Data Processing Agreement (DPA)
Version: 6 September 2026.
1. Parties and entering into the agreement
This Data Processing Agreement (DPA) covers KSeF Kit, available in Stripe as KSeF e-Invoicing for Poland. It supplements the Terms of Service and sets out how we process data on your behalf under Article 28 of the GDPR — Regulation (EU) 2016/679.
- Controller (you): the business using the service, identified in the DPA acceptance.
- Processor (we): Ernest Bursa, ul. Dąbrowskiego 96/5b, 60-576 Poznań, Poland, tax ID (NIP) 7831677335. Contact: [email protected].
You can enter into this DPA by email. An authorised representative of your business sends an email to the address above with the business name, address, tax ID and KSeF Kit account email, stating: “I accept the KSeF Kit Data Processing Agreement, version dated 6 September 2026.” The agreement is concluded when we receive that email. We may also agree and sign it separately. Keep a copy of the accepted text; it is also available as a text download. Creating an account or installing the app alone does not confirm acceptance of this DPA version.
The agreement covers the cloud service. Running the software on your own infrastructure without giving us access to data does not constitute entrustment. Access to data during additional support requires prior agreement on the scope of processing.
2. Scope and duration of processing
We process data to retrieve invoices and credit notes from Stripe, convert them to FA(3), submit them to KSeF on your behalf, receive and store KSeF numbers and UPO receipts, update documents in Stripe, and provide filing history and exports. This includes reading, organising, transforming, transmitting, storing, making data available to you and deleting it, together with the error handling and technical support necessary for these activities.
- Data subjects: your counterparties who are natural persons, including sole traders, and your or their representatives, employees and contacts named in documents.
- Data: names, business names, addresses, tax identifiers, contact details, line descriptions, amounts, dates, payment details and other personal data in the invoices and credit notes you provide; document identifiers, KSeF numbers, UPO receipts and filing information. Integration credentials are also covered to the extent they constitute personal data.
- Duration: the period of services involving processing, until data is returned or deleted under section 7. The DPA safeguards continue to apply until then.
The service is not intended for special categories of data under Article 9 GDPR or data under Article 10 GDPR. Do not include them in descriptions or other document fields without first agreeing appropriate terms and safeguards with us.
3. Instructions and controller obligations
We process data only on your documented instructions, including for transfers outside the EEA. Instructions comprise the DPA, integration configuration, actions of authorised users and arrangements made by email. We do not use entrusted data for our own marketing or profiling.
You are responsible for the lawfulness of entrustment, the legal basis for processing, information provided to data subjects, data accuracy and user permissions. You may give instructions, request information about processing and exercise the rights in this DPA. You remain the taxpayer responsible for invoices and their retention.
If Union or Member State law requires processing beyond your instructions, we will inform you before processing, unless the law prohibits that notice. We will also inform you immediately if we consider an instruction to infringe the GDPR or other data protection law, and suspend that instruction pending clarification.
4. Confidentiality and security
We ensure that authorised persons are bound to confidentiality. Access is limited to the people and scope necessary to provide the service. We implement technical and organisational measures required by Article 32 GDPR, appropriate to the risk, and assess their effectiveness. These include:
- HTTPS/TLS encryption for communication with browsers and the Stripe and KSeF APIs;
- encryption of locally stored tokens, certificates, private keys and integration secrets; in the Stripe App edition, KSeF credentials are stored in Stripe Secret Store;
- separation of account data and access controls;
- minimising data in error reports, particularly removing invoice content, UPO receipts and secrets;
- maintaining confidentiality, integrity, availability and the ability to restore access to data after an incident, appropriate to the processing risk.
5. Sub-processing and recipients
You grant general authorisation to use sub-processors as necessary to provide the service:
| Provider | Scope |
|---|---|
| Hetzner Online GmbH (DPA) | Hosting the application, database and our mail infrastructure. |
| Cloudflare, Inc. (DPA) | Handling and protecting traffic across its global network: request and response content, including invoice data and transmitted credentials, together with IP addresses and technical HTTP data. |
| Functional Software, Inc., doing business as Sentry (DPA) | Error diagnostics based on reports with a limited data scope. Account and Stripe document identifiers, and the part of a KSeF number remaining after removal of the tax ID (NIP), may remain. |
Before sending reports to Sentry, we filter invoice and UPO content, buyer data and secrets. Reports undergo data minimisation and pseudonymisation; retained identifiers may allow an event to be linked to a person using additional information.
We contractually impose the same data protection obligations on sub-processors as those in this DPA and remain responsible to you for the performance of their obligations. We will notify you by email at least 14 days before adding or replacing a sub-processor we engage directly. You may object on data protection grounds during that period. We will agree a solution before the new processing begins; if no solution is possible, you may terminate the affected service without an additional fee.
We also make available current information on the identity, role and processing location of further sub-processors involved in processing your data. We inform you of planned changes in that chain without undue delay after receiving the provider's notice, allowing time to object before the new processing starts. The same process for agreeing a solution and terminating the service described above applies to those objections.
KSeF (the Ministry of Finance) is a separate statutory recipient, not our sub-processor.
The integration uses your Stripe account to retrieve documents and record filing information. In the Stripe App edition, it also stores the KSeF token, certificate and private key in Secret Store scoped to your account and our app. Stripe services are governed by the applicable agreements with Stripe, including its DPA for operations within its scope. Requests to NBP contain only the currency and exchange-rate date, without personal data from invoices.
Cloudflare and cloud-hosted Sentry may process data outside the EEA, including in the USA. Their DPAs provide for the Data Privacy Framework for transfers covered by that mechanism and standard contractual clauses (SCCs) for transfers requiring those safeguards, including if the DPF ceases to be valid.
Transfers of entrusted data outside the EEA, including access from a third country, take place only under your documented instructions and Chapter V GDPR: on the basis of an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses, with supplementary measures where needed. On request, we will provide information on processing locations and transfer grounds. Listing a provider above does not replace the required transfer mechanism.
6. Assistance and breaches
Taking into account the nature of processing, we assist you through appropriate technical and organisational measures with requests under Chapter III GDPR. We forward requests concerning entrusted data to you and do not decide them independently without your instructions unless required by law. We also assist with obligations under Articles 32–36 GDPR, including impact assessments and prior consultation, taking into account the information available to us.
We will notify you without undue delay after becoming aware of a personal data breach affecting entrusted data, using the account contact email. We will provide available information on the nature of the breach, affected people and data, approximate scale, likely consequences, measures taken or proposed, and a contact handling the incident. We will supply missing information without undue delay and cooperate in mitigating the effects and meeting your notification obligations.
7. End of processing
After services involving processing end, at your choice we return or delete entrusted data and delete existing copies, without undue delay, unless Union or Member State law requires us to retain it. In that case we will inform you of the legal basis and retention period, unless the law prohibits this, and restrict processing to that purpose.
Send your choice and instructions to end processing to [email protected]. We provide data and UPO exports. Disconnecting an integration stops access and initiates credential deletion, but does not automatically delete filing history. Continuing to store that history on your behalf requires your documented instruction and an agreed period. Your tax record-keeping duties do not, by themselves, justify our retaining those records after services end. The DPA does not change retention by KSeF or by Stripe under your agreement with that provider.
8. Information and audits
We make available the information necessary to demonstrate compliance with Article 28 GDPR and allow and contribute to audits, including inspections, by you or an authorised auditor. Contact [email protected] to arrange an audit. We agree its scope and timing while protecting other customers' data and service continuity; this does not restrict supervisory authority powers or an urgent audit justified by a breach.
9. Other provisions
This DPA prevails over the Terms and Privacy Policy on entrusted processing. The remaining Terms, including Polish law, disputes and liability, apply to the extent permitted by law. This does not limit data subjects' rights or liability under mandatory GDPR provisions, including Article 82, or our responsibility for sub-processors under section 5.
Changes to the agreed DPA require acceptance by both parties electronically or in writing; sub-processor list updates follow section 5. Data for which we are a separate controller, such as your account billing, is described in the Privacy Policy. The Polish version prevails in case of discrepancies between language versions.
Questions? Email [email protected].