Data processing
Data processing agreement under Art. 28 GDPR. It is accepted together with the terms and conditions and no signature is needed. Last updated: 20 September 2026.
1. Parties and roles
The processor is Tobias Benkner, Calle Doctor Alfonso Chiscano Diaz 10, 35010 Las Palmas de Gran Canaria, España.
The controller is the customer using HolaKiko. Whoever uploads documents decides on the purposes and means of their processing; we process them exclusively on their behalf.
This agreement therefore applies to companies, the self-employed and tax practices, to everyone using the service professionally. Anyone using it as a consumer for their own records is not a controller within the meaning of the GDPR but a data subject: for them we process on our own responsibility and the privacy policy alone applies. This agreement then has no effect.
If a tax practice uses the service for its clients, the client remains the controller for their own documents. The practice receives read access because and for as long as the client has granted it.
2. Subject matter and duration
The subject matter is the processing of personal data in the course of providing HolaKiko: storing uploaded documents, reading out their details automatically, providing the interface and producing the export packages.
The agreement runs for as long as the account exists and ends with it.
3. Nature, scope and purpose
Processing happens in order to provide the service, not for our own purposes. The data is not used to train AI models, neither by us nor by the sub-processors named in Annex 2.
4. Categories of data and data subjects
Data subjects: the customer themselves and persons appearing in the uploaded documents, typically contacts at the issuing companies.
- Account master data: name, e-mail address
- Contents of the documents: issuer including address, date, amounts, tax rates, document numbers, tax and VAT identification numbers, notes
- The uploaded files themselves (PDF, photo)
- Usage data: time and address of accesses, IP address
Special categories under Art. 9 GDPR are not requested. Anyone uploading a medical invoice nonetheless brings them in and the processing then follows the same instruction as any other document.
5. Bound by instructions
We process the data only on documented instructions: using the service and this agreement are the instruction. If we consider an instruction unlawful, we say so and may suspend carrying it out.
6. Confidentiality
Everyone with access to the data is bound to confidentiality. Access is limited to what is necessary for operating the service.
7. Security of processing
The measures taken are set out in Annex 1.
8. Sub-processors
Those currently engaged are listed in Annex 2. We bind them to the same obligations that bind us here.
We announce any change by e-mail at least four weeks in advance. Anyone who objects may terminate the agreement as of the date the change takes effect; the data can be downloaded in full beforehand.
9. Assistance
We assist with access, rectification, erasure, restriction and portability. For portability we are not needed at all: a button in the settings hands out all the data as a ZIP at any time: original files sorted by month, plus spreadsheets with every captured value.
In the event of a data breach we notify the controller without delay once we become aware of it, so that they can meet their deadline under Art. 33 GDPR.
10. Deletion and return
After processing ends we delete the data. The account can be deleted by the customer at any time: it is marked and locked, removed for good after 30 days and during that time the deletion can be undone and the data package remains available. Anyone who does not want to wait can delete immediately.
Backups remain excluded from this until they expire. They are not edited after the fact and are used for nothing other than recovery in an emergency. That is also the position taken by the supervisory authorities: what matters is that the data is locked until then and that one says so openly.
11. Evidence and audits
We demonstrate compliance on request, primarily through the information in this document and through the evidence provided by our sub-processors. An on-site audit is possible after notice and during normal business hours.
Annex 1: Technical and organisational measures
What is described is what is in place, not what would be customary.
Separation of clients
Every record belongs to exactly one account. The owner is set server-side from the sign-in and never taken from the request; the database access rules let only your own records through. One account can neither read nor change another's data, not even by altering requests.
Access
Signing in is done with a one-time code sent to the address on file and there is no password that could be stolen or reused. Sign-in attempts and registrations are rate-limited per sender address. In the app an additional lock via Face ID or device passcode can be switched on.
Transmission
Exclusively over TLS, with certificates issued by Let's Encrypt. The connection to the AI service is TLS-secured as well.
Integrity
Uploaded files are never altered. Corrections only ever touch the values beside them; converted versions sit next to the original, not in its place. A SHA-256 checksum is formed over every file, which detects duplicates and evidences integrity.
Availability
Daily backups and a second, monthly series that outlasts the months. A watchdog reports when a backup fails to appear. What is reported is the absence, not the success, because nobody reads a daily success message after a week.
Logging
Accesses and errors are logged and deleted after 30 days. Errors in operation report themselves to the operator immediately, so that faults do not only surface the next time somebody looks.
Resilience
The service limits its own costs and its requests to the AI service, so that an overload neither loses data nor incurs costs unnoticed.
Annex 2: Sub-processors
Hetzner Online GmbH
Registered office: Gunzenhausen, Germany · Processing: Germany
Servers, storage of the uploaded files and backups
IONOS SE
Registered office: Montabaur, Germany · Processing: Germany (de-txl data centre)
Reading out the documents automatically with an AI model
Scaleway SAS
Registered office: Paris, France · Processing: France (fr-par region)
Sending sign-in codes and notification e-mails
Changes to this list are announced by e-mail at least four weeks in advance.