Data Processing Agreement

Add your details, then download the completed agreement as a PDF.

This Data Processing Agreement ("DPA") is between Billpal e.U. (Roman Leeb) ("Billpal", "Processor") and [Customer legal name] ("Customer", "Controller"). It forms part of the Billpal Terms of Service (https://billpal.io/terms) and governs personal data Billpal processes on Customer's behalf when providing the Service.

Effective date: 10 September, 2026. Template last updated: 10 September, 2026.

This DPA applies through the Terms when you use the Service. Generating this PDF is a copy for your file. Billpal's details are pre-filled.

1. Parties

Processor: Billpal e.U. (Roman Leeb), Erdberger Lände 36/90, 1030 Vienna, Austria, VAT ATU79798417. Contact: support@billpal.io.

Customer: [Customer legal name]. Signed for Customer by [Signatory name], [Signatory title].

2. Roles

Customer is controller of personal data in Customer's Billpal workspaces (documents, mailbox captures, WhatsApp media, portal sessions, contacts, and related records), or is itself a processor acting for an underlying controller (for example a CPA holding client files). Billpal is processor of that data, or sub-processor where Customer is a processor.

Billpal is controller of Customer's account, billing, product emails, security logs, and visits to billpal.io. That controller processing is described in the Privacy Policy and is outside this DPA.

Where Customer is a processor for its own clients, Customer warrants it has the right to instruct Billpal, and that those clients (the controllers) have authorized this processing. Billpal may rely on Customer's instructions as reflecting the underlying controller's instructions.

3. Subject matter

Subject matter: hosting and processing workspace data so Billpal can capture, extract, categorize, store, collaborate on, and export billing documents.

Duration: for as long as Customer uses the Service and until deletion or return as set out below.

Nature and purpose: capture from email, WhatsApp, portals, and upload; AI admission and extraction; categorization; contacts; rules; export; support that Customer requests.

Types of personal data: names, contact details, tax IDs, addresses, invoice and receipt content, email message content we fetch to find documents, WhatsApp numbers and messages, portal session cookies, and similar business records Customer stores.

Data subjects: Customer's staff, Customer's suppliers and customers, and (where applicable) Customer's clients and their counterparties.

4. Instructions

Billpal processes personal data only on documented instructions from Customer: the Terms of Service, the Privacy Policy, this DPA, and settings Customer configures in the Service (including connected inboxes, WhatsApp, portals, invites, and deletion).

Billpal will tell Customer if it believes an instruction infringes GDPR, unless the law forbids that notice.

5. Confidentiality

Billpal ensures persons authorized to process the data are bound by confidentiality.

6. Security

Billpal implements appropriate technical and organisational measures, including TLS in transit, encryption at rest, AES-256 for sensitive tokens, row-level access controls, rate limiting, and bot protection. IMAP mailbox passwords are stored on Billpal's email host in Germany. Portal vendor passwords are not stored; session cookies are held by the portal provider. Details are in the Privacy Policy.

7. Subprocessors

Customer authorizes Billpal to use the subprocessors listed in the Privacy Policy (https://billpal.io/privacy), section "Subprocessors", including their privacy and DPA links. That list is the current list.

Customer gives a general authorization for Billpal to add or replace subprocessors. Billpal will update the Privacy Policy list when a subprocessor that processes workspace data changes. Customer may object on reasonable data-protection grounds by emailing support@billpal.io. If the parties cannot agree, Customer may stop using the affected feature or terminate the Service.

Billpal will impose data-protection obligations on subprocessors that are no less protective than this DPA, so far as they apply to that subprocessor's work.

8. International transfers

Some subprocessors are outside the EEA. Billpal relies on that provider's DPA, Standard Contractual Clauses, the EU-US Data Privacy Framework where the provider participates, or an equivalent safeguard, as described in the Privacy Policy.

9. Assistance

Taking into account the nature of processing, Billpal will assist Customer, by appropriate technical and organisational measures, in responding to data-subject requests and in meeting Customer's obligations on security, breach notification, and data-protection impact assessments, so far as possible. The Service's Settings, export, and deletion tools are the first line of that assistance. Further help is via support@billpal.io.

10. Personal data breach

Billpal will notify Customer without undue delay after becoming aware of a personal data breach affecting data processed under this DPA, and will provide information Customer reasonably needs to meet Art. 33 and 34 GDPR.

11. Deletion and return

During the Service, Customer can export documents and contacts and can delete documents, connections, and workspaces as described in the Privacy Policy.

When Customer deletes an account, Customer chooses Transfer or Delete for every workspace it owns. Transfer moves that workspace to another member. Delete removes that workspace's data. Email and portal access is revoked. Private credentials never transfer.

Billing records are kept as required by Austrian tax law (up to 7 years). Stripe is the tax archive for invoices and settlements. After a Billpal account is deleted, Billpal keeps a minimal record that the account existed, then deletes it when that window ends.

12. Audits

Billpal will make available information reasonably necessary to demonstrate compliance with this DPA. Onsite audits are limited to what is necessary, on reasonable notice, no more than once per year unless a competent authority or a documented breach requires more. Customer may use a qualified independent auditor bound by confidentiality. Billpal may refuse an auditor who is a competitor. Customer bears its own audit costs.

13. Customer warranties

Customer warrants it has a lawful basis to collect the data and to instruct Billpal, including a basis for any client, supplier, or staff personal data. Customer will not instruct Billpal to process data in a way that infringes data-protection law.

Customer is responsible for connecting only email accounts, WhatsApp numbers, and vendor websites it is authorized to access, and for those third parties' terms.

14. Liability

Liability under this DPA follows the limitation of liability in the Terms of Service, except that nothing excludes liability that cannot be limited under applicable data-protection law.

15. Governing law

This DPA is governed by the laws of Austria. The courts of Vienna, Austria have exclusive jurisdiction, without prejudice to mandatory consumer protections where they apply.

16. Signatures

For Billpal: Roman Leeb, Owner. Signed by providing this DPA for download.

For Customer: [Signatory name], [Signatory title], on behalf of [Customer legal name]. Signed by generating this PDF on 10 September, 2026.

Live subprocessor list: https://billpal.io/privacy