Skip to content
HolaKiko
HolaKiko

Choose language

Data processing

Data processing agreement under Art. 28 GDPR. It is accepted together with the terms and conditions and no signature is needed. Last updated: 20 September 2026.

1. Parties and roles

The processor is Tobias Benkner, Calle Doctor Alfonso Chiscano Diaz 10, 35010 Las Palmas de Gran Canaria, España.

The controller is the customer using HolaKiko. Whoever uploads documents decides on the purposes and means of their processing; we process them exclusively on their behalf.

This agreement therefore applies to companies, the self-employed and tax practices, to everyone using the service professionally. Anyone using it as a consumer for their own records is not a controller within the meaning of the GDPR but a data subject: for them we process on our own responsibility and the privacy policy alone applies. This agreement then has no effect.

If a tax practice uses the service for its clients, the client remains the controller for their own documents. The practice receives read access because and for as long as the client has granted it.

2. Subject matter and duration

The subject matter is the processing of personal data in the course of providing HolaKiko: storing uploaded documents, reading out their details automatically, providing the interface and producing the export packages.

The agreement runs for as long as the account exists and ends with it.

3. Nature, scope and purpose

Processing happens in order to provide the service, not for our own purposes. The data is not used to train AI models, neither by us nor by the sub-processors named in Annex 2.

4. Categories of data and data subjects

Data subjects: the customer themselves and persons appearing in the uploaded documents, typically contacts at the issuing companies.

Special categories under Art. 9 GDPR are not requested. Anyone uploading a medical invoice nonetheless brings them in and the processing then follows the same instruction as any other document.

5. Bound by instructions

We process the data only on documented instructions: using the service and this agreement are the instruction. If we consider an instruction unlawful, we say so and may suspend carrying it out.

6. Confidentiality

Everyone with access to the data is bound to confidentiality. Access is limited to what is necessary for operating the service.

7. Security of processing

The measures taken are set out in Annex 1.

8. Sub-processors

Those currently engaged are listed in Annex 2. We bind them to the same obligations that bind us here.

We announce any change by e-mail at least four weeks in advance. Anyone who objects may terminate the agreement as of the date the change takes effect; the data can be downloaded in full beforehand.

9. Assistance

We assist with access, rectification, erasure, restriction and portability. For portability we are not needed at all: a button in the settings hands out all the data as a ZIP at any time: original files sorted by month, plus spreadsheets with every captured value.

In the event of a data breach we notify the controller without delay once we become aware of it, so that they can meet their deadline under Art. 33 GDPR.

10. Deletion and return

After processing ends we delete the data. The account can be deleted by the customer at any time: it is marked and locked, removed for good after 30 days and during that time the deletion can be undone and the data package remains available. Anyone who does not want to wait can delete immediately.

Backups remain excluded from this until they expire. They are not edited after the fact and are used for nothing other than recovery in an emergency. That is also the position taken by the supervisory authorities: what matters is that the data is locked until then and that one says so openly.

11. Evidence and audits

We demonstrate compliance on request, primarily through the information in this document and through the evidence provided by our sub-processors. An on-site audit is possible after notice and during normal business hours.


Annex 1: Technical and organisational measures

What is described is what is in place, not what would be customary.

Separation of clients

Every record belongs to exactly one account. The owner is set server-side from the sign-in and never taken from the request; the database access rules let only your own records through. One account can neither read nor change another's data, not even by altering requests.

Access

Signing in is done with a one-time code sent to the address on file and there is no password that could be stolen or reused. Sign-in attempts and registrations are rate-limited per sender address. In the app an additional lock via Face ID or device passcode can be switched on.

Transmission

Exclusively over TLS, with certificates issued by Let's Encrypt. The connection to the AI service is TLS-secured as well.

Integrity

Uploaded files are never altered. Corrections only ever touch the values beside them; converted versions sit next to the original, not in its place. A SHA-256 checksum is formed over every file, which detects duplicates and evidences integrity.

Availability

Daily backups and a second, monthly series that outlasts the months. A watchdog reports when a backup fails to appear. What is reported is the absence, not the success, because nobody reads a daily success message after a week.

Logging

Accesses and errors are logged and deleted after 30 days. Errors in operation report themselves to the operator immediately, so that faults do not only surface the next time somebody looks.

Resilience

The service limits its own costs and its requests to the AI service, so that an overload neither loses data nor incurs costs unnoticed.

Annex 2: Sub-processors

Hetzner Online GmbH

Registered office: Gunzenhausen, Germany · Processing: Germany

Servers, storage of the uploaded files and backups

IONOS SE

Registered office: Montabaur, Germany · Processing: Germany (de-txl data centre)

Reading out the documents automatically with an AI model

Scaleway SAS

Registered office: Paris, France · Processing: France (fr-par region)

Sending sign-in codes and notification e-mails

Changes to this list are announced by e-mail at least four weeks in advance.

Questions

info@pulpo.cloud