Last updated: 31 August 2026
1. Purpose and contractual integration
This Data Processing Agreement (hereinafter, the “Processing Agreement”) governs the processing of personal data that Conductiva Online Services, S.L. (NIF B65152100, C/ de la Llotja, sn, VIT, 08500 Vic, Barcelona, Spain; hereinafter, the “Processor” or “Conductiva”) carries out on behalf of the User of the FacturaDirecta service (hereinafter, the “Controller”), in accordance with Regulation (EU) 2016/679 (“GDPR”) and Organic Law 3/2018 (“LOPDGDD”).
This Processing Agreement forms an integral part of the Service agreement and is formalised upon acceptance of that agreement when creating the account or by continuing to use the service. In matters of data protection, the provisions of this Processing Agreement prevail over any other clause of the Service agreement.
2. Identification of the parties and roles
- Controller: the natural or legal person who holds the FacturaDirecta account, identified by the details declared in the account itself.
- Processor: Conductiva Online Services, S.L.
This Processing Agreement applies to the personal data that the Controller enters into the service or that is generated through its use (data of their customers, suppliers, employees and other third parties). It does not apply to the data that Conductiva processes as controller (the User’s own registration, contact and billing data), which is governed by the Privacy policy.
3. Description of the processing
Subject matter. The Processor will process, on behalf of the Controller, the personal data necessary to provide the FacturaDirecta services contracted, including: the hosting, storage, organisation and processing of the information entered into the service; the generation, management, sending and retention of invoicing, accounting and employment documents; the automatic scanning and extraction of data from documents; bank information aggregation and reconciliation; the generation of invoicing records and, where applicable, their signing, chaining and submission to the Spanish Tax Agency (AEAT) or other administrations (VeriFactu, TicketBAI, Facturae/FACe); the collection of invoice payments through payment providers; and any other processing operations necessary to provide the contracted features.
Nature. The processing comprises the operations of collection, recording, structuring, storage, modification, retrieval, consultation, use, communication (when ordered by the Controller or required by law), comparison, blocking and erasure.
Purpose. The provision to the Controller of the contracted services, in accordance with the Service agreement.
Duration. That of the Service agreement. Upon its termination, the provisions of clause 13 will apply.
Categories of data subjects. Customers and prospective customers of the Controller, suppliers, employees and collaborators, professional contacts and, where applicable, recipients of the documents shared through the portal.
Categories of data. Identification and contact data (name, tax ID number (NIF), address, email, telephone), economic, financial and banking data (amounts, IBAN, bank transactions, means of collection and payment), invoicing and accounting data and, if the Controller uses the corresponding features, employment and payroll data of their employees. The service is not designed to process special categories of data (Article 9 GDPR); the Controller undertakes not to enter them unless they are essential and the Controller has a legal basis for doing so (for example, incidental data contained in payslips or receipts).
4. Instructions from the Controller
The Processor will process the data only on documented instructions from the Controller. The instructions derive from the Service agreement, from the configuration and use of the service by the Controller and its users (including operations carried out through the API or through integrations enabled by the Controller) and from other written instructions communicated to the Processor. If the Processor considers that an instruction infringes the GDPR or other data protection regulations, it will immediately inform the Controller.
5. Confidentiality
The Processor will maintain the duty of secrecy regarding the personal data processed, even after the processing engagement ends, and will ensure that the persons authorised to process data have committed themselves to confidentiality, receive the necessary training and are aware of the applicable security measures.
6. Security measures
The Processor will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 GDPR), including, among others: encryption of communications (TLS); irreversible storage of access credentials and encryption of sensitive keys and secrets (including the read-only bank aggregation keys); role-based access control and the principle of least privilege; separation of environments; regular backups; activity logging; hosting in European Union data centres with recognised security certifications; and procedures for incident management and for regularly verifying the effectiveness of the measures.
7. Sub-processors
The Controller grants the Processor a general authorisation to engage other processors (sub-processors) where necessary for the provision of the service.
The Processor maintains a public and up-to-date list of sub-processors, with their identity, purpose, location and, where applicable, the mechanism applicable to international transfers. The Processor will give notice of any intended addition or replacement by updating that list at least 30 days in advance and, in the case of significant changes, by means of a notice in the service itself or by email, giving the Controller the opportunity to raise reasonable objections before the new sub-processor begins to process data. If the Controller raises a reasonable objection and there is no viable alternative, the Controller may terminate the Service agreement without penalty.
The Processor will impose on each sub-processor, by contract, data protection obligations equivalent to those of this Processing Agreement, and will remain liable to the Controller for the compliance of its sub-processors.
8. International transfers
As a general rule, data is processed in the European Union. Where the provision of a service requires processing by sub-processors located outside the European Economic Area (identified in the list of sub-processors), the transfer is covered by the safeguards of Chapter V of the GDPR: adequacy decisions of the European Commission (including, where applicable, the EU–US Data Privacy Framework) or standard contractual clauses approved by the European Commission, supplemented where appropriate by additional measures.
9. Rights of data subjects
The Processor will assist the Controller, taking into account the nature of the processing and through the features of the service itself or the support channels, in fulfilling its obligation to respond to the exercise of the rights of access, rectification, erasure, objection, restriction of processing, portability and not to be subject to automated individual decisions. If a data subject exercises their rights directly before the Processor, the Processor will inform the Controller without undue delay.
10. Assistance to the Controller
The Processor will assist the Controller, taking into account the nature of the processing and the information available to it, in fulfilling its obligations regarding security of processing, notification of personal data breaches, data protection impact assessments and prior consultations with the supervisory authority (Articles 32 to 36 GDPR).
11. Personal data breaches
The Processor will notify the Controller, without undue delay after becoming aware of it, of any breach of the security of the personal data processed on its behalf, through the account’s contact channels. The notification will include, as a minimum and to the extent that the information is available: the nature of the breach; the categories and approximate number of data subjects and records affected; the point of contact where more information can be obtained; the likely consequences; and the measures taken or proposed by the Processor to remedy the breach or mitigate its effects.
12. Information and audits
The Processor will make available to the Controller the information necessary to demonstrate compliance with the obligations of this Processing Agreement, and will allow and contribute to audits or inspections conducted by the Controller or by an independent auditor authorised by the Controller, on reasonable terms: with at least 30 days’ notice, during business hours, without access to other customers’ information or to the Processor’s trade secrets and, at most, once a year unless there is an incident that justifies it. The costs of the audit will be borne by the Controller.
13. End of the processing engagement: return, blocking and erasure
During the term of the service, the Controller may export its data at any time in accordance with the Service agreement.
Upon termination of the service (deletion of the account or termination of the Agreement), the Processor will keep the data blocked for a maximum period of 18 months, during which the Controller may request its free export in a structured, commonly used format, or its early erasure. Once that period has elapsed, the Processor will permanently erase the data.
As an exception, the Processor may keep blocked: (a) the data necessary for as long as liabilities may arise from the performance of the service; and (b) data subject to a legal retention obligation (in particular, the invoicing records generated by the VeriFactu or TicketBAI systems and other information of tax relevance, for the periods provided for by tax regulations), solely at the disposal of the competent administrations and bodies.
14. Obligations of the Controller
The Controller is responsible for: providing the Processor only with the data necessary for the provision of the service; ensuring that it has a legal basis for its processing and that it has fulfilled its duty to inform the data subjects; carrying out any prior consultations that may be required; and supervising the processing, including conducting the audits provided for in this Processing Agreement.
15. Liability, governing law and jurisdiction
Each party will be liable for the damage it causes through breach of the obligations that the GDPR specifically imposes on it according to its role. The interpretation and performance of this Processing Agreement are governed by Spanish law, with the same jurisdiction rules as provided in the Service agreement.
Do you need a copy of this agreement for your compliance documentation? You can print or save this page as a PDF. The agreement is formalised upon acceptance of the Service agreement when creating your account, with no additional signature required.