Skip to content

Version 1.0

Data processing agreement

This is the data processing agreement under Article 28 GDPR. It forms part of the Terms of service and is concluded by accepting them when you open your firm in Kolektro. Your firm is the controller of its clients’ data, MCODE is the processor. The three annexes at the end set out exactly what is processed, how it is protected, and who the sub-processors are, with their processing locations and transfer bases.

Last updated:

1. The parties

The Processor is MCODE, obrt za računalno programiranje, vl. Matko Setnik. The Processor’s details — registered seat, OIB (tax number), entry in the Croatian craft register and notice address — are at the bottom of this page.

The Controller is the accounting firm using the Service. The Controller is identified by the details it enters when opening its firm in Kolektro — firm name and OIB — and its notice address is the account address of the firm’s owner.

The Controller uses the Kolektro service (the “Service”) under the Terms of service. This agreement governs the processing of personal data carried out by the Processor for the Controller within the Service and is concluded under Article 28 of Regulation (EU) 2016/679 (GDPR).

The agreement is concluded by accepting the Terms of service when opening a firm in Kolektro, of which it forms part. Article 28(9) GDPR expressly permits electronic form, so no signature is required and none is provided for; the firm record permanently carries which version was accepted, when, and by which user. A Controller that needs a separately signed copy for its own records receives one on request to the notice address.

2. Subject matter, nature, purpose and duration

The Processor processes personal data solely in order to provide the Service: sending document reminders to the Controller’s clients, receiving the documents those clients upload, and showing the status per client and period.

The description of the processing, the types of personal data and the categories of data subjects are set out in Annex I.

This agreement runs for as long as the contract for the Service and ends with it, subject to the obligations in clause 10, which survive.

3. Processing on the Controller’s instructions

3.1. The Processor processes personal data only on the Controller’s documented instructions, including as regards transfers to third countries, unless required to do so by Union or Member State law to which the Processor is subject. In that case the Processor informs the Controller of that legal requirement before processing, unless such information is prohibited.

3.2. The Controller’s instructions consist of: this agreement, the terms of service, the settings and actions the Controller takes in the Service (adding clients, defining the documents requested, the reminder schedule, sending by hand, issuing and revoking upload links), and written requests sent to the Processor’s notice address.

3.3. The Processor informs the Controller without delay if it considers that an instruction infringes the GDPR or other data protection law.

3.4. The Processor does not use personal data for its own purposes, does not sell it, and does not use it to develop or train artificial-intelligence models.

4. Confidentiality

The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that their access is limited to what their tasks require.

5. Security of processing

The Processor implements appropriate technical and organisational measures within the meaning of Article 32 GDPR. The measures in place when this agreement is concluded are set out in Annex II. The Processor may change them provided the level of security is not reduced.

6. Sub-processors

6.1. The Controller gives the Processor general written authorisation to engage sub-processors. Those engaged when this agreement is concluded are listed in Annex III.

6.2. The Processor informs the Controller by email to the notice address at least 30 days before adding or replacing a sub-processor.

6.3. The Controller may object on reasoned grounds within that period. If the parties reach no resolution within a further 30 days, the Controller may terminate the contract for the Service at no cost with effect from the date of the objection, with a proportionate refund of the fee paid for the unused period.

6.4. The Processor imposes on each sub-processor data protection obligations no less protective than those in this agreement and remains fully liable to the Controller for the sub-processor’s performance.

7. Data subject rights

7.1. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests under Chapter III GDPR.

7.2. The Processor does not respond to a data subject request it receives directly; it forwards the request to the Controller without undue delay and tells the data subject it has done so.

7.3. The Controller can view and export its client data in the Service at any time. For actions the Service’s interface does not offer — permanently deleting an individual document or client — the Processor acts on the Controller’s written request within the period in clause 10.

8. Assistance to the Controller

Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in complying with Articles 32 to 36 GDPR (security of processing, breach notification, data protection impact assessment and prior consultation).

9. Personal data breach

9.1. The Processor notifies the Controller of any personal data breach affecting the Controller’s data without undue delay and no later than 48 hours after becoming aware of it.

9.2. The notification contains, so far as known: a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact point for further information. Information not available at the time is provided subsequently without further delay.

9.3. Notification to the supervisory authority and communication to data subjects are made by the Controller as controller.

10. Deletion and return of data

10.1. During the term. On the Controller’s written request the Processor deletes an individual document, an individual client’s data or other specified data within 30 days of the request.

10.2. After termination. The Processor keeps data and documents for a further 30 days after the contract ends so that an export remains possible, and then deletes them — no later than 60 days after termination. On the Controller’s express request it deletes them earlier, within the period in clause 10.1.

10.3. Export before deletion. The Controller can download documents as a ZIP and export client and request data as CSV. If an export is needed at termination, the Processor prepares one on request whatever plan the Controller was on.

10.4. Deletion covers all copies of the data under the Processor’s control. The Processor retains only what law requires it to keep — invoices and accounting records, which contain no personal data of the Controller’s clients — and the confidentiality obligation continues to apply to them.

10.5. The Processor confirms in writing, on request, that deletion has been carried out.

11. Demonstrating compliance and audit

11.1. The Processor makes available to the Controller, on request, all information necessary to demonstrate compliance with Article 28 GDPR.

11.2. The Controller may audit, including by inspection, itself or through an auditor it mandates. An audit is announced at least 30 days in advance, takes place during business hours, must not unreasonably disrupt the Processor’s operations, and may be carried out once a year — and beyond that after a personal data breach affecting the Controller’s data. The Controller bears the cost of the audit unless the audit establishes a material breach of this agreement.

11.3. Persons carrying out an audit undertake to keep other customers’ data confidential; an audit must not extend to the data of other controllers.

12. Transfers outside the European Economic Area

12.1. Processing locations are set out in Annex III.

12.2. For processing outside the European Economic Area the transfer basis is the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), contained in the relevant sub-processor’s data processing terms, which form part of the Processor’s contract with it.

12.3. The Processor establishes no new transfer outside the European Economic Area without first notifying the Controller in the manner and within the period set out in clause 6.

13. Liability

Liability between the parties is governed by the Terms of service. The limitations of liability in the terms of service do not apply to liability towards data subjects under Article 82 GDPR or to administrative fines, which are apportioned between the parties according to each party’s actual contribution to the damage.

14. Final provisions

14.1. This agreement prevails over the terms of service in matters of personal data processing.

14.2. Amendments are valid in writing. Amendments to the annexes that follow from a change of sub-processor are made under the procedure in clause 6. The Processor notifies the Controller of material changes by email at least 30 days before they take effect, and the version and date of the last change are at the top of this page.

14.3. This agreement is governed by the law of the Republic of Croatia. The competent court at the Processor’s registered seat has jurisdiction.

14.4. If a provision is invalid, the remainder stays in force.

14.5. This agreement was drawn up in Croatian. This English translation is for understanding; in case of any discrepancy the Croatian text prevails.

Annex I — Description of the processing

Subject matter. Providing the Kolektro service: sending document reminders to the Controller’s clients, receiving the documents those clients upload, and showing the status per client and period.

Nature of the processing. Collection, recording, storage, consultation, transmission (sending a message and an upload link), organisation and erasure.

Purpose. Collecting the accounting paperwork the Controller needs from its clients.

Duration. For the term of the contract for the Service, subject to the deletion periods in clause 10.

Categories of data subjects

  • The Controller’s clients: natural persons, and natural persons who represent or work for the Controller’s business clients.
  • The Controller’s users: people at the accounting firm who sign in to the Service.

Types of personal data

  • Client details: name, email address, mobile number, language, and the internal note written by the Controller.
  • Request data: the period, the list of requested documents, due dates, the status of each item, and the note in which the Controller explains to the client what is missing.
  • The contents of the documents a client uploads, with the original file name, size and type. Which personal data a document contains depends on what the client sends and is determined by the Controller when it defines what to request.
  • Send and usage records: the time and channel of a reminder sent, the time and number of link openings, the time a document was received, and which person at the firm accepted or rejected it.
  • Email deliverability status: a mark that an address permanently rejected a message or reported it as spam, with the time and a short reason.
  • WhatsApp consent record: whether the client opted in, when, and which of the Controller’s users recorded it.
  • The Controller’s user data: email address and account identifier, and for Google sign-in also the name and profile picture link.

Special categories of data. The Service is not intended for processing special categories of personal data under Article 9 GDPR. The Controller undertakes not to request documents containing them; if a client sends them anyway, the Controller informs the Processor so that deletion can be arranged.

Annex II — Technical and organisational measures

Measures in place when this agreement is concluded:

Access control

  • Only signed-in users of a given accounting firm can reach that firm’s data. The check is enforced in the database rules and in server-side checks, on every read and write, not only in the interface.
  • The Controller’s clients have no account and no database access. Through the link they see only the firm’s name, their own name and the list of documents being requested from them.
  • Administrative access to the production environment is held by the owner of the business alone.
  • Firm users sign in by email link or with a Google account; no passwords are stored.

Upload links

  • Bound to one client and one period.
  • Expire 14 days after issue and can be revoked at any time.
  • Limited by number of openings and by uploads per day.
  • Only a cryptographic hash (SHA-256) of the link is kept in the link record.
  • A request with an unknown, expired or revoked link is refused with an identical response that does not disclose the reason.

Cryptography

  • All access to the Service goes over HTTPS.
  • Outbound email is sent over a TLS connection.
  • Data and documents are encrypted at rest at the infrastructure provider’s level. No additional application-level encryption is applied.

Input restrictions

  • Only file types on an explicit allow-list are accepted: PDF, images, office documents (xlsx, xls, docx), CSV and ZIP archives, up to 20 MB per file. The type is verified on the server, not merely from the filename extension.
  • File name and content type are validated server-side.

Logging and monitoring

  • What was sent and when, when a link was opened and when a document arrived are recorded; these records are visible to the Controller in the Service.
  • Message contents and upload links are not written to diagnostic logs.

Organisational measures

  • Processing takes place at the infrastructure providers listed in Annex III, under their data processing terms.
  • Persons with access are bound by confidentiality.
  • Handling of a personal data breach is governed by clause 9 of this agreement.

Annex III — Sub-processors

The sub-processors engaged when this agreement is concluded, with their purpose, processing location and basis for any transfer outside the European Economic Area:

Google (Firebase, Google Cloud)

  • Purpose: application hosting, database, document storage, user sign-in, secret management and infrastructure logs.
  • Processing location: application and background jobs in europe-west1 (Belgium); database in the EU multi-region eur3; document storage in europe-west1 (Belgium); user sign-in on the provider’s global infrastructure.
  • Transfer basis outside the EEA: Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in the provider’s data processing terms.

Amazon Web Services (Amazon SES, SNS)

  • Purpose: outbound email delivery (reminders, upload receipts, the daily digest) and the bounce and complaint notifications it reports back.
  • Processing location: eu-west-1 (Ireland).
  • Transfer basis outside the EEA: not applicable — processing takes place within the European Union.

Stripe

  • Purpose: subscription billing and invoicing.
  • Processing location: European Union and United States.
  • Transfer basis outside the EEA: Standard Contractual Clauses in the provider’s data processing terms.

Notes

  • Stripe receives the Controller’s name, OIB and internal account identifiers. Payment details are collected by Stripe directly from the Controller and are also processed by Stripe as an independent controller in order to meet its own legal obligations. No client data and no documents are sent to Stripe.
  • The WhatsApp channel (Bird) is not active: it sends no messages and has never received any data. Switching it on counts as adding a sub-processor and is done under the procedure in clause 6.
  • The same sub-processor list, with the same processing locations, is also set out in the “Sub-processors” section of the Privacy policy.

Provider details and contact

MCODE, obrt za računalno programiranje, vl. Matko Setnik

Registered seat
D. Cesarića 67, 31550 Valpovo, Hrvatska
OIB (tax number)
58358056658
Register
Obrtni registar, MBO 98583441
Web
kolektro.com

Questions about this document, data requests and requests for a signed copy of the data processing agreement go to the address above.

Data processing agreement — Kolektro