Attesta writes invoices, so it processes personal data about your buyers on your behalf. This agreement sets out the terms of that processing under Art. 28 GDPR. It takes effect when you install the App and runs for as long as the installation does. You do not need to sign anything separately.
You, the merchant who installed Attesta, are the controller of your buyers' personal data. Obarito, which operates Attesta, is your processor for that data.
This agreement covers only that relationship. Data about you and your shop, meaning your account, your seller details and your billing, is handled by Obarito as controller and is covered by the Privacy Policy instead. Where this agreement and the Terms of Service disagree about personal data, this agreement wins.
We generate German e-invoices from your paid Shopify orders, validate them against EN 16931, archive them, and deliver them to your buyers where you have switched that on. Processing runs for the term of your installation, and for archived invoices, for the statutory retention period described below.
Processing is automated and serves one purpose: producing, validating, archiving, exporting and delivering invoices that satisfy §14 UStG, the GoBD and EN 16931. We do not use your buyers' data for anything else. We do not sell or share it, do not use it for marketing, do not build profiles from it, do not enrich it against outside sources, and do not use it to train machine learning models.
The data subjects are your customers, and where a business buys from you, the people representing that business. The categories we process are the buyer's name or company name, their billing address, their email address, their VAT identification number where they give one, and the contents of their order. The full inventory, and the reason each field is needed, is in the Privacy Policy.
We request the minimum that the job needs. Phone numbers are not requested and we have no use for them.
We process your buyers' data only on your documented instructions. The App's settings and this agreement are those instructions. If an instruction looks to us like it would infringe data protection law, we will tell you, and we may decline to carry it out.
One case is settled here in advance, because it comes up often enough to deserve a written answer rather than an improvised one. Where an erasure request arrives for a buyer whose invoice has already been issued, we retain the invoice under Art. 17(3)(b) GDPR, because you are legally required to keep it. Erasing it on request would put you in breach of your own retention duty. What can be erased is erased, and the request is recorded.
Everyone we authorise to handle personal data is bound to confidentiality in writing, and that obligation outlives their involvement. Attesta has no admin panel and no support login, so reaching your data at all requires deliberate server access rather than a screen someone can wander into.
Under Art. 32 GDPR we apply at least the following:
Issued invoices are kept for ten years, as the GoBD and §14b UStG require. The order payload held behind a failed invoice attempt is erased once the attempt succeeds, on a buyer erasure request, or on your instruction. When you uninstall, we erase everything we hold for your shop as your processor once Shopify's shop/redact request reaches us, about 48 hours later.
Your ten-year duty does not end with the uninstall, it stays with you as the controller, so export your GoBD ZIP before you leave. You can export it from the App at any time while the installation lasts.
You give general authorisation for the sub-processors listed in the Privacy Policy: Shopify, our hosting provider, our email provider, and the European Commission's VIES service. We will announce any intended addition or replacement before it takes effect, and you may object.
Invoice generation itself happens on our own server. The PDF renderer and the ZUGFeRD writer are libraries running locally, so no invoice content is sent anywhere to be processed. No AI or language model provider receives your buyers' data.
We help you answer requests from your buyers, mainly through Shopify's privacy webhooks, all three of which Attesta implements. A data request returns the invoice records we hold for the named orders so you can answer the buyer, since the answer is yours to give.
We also help with data protection impact assessments and with notifications to supervisory authorities, so far as the information is ours to give.
If we become aware of a breach affecting your data, we will tell you without undue delay and at the latest within 48 hours. Your own 72-hour clock under Art. 33 GDPR starts when you are told, so telling you late would cost you time you need.
The notice will say what happened, which categories of data and roughly how many records are affected as far as we know, what the likely consequences are, and what we have done about it. Where we cannot yet tell, we will say that rather than guess.
We will give you the information needed to show compliance with Art. 28 GDPR, and allow an audit by you or an auditor you appoint, on reasonable notice and without disrupting the service.
When the installation ends, we delete your data as described under Retention and deletion. Export your archive first: once the erasure runs, it is gone from our side, and the retention duty remains yours.
Questions about this agreement, or a request for the current sub-processor list with each entity and country, go to support@obarito.com.