Nordlet

Docs / Legal

Data Processing Agreement

The GDPR Article 28 agreement under which Nordlet processes personal data on behalf of its customers.

Last updated: 2026-08-30

This Data Processing Agreement ("DPA") is part of the Terms of Service between Nordlet ("Nordlet", the "Processor") and the business that holds the account (the "Customer", the "Controller"). It applies whenever Nordlet processes personal data contained in Customer Data on the Customer's behalf. It is accepted together with the Terms of Service; no signature is needed. A Customer that needs a signed copy can ask at info@nordlet.com.

Processor: Nordlet, Republic of Estonia.

1. Definitions

Terms written with a capital letter and not defined here have the meaning given in the Terms of Service. "GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Data Subject", "Personal Data Breach", "Supervisory Authority" and "Sub-processor" have the meaning given in the GDPR. "Customer Personal Data" means Personal Data contained in Customer Data.

2. Roles and scope

2.1. The Customer is the Controller of Customer Personal Data and Nordlet is its Processor. Where the Customer itself acts as a processor for another business (for example an accounting firm keeping the books of its clients), the Customer confirms that it is authorised by that business to appoint Nordlet as a sub-processor on the terms of this DPA.

2.2. This DPA does not cover Personal Data that Nordlet processes as a Controller (account, billing and support data), which is described in the Privacy Policy.

2.3. The details of the Processing are set out in Annex 1.

3. Customer's obligations

3.1. The Customer is responsible for the lawfulness of Customer Personal Data and of the instructions it gives, including for having a legal basis for the Processing and for informing Data Subjects as the GDPR requires.

3.2. The Customer will not enter into the Service special categories of Personal Data (GDPR Article 9) or data about criminal convictions, except to the extent unavoidable for payroll and HR functions (for example sick-leave records or trade union membership where the law requires payroll to reflect them), and will configure user roles so that only authorised people can see such data.

4. Processor's obligations

Nordlet will:

4.1. process Customer Personal Data only on the Customer's documented instructions. The Terms of Service, this DPA, the configuration the Customer sets in the Service, and every action taken through the application or the API are the Customer's instructions. Nordlet will inform the Customer if, in its opinion, an instruction infringes the GDPR;

4.2. process Customer Personal Data outside those instructions only where Union or Member State law requires it, and in that case inform the Customer before processing, unless the law prohibits that;

4.3. ensure that every person authorised to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality;

4.4. implement the technical and organisational measures described in Annex 2, and keep them under review so that they remain appropriate to the risk;

4.5. respect the conditions for engaging Sub-processors set out in section 5;

4.6. taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures in fulfilling its obligation to respond to requests from Data Subjects. The application and the API let the Customer find, correct, export and delete a Data Subject's records without Nordlet's involvement. Where a Data Subject contacts Nordlet directly about Customer Personal Data, Nordlet will refer them to the Customer and tell the Customer within 5 working days;

4.7. assist the Customer in ensuring compliance with GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the Processing and the information available to Nordlet;

4.8. at the end of the provision of the Service, delete or return Customer Personal Data as set out in section 8;

4.9. make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits as set out in section 9.

5. Sub-processors

5.1. The Customer gives Nordlet general authorisation to engage the Sub-processors listed in Annex 3. Several of them are used only when the Customer enables the corresponding feature (document scanning, bank feeds, e-invoicing).

5.2. Nordlet will notify the Customer by email to the account owner at least 30 days before a new Sub-processor starts processing Customer Personal Data, and will keep Annex 3 current on this page. The Customer may object within that period on reasonable data-protection grounds. If Nordlet cannot resolve the objection, the Customer may terminate the Terms of Service for the affected Service before the change takes effect, and Nordlet will refund unused purchased Credits.

5.3. Nordlet will impose on every Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the Sub-processor's performance.

6. Personal Data Breach

6.1. Nordlet will notify the Customer without undue delay, and at the latest 48 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, by email to the account owner.

6.2. The notification will describe, as far as known at the time, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Nordlet will provide further information as it becomes available.

6.3. Nordlet will not notify Supervisory Authorities or Data Subjects on the Customer's behalf unless the Customer asks it to in writing.

7. International transfers

7.1. Customer Personal Data is stored and processed in the European Union. Nordlet will not transfer Customer Personal Data to a country outside the European Economic Area, except through a Sub-processor listed in Annex 3 and only with an appropriate safeguard under Chapter V GDPR: an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for certified organisations) or the Standard Contractual Clauses adopted by the Commission.

7.2. On request Nordlet will provide the Customer with a copy of the safeguard relied on, with commercial information removed.

8. Deletion and return of data

8.1. Throughout the term the Customer can export all Customer Personal Data in a structured, machine-readable form through the API and the export functions of the application.

8.2. When a Company is deleted, its data can be restored for 10 days, after which it is permanently deleted. When the Customer's account is deleted, or 30 days after the Terms of Service end, whichever is earlier, Nordlet deletes all remaining Customer Personal Data from live systems, unless Union or Member State law requires storage. Copies in backups are overwritten in the ordinary backup cycle, at most 35 days later, and are not accessed in the meantime except to restore the service after a failure.

8.3. Nordlet will confirm deletion in writing on request.

9. Audits

9.1. Nordlet will answer the Customer's reasonable written questions about the Processing and provide the documentation described in Annex 2 on request.

9.2. Where the Customer, or a Supervisory Authority, needs more than that, the Customer may audit Nordlet's compliance with this DPA once in any 12-month period, or more often after a Personal Data Breach or when a Supervisory Authority requires it. The Customer gives at least 30 days' written notice, the audit takes place during business hours, does not unreasonably disrupt Nordlet's operations, and is conducted by the Customer or by an independent auditor bound by confidentiality who is not a competitor of Nordlet. Each party bears its own costs.

9.3. The Customer will share the audit findings with Nordlet, and Nordlet will remedy any confirmed non-compliance within a reasonable time.

10. Liability

The liability of each party under this DPA is subject to the limitations and exclusions in the Terms of Service, except that those limitations do not apply to liability that GDPR Article 82 does not allow to be limited between controller and processor.

11. Term

This DPA applies for as long as Nordlet processes Customer Personal Data, and section 8 survives until the deletion it describes has been completed.

12. Precedence and governing law

If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails. In all other respects the Terms of Service, including their governing-law and dispute clauses, apply. This DPA is published in English and Lithuanian; if the two versions differ, the English version governs.

Annex 1 — Details of the Processing

Item Description
Subject matter Provision of the Nordlet cloud accounting platform and API to the Customer
Duration The term of the Terms of Service, plus the deletion period in section 8
Nature and purpose Storing, structuring, calculating, reporting, transmitting and displaying accounting and related business records on the Customer's instructions; generating invoices, declarations, payment files and reports; exchanging e-invoices and bank data with the providers the Customer connects
Categories of Data Subjects The Customer's employees and contractors; contact persons at the Customer's customers, suppliers and other business partners; sole traders who are the Customer's partners; the Customer's own users; shareholders and directors where recorded; other persons named in accounting documents
Categories of Personal Data Names, job titles, business contact details (email, phone, address); identification numbers of sole traders and, where the law requires, personal identification codes of employees; bank account numbers and transaction details; salary, tax, social-insurance and leave data for payroll; vehicle and asset assignments; content of uploaded documents; user activity in the audit log
Special categories Not intended. May occur incidentally in payroll and HR records (for example sick-leave data) where the law requires it
Location of Processing European Union; see section 7 for Sub-processors outside the EEA

Annex 2 — Technical and organisational measures

Area Measure
Encryption in transit TLS on every connection to the website, the application, the API and between the service and its Sub-processors
Encryption at rest Uploaded files are stored encrypted at rest; database volumes are on encrypted storage
Authentication Passwordless sign-in through one-time links valid for 15 minutes; session, invitation and sign-in tokens stored only as hashes; API keys stored only as hashes and issued with explicit scopes per company
Tenant isolation Every table holding Customer Data carries the company identifier; row-level security policies in the database restrict each session to the company it is authenticated for
Access control Users are invited per company and assigned roles; the Customer administers its own users; Nordlet staff access to production is restricted to named administrators, uses individual credentials, and is limited to what operating the service requires
Integrity Posted journal entries are immutable; corrections are made by reversing entries; an audit log records who changed what and when
Logging and monitoring Server and application logs are kept for 90 days for security and reliability; rate limiting protects against abuse
Availability Redundant database nodes and regular backups; backups are retained on a rolling schedule and tested by restore
Data minimisation The Customer controls which fields it fills; optional integrations send only the data the integration needs (for example only the VAT number to VIES, only the uploaded document to the OCR provider)
Sub-processor management Written contracts with every Sub-processor; list published in Annex 3; 30-day notice of changes
Deletion Company deletion with a 10-day restore window, then permanent removal; account deletion removes all Customer Data; backup copies overwritten within 35 days
Staff All staff bound by confidentiality; access removed when a person leaves
Incident response Documented procedure for detecting, containing and reporting Personal Data Breaches within the 48-hour window in section 6

Annex 3 — Sub-processors

Sub-processor Service Location When used
Amazon Web Services EMEA SARL Hosting of the web application, storage of uploaded files European Union Always
Stripe Payments Europe, Ltd. Payment processing for credit purchases Ireland, with Stripe, Inc. (United States) for card processing When the Customer buys Credits. Stripe processes the Customer's own billing data, not Customer Personal Data of Data Subjects
Resend, Inc. Transactional email delivery United States (EU region) Customer email address
Mistral AI Optical character recognition of uploaded documents France Only when the Customer uses document scanning
Enable Banking Oy Retrieval of bank account transactions Finland Only when the Customer connects a bank account
Peppol access point provider configured for the Customer's company Exchange of e-invoices over the Peppol network Depends on the provider Only when the Customer enables e-invoicing

The European Commission's VIES service, which validates VAT numbers, is an independent public service and not a Sub-processor; only the VAT number is sent to it.