1. Definitions
Controller: the customer who uses VATManager to process data relating to their business. Processor: VATManager, as the provider of the platform. VATManager does not acquire or process the Controller's end-customer data for its own purposes. All transaction data uploaded or acquired via marketplace APIs remains under the exclusive control of the Customer.
2. Subject matter and instructions
VATManager processes the personal data uploaded by the customer solely to deliver the agreed service and on the Controller's documented instructions. No further processing is carried out without authorisation.
3. Security measures
VATManager adopts appropriate technical and organisational measures: encryption in transit (TLS 1.3) for the site and the app, encryption at rest (AES) for data in the database, role-based access control, periodic backups, anomaly monitoring and documented incident-response procedures.
4. Sub-processors
VATManager uses the following sub-processors to deliver the service:
| Sub-processor | Service | Location | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Hosting / VPS | Germany (EU) | — |
| Cloudflare Inc. | CDN / DNS / Analytics | USA | SCCs + Data Privacy Framework |
| Mollie B.V. | Payments | Netherlands (EU) | — |
| GlitchTip | Error monitoring (only with user consent) | Germany (EU) — DigitalOcean, Frankfurt | Processing entirely within the EU (GlitchTip DPA on request) |
The customer will be notified 30 days in advance of any changes to the sub-processors.
5. International transfers
Data is processed and stored in European data centres (EU/EEA). Cloudflare, although based in the USA, operates within Europe with metadata on global edge nodes and relies on Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework to ensure adequate protection. GlitchTip processes, only if the user consents to error monitoring, technical data (including IP address) exclusively on servers located in Germany (EU); no non-EU transfer is therefore required for this processing. Any other non-EU transfers take place solely with adequate safeguards (Standard Contractual Clauses or EU Commission adequacy decisions).
6. Data breaches
In the event of a significant data breach, VATManager notifies the Controller within 72 hours of discovery, providing all the information needed to comply with notification obligations to the supervisory authority.
7. Deletion and portability
At the end of the contractual relationship, the customer's data is deleted within 30 days, except where legal retention obligations apply. On request, a full export of the data in a structured format can be obtained.
8. Audit and compliance
The customer has the right to request periodic audits or documentation attesting to GDPR compliance. Audit requests must be notified at least 30 days in advance. Audits take place during business hours without interfering with the operation of the service. Costs are borne by the Customer unless the audit reveals breaches attributable to VATManager. VATManager undertakes to provide all necessary cooperation.
9. Privacy contact
For matters relating to the DPA: info@vatmanager.eu
10. Acceptance
This DPA is an integral part of VATManager's Terms of Service. The Customer's use of the platform constitutes acceptance of the DPA in the version in force at the date of registration. Changes to the DPA will be communicated with 30 days' notice.