Legal

Data Processing Addendum

Last updated: 7 July 2026

This addendum (the “DPA”) governs how we process the personal data of your clients on your behalf when you use UntilPaid. It forms part of the Terms of Service and reflects Article 28 of the GDPR (and the UK GDPR) and the Czech Act No. 110/2019 Coll. If there’s a conflict on data-protection matters, this DPA wins.

In this DPA, “Customer,” “you” is the controller; “Processor,” “we,” “us” is Jonas Vondracek, an individual established in the Czech Republic (as identified in the Terms of Service). “Client Personal Data” means personal data about your clients that we process on your behalf to run your follow-ups. Terms like personal data, processing, controller, processor, sub-processor, and data subject have the meanings given in the GDPR.

1. Roles & scope

You are the controller of the Client Personal Data and we are your processor. You’re responsible for making sure you have a lawful basis to collect that data and to have us process it, and for giving your clients any privacy notice the law requires. We process it only to provide the service, as set out in Annex A.

2. Our instructions

We process Client Personal Data only on your documented instructions — which include your use of the service’s settings (your rules, templates, schedule, and the webhook endpoints you configure), this DPA, and the Terms. We won’t process it for our own purposes. If we believe an instruction breaks data-protection law, we’ll tell you. If the law requires us to process data beyond your instructions, we’ll let you know first, unless the law forbids it.

3. Confidentiality

We make sure the people who process Client Personal Data are bound by confidentiality and only access what they need to do their job.

4. Security

We put in place appropriate technical and organisational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs, and the risk. Those measures are described in Annex B, and we may update them provided protection isn’t reduced.

5. Sub-processors

You give us general authorisation to use sub-processors to help provide the service. The current list is in Annex C. When we engage a sub-processor we impose data-protection obligations on it that are no less protective than those in this DPA, and we remain responsible for its performance.

If we plan to add or replace a sub-processor, we’ll give you reasonable notice (by updating Annex C and/or emailing you). If you have a reasonable, data-protection-based objection, tell us within 30 days and we’ll work with you in good faith — which may mean adjusting the service or, if we can’t resolve it, letting you terminate the affected part.

6. Helping you comply

Taking into account the nature of the processing, we’ll help you:

7. Breach notification

If we become aware of a personal-data breach affecting Client Personal Data, we’ll notify you without undue delay and give you the information you reasonably need to meet your own notification duties. We’ll also take reasonable steps to contain and remedy it.

8. International transfers

Where providing the service involves transferring Client Personal Data outside the EEA or UK, we rely on a valid transfer mechanism — normally the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, which are incorporated into this DPA by reference where they apply.

9. Audits

We’ll make available the information reasonably needed to show we’re meeting this DPA, and allow for audits — including inspections — by you or an auditor you appoint. To keep things practical and protect other customers, audits happen on reasonable notice, no more than once a year (unless a regulator or a breach requires otherwise), during business hours, and subject to confidentiality. Where available, we may satisfy an audit request by providing a recent third-party report.

10. Return & deletion

When you stop using the service, or on your request, we delete Client Personal Data. Disconnecting Stripe from your settings triggers deletion of your data, including the data we processed on your behalf, except where we’re required by law to keep a copy or where it remains briefly in routine backups before they rotate out.

11. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

Annex A — Details of processing

Subject matterAutomated follow-up on the Customer’s overdue Stripe invoices.
DurationFor as long as the Customer uses the service, then deletion per section 10.
Nature & purposeReading invoice and customer data from Stripe; sending reminder emails and SMS; maintaining a suppression list of opt-outs, bounces, and complaints; and, where configured, sending a signed webhook to the Customer’s endpoint to restrict client access.
Categories of data subjectsThe Customer’s clients — the individuals and business contacts named on the invoices being chased.
Types of personal dataNames; email addresses; phone numbers; invoice details (numbers, amounts, due dates, status); and delivery/opt-out records. No special-category data is intended to be processed.
FrequencyContinuous, on an automated schedule set by the Customer, plus a periodic reconciliation with Stripe.

Annex B — Security measures

Annex C — Sub-processors

Sub-processorPurposeLocation
StripeSource of invoice/customer data (via Stripe Connect)Ireland (Stripe Technology Europe) / United States — EU–U.S. Data Privacy Framework & SCCs
Postmark (ActiveCampaign, LLC)Transactional email delivery & bounce handlingUnited States — EU–U.S. Data Privacy Framework & SCCs
Twilio Inc.SMS delivery & opt-out handlingUnited States — EU–U.S. Data Privacy Framework & SCCs
Railway Corp.Application hosting, database, job queueUnited States [or EU — confirm the deploy region in the Railway dashboard] — SCCs
PostHog, Inc.Product analytics & error reporting (identifiers such as email addresses and phone numbers are redacted before transmission)EU Cloud — hosted in Frankfurt, Germany (provider is US-incorporated; SCCs as fallback safeguard)