Data Processing Agreement
Version 1.0 · 27/08/2026
This agreement under Article 28 GDPR applies automatically between the company holding the account (the controller) and Luxxow S.à r.l.-S (the processor) from the moment the account is created, as part of the Terms of Service.
1. Subject matter and duration. Processing of the personal data the controller enters into Luxxow Invoice, for as long as the account exists plus the export and deletion periods in the Terms.
2. Nature and purpose. Hosting, storage, display, document generation (PDF, UBL, FAIA, CSV), transmission by email and over the Peppol network, reception of e-invoices, bank statement matching, and backups — solely to provide the service.
3. Data and data subjects. Identification and billing data of the controller's customers, suppliers and contact persons: names, addresses, email addresses, phone numbers, VAT numbers, bank details appearing on documents, and the contents of invoices, quotes and reminders.
4. Instructions. Luxxow processes this data only on the controller's documented instructions — in practice, the actions taken in the application — unless EU or Luxembourg law requires otherwise, in which case Luxxow informs the controller before processing, where the law permits.
5. Confidentiality. Persons authorised to process the data are bound by confidentiality obligations.
6. Security (Art. 32). TLS in transit; per-company database isolation; encrypted secrets at rest; optional two-factor authentication; signed webhooks; append-only audit trail; nightly encrypted backups; access limited to what operating the service requires.
7. Subprocessors. The controller authorises the subprocessors listed in the Privacy Policy (currently Hostinger, MXroute, Recommand, and Stripe once payments start). Luxxow informs account holders of intended additions or replacements, giving the controller the opportunity to object; the same data protection obligations are imposed on every subprocessor.
8. Assistance. Taking into account the nature of the processing, Luxxow assists the controller with data subject requests (the export tools serve access and portability directly) and with the controller's obligations under Articles 32–36 GDPR.
9. Personal data breaches. Luxxow notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, with the information needed for the controller's own notifications.
10. End of processing. At the end of the service, the controller exports its data with the built-in tools; after the 30-day export period Luxxow deletes the company's database and files, and backups roll off within a further 30 days, unless EU or Luxembourg law requires longer storage.
11. Audit. Luxxow makes available the information necessary to demonstrate compliance with this agreement and allows for and contributes to audits conducted by the controller or an auditor mandated by it, at reasonable intervals and on reasonable notice.