_Version: 6 September 2026._

## 1. Parties and entering into the agreement

This Data Processing Agreement (DPA) covers **KSeF Kit**, available in Stripe as
**KSeF e-Invoicing for Poland**. It supplements the [Terms of Service](/terms?locale=en) and sets
out how we process data on your behalf under Article 28 of the
[GDPR — Regulation (EU) 2016/679](https://eur-lex.europa.eu/eli/reg/2016/679/oj?locale=en).

- **Controller (you):** the business using the service, identified in the DPA acceptance.
- **Processor (we):** Ernest Bursa, ul. Dąbrowskiego 96/5b, 60-576 Poznań, Poland,
  tax ID (NIP) 7831677335. Contact: [hello@startupkit.app](mailto:hello@startupkit.app).

**You can enter into this DPA by email.** An authorised representative of your business sends an
email to the address above with the business name, address, tax ID and KSeF Kit account email,
stating: “I accept the KSeF Kit Data Processing Agreement, version dated 6 September 2026.” The
agreement is concluded when we receive that email. We may also agree and sign it separately. Keep
a copy of the accepted text; it is also available [as a text download](/dpa.md?locale=en).
Creating an account or installing the app alone does not confirm acceptance of this DPA version.

The agreement covers the cloud service. Running the software on your own infrastructure without
giving us access to data does not constitute entrustment. Access to data during additional support
requires prior agreement on the scope of processing.

## 2. Scope and duration of processing

We process data to retrieve invoices and credit notes from Stripe, convert them to FA(3), submit
them to KSeF on your behalf, receive and store KSeF numbers and UPO receipts, update documents in
Stripe, and provide filing history and exports. This includes reading, organising, transforming,
transmitting, storing, making data available to you and deleting it, together with the error
handling and technical support necessary for these activities.

- **Data subjects:** your counterparties who are natural persons, including sole traders, and
  your or their representatives, employees and contacts named in documents.
- **Data:** names, business names, addresses, tax identifiers, contact details, line descriptions,
  amounts, dates, payment details and other personal data in the invoices and credit notes you
  provide; document identifiers, KSeF numbers, UPO receipts and filing information. Integration
  credentials are also covered to the extent they constitute personal data.
- **Duration:** the period of services involving processing, until data is returned or deleted
  under section 7. The DPA safeguards continue to apply until then.

The service is not intended for special categories of data under Article 9 GDPR or data under
Article 10 GDPR. Do not include them in descriptions or other document fields without first
agreeing appropriate terms and safeguards with us.

## 3. Instructions and controller obligations

We process data only on your documented instructions, including for transfers outside the EEA.
Instructions comprise the DPA, integration configuration, actions of authorised users and
arrangements made by email. We do not use entrusted data for our own marketing or profiling.

You are responsible for the lawfulness of entrustment, the legal basis for processing, information
provided to data subjects, data accuracy and user permissions. You may give instructions, request
information about processing and exercise the rights in this DPA. You remain the taxpayer
responsible for invoices and their retention.

If Union or Member State law requires processing beyond your instructions, we will inform you
before processing, unless the law prohibits that notice. We will also inform you immediately if
we consider an instruction to infringe the GDPR or other data protection law, and suspend that
instruction pending clarification.

## 4. Confidentiality and security

We ensure that authorised persons are bound to confidentiality. Access is limited to the people
and scope necessary to provide the service. We implement technical and organisational measures
required by Article 32 GDPR, appropriate to the risk, and assess their effectiveness. These include:

- HTTPS/TLS encryption for communication with browsers and the Stripe and KSeF APIs;
- encryption of locally stored tokens, certificates, private keys and integration secrets;
  in the Stripe App edition, KSeF credentials are stored in Stripe Secret Store;
- separation of account data and access controls;
- minimising data in error reports, particularly removing invoice content, UPO receipts and secrets;
- maintaining confidentiality, integrity, availability and the ability to restore access to data
  after an incident, appropriate to the processing risk.

## 5. Sub-processing and recipients

You grant general authorisation to use sub-processors as necessary to provide the service:

| Provider | Scope |
| --- | --- |
| Hetzner Online GmbH ([DPA](https://www.hetzner.com/AV/DPA_en.pdf)) | Hosting the application, database and our mail infrastructure. |
| Cloudflare, Inc. ([DPA](https://www.cloudflare.com/cloudflare-customer-dpa/)) | Handling and protecting traffic across its global network: request and response content, including invoice data and transmitted credentials, together with IP addresses and technical HTTP data. |
| Functional Software, Inc., doing business as Sentry ([DPA](https://sentry.io/legal/dpa/)) | Error diagnostics based on reports with a limited data scope. Account and Stripe document identifiers, and the part of a KSeF number remaining after removal of the tax ID (NIP), may remain. |

Before sending reports to Sentry, we filter invoice and UPO content, buyer data and secrets.
Reports undergo data minimisation and pseudonymisation; retained identifiers may allow an event
to be linked to a person using additional information.

We contractually impose the same data protection obligations on sub-processors as those in this
DPA and remain responsible to you for the performance of their obligations. We will notify you
by email **at least 14 days before** adding or replacing a sub-processor we engage directly.
You may object on data protection grounds during that period. We will agree a solution before
the new processing begins; if no solution is possible, you may terminate the affected service
without an additional fee.

We also make available current information on the identity, role and processing location of
further sub-processors involved in processing your data. We inform you of planned changes in
that chain without undue delay after receiving the provider's notice, allowing time to object
before the new processing starts. The same process for agreeing a solution and terminating the
service described above applies to those objections.

**KSeF (the Ministry of Finance) is a separate statutory recipient, not our sub-processor.**

The integration uses your Stripe account to retrieve documents and record filing information.
In the Stripe App edition, it also stores the KSeF token, certificate and private key in Secret
Store scoped to your account and our app. Stripe services are governed by the applicable
agreements with Stripe, including its [DPA](https://stripe.com/legal/dpa) for operations within
its scope. Requests to NBP contain only the currency and exchange-rate date, without personal
data from invoices.

Cloudflare and cloud-hosted Sentry may process data outside the EEA, including in the USA.
Their DPAs provide for the Data Privacy Framework for transfers covered by that mechanism and
standard contractual clauses (SCCs) for transfers requiring those safeguards, including if the
DPF ceases to be valid.

Transfers of entrusted data outside the EEA, including access from a third country, take place only
under your documented instructions and Chapter V GDPR: on the basis of an applicable adequacy
decision or appropriate safeguards, such as standard contractual clauses, with supplementary
measures where needed. On request, we will provide information on processing locations and transfer
grounds. Listing a provider above does not replace the required transfer mechanism.

## 6. Assistance and breaches

Taking into account the nature of processing, we assist you through appropriate technical and
organisational measures with requests under Chapter III GDPR. We forward requests concerning
entrusted data to you and do not decide them independently without your instructions unless required
by law. We also assist with obligations under Articles 32–36 GDPR, including impact assessments and
prior consultation, taking into account the information available to us.

We will notify you **without undue delay** after becoming aware of a personal data breach affecting
entrusted data, using the account contact email. We will provide available information on the
nature of the breach, affected people and data, approximate scale, likely consequences, measures
taken or proposed, and a contact handling the incident. We will supply missing information without
undue delay and cooperate in mitigating the effects and meeting your notification obligations.

## 7. End of processing

After services involving processing end, **at your choice we return or delete entrusted data and
delete existing copies**, without undue delay, unless Union or Member State law requires us to
retain it. In that case we will inform you of the legal basis and retention period, unless the law
prohibits this, and restrict processing to that purpose.

Send your choice and instructions to end processing to
[hello@startupkit.app](mailto:hello@startupkit.app). We provide data and UPO exports. Disconnecting
an integration stops access and initiates credential deletion, but does not automatically delete
filing history. Continuing to store that history on your behalf requires your documented
instruction and an agreed period. Your tax record-keeping duties do not, by themselves, justify
our retaining those records after services end. The DPA does not change retention by KSeF or by
Stripe under your agreement with that provider.

## 8. Information and audits

We make available the information necessary to demonstrate compliance with Article 28 GDPR and
allow and contribute to audits, including inspections, by you or an authorised auditor. Contact
[hello@startupkit.app](mailto:hello@startupkit.app) to arrange an audit. We agree its scope and
timing while protecting other customers' data and service continuity; this does not restrict
supervisory authority powers or an urgent audit justified by a breach.

## 9. Other provisions

This DPA prevails over the Terms and Privacy Policy on entrusted processing. The remaining Terms,
including Polish law, disputes and liability, apply to the extent permitted by law. This does not
limit data subjects' rights or liability under mandatory GDPR provisions, including Article 82,
or our responsibility for sub-processors under section 5.

Changes to the agreed DPA require acceptance by both parties electronically or in writing;
sub-processor list updates follow section 5. Data for which we are a separate controller, such as
your account billing, is described in the [Privacy Policy](/privacy?locale=en). The Polish version
prevails in case of discrepancies between language versions.
