Skip to content

Legal

Data Processing Agreement

Version 2026-09-B Effective

Controller and contact

KRONENWERK

230 boul. HarwoodVaudreuil-Dorion (Québec) J7V 0L4Canada

Contact support@kronenwerk.org

Person in charge of the protection of personal information Tyler Pernitsch support@kronenwerk.org

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the business using KRONENWERK (the "Customer") and the provider identified in the Legal Notice ("KRONENWERK"). It applies wherever KRONENWERK processes personal data on the Customer's behalf and the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the Swiss FADP or a comparable law requires such an agreement. It is written to describe what the software actually does; where something is not done, this DPA does not promise it.

1. Roles

For the records the Customer creates in KRONENWERK — its customers, suppliers, contacts, invoices, quotes, receipts, bank transactions, accounting entries and documents — the Customer is the controller and KRONENWERK is the processor within the meaning of Article 28 GDPR.

For the Customer's own account, sign-in credentials, subscription and billing, KRONENWERK is the controller; that processing is described in the Privacy Policy and is not the subject of this DPA.

2. Subject matter, duration, nature and purpose

Subject matter: the provision of accounting, invoicing and e-invoicing software as a service, including the generation, validation, storage, transmission and receipt of structured invoices.

Duration: the term of the Customer's subscription, plus the retrieval period and the retention periods described in section 9 of the Privacy Policy and in section 8 below.

Nature of processing: storage, structuring, rendering, validation, transmission over the delivery route the Customer's country prescribes, receipt, and backup.

Purpose: enabling the Customer to keep its books, issue and receive invoices and meet its statutory invoicing obligations. KRONENWERK processes Customer data for no other purpose, and in particular does not use it for advertising, profiling, model training or sale.

3. Types of personal data and categories of data subjects

Data subjects: the Customer's customers, suppliers and their contact persons; the Customer's employees and members who use KRONENWERK; persons named in documents the Customer uploads.

Types of data: names, business and postal addresses, email addresses, telephone numbers, tax identifiers (VAT identification numbers, national tax numbers, business registration numbers), bank account identifiers (IBAN, BIC), invoice and payment data, and the content of uploaded documents. KRONENWERK does not require and does not knowingly process special categories of data under Article 9 GDPR; the Customer undertakes not to enter such data.

4. KRONENWERK's obligations as processor

  1. Instructions. KRONENWERK processes personal data only on the Customer's documented instructions, which are the Terms of Service, this DPA and the Customer's use of the software's functions. KRONENWERK informs the Customer if it considers an instruction to infringe the GDPR. Where Union or Member State law requires KRONENWERK to process data otherwise, it informs the Customer before processing unless that law prohibits it.
  2. Confidentiality. Persons authorised to process personal data are bound by confidentiality. Access to production systems is limited to the operator.
  3. Security. KRONENWERK implements the technical and organisational measures in Annex 1. They are stated factually; they are measures, not guarantees.
  4. Sub-processors. KRONENWERK uses the sub-processors listed in Annex 2 and the Customer authorises them. KRONENWERK informs the Customer of any intended addition or replacement by publishing an updated Annex 2 at this address at least 30 days before the change, and by email to the account owner. The Customer may object on reasonable data-protection grounds within that period; if no solution is found, the Customer may terminate the subscription for the affected service with effect from the change. KRONENWERK imposes on each sub-processor data-protection obligations equivalent to this DPA and remains liable to the Customer for the sub-processor's performance.
  5. Assistance. Taking into account the nature of the processing, KRONENWERK assists the Customer with appropriate technical measures in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection), and assists with the Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation) with the information KRONENWERK holds.
  6. Personal-data breaches. KRONENWERK notifies the Customer without undue delay after becoming aware of a personal-data breach affecting Customer data, and in any event within 48 hours, with the information available at that time (nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, measures taken or proposed) and supplements it as further information becomes available.
  7. Deletion and return. At the end of the subscription the Customer may export its records during the retrieval period described in the Privacy Policy; Settings → Data export produces a complete archive (master data, customers and suppliers, issued invoices with their PDF and structured files, quotes, accounting entries, documents, members) at any time during the subscription and the retrieval period. After that period KRONENWERK deletes or anonymises personal data it is not legally required to keep. Issued invoices, accounting entries, subscription tax records and append-only security records are retained for the periods the law requires and are not deleted on request; see section 8.
  8. Information and audit. KRONENWERK makes available the information necessary to demonstrate compliance with Article 28 GDPR: this DPA, Annex 1, Annex 2 and the Privacy Policy, and on request a written description of the measures and the results of internal security testing. KRONENWERK allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, once per year or after a breach, with 30 days' notice, during business hours, at the Customer's expense, under a confidentiality undertaking and without access to other customers' data. KRONENWERK holds no third-party security certification and this DPA claims none.

5. The Customer's obligations

The Customer is responsible for the lawfulness of the data it enters, for informing its own data subjects, for the accuracy of the instructions it gives through the software, for the members it invites and the roles it assigns them, for the credentials and tokens it entrusts to KRONENWERK for delivery networks, and for observing the retention obligations that apply to its own accounting records.

6. International transfers

The application and its database run in Frankfurt, Germany. KRONENWERK is operated from Québec, Canada, which the European Commission recognises as providing an adequate level of protection for commercial organisations (Decision 2002/2/EC, as confirmed in 2024). Sub-processors established outside the EEA are listed in Annex 2 with the transfer mechanism each relies on. KRONENWERK does not transfer Customer data to any other country.

7. Delivery networks and national systems

Where the Customer's country prescribes a route for invoices — a Peppol access point, an approved platform, or a national tax-administration system — and the Customer connects to it in Settings, KRONENWERK transmits the Customer's invoices to that route and receives invoices from it on the Customer's instruction. The operator of the route is either a sub-processor (Annex 2) or, for a national tax-administration system, an independent controller under its own law. The Customer's own token for a national system is stored encrypted and used only for that Customer's transmissions.

8. Retention that the Customer cannot instruct away

Issued invoices, credit notes and accounting entries are records the Customer is legally required to retain (for example eight or ten years) and KRONENWERK preserves them as issued; correction is by credit note. KRONENWERK's own tax and billing records of the subscription are kept for the period the provider's tax law requires. Security and audit records are append-only. Where a data subject has a right to erasure, KRONENWERK removes the personal references it lawfully can while preserving the accounting record.

9. Liability and law

Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise. This DPA is governed by the law that governs the Terms of Service; the provisions of the GDPR that apply mandatorily to the processor apply regardless. If the parties enter into the European Commission's standard contractual clauses for processors (Decision (EU) 2021/915), those clauses prevail over this DPA in case of conflict.

10. Changes

Each version of this DPA carries a version identifier and an effective date at the top of the page. A materially changed version is published here before it takes effect. The English text is the authoritative version; translations, where provided, are for convenience.

Annex 1 — Technical and organisational measures

Stated as facts about the software and its operation on the date above.

  • Encryption in transit: all traffic is served over TLS 1.2 or higher with HTTP Strict Transport Security; the connection between the application and its database is encrypted inside the hosting provider's private network.
  • Encryption at rest: the hosting provider encrypts database and backup storage at rest. Integration credentials and delivery-network tokens are additionally encrypted by KRONENWERK under a key held only in the production environment.
  • Credentials: passwords are hashed with Argon2id; sign-in codes, reset tokens, trusted-device tokens and API keys are stored only as one-way hashes. A password sign-in from a device the account has not confirmed before requires a code sent to the account's email address; a password change ends every other session and forgets every confirmed device.
  • Tenant isolation: every record is bound to the Customer's organisation and every query is scoped to it on the server; identifiers alone confer no access. This boundary is covered by automated regression tests run before every release.
  • Access control: role-based permissions within the Customer's organisation; operator access to the console requires a separate credential; operator actions on a Customer's account are recorded in an append-only audit record.
  • Integrity: issued documents, subscription tax records, legal-acceptance records, security events and the operator's audit record are append-only and enforced at the database level (triggers refuse updates and deletes; the only permitted change is the removal of a personal reference on an erasure request).
  • Availability and backup: the hosting provider retains daily backups of the database. A restore rehearsal has not yet been performed by the operator; this line will be updated when it has, with the measured recovery time.
  • Logging: application logs contain no passwords, codes, tokens or secrets; security-relevant actions produce audit records.
  • Development: changes are made through version control with an automated test suite covering validation, tenant isolation and financial integrity that runs before every release; dependencies are pinned and reviewed when updated.
  • Uploads: uploaded files are validated by content, stored under system-generated keys, served without execution and never rendered as trusted application content.

Annex 2 — Sub-processors

Sub-processorServiceDataLocationTransfer mechanism
Render Services, Inc.Application hosting, PostgreSQL database, backupsAll Customer dataFrankfurt, Germany (EU)Processing in the EU; provider based in the United States, EU standard contractual clauses in its terms
Cloudflare, Inc.Content delivery, DNS, TLS termination, protection against malicious trafficRequest metadata including IP addresses; content in transitGlobal network; company based in the United StatesEU standard contractual clauses; EU–US Data Privacy Framework participant
Stripe, Inc. / Stripe Payments Europe Ltd.Subscription payments and payment links the Customer offers its own customersBilling details, payment data, tax identifiersUnited States and IrelandEU standard contractual clauses; EU–US Data Privacy Framework participant
Resend, Inc.Transactional email (invoices, quotes, reminders, sign-in codes)Recipient address, subject and content of emails sent on the Customer's behalfUnited StatesEU standard contractual clauses
Storecove B.V.Peppol access point and, where contracted, French approved platform; used only for Customers who connect their company in Settings → DeliveryInvoices and credit notes transmitted or received over the network, and the Customer's registration on itNetherlands (EU)Processing in the EU
Enable Banking OyBank account connection (European banks); used only for Customers who connect a bank account in Settings → BankingAccount identifiers, balances and transactions of the connected account; connection referenceFinland (EU)Processing in the EU
Plaid, Inc.Bank account connection (Canadian and US banks); used only for Customers who connect a bank account in Settings → BankingAccount identifiers, balances and transactions of the connected account; connection referenceUnited StatesEU standard contractual clauses; the Customer connecting a Canadian or US bank is, as a rule, itself established outside the EEA

The European Commission's VIES service is not a sub-processor: it is asked whether a VAT identification number is valid, receives only that number, and returns a public register answer.

National tax-administration systems (for example the Polish National e-Invoicing System, KSeF) are not sub-processors: they receive the Customer's invoices as independent controllers under their own law, on the Customer's instruction and with the Customer's own credentials.

Google is not a sub-processor for Customer data; it is used only to authenticate users who choose to sign in with Google, as described in the Privacy Policy.