Skip to content

Legal

Data Processing Agreement

Bilantio — owned and operated by TAXNXT sp. z o.o.

Last updated: 4 August 2026

This Data Processing Agreement, including its Annexes, forms part of the agreement governing the Customer’s use of Bilantio.

It applies where TAXNXT sp. z o.o. processes Personal Data on behalf of the Customer in connection with Bilantio.

Parties

Processor

TAXNXT sp. z o.o.ul. Toruńska 15/7780-747 GdańskNIP: 6783218496REGON: 529197763KRS: 0001117478PolandEmail: support@taxnxt.euBilantio website: bilantio.com

In this Data Processing Agreement, TAXNXT sp. z o.o. is referred to as the “Processor”, “TAXNXT”, “Bilantio”, “we”, “us”, or “our”.

Customer

The company, entrepreneur, accounting firm, organization, or other business entity that enters into an agreement for the use of Bilantio.

In this Data Processing Agreement, that entity is referred to as the “Controller” or the “Customer”.

Where the Customer processes Personal Data on behalf of another controller, the Customer may act as a processor and TAXNXT may act as a subprocessor. References to the Controller shall then be interpreted as references to the Customer acting in its relevant capacity.

§1. Definitions

For the purposes of this DPA:

  1. Applicable Data Protection Law means:
    1. Regulation (EU) 2016/679, the General Data Protection Regulation, or GDPR;
    2. applicable Polish data-protection legislation;
    3. applicable legislation implementing or supplementing the GDPR;
    4. applicable binding decisions, orders, or requirements of a competent supervisory authority; and
    5. other data-protection or privacy laws applicable to the processing covered by this DPA.
  2. Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, Supervisory Authority, and Special Categories of Personal Data have the meanings assigned to them under the GDPR.
  3. Customer Data means information, documents, files, prompts, records, instructions, accounting data, invoice data, payroll data, HR data, tax-related data, and other materials submitted to or processed through Bilantio by or on behalf of the Customer.
  4. Main Agreement means the Bilantio Terms of Service, applicable Order, subscription agreement, service agreement, or other agreement governing the Customer’s use of Bilantio.
  5. Restricted Transfer means a transfer of Personal Data to a country or recipient for which an appropriate safeguard or transfer mechanism is required under Applicable Data Protection Law.
  6. Services means the Bilantio software platform and the services provided under the Main Agreement.
  7. Subprocessor means a third party appointed by TAXNXT to process Personal Data on behalf of the Customer.
  8. Standard Contractual Clauses or SCCs means the standard contractual clauses approved by the European Commission for transfers of Personal Data to third countries, as amended, replaced, or updated from time to time.
  9. User means an individual authorized by the Customer to access or use Bilantio.

§2. Scope and relationship with the Main Agreement

  1. This DPA forms part of the Main Agreement.
  2. This DPA applies only to Processing in which TAXNXT acts as:
    1. a Processor on behalf of the Customer; or
    2. a Subprocessor where the Customer processes Personal Data on behalf of another controller.
  3. This DPA does not apply to Processing for which TAXNXT acts as an independent Controller.
  4. TAXNXT may act as an independent Controller when Processing Personal Data for its own legitimate purposes, including:
    1. creating and managing User accounts;
    2. administering subscriptions;
    3. billing and payment administration;
    4. preventing fraud and misuse;
    5. maintaining platform security;
    6. communicating with Users;
    7. providing customer support;
    8. complying with legal obligations;
    9. maintaining business records;
    10. establishing, exercising, or defending legal claims; and
    11. improving Bilantio using aggregated or anonymized information.
  5. Processing performed by TAXNXT as an independent Controller is governed by Bilantio’s Privacy Policy rather than this DPA.
  6. If there is a conflict between this DPA and the Main Agreement concerning Processing covered by this DPA, this DPA prevails.
  7. If there is a conflict between this DPA and applicable Standard Contractual Clauses, the Standard Contractual Clauses prevail for the relevant Restricted Transfer.

§3. Roles of the parties

  1. The Customer determines the purposes and essential means of Processing Personal Data through Bilantio.
  2. TAXNXT processes Personal Data on behalf of the Customer and according to the Customer’s documented instructions.
  3. The Customer is responsible for determining whether it acts as:
    1. a Controller;
    2. a Joint Controller;
    3. a Processor on behalf of another Controller; or
    4. another role recognized under Applicable Data Protection Law.
  4. Where the Customer acts as a Processor for another Controller:
    1. the Customer confirms that it is authorized to appoint TAXNXT as a Subprocessor;
    2. the Customer shall ensure that its instructions are consistent with the instructions of the relevant Controller;
    3. references in this DPA to the Customer’s rights and obligations shall apply subject to the Customer’s own processing agreement with that Controller; and
    4. TAXNXT shall process Personal Data only within the scope of the Customer’s lawful instructions.
  5. Neither party becomes a Joint Controller solely because it enters into this DPA.
  6. If TAXNXT determines the purposes and essential means of a specific Processing operation independently, TAXNXT shall act as a Controller for that operation and shall comply with the obligations applicable to Controllers.

§4. Subject matter and duration

  1. The subject matter of Processing is the provision, operation, security, support, maintenance, and improvement of the Bilantio Services requested by the Customer.
  2. Processing may include:
    1. account and User administration;
    2. invoice creation and management;
    3. processing and transmission of structured invoices;
    4. KSeF-related workflows;
    5. document uploading and storage;
    6. optical character recognition;
    7. extraction of information from documents;
    8. classification and organization of accounting documents;
    9. preparation of summaries and reports;
    10. accounting and bookkeeping workflows;
    11. VAT and tax-related workflows;
    12. payroll and HR-related administrative workflows;
    13. AI-assisted processing;
    14. support services;
    15. security monitoring;
    16. data export and migration;
    17. backups and disaster recovery; and
    18. integrations activated by the Customer.
  3. Processing begins when the Customer first submits Personal Data to Bilantio or otherwise instructs TAXNXT to process Personal Data.
  4. Processing continues for the duration of the Main Agreement and any additional retention or retrieval period permitted under this DPA.
  5. Further details of Processing are specified in Annex I and Annex II.

§5. Processing instructions

  1. TAXNXT shall process Personal Data only on documented instructions from the Customer, unless Processing is required by applicable European Union or Member State law.
  2. Documented instructions include:
    1. the Main Agreement;
    2. this DPA;
    3. the Customer’s configuration of Bilantio;
    4. actions performed by authorized Users;
    5. API instructions;
    6. integration settings;
    7. support requests;
    8. written instructions submitted by an authorized Customer representative; and
    9. instructions reasonably necessary to provide the Services selected by the Customer.
  3. The Customer instructs TAXNXT to process Personal Data as necessary to:
    1. provide the Services;
    2. maintain and secure Bilantio;
    3. prevent unauthorized access and misuse;
    4. provide support;
    5. perform backups and recovery;
    6. engage approved Subprocessors;
    7. comply with lawful Customer requests; and
    8. delete or return Personal Data in accordance with this DPA.
  4. TAXNXT shall not:
    1. sell Personal Data;
    2. use Personal Data for advertising unrelated to Bilantio;
    3. use Customer invoice, accounting, payroll, document, prompt, or chat data to train artificial intelligence models; or
    4. process Personal Data for purposes incompatible with the Customer’s instructions.
  5. TAXNXT may process aggregated or anonymized information where individuals and the Customer cannot reasonably be identified.
  6. If TAXNXT is required by law to process Personal Data other than according to the Customer’s instructions, TAXNXT shall inform the Customer before Processing unless the law prohibits such notification.
  7. TAXNXT shall promptly inform the Customer if, in TAXNXT’s reasonable opinion, an instruction infringes Applicable Data Protection Law.
  8. TAXNXT may suspend implementation of an instruction while the parties clarify its legality.
  9. TAXNXT is not required to comply with an instruction that:
    1. is unlawful;
    2. falls outside the scope of the Services;
    3. would materially compromise the security of Bilantio;
    4. would infringe the rights of another customer or third party;
    5. is technically impossible using the agreed Services; or
    6. requires disproportionate custom development not included in the Main Agreement.
  10. The parties may agree on additional services or fees where an instruction requires material work beyond the standard Services.

§6. Compliance with applicable law

  1. Each party shall comply with Applicable Data Protection Law in relation to its own obligations.
  2. TAXNXT shall:
    1. process Personal Data according to this DPA;
    2. implement appropriate technical and organizational measures;
    3. ensure that persons authorized to process Personal Data are subject to confidentiality obligations;
    4. assist the Customer as described in this DPA;
    5. maintain records required of a Processor;
    6. cooperate with competent Supervisory Authorities where legally required; and
    7. provide information reasonably necessary to demonstrate compliance.
  3. The Customer shall ensure that:
    1. Processing through Bilantio is lawful;
    2. there is an appropriate legal basis for Processing;
    3. required privacy notices have been provided;
    4. required permissions, authorizations, and consents have been obtained;
    5. the Customer’s instructions comply with Applicable Data Protection Law;
    6. Processing is limited to what is necessary and proportionate;
    7. retention periods have been established;
    8. appropriate User access permissions are configured; and
    9. Bilantio is suitable for the Customer’s intended Processing activities.

§7. Confidentiality and authorized personnel

  1. TAXNXT shall ensure that persons authorized to process Personal Data:
    1. access Personal Data only where necessary for their duties;
    2. process Personal Data only according to applicable instructions;
    3. are bound by contractual or statutory confidentiality obligations;
    4. receive appropriate privacy and security guidance; and
    5. are subject to appropriate access controls.
  2. Access to Personal Data shall be granted according to the principle of least privilege.
  3. TAXNXT shall periodically review access rights and remove access that is no longer required.
  4. Confidentiality obligations shall continue after the person’s employment, engagement, or authorization ends.
  5. TAXNXT shall not disclose Personal Data to a third party except:
    1. according to the Customer’s instructions;
    2. through an approved Subprocessor;
    3. where required by law;
    4. where necessary to protect the security of the Services; or
    5. with the Customer’s authorization.

§8. Security of processing

  1. TAXNXT shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against:
    1. accidental or unlawful destruction;
    2. loss;
    3. alteration;
    4. unauthorized disclosure;
    5. unauthorized access;
    6. misuse; and
    7. other unlawful Processing.
  2. The measures shall take account of:
    1. the state of the art;
    2. implementation costs;
    3. the nature, scope, context, and purposes of Processing;
    4. the likelihood and severity of risks to individuals; and
    5. the categories and volume of Personal Data processed.
  3. The measures maintained by TAXNXT are described in Annex III.
  4. TAXNXT may update its security measures provided that the overall level of protection is not materially reduced.
  5. TAXNXT does not guarantee that every security incident can be prevented.
  6. The Customer is responsible for security matters under its control, including:
    1. User devices;
    2. local networks;
    3. password and credential management;
    4. User permissions;
    5. internal access policies;
    6. data entered into Bilantio;
    7. third-party integrations selected by the Customer; and
    8. downloads or exports stored outside Bilantio.
  7. The Customer shall notify TAXNXT without undue delay if it becomes aware of:
    1. unauthorized Account access;
    2. compromised credentials;
    3. a vulnerability affecting Bilantio;
    4. an accidental disclosure involving Bilantio; or
    5. any other security incident relevant to the Services.

§9. Personal Data Breaches

  1. TAXNXT shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
  2. Notification shall be sent to the Customer’s designated security, privacy, or Account contact.
  3. To the extent information is reasonably available, the notification shall include:
    1. the nature of the Personal Data Breach;
    2. the categories of affected Data Subjects;
    3. the categories of affected Personal Data;
    4. the approximate number of affected Data Subjects and records;
    5. the likely consequences;
    6. measures taken or proposed to address the breach;
    7. measures intended to reduce possible adverse effects; and
    8. contact information for further communication.
  4. Where all information is not available at the same time, TAXNXT may provide information in phases without undue further delay.
  5. TAXNXT shall take reasonable steps to:
    1. contain the breach;
    2. investigate its cause;
    3. mitigate adverse effects;
    4. restore appropriate security; and
    5. prevent recurrence.
  6. TAXNXT’s notification does not constitute an admission of fault or liability.
  7. The Customer is responsible for determining whether notification must be made to:
    1. a Supervisory Authority;
    2. affected Data Subjects;
    3. another Controller; or
    4. another competent authority.
  8. TAXNXT shall provide reasonable assistance with such notification obligations, taking account of the nature of Processing and the information available to TAXNXT.
  9. Where the Personal Data Breach was caused by the Customer, a User, the Customer’s systems, or an integration controlled by the Customer, additional assistance may be charged at the agreed professional-services rate.

§10. Data-subject requests

  1. Taking account of the nature of Processing, TAXNXT shall provide reasonable assistance to enable the Customer to respond to requests concerning:
    1. access;
    2. rectification;
    3. erasure;
    4. restriction;
    5. objection;
    6. data portability;
    7. withdrawal of consent; and
    8. rights relating to automated decision-making.
  2. Where a Data Subject submits a request directly to TAXNXT concerning Personal Data processed on behalf of the Customer, TAXNXT shall:
    1. not respond substantively unless authorized by the Customer or required by law;
    2. direct the Data Subject to the Customer where appropriate; and
    3. forward the request to the Customer without undue delay where the relevant Customer can reasonably be identified.
  3. TAXNXT may request information necessary to identify the relevant Customer and Personal Data.
  4. The Customer is responsible for:
    1. verifying the identity of the requester;
    2. determining whether the request is valid;
    3. deciding how to respond;
    4. communicating with the Data Subject; and
    5. complying with applicable deadlines.
  5. Standard assistance available through Bilantio’s functionality is included in the Services.
  6. Material additional work may be charged where permitted by law and agreed with the Customer in advance.

§11. Assistance with compliance

  1. Taking account of the nature of Processing and the information available to TAXNXT, TAXNXT shall provide reasonable assistance with the Customer’s obligations relating to:
    1. security of Processing;
    2. Personal Data Breach assessment and notification;
    3. Data Protection Impact Assessments;
    4. prior consultation with Supervisory Authorities;
    5. data-subject rights;
    6. records of Processing activities; and
    7. demonstrations of compliance.
  2. Assistance may include:
    1. providing relevant security documentation;
    2. providing information about Subprocessors;
    3. explaining Bilantio’s Processing activities;
    4. providing available audit or compliance reports;
    5. providing reasonable information about data locations;
    6. supporting exports or deletion;
    7. providing available incident information; and
    8. responding to reasonable compliance questionnaires.
  3. TAXNXT is not responsible for:
    1. preparing the Customer’s entire compliance program;
    2. determining the Customer’s legal basis;
    3. drafting the Customer’s privacy notices;
    4. acting as the Customer’s data protection officer;
    5. providing legal advice; or
    6. guaranteeing that the Customer’s use of Bilantio complies with all applicable laws.
  4. Assistance requiring material custom work may be subject to additional fees where legally permissible.

§12. Data Protection Impact Assessments

  1. Where the Customer reasonably determines that use of Bilantio requires a Data Protection Impact Assessment, TAXNXT shall provide information reasonably available to it and relevant to:
    1. the nature and purposes of Processing;
    2. data flows;
    3. categories of Personal Data;
    4. Subprocessors;
    5. international transfers;
    6. retention and deletion;
    7. security measures; and
    8. identified risks relating to the Services.
  2. The Customer remains responsible for:
    1. deciding whether a Data Protection Impact Assessment is required;
    2. conducting the assessment;
    3. documenting the outcome;
    4. identifying appropriate legal bases;
    5. implementing Customer-controlled safeguards; and
    6. consulting a Supervisory Authority where necessary.
  3. TAXNXT shall reasonably cooperate with prior consultation required under Applicable Data Protection Law.

§13. Subprocessors

  1. The Customer grants TAXNXT general written authorization to appoint Subprocessors for the purposes of providing the Services.
  2. TAXNXT shall maintain an up-to-date Subprocessor register containing, where applicable:
    1. the Subprocessor’s full legal name;
    2. registered address or principal business address;
    3. contact details;
    4. description of the Processing performed;
    5. categories of Personal Data involved;
    6. Processing location;
    7. applicable international transfer mechanism; and
    8. relevant service or function.
  3. The current approved Subprocessors are identified in Annex IV or in the Subprocessor register published or made available through Bilantio.
  4. TAXNXT shall provide notice of a new or replacement Subprocessor before that Subprocessor begins materially processing Personal Data.
  5. Notice may be provided through:
    1. email;
    2. the Customer’s Account;
    3. Bilantio’s Subprocessor register; or
    4. another agreed communication channel.
  6. The Customer may object to a new Subprocessor on reasonable and documented data-protection grounds.
  7. An objection must:
    1. be submitted within 15 calendar days after notice;
    2. identify the specific data-protection concern;
    3. explain why the proposed Subprocessor creates a material risk; and
    4. provide reasonable supporting information.
  8. The parties shall work in good faith to address a valid objection.
  9. TAXNXT may address an objection by:
    1. providing additional information;
    2. introducing reasonable safeguards;
    3. offering a commercially reasonable alternative;
    4. disabling the affected optional function; or
    5. allowing the Customer to terminate the affected Service.
  10. If no reasonable solution is available, either party may terminate the affected part of the Services before the new Subprocessor begins Processing the Customer’s Personal Data.
  11. Objection rights do not permit the Customer to object solely because of:
    1. the Subprocessor’s commercial identity;
    2. a general preference for another provider;
    3. an objection unrelated to data protection; or
    4. a risk already adequately addressed by applicable safeguards.
  12. TAXNXT shall enter into a written agreement with each Subprocessor requiring data-protection obligations that provide a level of protection materially equivalent to the obligations applicable to TAXNXT under this DPA.
  13. TAXNXT shall remain responsible to the Customer for the performance of each Subprocessor’s data-protection obligations to the extent required by Applicable Data Protection Law.
  14. TAXNXT shall use reasonable measures to verify that Subprocessors provide sufficient guarantees concerning data protection and security.
  15. TAXNXT may use its affiliates as Subprocessors subject to this section.
  16. Emergency appointment of a Subprocessor without advance notice is permitted where reasonably necessary to address:
    1. a critical security incident;
    2. service continuity;
    3. legal compliance; or
    4. an urgent technical failure.
  17. In such a case, TAXNXT shall notify the Customer as soon as reasonably practicable.

§14. International transfers

  1. TAXNXT shall not make a Restricted Transfer unless it complies with Applicable Data Protection Law.
  2. An international transfer may be based on:
    1. an adequacy decision;
    2. Standard Contractual Clauses;
    3. Binding Corporate Rules;
    4. an approved certification or code of conduct;
    5. a legally permitted derogation; or
    6. another lawful transfer mechanism.
  3. Where TAXNXT appoints a Subprocessor outside the EEA or in a country without an applicable adequacy decision, TAXNXT shall ensure that an appropriate transfer mechanism is in place.
  4. Where Standard Contractual Clauses are used, TAXNXT shall:
    1. select the appropriate module;
    2. complete the relevant annexes;
    3. conduct or obtain an appropriate transfer assessment where required;
    4. implement supplementary safeguards where reasonably necessary; and
    5. take reasonable steps to monitor relevant changes.
  5. Where a Restricted Transfer occurs directly between the Customer and TAXNXT and no other lawful transfer mechanism applies, the parties shall enter into the applicable Standard Contractual Clauses.
  6. Where applicable, the following selections shall apply unless otherwise agreed:
    1. the docking clause may be used;
    2. general authorization for Subprocessors shall apply;
    3. the competent Supervisory Authority shall be determined according to the Standard Contractual Clauses and Applicable Data Protection Law;
    4. the governing law shall be the law of Poland where legally permitted; and
    5. disputes shall be submitted to the courts of Poland where legally permitted.
  7. TAXNXT shall provide reasonable information concerning applicable transfer mechanisms upon request.
  8. TAXNXT shall not be required to disclose information where disclosure would:
    1. compromise security;
    2. breach confidentiality owed to another party;
    3. disclose trade secrets beyond what is reasonably necessary; or
    4. violate applicable law.

§15. Government and authority requests

  1. Where TAXNXT receives a legally binding request from a court, public authority, law-enforcement body, regulatory authority, or other government body for Personal Data processed on behalf of the Customer, TAXNXT shall, where legally permitted:
    1. review the legal validity and scope of the request;
    2. notify the Customer before disclosure;
    3. challenge requests that are manifestly unlawful or disproportionate where reasonable grounds exist;
    4. disclose only the minimum Personal Data legally required; and
    5. document the request and response.
  2. Where TAXNXT is prohibited from notifying the Customer, TAXNXT shall use reasonable efforts to seek permission to provide notice where appropriate.
  3. TAXNXT may provide general transparency information regarding government requests where legally permitted.
  4. This section does not require TAXNXT to pursue legal proceedings where doing so would be unreasonable, unlawful, or disproportionate.

§16. Records and compliance information

  1. TAXNXT shall maintain records of Processing activities required of a Processor under Applicable Data Protection Law.
  2. The records may include:
    1. categories of Processing;
    2. categories of Customers;
    3. Subprocessors;
    4. international transfers;
    5. transfer safeguards; and
    6. general descriptions of security measures.
  3. TAXNXT shall make relevant records available to a competent Supervisory Authority where legally required.
  4. Upon reasonable request, TAXNXT shall provide the Customer with information necessary to demonstrate compliance with this DPA.
  5. TAXNXT may satisfy information requests by providing:
    1. this DPA;
    2. the Privacy Policy;
    3. security documentation;
    4. Subprocessor information;
    5. audit summaries;
    6. certifications;
    7. penetration-test summaries;
    8. compliance reports; or
    9. written responses.
  6. Information provided may be subject to confidentiality restrictions.

§17. Audits and inspections

  1. The Customer may audit TAXNXT’s compliance with this DPA where reasonably necessary.
  2. Before requesting an on-site inspection, the Customer shall first review documentation made available by TAXNXT.
  3. An audit shall:
    1. relate specifically to Processing under this DPA;
    2. be conducted no more than once in any 12-month period;
    3. be requested with at least 30 days’ written notice;
    4. occur during normal business hours;
    5. avoid unreasonable disruption;
    6. comply with TAXNXT’s security and confidentiality requirements;
    7. protect information concerning other customers; and
    8. be performed by qualified personnel subject to confidentiality obligations.
  4. The annual limit and notice period do not apply where:
    1. a Personal Data Breach materially affecting the Customer has occurred;
    2. a Supervisory Authority requires an audit;
    3. there is credible evidence of material non-compliance; or
    4. mandatory law requires otherwise.
  5. TAXNXT may require that an independent auditor:
    1. is not a direct competitor of TAXNXT;
    2. signs an appropriate confidentiality agreement;
    3. provides evidence of appropriate qualifications; and
    4. follows reasonable site and information-security rules.
  6. TAXNXT may restrict access to:
    1. Personal Data belonging to other customers;
    2. TAXNXT employee data unrelated to the audit;
    3. source code;
    4. live credentials;
    5. information whose disclosure would create a security risk;
    6. privileged legal advice; and
    7. trade secrets not necessary to establish compliance.
  7. TAXNXT may provide redacted, summarized, or independently verified information where direct disclosure would create a material risk.
  8. Each party shall bear its own audit costs.
  9. The Customer shall reimburse reasonable costs of an audit where:
    1. the audit exceeds one audit per year without a qualifying reason;
    2. substantial custom work is required;
    3. the audit is unnecessarily duplicative; or
    4. no material non-compliance attributable to TAXNXT is found.
  10. TAXNXT shall bear reasonable audit costs where an audit identifies material non-compliance attributable to TAXNXT.
  11. TAXNXT shall promptly address confirmed material deficiencies within a reasonable remediation period.

§18. Return and deletion of Personal Data

  1. During the term of the Main Agreement, the Customer may export Personal Data using available export functions.
  2. Upon termination or expiry of the Main Agreement, the Customer may choose, where technically available, to:
    1. export Personal Data;
    2. request return of Personal Data;
    3. request transfer to another provider; or
    4. request deletion.
  3. The Customer must submit any special return or deletion instructions before the end of the applicable retrieval period.
  4. Unless otherwise stated in the Main Agreement, TAXNXT shall provide a retrieval period of at least 30 calendar days after termination.
  5. After the retrieval period, TAXNXT may delete Personal Data unless retention is required or permitted by law.
  6. TAXNXT may retain Personal Data where necessary for:
    1. tax or accounting obligations;
    2. legal recordkeeping;
    3. the establishment, exercise, or defence of legal claims;
    4. fraud prevention;
    5. compliance with a binding legal request; or
    6. other legal obligations.
  7. Personal Data retained under paragraph 6 shall:
    1. remain protected under this DPA;
    2. be isolated from ordinary commercial Processing where appropriate;
    3. be processed only for the applicable retention purpose; and
    4. be deleted when the retention purpose ends.
  8. Personal Data stored in backups may remain until overwritten or deleted through the ordinary backup cycle.
  9. During that period, backup data shall remain subject to appropriate security measures and shall not be restored except where necessary for:
    1. disaster recovery;
    2. security investigation;
    3. legal compliance; or
    4. continuity of the Services.
  10. TAXNXT may retain information that has been irreversibly anonymized.
  11. Upon reasonable request, TAXNXT shall confirm completion of deletion, subject to the exceptions described above.

§19. Controller obligations

  1. The Customer represents and warrants that:
    1. it is entitled to provide Personal Data to TAXNXT;
    2. it has provided all required information to Data Subjects;
    3. it has an appropriate legal basis for Processing;
    4. its instructions are lawful;
    5. its use of Bilantio does not infringe third-party rights;
    6. it has obtained any authorization required to appoint TAXNXT;
    7. it has established appropriate retention periods; and
    8. it will not instruct TAXNXT to perform unlawful Processing.
  2. The Customer is responsible for:
    1. the accuracy and quality of Personal Data;
    2. the lawfulness of collection;
    3. the categories of Personal Data uploaded;
    4. configuring permissions;
    5. managing Users;
    6. protecting credentials;
    7. reviewing integrations;
    8. responding to Data Subjects;
    9. notifying Supervisory Authorities where required; and
    10. determining whether special safeguards are necessary.
  3. The Customer shall avoid uploading Personal Data that is unnecessary for the selected purpose.
  4. The Customer shall not upload Special Categories of Personal Data unless:
    1. Processing is necessary for an authorized Bilantio function;
    2. the Customer has a valid legal basis under Applicable Data Protection Law;
    3. appropriate safeguards have been implemented; and
    4. the Customer has assessed the related risks.
  5. The Customer shall not upload Personal Data concerning criminal convictions or offences unless Processing is lawful and specifically authorized.
  6. The Customer shall not use Bilantio as the sole repository for records where independent retention or backup is required by law or the Customer’s professional obligations.

§20. Liability

  1. Each party is responsible for its own compliance with Applicable Data Protection Law.
  2. Liability between the parties arising from this DPA is subject to the exclusions and limitations in the Main Agreement, except where:
    1. Applicable Data Protection Law requires otherwise;
    2. the limitation would unlawfully restrict the rights of Data Subjects;
    3. the liability results from intentional misconduct; or
    4. liability cannot legally be limited.
  3. Nothing in this DPA limits a Data Subject’s rights under Applicable Data Protection Law.
  4. Where a party pays compensation or an administrative fine attributable partly or entirely to the other party’s breach, the parties’ rights of recourse shall be determined according to:
    1. their respective responsibility;
    2. the Main Agreement;
    3. Applicable Data Protection Law; and
    4. the decision of the competent court or Supervisory Authority.
  5. The Customer shall remain responsible for damage caused by:
    1. unlawful instructions;
    2. lack of a legal basis;
    3. failure to provide required privacy information;
    4. unauthorized uploading of Personal Data;
    5. inadequate management of Users or credentials;
    6. failure to respond to Data Subjects; or
    7. misuse of the Services.
  6. TAXNXT shall remain responsible for damage caused by Processing that breaches obligations specifically applicable to Processors or that falls outside lawful Customer instructions.

§21. Duration and termination

  1. This DPA takes effect when:
    1. the Customer accepts the Main Agreement;
    2. the Customer accepts this DPA electronically;
    3. the Customer signs an Order incorporating this DPA; or
    4. TAXNXT begins processing Personal Data on behalf of the Customer.
  2. This DPA remains in force for as long as TAXNXT processes Personal Data on behalf of the Customer.
  3. Termination of the Main Agreement automatically terminates this DPA, subject to:
    1. retrieval periods;
    2. deletion obligations;
    3. lawful retention;
    4. audit obligations concerning prior Processing;
    5. confidentiality; and
    6. provisions intended to survive termination.
  4. Either party may terminate this DPA where continued Processing would violate Applicable Data Protection Law.
  5. Where only a particular Processing activity is unlawful, the parties shall first attempt to suspend or modify that activity without terminating the entire Main Agreement.

§22. Changes to this DPA

  1. TAXNXT may update this DPA where necessary to:
    1. reflect changes in law;
    2. comply with a Supervisory Authority’s requirements;
    3. update security or operational arrangements;
    4. reflect changes in the Services;
    5. update Subprocessor procedures;
    6. adopt new approved contractual clauses; or
    7. improve data-protection safeguards.
  2. TAXNXT shall provide reasonable notice of material changes.
  3. Changes required by law, a binding authority decision, or an urgent security concern may take effect immediately.
  4. An update shall not materially reduce the protection of Personal Data without a valid legal or operational reason and appropriate safeguards.
  5. If the Customer reasonably believes that a material change causes the Customer to breach Applicable Data Protection Law, the Customer may notify TAXNXT before the change becomes effective.
  6. The parties shall attempt to resolve the concern in good faith.
  7. Where no reasonable solution is available, the Customer may terminate the affected Services.

§23. Governing law and disputes

  1. This DPA is governed by Polish law, without prejudice to mandatory Applicable Data Protection Law.
  2. The parties shall first attempt to resolve disputes through good-faith negotiations.
  3. Unless mandatory law or applicable Standard Contractual Clauses provide otherwise, disputes shall be submitted to the courts having jurisdiction over TAXNXT’s registered office.
  4. Nothing in this section limits:
    1. the powers of a competent Supervisory Authority;
    2. the rights of Data Subjects;
    3. rights under applicable Standard Contractual Clauses; or
    4. mandatory rights under Applicable Data Protection Law.

§24. Miscellaneous provisions

  1. This DPA constitutes the parties’ data-processing agreement for Processing covered by it.
  2. Amendments must be made in writing or through an electronic process that records acceptance.
  3. Electronic acceptance has the same effect as a handwritten signature to the extent permitted by law.
  4. If a provision is invalid or unenforceable, the remaining provisions remain effective.
  5. The invalid provision shall be interpreted or replaced to reflect its lawful purpose as closely as possible.
  6. Failure to enforce a provision does not constitute a waiver.
  7. Headings are included for convenience and do not affect interpretation.
  8. The words “including” and “for example” do not limit the preceding language.
  9. This DPA may be executed in counterparts or accepted electronically.
  10. Different language versions may be published.
  11. The version expressly identified as governing in the Main Agreement shall prevail in case of inconsistency.
  12. Where no version is expressly designated, the English version shall prevail, subject to mandatory Polish law.

§25. Contact

Data-protection questions and requests concerning this DPA may be sent to:

TAXNXT sp. z o.o.ul. Toruńska 15/7780-747 GdańskNIP: 6783218496REGON: 529197763KRS: 0001117478PolandEmail: support@taxnxt.eu

The Customer should provide and maintain current contact information for its:

  • Account Administrator;
  • data-protection contact;
  • security contact; and
  • legal-notice contact.

Annex I — Details of processing

1. Subject matter

Processing of Personal Data necessary to provide, operate, secure, support, maintain, and improve Bilantio as instructed by the Customer.

2. Nature of Processing

Processing may include:

  • collection;
  • receipt;
  • recording;
  • organization;
  • structuring;
  • storage;
  • hosting;
  • uploading and downloading;
  • retrieval;
  • consultation;
  • access;
  • extraction;
  • optical character recognition;
  • classification;
  • tagging;
  • comparison;
  • calculation;
  • analysis;
  • summarization;
  • generation of draft content;
  • transmission;
  • disclosure to authorized recipients;
  • integration with third-party systems;
  • restriction;
  • export;
  • backup;
  • restoration;
  • correction;
  • anonymization;
  • pseudonymization where applicable;
  • deletion; and
  • destruction.

3. Purposes of Processing

Processing may be performed to:

  • create and manage invoices;
  • prepare invoice drafts;
  • send or receive structured invoices;
  • support KSeF workflows;
  • store accounting documents;
  • extract information from documents;
  • classify invoices and receipts;
  • organize accounting records;
  • prepare summaries and reports;
  • support bookkeeping workflows;
  • support VAT and tax-related workflows;
  • support payroll and HR administration;
  • provide AI-assisted functions;
  • respond to Customer prompts;
  • manage integrations;
  • provide support;
  • maintain security and audit logs;
  • prevent misuse;
  • perform backups;
  • restore service availability;
  • facilitate data export and switching; and
  • fulfil other documented Customer instructions within the scope of the Services.

4. Duration

For the duration of the Main Agreement, including any applicable transition, retrieval, backup, legal-retention, or deletion period.

5. Processing frequency

Continuous or recurring, depending on the Customer’s use of Bilantio.

6. Processing locations

Processing locations shall be identified in Bilantio’s current Subprocessor register and infrastructure documentation.

TAXNXT intends to configure its principal database and storage infrastructure in European regions where available and appropriate.

Annex II — Categories of Personal Data and Data Subjects

1. Categories of Data Subjects

Depending on the Customer’s use of Bilantio, Data Subjects may include:

  • Customer employees;
  • Customer Users and Administrators;
  • directors and management-board members;
  • shareholders;
  • beneficial owners;
  • authorized representatives;
  • commercial proxies;
  • contractors;
  • consultants;
  • job applicants;
  • former employees;
  • payroll recipients;
  • customers and prospective customers;
  • individual entrepreneurs;
  • suppliers;
  • service providers;
  • subcontractors;
  • business partners;
  • invoice contacts;
  • payment recipients;
  • debtors and creditors;
  • bank account holders;
  • accounting-office clients;
  • employees and representatives of accounting-office clients;
  • persons named in invoices, receipts, contracts, payroll documents, accounting records, or uploaded files; and
  • other individuals whose Personal Data is submitted by the Customer.

2. Account and identification data

This may include:

  • name and surname;
  • business email address;
  • telephone number;
  • username;
  • login identifier;
  • authentication information;
  • company name;
  • role;
  • job title;
  • User permissions;
  • language preference; and
  • Account settings.

3. Business and company information

This may include:

  • business names;
  • business addresses;
  • correspondence addresses;
  • NIP and VAT numbers;
  • REGON;
  • KRS information;
  • other registration identifiers;
  • business contact details;
  • board-member information;
  • shareholder information;
  • beneficial-owner information;
  • representative information;
  • power-of-attorney information; and
  • organizational relationships.

4. Invoice and accounting data

This may include:

  • invoice numbers;
  • invoice dates;
  • sale or supply dates;
  • buyer and seller information;
  • addresses;
  • NIP and VAT numbers;
  • descriptions of goods and services;
  • quantities and units;
  • net amounts;
  • VAT rates and amounts;
  • gross amounts;
  • currencies;
  • payment terms;
  • payment status;
  • bank account information;
  • transaction references;
  • accounting classifications;
  • cost centers;
  • accounting notes;
  • receipts;
  • supporting documents;
  • bookkeeping records;
  • accounting registers;
  • reports; and
  • financial summaries.

5. KSeF and tax-related data

This may include:

  • structured invoice data;
  • invoice XML files;
  • KSeF identifiers;
  • official submission statuses;
  • official confirmations;
  • tax classifications;
  • VAT information;
  • tax-reporting information;
  • accounting registers; and
  • data required for communication with invoicing or tax systems.

6. Payroll and HR data

This may include:

  • employee names;
  • employee identifiers;
  • contact details;
  • employment information;
  • contract information;
  • salary information;
  • payroll calculations;
  • bonuses and deductions;
  • tax information;
  • social-security information;
  • bank account details;
  • working-time information;
  • leave and absence information;
  • benefits information;
  • organizational role;
  • employment dates; and
  • other information uploaded for payroll or HR administration.

7. AI prompt and Output data

This may include:

  • prompts;
  • User instructions;
  • documents included in prompts;
  • business questions;
  • generated responses;
  • invoice drafts;
  • document drafts;
  • accounting summaries;
  • classifications;
  • extracted information; and
  • technical logs associated with AI processing.

8. Technical and security data

This may include:

  • IP addresses;
  • device information;
  • browser information;
  • operating-system information;
  • session identifiers;
  • login timestamps;
  • access logs;
  • audit logs;
  • API logs;
  • error logs;
  • security events;
  • system activity; and
  • integration identifiers.

9. Special Categories of Personal Data

Bilantio is not designed primarily for processing Special Categories of Personal Data.

However, depending on the Customer’s use of payroll, HR, or document functions, uploaded documents may contain:

  • health information;
  • medical-leave information;
  • disability-related information;
  • trade-union information;
  • biometric information included in identity documents; or
  • other sensitive information.

The Customer must ensure that any such Processing is necessary, lawful, and subject to appropriate safeguards.

10. Criminal-conviction and offence data

Bilantio is not designed primarily for Processing Personal Data concerning criminal convictions or offences.

The Customer must not submit such information unless Processing is lawful, necessary, and properly authorized.

Annex III — Technical and organizational measures

TAXNXT shall maintain technical and organizational measures appropriate to the risks associated with the Services.

The measures may be adapted as technology and risks change, provided the overall level of protection is not materially reduced.

1. Information-security governance

Measures include, as appropriate:

  • defined responsibility for information security;
  • internal security and confidentiality rules;
  • risk-based security reviews;
  • access-control procedures;
  • incident-response procedures;
  • vendor and Subprocessor review;
  • secure-development practices;
  • business-continuity planning; and
  • periodic review of security measures.

2. Access control

Measures include:

  • individual User accounts;
  • role-based permissions;
  • least-privilege access;
  • restriction of production-system access;
  • periodic access reviews;
  • prompt removal of unnecessary access;
  • separation of administrative permissions;
  • authentication controls; and
  • logging of relevant administrative activity.

3. Authentication

Measures include:

  • password-protection requirements;
  • secure authentication mechanisms;
  • session controls;
  • protection against unauthorized login attempts;
  • secure credential handling;
  • optional or required multi-factor authentication where implemented; and
  • procedures for revoking compromised credentials.

4. Encryption and transmission security

Measures include:

  • encryption of Personal Data in transit using appropriate transport-security protocols;
  • secure API communication;
  • secure authentication tokens;
  • restrictions on insecure transmission methods; and
  • encryption at rest where supported and appropriate for the relevant infrastructure.

5. Data storage and segregation

Measures include:

  • logical segregation of customer environments or data;
  • access controls at application and database levels;
  • controlled storage permissions;
  • restriction of direct database access;
  • separation of production and development environments where appropriate; and
  • procedures designed to prevent unauthorized cross-customer access.

6. Logging and monitoring

Measures include:

  • access logs;
  • authentication logs;
  • audit logs;
  • error logging;
  • security-event monitoring;
  • monitoring of relevant system activity;
  • investigation of suspicious events; and
  • protection of logs against unauthorized alteration where appropriate.

7. Availability and resilience

Measures include:

  • backups;
  • recovery procedures;
  • system monitoring;
  • redundancy where appropriate;
  • incident-management procedures;
  • restoration testing where appropriate;
  • capacity monitoring; and
  • measures designed to support continued availability.

8. Secure software development

Measures include:

  • controlled development processes;
  • source-code access restrictions;
  • code review where appropriate;
  • dependency management;
  • testing before material releases;
  • vulnerability remediation;
  • separation of development and production access where appropriate;
  • change-management procedures; and
  • secure handling of secrets and credentials.

9. Vulnerability management

Measures include:

  • security updates;
  • dependency monitoring;
  • vulnerability assessment;
  • remediation according to risk;
  • restricted access to vulnerability information;
  • review of security reports; and
  • penetration testing or equivalent technical testing where appropriate.

10. Incident response

Measures include:

  • security-incident reporting channels;
  • incident identification and triage;
  • containment;
  • investigation;
  • remediation;
  • recovery;
  • breach-notification procedures;
  • documentation; and
  • post-incident review.

11. Personnel security

Measures include:

  • confidentiality obligations;
  • access granted according to duties;
  • privacy and security guidance;
  • access revocation following role changes or departure;
  • disciplinary measures for unauthorized access; and
  • background screening where lawful, appropriate, and proportionate.

12. Subprocessor management

Measures include:

  • privacy and security review;
  • written data-processing terms;
  • confidentiality obligations;
  • assessment of Processing locations;
  • assessment of international transfer mechanisms;
  • monitoring of material changes;
  • maintenance of a Subprocessor register; and
  • procedures for replacing or terminating Subprocessors.

13. Data minimization and purpose limitation

Measures include:

  • limiting Processing to Services selected by the Customer;
  • restricting internal access;
  • limiting information collected through support requests;
  • use of anonymized or aggregated information where appropriate;
  • deletion or de-identification when information is no longer required; and
  • configuration options allowing Customers to control submitted data.

14. Deletion and disposal

Measures include:

  • Account-deletion procedures;
  • data-retention controls;
  • deletion after applicable retrieval periods;
  • secure deletion or overwriting where appropriate;
  • backup expiration procedures;
  • restriction of retained information; and
  • secure disposal of storage media where applicable.

15. Customer-controlled measures

Bilantio provides or may provide measures enabling Customers to:

  • manage Users;
  • assign permissions;
  • remove User access;
  • export data;
  • correct information;
  • delete information where functionality permits;
  • review logs or activity information where included in the applicable Plan;
  • control integrations; and
  • protect their Accounts through authentication settings.

Annex V — International transfer arrangements

1. EEA Processing

Where Personal Data is processed only within the EEA and no third-country access occurs, no Restricted Transfer mechanism is required.

2. Adequacy decisions

Where Personal Data is transferred to a country covered by a valid adequacy decision, the transfer may rely on that decision.

3. Standard Contractual Clauses

Where no adequacy decision applies, TAXNXT may use the Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 or their lawful replacement.

4. Subprocessor transfers

Where an approved Subprocessor receives Personal Data outside the EEA, TAXNXT shall ensure that:

  • a lawful transfer mechanism applies;
  • the relevant transfer documentation is completed;
  • the Subprocessor is contractually bound to appropriate data-protection obligations;
  • the transfer is described in the Subprocessor register; and
  • supplementary safeguards are implemented where reasonably required.

5. Transfer assessments

Where required, TAXNXT shall assess:

  • the nature of the Personal Data;
  • the purpose of the transfer;
  • the recipient;
  • the destination country;
  • relevant local laws and practices;
  • the likelihood of public-authority access;
  • contractual safeguards;
  • technical safeguards; and
  • organizational safeguards.

6. Supplementary safeguards

Supplementary safeguards may include:

  • encryption;
  • access restrictions;
  • data minimization;
  • pseudonymization;
  • contractual commitments;
  • transparency obligations;
  • procedures for government requests;
  • restrictions on onward transfers; and
  • enhanced audit or monitoring rights.

7. Conflicting law

If TAXNXT or a Subprocessor can no longer comply with an applicable transfer mechanism, TAXNXT shall:

  • notify the Customer where legally permitted;
  • suspend the affected transfer where required;
  • implement an alternative lawful safeguard where possible; or
  • terminate the affected Processing where no lawful solution is available.