Data Processing Agreement
Last updated: September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Portal, Lda ("Processor", "we", "us") and the Customer ("Controller", "you") using Faturado ("Service"). This DPA is designed to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR).
Hosted MCP processing summary
- Portal processes provider credentials, grants, and provider records only to provide the Service under the Controller's instructions.
- Connected AI Clients selected by the Controller are not Sub-processors of Portal unless Portal independently engages them.
- Provider credentials are encrypted at rest and can be revoked or cryptographically erased where supported.
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person processed through the Service.
- Processing: Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and erasure.
- Data Subject: The individual whose Personal Data is processed.
- Sub-processor: A third party engaged by the Processor to process Personal Data on behalf of the Controller.
2. Scope and Purpose
The Processor processes Personal Data on behalf of the Controller solely for the purpose of providing the Service, which includes:
- Receiving payment transaction data from Stripe
- Creating invoices in the Controller's billing provider
- Delivering invoices to Data Subjects via email
- Providing dashboard and reporting functionality
- Storing encrypted provider credentials for TOConline and InvoiceXpress accounts configured by the Controller
- Providing Hosted MCP read-only access to provider records for Connected AI Clients authorized by the Controller
- Enforcing grants, revocations, and audit logs for Hosted MCP
3. Categories of Data
The Personal Data processed may include:
- Contact information (names, email addresses)
- Transaction data (payment amounts, dates, payment methods)
- Billing addresses
- Tax identification numbers (where provided)
- Provider account identifiers and document references
- Provider credentials, OAuth tokens, credential metadata, and grant records
- Provider records returned through Hosted MCP, including customer, invoice, company, and accounting metadata
- Hashed email and tax identifiers, where retained for matching or audit purposes
4. Data Subjects
Data Subjects include:
- Controller's customers who make payments
- Controller's authorized users of the Service
- Client companies and business contacts represented in provider records connected by the Controller
5. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to Data Subject requests
- Delete or return all Personal Data upon termination of the Service unless retention is required by law
- Make available information necessary to demonstrate compliance with GDPR
- Allow for and contribute to audits conducted by the Controller
- Enforce Hosted MCP grants and revocations according to documented Controller instructions
6. Security Measures
The Processor implements the following security measures:
- Encryption: All data encrypted in transit (TLS 1.2+) and at rest. Provider credentials are stored in encrypted envelopes using AES-256-GCM.
- Access Control: Role-based access with multi-factor authentication
- Audit Logging: All access and modifications are logged
- Network Security: Firewalls, intrusion detection, DDoS protection
- Hosted MCP Controls: OAuth-only client access, read-only endpoint allowlists, grant enforcement, rate limiting, and token revocation
- Credential Revocation: Provider credentials can be revoked, replaced, or cryptographically erased where supported by the Service
- Backup: Regular encrypted backups with tested recovery procedures
- Incident Response: Documented procedures for security incidents
7. Sub-processors
The Controller authorizes the Processor to engage Sub-processors. The current list of Sub-processors is:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting infrastructure | USA (EU data region) |
| Neon Inc. | Database hosting | USA (EU data region) |
| Stripe Inc. | Payment processing | USA (SCCs in place) |
| Resend Inc. | Email delivery | USA (SCCs in place) |
| Inngest Inc. | Background job processing | USA (SCCs in place) |
| PostHog Inc. | Product analytics | EU |
| Conscious Digital OÜ (Fathom Analytics) | Website analytics (cookieless, aggregated) | EU |
The Processor will notify the Controller of any intended changes to Sub-processors with at least 30 days' notice. The Controller may object to changes by terminating the Service.
Connected AI Clients authorized directly by the Controller, such as Claude, ChatGPT, Cursor, or other MCP-compatible tools, are selected by the Controller and are not Sub-processors of the Processor unless the Processor separately engages them to process Personal Data on behalf of the Controller.
8. International Transfers
Where Personal Data is transferred outside the EEA, the Processor ensures appropriate safeguards through:
- Standard Contractual Clauses (SCCs) approved by the EU Commission
- Adequacy decisions where applicable
- Data processing in EU regions where available (hosting, database)
9. Data Subject Rights
The Processor will assist the Controller in responding to Data Subject requests for:
- Access to Personal Data
- Rectification of inaccurate data
- Erasure of data
- Restriction of processing
- Data portability
- Objection to processing
Requests will be handled within the timeframes required by GDPR (30 days).
10. Data Breach Notification
The Processor will notify the Controller without undue delay (and within 72 hours) upon becoming aware of a Personal Data breach. Notification will include:
- Nature of the breach
- Categories and approximate number of Data Subjects affected
- Likely consequences
- Measures taken or proposed to address the breach
11. Audits
The Controller may request audits to verify compliance with this DPA. Audits require 30 days' notice and shall be conducted during normal business hours at the Controller's expense. The Processor may satisfy audit requirements by providing:
- SOC 2 Type II reports
- Third-party security assessments
- Responses to security questionnaires
12. Data Retention and Deletion
Upon termination of the Service:
- The Controller may request export of Personal Data within 30 days
- The Processor will delete Personal Data within 90 days of termination unless retention is required by law or needed to complete revocation, export, or security processes
- Some data may be retained longer where required by law (e.g., tax records for up to 10 years)
- Provider credentials and active Hosted MCP grants will be disabled or deleted after revocation or termination where supported by the Service
13. Liability
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service.
14. Term
This DPA remains in effect for the duration of the Service agreement and until all Personal Data is deleted or returned.
15. Contact
For DPA-related inquiries:
Email: [email protected]