---
title: "Data processing agreement | tobbli"
canonical_url: "https://tobbli.com/it/avv"
last_updated: "2026-09-20T21:12:11.260Z"
meta:
  description: "Art. 28 GDPR processor terms for workspace content in tobbli invoice software."
  "og:description": "Art. 28 GDPR processor terms for workspace content in tobbli invoice software."
  "og:title": "Data processing agreement | tobbli"
  "twitter:description": "Art. 28 GDPR processor terms for workspace content in tobbli invoice software."
  "twitter:title": "Data processing agreement | tobbli"
---

**Last updated**

# **Data processing agreement**

Last updated: 20 September 2026

**The German version is authoritative.**

This agreement (DPA) is between you as controller (“customer”) and Emilio Ybarra, Meller Straße 17, 49143 Bissendorf (“processor”) once you use tobbli and store third-party personal data in the workspace. It supplements the [**terms**](https://tobbli.com/it/agb) and the [**privacy policy**](https://tobbli.com/it/datenschutz). You conclude this DPA by registering. The German version is authoritative.

## **§ 1 Subject and term**

The processor hosts the tobbli workspace and processes personal data on the customer’s behalf: storage, display, sending (email, PDF, e-invoice), hosted document links, portal, studio access, export, and — when enabled — payment status via Stripe payment links.

The DPA lasts for the service contract and ends when the data is fully deleted after account closure, subject to legal retention and short backup windows.

## **§ 2 Types of data and data subjects**

Data categories: master and contact data of the customer’s clients, invoice and quote content, tax and bank data (including IBAN and VAT IDs), time, expenses, receipts and other files, portal uploads, usage and delivery data (for example first view of a hosted document), and invite/access data for portal and studio users.

Data subjects: clients, contacts, staff, and other third parties whose data the customer puts in tobbli, plus invited portal and studio users.

## **§ 3 Instructions**

The processor processes the data only on documented instructions from the customer, unless Union or Member State law requires otherwise. Using the app (create, send, share, export, delete) counts as an instruction. Oral instructions must be confirmed by the customer in text form without delay.

If the processor believes an instruction is unlawful, it will tell the customer.

## **§ 4 Technical and organisational measures**

The processor implements appropriate TOMs under Art. 32 GDPR, including:

- TLS in transit for the web services.
- Access control through authentication; separate roles for owner, studio, and portal.
- Tenant separation in the database (row-level security) and separate file prefixes per owner.
- Hosted documents shared only with the relevant token.
- Logging of security-relevant events where operationally possible.
- Backups (point-in-time recovery when enabled) and orderly deletion on account delete.

The processor may change the TOMs if the level of protection does not fall.

## **§ 5 Sub-processors**

The customer authorises the following sub-processors. A change will be published in this list or by email. The customer may object for an important data-protection reason; if so, the processor may terminate the contract.

- Netlify, Inc. — hosting and delivery of the application.
- Supabase — authentication, database, file storage.
- Stripe — billing for tobbli Pro and, when enabled, payment links on hosted invoices.
- The configured SMTP/email vendor for transactional mail.
- Sentry when error reporting is enabled.

The processor will have Art. 28 GDPR contracts with sub-processors. Transfers outside the EEA use appropriate safeguards (in particular standard contractual clauses).

## **§ 6 Assistance, data-subject rights, notices**

The processor assists the customer with data-subject requests, DPIAs, and notices to authorities, to the extent the nature of the processing allows. Incoming requests that concern the customer are forwarded.

The processor will notify the customer without undue delay after becoming aware of a personal-data breach.

## **§ 7 Return and deletion**

The customer may export the workspace as a ZIP at any time. After the service ends or on instruction, the processor deletes the personal data in production systems (account and file deletion), unless law requires retention. Backups expire within the technical window.

## **§ 8 Evidence and audits**

On request the processor will provide the information needed to meet Art. 28(3)(h) GDPR. On-site audits must be announced with reasonable notice and must not disrupt operations; the processor may limit them to recognised certificates or written answers where that is enough.

## **§ 9 Final provisions**

German law applies. Venue is, where permitted, Osnabrück. For processing, this DPA prevails over the terms if they conflict.

**Other legal pages**

- [**Imprint**](https://tobbli.com/it/impressum)
- [**Privacy policy**](https://tobbli.com/it/datenschutz)
- [**Terms of service**](https://tobbli.com/it/agb)

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
