Data Processing Agreement (DPA)
Version: 1.5-draft · Last reviewed: 2026-05-12
This DPA is entered into pursuant to GDPR Art. 28 between you, as Controller, and Nodex, as Processor for specific data categories. It is an integral part of the Terms of Service.
Operator (Nodex)
The current operator of the Nodex service is Andrei Buliga PFA, CUI 54243750, Strada General Petre Popovăț 57, et. 1, ap. 11, Sector 6, Bucharest. Upon incorporation of Nodex SRL (planned mid-2026), the operator will transfer to the new legal entity with 30 days' prior notice to all active users, pursuant to GDPR Art. 13 and the terms below.
Roles
| Data set | User role | Nodex role | | ------------------------------------------------------------- | -------------- | ----------------------------------------------------------------- | | User's customer fiscal data (CUI, IBAN, invoices, line items) | Controller | Processor | | Supplier data extracted via OCR (Mistral) | Controller | Processor | | Accountant-client cross-references | Controller | Processor | | User's own account data (email, password, organization) | — | Independent Controller (see Privacy Policy) |
Data categories and subjects
- Data subjects: the User's customers and suppliers (Romanian individuals and legal entities), the User's employees insofar as they appear on invoices, the User's accountant.
- Categories: tax IDs (CUI/CNP/IBAN), invoice line items (product/service descriptions, amounts, VAT), supplier data extracted by OCR (company name, amounts, VAT rates), accountant cross-references.
- Special categories (Art. 9 GDPR): Not processed intentionally. If the User uploads such data, responsibility rests with the User.
Duration of processing
Active subscription duration + legal retention periods (see Privacy Policy).
Sub-processors
All sub-processors are EU-resident; no SCCs are required for V1.5.
| Sub-processor | Role | Region |
| --------------------- | ------------------------------------- | -------------------------------------- |
| Supabase Cloud Pro | Postgres + Auth + Realtime | Ireland (eu-west-1) |
| Cloudflare R2 | Fiscal archive (Object Lock 10 years) | EU jurisdiction |
| Hetzner | Application hosting | Frankfurt, Germany |
| Resend | Transactional email | Germany |
| Stripe Direct | Payment processing | Ireland (EU) / USA (non-EU, disclosed) |
| Mistral La Plateforme | Document OCR, no training on input | Paris, France |
| Google Vertex AI | LLM categorization (V1.5+) | Frankfurt (europe-west4) |
Change notice: Nodex will notify the User 14 days before adding a new sub-processor. The User may object on reasoned grounds; if the objection cannot be resolved technically, the User has the right to terminate the subscription without penalty, with pro-rata refund for the unserved period.
Technical and organizational measures (Art. 32)
| Measure | Implementation |
| ------------------------ | -------------------------------------------------------------------------------------------------------------- |
| Encryption in transit | TLS 1.3 enforced (Cloudflare, Hetzner) |
| Encryption at rest | AES-256 (Supabase default + R2 default) |
| Tenant data isolation | Postgres Row-Level Security (RLS) with policies based on org_id in JWT claims |
| Access control | Supabase RLS + org-scoped JWT claims + 2FA for admin accounts (V1.5+) |
| Audit log | Trigger on every mutation, append-only, 5-year retention per Law 82/1991 Art. 25 as amended by Law 36/2023 |
| Pseudonymization | Applied where feasible (UUIDs in audit log) |
| Backup | Daily Supabase snapshots + 7-day retention; R2 intra-regional replication |
| Vulnerability management | Dependency scanning via CI; response to critical CVEs within 7 days |
Controller assistance (Art. 28(3)(e))
Nodex provides the User with export tools (CSV/JSON of its data) and erasure tools (subject to fiscal constraints). The User remains Controller for its end-customers' data and responds directly to those data subject requests; Nodex provides reasonable technical assistance.
Breach notification (Art. 28(3)(f) + Art. 33)
Nodex will notify the User without undue delay and no later than 72 hours after becoming aware of a security breach affecting data processed on behalf of the User. The notification will include: nature of the breach, approximate categories and number of affected persons, measures taken or proposed.
Audit rights (Art. 28(3)(h))
- All plans: annual written report on request, covering security policies, active sub-processors, and incidents from the prior year.
- Business+ plan: on-site audit possible with 30 days' prior notice, during business hours, reasonable costs borne by the User if the audit exceeds reasonable scope. Auditors are bound by confidentiality.
Return/deletion at end (Art. 28(3)(g))
Upon subscription termination, the User benefits from a 90-day grace period for export. After that, data is deleted, except fiscal documents subject to legal retention (Law 82/1991 Art. 25 + MFP Order 2634/2015) — these remain in R2 Object Lock until legal retention expires (10 years for fiscal documents; 5 years for audit log). The User remains the data owner and can request access during this interval.
Confidentiality
All sub-processors are contractually bound to equivalent confidentiality. Nodex personnel sign confidentiality agreements. Access to User data is limited on a need-to-know basis.
DPA contact
privacy@nodex.nodera.ro.