← Home · Terms · Privacy · DPA
Data Processing Agreement (GDPR Art. 28)
This agreement is part of the Terms and applies between each firm/company (controller) and NET Partner OÜ (processor) using the Paberid service.
1. Subject and duration. Storage, display and archiving of documents (invoices, receipts, statements, reports and other source documents) and personal data they contain, for the duration of the service and the plan's retention period.
2. Data and subjects. Data inside documents (names, contacts, bank account numbers, invoice data) — customers, suppliers, employees; account data — the controller's staff.
3. Instructions. We process only on the controller's instructions (service functions). Content is not read, indexed or used for other purposes.
4. Confidentiality and security. TLS, files outside the web root, role-based access, activity log, SHA-256 hashes, hashed IPs, EU servers, backups. Staff are bound by confidentiality.
5. Sub-processors. Hostinger International Ltd (hosting, EU), Brevo SAS (e-mail, EU), Stripe Payments Europe Ltd (payments, EU), Cloudflare Inc (R2 archive storage, EU jurisdiction; only when enabled), Telegram (only if the user connects it). Changes announced 30 days ahead; the controller may object.
6. Assistance. We assist with data-subject requests (access, erasure, portability — ZIP export) and incidents; breaches are notified to the controller without undue delay, at the latest 48 hours after discovery.
7. Termination. After the service ends the controller can download the data as ZIP archives within the retention rules; then data is permanently deleted (backups within 30 days).
8. Audit. We provide reasonable information on security measures (info@paberid.ee). Updated 07.09.2026.