This Data Processing Agreement ("DPA") specifies the parties' data protection obligations under Art. 28 GDPR and Art. 9 revised FADP resulting from the use of RolakInvoice. It is an integral part of the GTC and the Privacy Policy.
1. Parties
- Client (Controller): the customer using RolakInvoice.
- Processor: Rolak Automation, Owner Jan Rolak, Switzerland.
2. Subject Matter of Processing
The Processor processes personal data exclusively for the purpose of providing the contractually agreed services of RolakInvoice. This includes in particular the collection, analysis, structuring, and storage of invoice data.
3. Nature and Purpose of Processing
- Automated collection of incoming invoices from email inboxes (IMAP/POP3)
- OCR-based text recognition and AI-supported data extraction
- Validation, structuring, and storage in a local SQLite database
- Export to accounting systems (e.g., Bexio, CSV)
- Provision of the dashboard, support, and error analysis
4. Categories of Data Subjects
- Employees of the Client (users)
- Senders of invoices (suppliers, service providers)
- Natural persons mentioned in invoices (customers, recipients)
5. Categories of Personal Data
- Contact details (name, address, email, phone)
- Invoice contents (amounts, line items, invoice numbers, VAT)
- Payment references and bank details, if included on invoices
- Usage and log data of the software
6. Rights and Obligations of the Client
- The Client remains the Controller within the meaning of the data protection laws and is responsible for the lawfulness of the data processing.
- The Client issues instructions to the Processor in written or electronic form (e.g., via email).
- The Client is obliged to answer requests from data subjects themselves. The Processor shall assist appropriately.
7. Obligations of the Processor
- Processing exclusively based on documented instructions from the Client
- Obligation of the deployed employees to maintain confidentiality
- Implementation of technical and organizational measures according to Art. 32 GDPR / Art. 8 Data Protection Ordinance (DPO-FADP) (see Section 9)
- Assistance to the Client in responding to data subject requests, reporting data breaches within 72 hours
- Proof of compliance with these obligations upon request
8. Sub-processors
The Client hereby grants general authorization to engage the sub-processors listed below. Changes will be announced to the Client by email at least 30 days in advance; a right to object exists within this period.
- Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) — primary AI extraction via the Google Gemini API (processing may also take place on Google infrastructure outside the EU). Safeguards: SCCs (EU) 2021/914 Module 2 under the Google Data Processing Addendum; Gemini API Additional Terms (no model-training use, API logs max. 55 days, human review only in individual cases for abuse detection).
- OpenAI, OpCo, LLC (3180 18th Street, San Francisco, CA 94110, USA) — cross-provider fallback for AI extraction (model
gpt-4o-mini, Chat Completions / Vision API). Used exclusively when the primary provider (Google Gemini) is unavailable. Safeguards: SCCs (EU) 2021/914 Module 2 with Swiss amendments, incorporated in the OpenAI Data Processing Addendum. Under the OpenAI API Terms, API content is not used to train the models; retention max. 30 days for abuse prevention. - Infomaniak Network SA (Rue Eugène-Marziano 25, 1227 Les Acacias / Geneva, Switzerland) — hosting of the cloud backend (VPS, DB, backups). Safeguards: revised FADP-compliant, ISO 27001 certified, data centre in Switzerland.
- Stripe Payments Europe Ltd. (The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland) — payment processing (credit card, SEPA). Safeguards: SCCs (EU) 2021/914, PCI-DSS Level 1.
- Apple Inc. (One Apple Park Way, Cupertino, CA 95014, USA) — delivery of transactional emails via iCloud+ mail alias (
[email protected]). Safeguards: SCCs (EU) 2021/914 with Swiss amendments, Apple Business DPA. - Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — delivery of contact-form replies via Gmail SMTP as well as web analytics via Google Analytics 4 (only upon consent; cookies, anonymised IP). Safeguards: EU-U.S./Swiss-U.S. Data Privacy Framework (Google LLC certified) and SCCs (EU) 2021/914; for Google Analytics, the Google Ads/Measurement Data Processing Terms additionally apply.
8a. Right to Audit
The Client has the right, at most once per calendar year, to conduct an audit of the measures taken by the Processor itself or through a qualified third party. The audit must be announced in writing at least 30 days in advance, is carried out during normal business hours, and must not unreasonably disrupt business operations. The Client bears the costs of the audit unless the audit reveals material violations; otherwise the Processor bears the costs. Audit reports from recognized external auditors (e.g., ISO 27001 certificate of the hosting provider) qualify as audit evidence.
9. Technical and Organizational Measures (TOM)
- Encrypted data transmission (HTTPS/TLS 1.2+)
- JWT-based authentication, Argon2id/bcrypt password hashing, role-based access control (customer vs. admin)
- Rate-limiting on all critical endpoints, Stripe-webhook idempotency
- Local SQLite database with invoice data primarily on the customer's device; account, plan and licence data as well as processing jobs with extraction results stored in the cloud; uploaded documents are automatically deleted after at most 7 days
- Swiss hosting at Infomaniak Network SA (Geneva, ISO 27001)
- Daily automated backups of the cloud DB, 7 days retention
- Access and admission controls at the hosting provider (Infomaniak)
- Logging of security-relevant events, central error log (no Sentry; own servers)
- Regular security updates of website and client; dependency audits (npm audit, dotnet list --vulnerable)
10. Deletion and Return of Data
Upon termination of the contract, all personal data provided to the Processor shall be deleted within 30 days (including backups), unless there is a statutory retention requirement (e.g., CO Art. 958f for accounting-related documents: 10 years). Structured data extracted via Gemini or OpenAI calls is deleted together with the main account. Google processes the actual Gemini requests under the Gemini API Additional Terms (no use for model training; standard API logs are deleted after at most 55 days, abuse-monitoring logs are time-limited). OpenAI processes API requests in fallback cases under the OpenAI Enterprise Privacy Commitments (no use for model training, retention max. 30 days for abuse prevention). The local SQLite database on the customer's device remains in their exclusive access; the customer must delete it themselves if required.
Upon request by the Client, a confirmation of deletion in textual form will be issued.
Contact
For questions regarding this DPA, please contact [email protected].