Beta Preview

Some compliance features are in active development. Learn more →

Data Processing Agreement (DPA)

Data Processing Agreement designed for GDPR Article 28 compliance (Enterprise Customers)

For Enterprise Customers

If you process personal data through EncryptInvoice, your organization may need a Data Processing Agreement (DPA) under GDPR Article 28. This is typically required for Business and Enterprise plans.

GDPR Article 28 Template

Our DPA follows the European Data Protection Board guidelines and covers all mandatory provisions.

Current Subprocessors

A current list of all third-party services that process data on behalf of EncryptInvoice.

Security Measures

Technical and organizational measures we implement to protect your data.

Data Subject Rights

How we support your obligations regarding data subject access requests.

Download DPA Template

Download our standard DPA template, review it with your legal team, and return the signed copy.

How to Use This DPA

  1. 1
    Download the Template

    Click the download button above to get our standard DPA template.

  2. 2
    Review with Your Legal Team

    Have your legal team review the agreement. Contact us if you need modifications.

  3. 3
    Fill in Your Details

    Add your company information to the designated sections.

  4. 4
    Sign and Return

    Sign the DPA and email it to legal@encryptinvoice.com.

  5. 5
    Confirmation

    We will countersign and return the fully executed DPA within 5 business days.

Frequently Asked Questions

Do I need a DPA?

If you process personal data of EU residents through EncryptInvoice (e.g., customer names, addresses on invoices), a DPA is required under GDPR Article 28.

Is the DPA included in my plan?

DPA execution is available on all plans at no additional cost. Enterprise customers get priority legal support.

Can I modify the DPA?

Our standard DPA covers most requirements. For Enterprise customers, we can accommodate reasonable modifications. Contact our legal team.

Where is my data processed?

All data is processed within the EU (Belgium/France data centers). See our subprocessor list for details.

We use cookies and privacy-respecting analytics

We use essential cookies for authentication and privacy-respecting analytics (self-hosted, respects Do Not Track). No advertising or third-party tracking. Learn more