Annex I — Treatment Order — FactuSimple
Developed and operated by RMTracker S.L.
This document is the Annex I to the Terms of Use of FactuSimple and forms an inseparable part of them. It regulates the processing of personal data that RMTracker is carried out by the account holder (self-employed, company or consultancy), with regard to the data of third parties entered into the application, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
1. Who is who
Data controller: the account holder (self-employed, company or consultancy), with regard to the data of third parties entered into the application. Decides for what and how the data is processed, and responds to those affected and to the supervisory authority.
Data processor:
- Data processor: RMTracker S.L. («RMTracker»)
- Tax identification number: B88803085
- Address: Avenida de Andalucía n.º 36, Local 2, 29793 Torrox, Málaga (Spain)
- Email for data protection matters:
legal@rmtrackersolutions.com
RMTracker processes the data only to provide the service. It does not use them for own purposes, it does not pass them on to third parties unless legally required, it does not sell them and it does not use them to train artificial intelligence systems.
2. Object, nature and purpose
RMTracker makes available to the controller an application to capture, organize, issue and deliver tax and labor documentation. In the course of this service, RMTracker hosts and processes the personal data of third parties that the controller enters: those of its commercial customers, which are in the invoices it issues, and those of its employees, if it uses the employment section. The processing consists of hosting, storing, organizing, making available and deleting this data, and has no other purpose.
3. Duration
This annex comes into effect when accepted and lasts as long as the service contract is in force. When it ends, section 9 applies.
4. Categories of data
| Category | What it includes |
|---|---|
| Identification of customers | Name or company name, NIF, address and contact details that the controller specifies on its invoices. |
| Economic data | Invoices issued and received with their breakdown of VAT and income tax, amounts, due dates and payment status. |
| Captured documents | Photographs and files of invoices and receipts that the controller uploads, stored in a private container accessible only from its own account. |
| Bank statements | N43, CSV or XLSX files that the controller sends for their advisor to reconcile the movements. |
| Personal data of third parties | Hires and dismissals of employees and payroll, when the controller uses the employment section. These are personal data of its employees, not its own. |
5. Categories of interested parties
- Customers of the controller, natural persons or representatives of legal entities, who appear on the invoices issued.
- Suppliers of the controller that appear on the received invoices.
- Employees of the controller, when using the employment section.
6. Obligations of RMTracker as the data processor
In accordance with Article 28.3 of the GDPR, RMTracker it is required to:
- Process the data only according to documented instructions from the controller, including those relating to international transfers. The normal use of the service constitutes such instruction. If RMTracker you believe that an instruction infringes the data protection legislation, you will inform this immediately.
- Ensure the confidentiality of those who access the data, through explicit agreement or legal obligation, which continues after the end of the relationship.
- Implement the measures of Article 32, described in paragraph 7.
- Do not resort to another processor without authorization. The controller authorizes the sub-processors listed in paragraph 8. Any appointment or replacement will be communicated with thirty days' in advance and the controller may object; if he objects and the change is necessary to provide the service, he may terminate the contract without penalty.
- Assist the controller to enable him to exercise the rights of access, rectification, erasure, limitation, portability and opposition. If a data subject directly contacts RMTracker, he will be referred to the controller and this will be informed without delay.
- Assist the controller in complying with Articles 32 to 36: security, breach notification and impact assessment.
- Report security breaches without undue delay and, in any case, within forty-eight hours those who need to be informed about them, with the information provided in article 33.3. Forty-eight and not seventy-two because the responsible party needs a margin to meet their own deadline.
- Delete or restore the data upon completion, according to section 9.
- Make available the responsible person must provide the necessary information to demonstrate compliance with this annex, and allow and contribute to audits, as specified in section 10.
7. Safety measures
The measures are described by what the system does, not by what is typically said in a contract. They are verifiable:
- Row-level security isolation in the database: each account only has access to its own rows, and the separation is enforced by the engine, not by the application code.
- The captured documents are stored in a container. privateunder the folder of the user themselves and with the same level of isolation. There is no public URL.
- Encryption in transit for all communications and encryption at rest for storage.
- Passwords are never stored in plain text; they are managed by the authentication service.
- The text recognition of photographed documents is executed on the device itselfThe image is not sent to any third party for analysis.
- Audit log of operations on tax data, which cannot be modified or deleted.
- A bill already registered with the Tax Agency cannot be altered or deleted: this is due to a trigger in the database, not a check in the interface.
- No analytics or advertising tools are available in the application: no third parties are receiving usage data.
The measures can evolve. RMTracker It will not degrade them: any change will maintain an equivalent or superior level of protection.
8. Authorized Sub-managers
| Sub-manager | For what purpose | Where |
|---|---|---|
| Supabase | Hosting, database, document storage and authentication. | European Union, region eu-north-1. |
With each sub-manager RMTracker maintains a contract that imposes the same obligations as this annex, and is liable to the responsible for their actions as well as the own.
9. End of assignment
Contract ended, RMTracker will delete the personal data processed on behalf of the responsible party, or will return them return in a common format and machine-readable if requested before deletion, and will delete existing copies.
With an exception that is not of RMTracker: the tax documentation is subject to legal retention periods that fall on the taxpayer. While those periods are in effect, invoices and associated labor documentation are retained even if the contract has ended, and its premature deletion cannot be requested from RMTracker because the obligation does not belong to them.
10. Audit
The responsible party may request, once a year and with fifteen days' notice, the information necessary to prove compliance with this annex. It can also carry out an audit, either itself or through an independent third party that is not a competitor of RMTracker, subject to prior agreement on date, scope and confidentiality, and without interrupting service.
Additional audits arising from a security breach, a requirement from the regulatory authority or proven non-compliance are not subject to this annual limit.
11. Confidentiality Commitment
This section replaces a separate confidentiality agreement, so that no separate document needs to be signed.
Both parties agree to keep the other party's confidential information secret to which they have access in connection with this relationship, to use it only for its execution and not to disclose it to third parties without written authorization. Technical, commercial, financial and organizational information that is not publicly available is considered confidential, in particular personal data processed under this annex.
The following information is not confidential:
- that was already public before being received, or becomes so without breaching this commitment;
- that legitimately existed in the possession of the receiving party without a duty of confidentiality;
- that has been developed independently without using the other party's information; or
- that must be disclosed by legal obligation or by a competent authority, in which case prior notice will be given to the other party if it is legally permissible.
This commitment remains in effect for three years after the relationship ends. For personal data there is no deadline: the confidentiality obligation of Article 28.3.b of the GDPR does not expire.
12. Liability
Each party is liable for damages caused by failing to comply with the obligations imposed on them by this annex and the GDPR, in accordance with Article 82 of the Regulation. RMTracker does not comply with the instructions of the responsible party nor with the legality of the treatments that it decides.
13. Acceptance without signature
This annex is accepted electronically when creating the account, in the form that allows the article 28.9 of the GDPR, and does not require a handwritten signature. Each acceptance will be documented with who performed it, when, and which version of the text was in effect. The responsible party can request a certificate of their acceptances at any time.
If this annex changes, prior notice will be given and a new acceptance will be obtained. The previous ones will remain: they are the history of what was valid at each moment.
14. Applicable law
This annex is governed by the GDPR, Law 3/2018 Organic on Protection of Personal Data and Guarantee of Digital Rights, and Spanish legislation. In cases not provided for here, the Terms of Use of FactuSimple, which it forms part of.
legal@rmtrackersolutions.com.