DPA
Data Processing Agreement Template
Last updated: 14 June 2026
This template summarizes the data processing terms Datadeft Kft. expects to use with CeleraTax business customers. The signed Order Form or separately executed DPA controls if it differs from this page.
1. Parties and Roles
The customer acts as Data Controller for Customer Data processed in its CeleraTax workspace. Datadeft Kft. acts as Data Processor under Article 28 GDPR, processing Customer Data only on documented customer instructions.
2. Subject Matter, Duration, Nature, and Purpose
- Subject matter: operation of the CeleraTax SaaS platform.
- Duration: the subscription term plus any agreed retrieval/deletion period.
- Nature: hosting, storage, retrieval, matching, logging, reminder handling, export, support, and deletion of Customer Data.
- Purpose: document collection, accounting reconciliation, month-end readiness, reminders, reporting, security, and support.
3. Categories of Data and Data Subjects
- Accounting documents and metadata, bank/reconciliation data, reminder/contact data, logs, support messages, and workspace configuration.
- Data subjects may include customer staff, customer clients, suppliers, contractors, and other persons appearing in accounting or business documents.
4. Processor Obligations
- Process Customer Data only on documented instructions.
- Ensure personnel with access are bound by confidentiality obligations.
- Maintain appropriate technical and organisational measures under Article 32 GDPR.
- Assist the customer with data subject requests, security obligations, DPIAs, and supervisory authority consultations where reasonably required.
- Notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
- Delete or return Customer Data after termination according to the Order Form or DPA.
5. Technical and Organisational Measures
- EU hosting in Germany for production customer data.
- Encryption in transit and at rest where supported by infrastructure.
- Least-privilege access controls and workspace-level permission design.
- Logging, monitoring, backup, retention, and deletion procedures.
- Incident response and vulnerability management processes.
6. Sub-processors
Approved sub-processors are listed on the Sub-processor List. The current production infrastructure sub-processor is AWS EMEA SARL for cloud hosting in Germany. We aim to notify customers before adding material production sub-processors.
7. International Transfers
Production customer data is intended to be processed and stored in Germany, within the European Union. If a transfer outside the EU/EEA becomes necessary, Datadeft Kft. will use appropriate safeguards such as European Commission Standard Contractual Clauses.
8. Audit and Information
Datadeft Kft. will make information reasonably necessary to demonstrate compliance with Article 28 GDPR available to the customer, subject to confidentiality, security, and reasonable notice. On-site audits require prior written agreement.
9. Contact
DPA contact: dpa@celeratax.eu.