500+ active sellers
2.4M+ transactions processed
27 EU countries covered
GDPR Compliant · Data in the EU
Updated on --/--/--
Legal

Data Processing Agreement (DPA)

Last updated: 2026-04-01

The Italian version of this document prevails in the event of any discrepancy.

1. Definitions

Controller: the customer who uses VATManager to process data relating to their business. Processor: VATManager, as the provider of the platform. VATManager does not acquire or process the Controller's end-customer data for its own purposes. All transaction data uploaded or acquired via marketplace APIs remains under the exclusive control of the Customer.

2. Subject matter and instructions

VATManager processes the personal data uploaded by the customer solely to deliver the agreed service and on the Controller's documented instructions. No further processing is carried out without authorisation.

3. Security measures

VATManager adopts appropriate technical and organisational measures: encryption in transit (TLS 1.3) for the site and the app, encryption at rest (AES) for data in the database, role-based access control, periodic backups, anomaly monitoring and documented incident-response procedures.

4. Sub-processors

VATManager uses the following sub-processors to deliver the service:

Sub-processor Service Location Safeguards
Hetzner Online GmbH Hosting / VPS Germany (EU)
Cloudflare Inc. CDN / DNS / Analytics USA SCCs + Data Privacy Framework
Mollie B.V. Payments Netherlands (EU)
GlitchTip Error monitoring (only with user consent) Germany (EU) — DigitalOcean, Frankfurt Processing entirely within the EU (GlitchTip DPA on request)

The customer will be notified 30 days in advance of any changes to the sub-processors.

5. International transfers

Data is processed and stored in European data centres (EU/EEA). Cloudflare, although based in the USA, operates within Europe with metadata on global edge nodes and relies on Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework to ensure adequate protection. GlitchTip processes, only if the user consents to error monitoring, technical data (including IP address) exclusively on servers located in Germany (EU); no non-EU transfer is therefore required for this processing. Any other non-EU transfers take place solely with adequate safeguards (Standard Contractual Clauses or EU Commission adequacy decisions).

6. Data breaches

In the event of a significant data breach, VATManager notifies the Controller within 72 hours of discovery, providing all the information needed to comply with notification obligations to the supervisory authority.

7. Deletion and portability

At the end of the contractual relationship, the customer's data is deleted within 30 days, except where legal retention obligations apply. On request, a full export of the data in a structured format can be obtained.

8. Audit and compliance

The customer has the right to request periodic audits or documentation attesting to GDPR compliance. Audit requests must be notified at least 30 days in advance. Audits take place during business hours without interfering with the operation of the service. Costs are borne by the Customer unless the audit reveals breaches attributable to VATManager. VATManager undertakes to provide all necessary cooperation.

9. Privacy contact

For matters relating to the DPA: info@vatmanager.eu

10. Acceptance

This DPA is an integral part of VATManager's Terms of Service. The Customer's use of the platform constitutes acceptance of the DPA in the version in force at the date of registration. Changes to the DPA will be communicated with 30 days' notice.

Privacy Policy Terms of Service Contact us