Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Portal, Lda ("Processor", "we", "us") and the Customer ("Controller", "you") using Faturado ("Service"). This DPA is designed to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR).

1. Definitions

2. Scope and Purpose

The Processor processes Personal Data on behalf of the Controller solely for the purpose of providing the Service, which includes:

3. Categories of Data

The Personal Data processed may include:

4. Data Subjects

Data Subjects include:

5. Processor Obligations

The Processor shall:

6. Security Measures

The Processor implements the following security measures:

7. Sub-processors

The Controller authorizes the Processor to engage Sub-processors. The current list of Sub-processors is:

Sub-processorPurposeLocation
Vercel Inc.Hosting infrastructureUSA (EU data region)
Neon Inc.Database hostingUSA (EU data region)
Stripe Inc.Payment processingUSA (SCCs in place)
Resend Inc.Email deliveryUSA (SCCs in place)
Inngest Inc.Background job processingUSA (SCCs in place)
PostHog Inc.Product analyticsEU
Conscious Digital OÜ (Fathom Analytics)Website analytics (cookieless, aggregated)EU

The Processor will notify the Controller of any intended changes to Sub-processors with at least 30 days' notice. The Controller may object to changes by terminating the Service.

Connected AI Clients authorized directly by the Controller, such as Claude, ChatGPT, Cursor, or other MCP-compatible tools, are selected by the Controller and are not Sub-processors of the Processor unless the Processor separately engages them to process Personal Data on behalf of the Controller.

8. International Transfers

Where Personal Data is transferred outside the EEA, the Processor ensures appropriate safeguards through:

9. Data Subject Rights

The Processor will assist the Controller in responding to Data Subject requests for:

Requests will be handled within the timeframes required by GDPR (30 days).

10. Data Breach Notification

The Processor will notify the Controller without undue delay (and within 72 hours) upon becoming aware of a Personal Data breach. Notification will include:

11. Audits

The Controller may request audits to verify compliance with this DPA. Audits require 30 days' notice and shall be conducted during normal business hours at the Controller's expense. The Processor may satisfy audit requirements by providing:

12. Data Retention and Deletion

Upon termination of the Service:

13. Liability

Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service.

14. Term

This DPA remains in effect for the duration of the Service agreement and until all Personal Data is deleted or returned.

15. Contact

For DPA-related inquiries:
Email: [email protected]