VERSION 2026-09-12
Data processing agreement.
This agreement forms part of the ApiVect business service terms. The registered business is the controller of personal data it submits for validation. KPdesign, CVR 41134194, is its processor for those operations. Account administration and security processing for KPdesign's own purposes are described separately in the privacy policy.
Processing instructions and scope
The controller instructs ApiVect to receive, validate and return invoice, VAT and public domain checks through the documented endpoints, maintain usage records, provide encrypted retry results and operate the necessary security and backup functions. Processing lasts for the account's use of the service and the retention periods below. Data can concern customers, suppliers, sole traders and business contacts, including invoice identifiers, business contact details, VAT identifiers and domain names. Special-category data is not permitted. The controller is responsible for lawful collection, notices and authority to issue these instructions.
Confidentiality and security
ApiVect limits access to authorized personnel subject to confidentiality. Technical measures include TLS, hashed passwords and keyed API-key hashes, mandatory portal MFA, tenant isolation in PostgreSQL, constrained outbound network checks, encrypted retry/mail payloads, secret separation, security logging and encrypted backups. ApiVect will maintain risk-appropriate security measures, investigate incidents and assist the controller with necessary security and impact-assessment information.
Assistance and incidents
ApiVect will notify the controller without undue delay after becoming aware of a personal data breach affecting its data, with known scope, consequences, response measures and contact details, and provide updates as information becomes available. ApiVect assists with requests to access, correct, export or erase data and with the controller's duties under GDPR Articles 32–36. Data-subject requests received directly are referred to the controller where applicable. ApiVect will inform the controller if an instruction appears to infringe data protection law, and will not use customer data for an unrelated purpose.
Providers and onward processing
The controller authorizes the following current infrastructure and lookup arrangements for their stated purpose. ApiVect remains responsible for any engaged subprocessor's contractual processing obligations and must use appropriate written terms and applicable safeguards for restricted transfers.
| Provider | Purpose and data |
|---|---|
| Contabo | Host infrastructure for the application, database and transactional email. |
| Google Drive | Offsite copies of encrypted backup archives. Decryption keys remain under the operator's control. |
| Cloudflare public DNS resolver | Requested public domains and selector names for DNS-over-HTTPS lookup; invoice XML is not sent. |
| European Commission / VIES | Country and VAT number for the requested lookup. Returned business names and addresses are discarded. |
Google reCAPTCHA and optional Analytics serve account/site protection and measurement described in the privacy policy, rather than invoice validation. Stripe will process billing data only when a paid checkout is enabled and chosen. Before adding or replacing a subprocessor, ApiVect will notify the account owner at least 30 days in advance, allow reasonable data-protection objections, and resolve them or allow affected processing to end. A public list alone is not the notice.
Retention, return and deletion
Invoice XML is processed in memory. Encrypted retry results expire after 24 hours, with cleanup every 30 seconds. Queued transactional email is erased after delivery or expiry; delivery metadata remains seven days. Security audit events remain 90 days. On verified account closure, ApiVect will return available customer data on request and delete or anonymize active account-linked data within 30 days, except a documented legal retention obligation. Encrypted backups expire under the seven daily, four weekly and six monthly snapshot schedule, within seven months. If restored, approved deletions must be reapplied before the recovered service resumes customer processing.
Information and audits
ApiVect will provide information needed to demonstrate compliance with this agreement and permit proportionate audits, including inspections by the controller or its mandated auditor, with reasonable arrangements that protect other customers and service security. Such arrangements do not remove statutory audit rights. ApiVect will notify the controller of a binding disclosure requirement unless prohibited by law. Requests and instructions should be sent to contact@apivect.com. This agreement prevails over conflicting service terms on processing personal data.