faith to resolve the objection. If no reasonable solution is available, Controller may terminate the service affected by the change on 30 days' notice to the end of a month; the remainder of the Main Agreement is unaffected.
7. International transfers
Processor will not transfer personal data to a third country or international organization except on documented instructions and with a lawful transfer mechanism. Where Processor or a subprocessor relies on standard contractual clauses, the applicable modules, supplementary measures, and transfer assessments will be made available as legally required. On request, Processor will identify the third countries to which personal data is actually transferred in connection with the service and the transfer mechanism used in each case (for example, an adequacy decision or standard contractual clauses, including the applicable module and supplementary measures).
8. Assistance to Controller
Considering the nature of processing and information available to Processor, Processor will reasonably assist Controller with:
- responding to requests to exercise data-subject rights;
- compliance with security obligations under Articles 32 to 34 GDPR;
- data-protection impact assessments and prior consultations under Articles 35 and 36 GDPR; and
- information reasonably necessary to demonstrate compliance with Article 28 GDPR.
If a data subject or supervisory authority contacts Processor directly about Controller data, Processor will refer the request to Controller unless legally required to respond and will not respond substantively without authorization.
Assistance within the ordinary scope is included in the service fees under the Main Agreement. If a Controller request substantially exceeds the ordinary scope or requires exceptional effort (including extensive manual preparation, separate technical analysis, or assistance with a regulatory audit), Processor may charge a reasonable fee at the rates recorded in the Main Agreement and will inform Controller of the expected effort before beginning that work. Requests must be sent to info@taxrouter.com; Processor will acknowledge receipt within 2 business days and provide an estimated processing time. Processor's mandatory obligations under Article 28(3)(e) and (f) GDPR remain unaffected.
9. Personal data breaches
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data. The notice will include available information required for Controller's assessment and notification duties, including the nature of the breach, likely consequences, affected data and persons, and measures taken or proposed. Information may be provided in phases where it is not available at the same time.
Processor aims to provide an initial notice to Controller within 24 hours after becoming aware of a breach, without limiting the obligation to notify without undue delay under the preceding paragraph. Notices will be sent to the contact address designated by Controller and through Processor's monitored security contact at info@taxrouter.com. If no response is received for more than 24 hours, Controller may escalate the matter through the contact form for the attention of the Managing Director. Communications will use an encrypted channel suitable for personal data.
10. Audit and evidence
Processor will provide information necessary to demonstrate compliance with this DPA and allow audits, including inspections, by Controller or an independent auditor mandated by Controller. Audits must respect confidentiality, security, other customers, and operational continuity and should ordinarily rely first on current certifications, independent reports, questionnaires, and remote evidence.
Unless a personal data breach, substantiated compliance concern, or supervisory authority requires otherwise, on-site audits are limited to once per calendar year, require reasonable advance notice, occur during business hours, and are conducted at Controller's cost. Auditors may not be direct competitors and must be bound by confidentiality.
11. Return and deletion
At Controller's choice and subject to the Main Agreement, Processor will return or delete personal data after the end of services and delete existing copies, unless Union or Member State law requires storage. Data in backups will be isolated from ordinary use and deleted through documented backup-expiration cycles.
Controller may request an export of its data in a commonly used, machine-readable format within 30 calendar days after the services end. After that export window expires, Processor will delete the data from production systems within a further 30 calendar days. Backup data will be overwritten or deleted through the regular backup-expiration cycle no later than 90 calendar days after the services end. On request, Processor will confirm completed deletion in text form. Records subject to a legal retention obligation will be isolated from further processing, retained solely to meet that obligation, and deleted when the applicable retention period expires.
12. Liability and term
This DPA remains in effect for as long as Processor processes personal data on Controller's behalf. Liability is governed by the Main Agreement to the extent permitted by applicable law and without limiting mandatory rights or liabilities under the GDPR.
Annex 1 — Description of processing
Subject matter and purpose
Provision, security, support, and maintenance of TaxRouter, including authorized marketplace-data synchronization, import normalization, VAT and accounting workflows, reconciliation, evidence handling, exports, user and access administration, support, and audit trails.
Nature of processing
Collection, receipt, access, organization, structuring, storage, adaptation, retrieval, consultation, matching, calculation, transmission to authorized recipients, restriction, export, and deletion as configured or instructed.
Duration
For the Main Agreement term plus agreed return and deletion periods and any mandatory legal retention.
Categories of data subjects
- Controller's users, employees, contractors, and advisers;
- Controller's customers, suppliers, and business contacts;
- marketplace buyers, sellers, recipients, and other persons represented in authorized source data; and
- other persons whose data Controller lawfully submits to the service.
Categories of personal data
- identity, account, role, and contact data;
- organization, contract, billing, and support data;
- transaction, order, invoice, payment-reference, settlement, tax, VAT, shipment, and accounting data;
- integration identifiers, authorization metadata, synchronization status, and logs;
- documents, exports, communications, and uploaded files; and
- device, IP, audit, diagnostic, and security data.
Processing special categories of personal data within the meaning of Article 9 GDPR or data relating to criminal convictions and offences within the meaning of Article 10 GDPR is not covered by this DPA and is prohibited within the service. Controller will ensure that it does not submit such data to the service; if it does, Controller is liable for the resulting damage and will indemnify Processor against third-party claims to that extent.
Controller instructions
The Main Agreement, this DPA, settings and actions of authorized users, documented support requests, and any further lawful written instructions agreed by the parties.
Annex 2 — Technical and organizational measures
The version of the Technical and Organizational Measures document identified in the contract or acceptance record forms Annex 2. The stable URL https://taxrouter.com/legal/technical-organizational-measures displays the latest approved version; the recorded version and immutable acceptance snapshot determine the version incorporated into this DPA.
Annex 3 — Authorized subprocessors
The version of the Subprocessor List identified in the contract or acceptance record forms Annex 3. The stable URL https://taxrouter.com/legal/subprocessors displays the latest approved version. Later changes are governed by Section 6 and do not alter the evidence of which version was accepted.