1. Roles of the parties
The User decides the purpose and means of processing the data it enters into Tezga and is therefore the controller; Go Simple processes that data only on the User's instructions and is the processor. The User warrants that it has a valid legal basis, gave data subjects the required notice, and collected the data lawfully.
2. Subject, nature and purpose of processing
The subject is storing and processing data within the Tezga eKasa service. The nature covers collection, recording, storage, access, change, transfer to the competent systems (Tax Administration, SEF), export and deletion. The purpose is issuing fiscal receipts and e-invoices, keeping sales and customer records, reporting and meeting the User's legal duties, and it lasts as long as the contract, plus the periods in section 9.
3. Data types and categories of persons
Categories of persons: the User's customers and business partners (individuals and contact persons at legal entities) and the User's staff and associates. Data types include name, business name, address, company number and PIB, email, phone, purchase and payment data, and statement and matching data. As a special case, a refund by law requires identity-document data, entered only where legally required; the Service is not meant for specially sensitive data.
4. Acting on instructions
The processor processes data only on the controller's documented instructions, which consist of this agreement, the Terms of Use and the actions the User takes in the Service. If the law requires processing beyond those instructions, the processor tells the controller first unless that is prohibited, and it will flag any instruction it believes breaches data-protection rules.
5. Confidentiality
Only persons who need access to provide the Service, and who are bound by a duty of confidentiality, may access the data. That duty continues after their employment or engagement ends.
6. Security measures
Data transfer is protected by HTTPS and passwords are stored only encrypted. The User's security element (certificate, password, PAK and PIN) is stored encrypted (AES-256-GCM), never shown back, and used only to issue fiscal receipts on the User's behalf under the authorization in section 10 of the Terms. Access is separated by firm and role, an activity log is kept, regular backups are made and restorable, and measures are reviewed against the state of the art and the assessed risk.
7. Sub-processors
The User gives a general authorization for the sub-processors listed here: Vercel Inc. (hosting, European Frankfurt region), Neon Inc. (database), Cloudflare, Inc. (DNS and traffic protection) and Resend (email). Go Simple gives at least 30 days notice before adding or replacing a sub-processor; the User may object with reasons and, if the objection cannot be resolved, terminate for the affected part without charge. Go Simple imposes protections no weaker than these and remains liable for its sub-processors.
8. Assisting the controller
The processor helps the controller answer data-subject requests through the tools the Service provides (access, correction, export, deletion). If a data subject contacts the processor directly, it forwards the request to the controller rather than acting alone. It also helps with the security of processing, breach notification and impact assessment, to the extent appropriate to the processing and the data available to it.
9. Personal data breach
The processor notifies the controller of a personal data breach without undue delay and at the latest within 48 hours of becoming aware. The notice describes the nature of the breach, the approximate number of persons and records affected, the likely consequences and the measures taken or proposed. Notifying the Commissioner and the data subjects is the controller's duty, which the processor supports.
10. Deletion and return of data
After the contract ends, the data remains available for export for at least 30 days. After that period the processor deletes or anonymizes it, except data it must keep longer by law. On the controller's written request the processor issues a confirmation that deletion was carried out.
11. Demonstrating compliance
On a reasoned written request, and at most once a year, the processor makes available the information needed to prove it meets its duties under this agreement. Any check is carried out so as not to endanger the security and confidentiality of other users' data, with prior notice and during business hours.
12. Transfers to other countries
Data is stored in European regions wherever a sub-processor offers it. If a transfer to a country without an adequate level of protection is necessary, the processor puts in place appropriate safeguards under the law and informs the controller.
13. Liability
Each party is liable for its own duties under personal data protection law. The liability limit from the Terms of Use also applies to this agreement, except that it does not apply to damage caused by intent or gross negligence, or where mandatory law does not allow limitation.
