Legal

Data Processing Addendum

Last updated: 16 September 2026

GDPR Article 28 Compliance

This Data Processing Addendum (“DPA”) is an addendum to the Kronoscube Terms of Service and governs the processing of personal data where Kronoscube acts as a data processoron behalf of you, the data controller, in compliance with the EU General Data Protection Regulation (GDPR) and Bulgarian data protection law.

1. Definitions

Controller (You)

The customer organization using Kronoscube who determines the purposes and means of processing personal data (debtor contact information and invoice data).

Processor (Kronoscube)

“Martin Solutions” Ltd, the provider of the Kronoscube service, who processes personal data on behalf of the Controller under documented instructions.

Personal Data

Debtor names, email addresses, phone numbers (if provided), company names, invoice amounts, due dates, and collection event data uploaded by the Controller.

Sub-processor

Third-party service providers engaged by Kronoscube to assist in processing personal data (e.g., Supabase, Resend, Fly.io). See our Sub-processor List.

2. Scope of Processing

2.1 Subject Matter

Processing of debtor contact information and invoice data to deliver automated collection email campaigns via the Kronoscube platform.

2.2 Duration

Processing continues for the duration of the Controller’s active subscription, plus a 30-day retention period for account recovery after cancellation (unless Controller requests immediate deletion).

2.3 Nature and Purpose

  • Storing debtor contact and invoice data in a secure database
  • Sending collection emails on Controller’s behalf via email service providers
  • Tracking email delivery, open, and click events
  • Optionally processing invoice content through AI services (if enabled by Controller)
  • Generating payment links via Stripe Connect (if enabled and onboarded)

2.4 Categories of Data Subjects

Individuals and business contacts of the Controller’s debtors (accounts receivable contacts, billing departments, business owners).

2.5 Categories of Personal Data

  • Identity: Names, email addresses, phone numbers (optional), company names
  • Financial: Invoice amounts, invoice numbers, due dates, payment status
  • Communication: Email open/click events, unsubscribe status

3. Controller Instructions

Kronoscube processes personal data only based on documented instructions from the Controller, as follows:

  1. To provide the Kronoscube Service as described in the Terms of Service
  2. To send collection emails according to Controller-configured collection policies
  3. To comply with legal obligations applicable to Kronoscube as a processor
  4. As otherwise instructed by Controller via the Kronoscube dashboard or API

If Kronoscube believes a Controller instruction violates GDPR or other applicable law, we will promptly inform the Controller and may suspend processing until the instruction is clarified or withdrawn.

4. Confidentiality

Kronoscube ensures that all personnel authorized to process personal data are bound by confidentiality obligations. Access to personal data is restricted to employees and contractors who require access to perform their duties.

5. Technical and Organizational Measures (TOMs)

Kronoscube implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

🔐 Encryption

  • • TLS 1.2+ for data in transit
  • • AES-256 encryption at rest (Supabase)
  • • HTTPS-only connections

👤 Access Control

  • • Multi-factor authentication (MFA)
  • • Row-level security (RLS) policies
  • • Least privilege principle

📊 Monitoring

  • • Error tracking with PII redaction
  • • Audit logs for data access
  • • Security vulnerability scanning

💾 Backup

  • • Daily automated backups (Supabase)
  • • Point-in-time recovery (PITR)
  • • 7-day retention for Pro plan

Kronoscube reviews and updates security measures regularly to address evolving threats and maintain compliance with GDPR Article 32 requirements.

6. Sub-processors

Controller grants general authorization for Kronoscube to engage sub-processors to assist in delivering the Service. Current sub-processors are listed on our Sub-processor page.

6.1 Sub-processor Requirements

Kronoscube ensures that all sub-processors are bound by data protection obligations equivalent to those in this DPA, including:

  • Processing only on documented instructions
  • Maintaining confidentiality
  • Implementing appropriate security measures
  • Assisting with data subject rights and breach notifications

6.2 Notification of Changes

Kronoscube will notify Controller of any intended changes to sub-processors (additions or replacements) by updating the Sub-processor page at least 30 days in advance. Controller may object to a new sub-processor on reasonable data protection grounds within 14 days of notification.

7. Data Subject Rights

Kronoscube assists Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) by:

  • Providing tools in the Kronoscube dashboard to export, modify, or delete debtor data
  • Responding promptly to Controller requests for data deletion or retrieval
  • Notifying Controller if we receive a data subject request directly (directing them to Controller)

Controller is responsible for responding to data subjects within GDPR timelines (1 month, extendable to 3 months for complex requests).

8. Personal Data Breaches

8.1 Notification Obligation

In the event of a personal data breach affecting Controller data, Kronoscube will notify Controller without undue delay and in any case within 72 hoursof becoming aware of the breach (target timeline; not a legal guarantee).

8.2 Breach Information

Notification will include (to the extent known):

  • Nature of the breach (categories and approximate number of affected data subjects/records)
  • Name and contact of Kronoscube’s data protection point of contact
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate harm

8.3 Controller Responsibility

Controller is responsible for assessing whether the breach must be reported to the supervisory authority (CPDP / КПДЗ in Bulgaria) or to affected data subjects under GDPR Articles 33-34.

9. Deletion and Return of Data

Upon termination of the Service or at Controller’s written request, Kronoscube will:

  1. Delete all personal data processed on Controller’s behalf within 30 days
  2. Or provide an export of personal data in CSV or JSON format before deletion (if requested)
  3. Certify deletion upon request (email confirmation from Kronoscube)

Exception: Data may be retained longer if required by applicable law (e.g., Bulgarian tax/accounting retention obligations for billing records).

10. Audit Rights

Controller has the right to audit Kronoscube’s compliance with this DPA, subject to:

  • Notice: Reasonable advance notice (minimum 30 days)
  • Frequency: Once per year, unless a breach or regulatory requirement necessitates more frequent audits
  • Scope: Audits limited to Kronoscube’s data protection practices relevant to Controller data
  • Confidentiality: Controller agrees to maintain confidentiality of audit findings
  • Cost: Controller bears audit costs unless audit reveals material non-compliance

In lieu of on-site audits, Kronoscube may provide SOC 2 reports, penetration test results, or similar third-party attestations upon request.

11. International Transfers

Kronoscube processes personal data primarily in the EU (Supabase eu-central-1, Resend eu-west-1). Where data is transferred to countries without an EU adequacy decision (e.g., US-based sub-processors like Fly.io, Vercel), Kronoscube relies on:

  • Standard Contractual Clauses (SCCs) — EU Commission-approved SCCs incorporated in sub-processor agreements
  • Supplementary Measures — Encryption, access controls, and contractual restrictions to ensure adequate protection

A copy of the SCCs is available upon request. See our Sub-processor List for transfer details.

12. Governing Law

This DPA is governed by the laws of the Republic of Bulgaria and the provisions of the GDPR (Regulation (EU) 2016/679) as applicable.

13. Liability

Each party’s liability under this DPA is subject to the liability caps and limitations set forth in the Terms of Service, except as prohibited by GDPR or applicable law.

Under GDPR Article 82, Kronoscube is liable for damages caused by processing only where we have not complied with GDPR obligations specifically directed to processors, or where we have acted outside or contrary to lawful instructions from Controller.

14. Contact

For DPA-related questions or data protection inquiries, contact Kronoscube at: martin.solutions.ltd@gmail.com

“Martin Solutions” Ltd

UIC/EIK: 208473110

(Not currently registered for VAT in Bulgaria)

36 Matey Preobrazhenski Street
Dryanovo 5370, Gabrovo Region
Bulgaria

Disclaimer: This Data Processing Addendum is a professionally structured GDPR Article 28 template compliant with EU and Bulgarian data protection law. It is not a substitute for legal advice from a licensed lawyer. If you have specific legal questions, please consult a qualified attorney.