Data Processing Agreement (DPA)
Last updated: June 27, 2026
1. Subject matter and legal framework
This Data Processing Agreement (the «DPA») governs the processing of personal data that Alastia SLU (the «Processor» or «Tributs») carries out on behalf of the Client (the «Controller») in the context of providing the Tributs service.
It is entered into pursuant to article 31 of Llei 29/2021, of 28 October, the qualified law on personal data protection (LQPD), which requires every processing-on-behalf to be governed by a contract. It forms an integral part of the Terms of service and prevails over them as regards the processing of third-party personal data.
2. Roles of the parties
The Client is the data controller for the third-party personal data (its customers, suppliers, employees and contacts) that it enters or uploads into the service. It determines the purposes and means of processing.
Alastia SLU is the data processor: it processes that data solely to provide the service and on the Controller's documented instructions. (For account and subscription-billing data, by contrast, Alastia is the controller: see the Privacy policy.)
3. Subject matter, duration, nature and purpose
Subject matter: the processing of personal data necessary to provide the Tributs service (accounting, tax, invoicing, banking and payroll management).
Duration: for the term of the subscription, plus the retention period and the return or deletion operations set out in section 11.
Nature and purpose: storage, organisation, consultation, calculation, generation of documents and filings, extraction of invoice data and communication to the listed sub-processors, always to provide the service and never for the Processor's own purposes.
4. Types of data and categories of data subjects
Categories of data subjects: the Controller's customers, suppliers, employees, directors and contacts.
Types of data: identification data (name, NRT/NIF), contact data (address, email, phone), financial and banking data (IBAN, payment means, movements), tax data (invoices, taxable bases, withholdings) and, for payroll, employment and contribution data (salary, CASS affiliation number, IRPF/IRNR withholdings). The service is not designed to process special categories of data; the Controller refrains from entering them.
5. Processor obligations (art. 31.4 LQPD)
a) Instructions: it will process the data solely on the Controller's documented instructions (including those relating to international transfers), unless a legal obligation requires otherwise; in that case it will inform the Controller. If it considers an instruction infringes the law, it will notify the Controller without delay.
b) Confidentiality: it will ensure that persons authorised to process the data have committed to confidentiality.
c) Security: it will apply the appropriate technical and organisational measures required by art. 35 LQPD (see section 7).
d) Sub-processors: it will comply with section 8 before engaging other processors.
e) Assistance — rights: it will assist the Controller, as far as possible and with appropriate technical and organisational measures, in responding to data-subject rights requests (Chapter 3 LQPD).
f) Assistance — compliance: it will help the Controller meet its impact-assessment, security and breach-notification obligations (arts. 32, 35, 36 and 37 LQPD).
g) Deletion or return: at the Controller's choice, it will delete or return the data at the end of the service (section 11).
h) Audit: it will make available the information needed to demonstrate compliance and allow audits (section 12).
6. Confidentiality
The Processor and its staff will keep the data confidential even after the relationship ends. Staff access is limited to what is strictly necessary to provide the service.
7. Security measures
The Processor applies, among others: encryption in transit (TLS 1.3); physical isolation of each client company's data in its own database (multi-site model); access control with two-factor authentication for internal staff; periodic backups with rotating retention; and access logging. Measures are commensurate with the risk and may be updated to maintain an equivalent or higher level of protection.
8. Sub-processors
The Controller generally authorises the Processor to engage sub-processors to provide the service. The current, up-to-date list of sub-processors —with each one's identity, purpose, location and safeguard, and the version date— is published and maintained on that page. Each is bound by a contract imposing the same data-protection obligations (art. 31.5 LQPD), and the Processor remains liable to the Controller for their compliance.
We will inform the Controller of any addition or replacement of sub-processors with at least 30 days' notice, by publishing the updated version on the list and notifying by email. During that period the Controller may object on reasonable data-protection grounds (art. 31.3 LQPD); if the objection is well-founded and there is no reasonable alternative, it may terminate the service without penalty for the unused portion.
9. International transfers
Andorra is recognised by the European Union as providing an adequate level of protection (Commission Decision 2010/625/EU of 19 October 2010, confirmed in the 2024 review). An EU/EEA Controller may therefore entrust processing to Alastia SLU without additional safeguards, as if it were an intra-EU transmission.
Where a sub-processor is outside the EEA (for example, in the United States), the transfer is made under the Standard Contractual Clauses (SCCs) approved by the EU Commission and other appropriate safeguards (arts. 42 to 45 LQPD), as indicated in the list of sub-processors (section 8).
10. Security breaches
If the Processor becomes aware of a security breach affecting data processed on the Controller's behalf, it will notify the Controller without delay (art. 36.2 LQPD), with the practical aim of doing so within 48 hours, providing the information available so the Controller can meet, where applicable, its duty to notify the APDA within 72 hours (art. 36.1) and, where relevant, the data subjects (art. 37).
11. Return or deletion at the end
At the end of the service, and at the Controller's choice, the Processor will return the data in standard format (CSV for structured data, PDF/image for attachments) or delete it, together with existing copies, unless a legal obligation requires retention. The Controller has self-service export tools before account closure.
12. Audit and information
The Processor will make available the information needed to demonstrate compliance with art. 31 LQPD and will allow and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, with reasonable notice and respecting the confidentiality and security of other clients.
13. Liability
Each party is liable for breach of the obligations incumbent on it under the LQPD and this DPA. The limitation of liability in the Terms of service also applies to this agreement, to the extent permitted by law and without affecting data subjects' rights before the supervisory authority.
14. Contact and supervisory authority
Questions about this agreement: hola@tributs.ad. The competent supervisory authority is the Andorran Data Protection Agency (APDA): www.apda.ad.