Data Processing Agreement (DPA)
Updated: 2026-08-10
This agreement governs how Numerio (MB „Blue age lab") processes your company's personal data while you use the Service. You (the Customer) remain the data controller — you decide what data is processed; Numerio acts as the data processor — it processes data only on your instructions and only in order to provide the Service. Below you will find what data is processed, what security measures apply and who our sub-processors are (see the table in section 8). This summary is not legally binding — the binding text is below.
1. Parties and scope
This Data Processing Agreement (the Agreement or DPA) is concluded between:
- the Customer — the company that uses the Numerio Service and that acts under this Agreement as the data controller (GDPR Article 4(7)); and
- MB „Blue age lab", company registration number 306656523, VAT number LT100016571516, registered office at Saulėtekio al. 15-1, LT-10224 Vilnius, Lithuania (hereinafter — Numerio or the Processor), which acts under this Agreement as the data processor (GDPR Article 4(8)).
This Agreement supplements the Terms of Service and applies automatically once the Customer begins using the Service and connects data sources containing personal data.
2. Subject matter, duration, nature and purpose of processing
| Aspect | Description |
|---|---|
| Subject matter | Automated collection, recognition and organisation of the Customer's purchase invoices and related documents |
| Duration | For as long as the Customer uses the Service; after use ends — until the data is deleted under section 10 |
| Nature | Automated document extraction and data capture, storage, matching of bank statement lines, assembly of the accountant package |
| Purpose | To provide the Customer with the invoice collection and control Service as described in the Terms of Service |
3. Categories of data subjects
- the Customer's employees and authorised representatives who use the Service;
- contact persons at the Customer's suppliers, whose data (for example name, email address, job title) may appear on invoices or in related emails;
- other natural persons whose data incidentally appears in the email correspondence examined when checking invoice-related messages.
4. Categories of data processed
| Data category | Description |
|---|---|
| Invoice documents and metadata | Supplier name, invoice number, date, amount, VAT, contact details present on the document itself |
| Email metadata | Sender, subject, date, attachment name — only for messages identified as invoice-related; the whole mailbox content is not processed |
| Bank statement lines | Dates, amounts and payment descriptions from bank statement files uploaded by the Customer, used only for matching against invoices |
| Account data | The Customer's user name, email address, sign-in events |
Numerio does not deliberately process special categories of personal data (GDPR Article 9) and does not ask for them to be provided; if such data incidentally appears in a document's content, it is processed only to the extent unavoidably connected with processing that document, and is in no circumstances analysed separately.
5. Documented instructions
Numerio processes personal data only on the Customer's documented instructions— meaning this Agreement, the Terms of Service and the Customer's actions in the Service interface (for example which sources to connect, which documents to confirm, when to generate the accountant package).
If Numerio considers that an instruction infringes the GDPR or other applicable data-protection law, it will inform the Customer without delay.
6. Confidentiality
Numerio ensures that persons with access to the Customer's personal data (employees, contractors) have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and that they are familiar with the data-protection requirements appropriate to the nature of their work.
7. Security measures
Numerio applies the following technical and organisational security measures:
- encryption in transit (TLS) and at rest;
- encryption of mailbox credentials (OAuth access tokens, Apple passwords) and the ability to revoke them (see section 6 of the Terms of Service for the disconnection mechanics);
- storage of data using managed infrastructure services in the EU region only;
- the principle of least privilege — access to data is granted only to those employees and systems that require it;
- operational logs that do not includedocument content or unnecessary personal data — logs record events only (for example “document processed”), not the content itself;
- regularly tested backup / restore;
- errors and failures logged so that they are noticeable, auditable and retryable — no invoice disappears without a trace down a silent error path.
8. Sub-processors
The Customer gives general authorisation for Numerio to engage the sub-processors listed in this table. Numerio will inform the Customer by email at least 30 days in advance of engaging or changing any sub-processor, giving the Customer the opportunity to raise reasoned objections.
This table is versioned and may change — the current version is always published at numerio.ai/dpa.
| Entity | Purpose | Region | Safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Content delivery (CDN) for the website and the Service interface, DNS and protection against network attacks | Globally distributed edge network; traffic routing may pass through nodes outside the EU under Cloudflare's network architecture | Cloudflare standard contractual clauses (SCCs, where applicable), encrypted connection (TLS) |
| Microsoft (Azure OpenAI, the "numerio-openai-sweden" resource) | Automated extraction of invoice document content and data fields | Sweden (Sweden Central), EU "EUR Data Zone" — inference takes place only within this EU-bounded zone, with no global fallback | Contractual data-processing agreement with Microsoft, response storage disabled, pinned endpoint and model version configuration |
| Google Ireland Limited (Gmail API) | Read access to invoice-related emails when the Customer connects a Gmail account | EU (Ireland) / Google infrastructure under the Google APIs Terms of Service | Google API Services User Data Policy, read-only OAuth scope, access-token encryption and revocability |
| Apple Distribution International Ltd (iCloud Mail) | Read access to invoice-related emails when the Customer connects iCloud Mail through an app-specific password | EU (Ireland) / Apple infrastructure under the Apple terms of service | Pinned, documented Apple sign-in endpoint; password encryption; Apple offers no remote revocation, so on disconnection Numerio immediately deletes the password it holds |
| Plausible Insights OÜ (Plausible Analytics) | Website traffic statistics — no cookies, no personal identification, no cross-site profiling | EU (Estonia; data processed on EU servers) | Data-processing agreement with Plausible; no personal data collected and no cookies used, so no consent banner is required |
| Stripe Technology Europe, Limited (Stripe) | Payment and subscription billing — billing name, email address and payment method only; no invoice content and no mailbox data | EU (Ireland); the Stripe group has a US parent, so limited intra-group transfers to the US can occur | Stripe data-processing terms in the Stripe Services Agreement; standard contractual clauses (SCCs) for any US transfer; card data is handled only by Stripe (PCI DSS Level 1) |
9. Assistance with data subject rights
Taking into account the nature of the processing, Numerio assists the Customer in responding to data subject requests (access, rectification, erasure, restriction, portability or objection to processing), by providing the necessary technical means or information within a reasonable period after the Customer's request.
10. Deletion or return of data after processing ends
Once the Customer deletes their workspace or ceases to use the Service, Numerio deletes the personal data associated with it from the active system; remaining backup records are removed through the ordinary backup cycle. The Customer may request an export of data (for example previously generated accountant packages) before the workspace is deleted.
11. Personal data breach notification
On becoming aware of a personal data breach affecting the Customer's data, Numerio informs the Customer without undue delay, providing the information available about the nature of the breach, its likely consequences and the measures taken or planned, so that the Customer can fulfil its own obligations as controller under GDPR Articles 33–34.
12. Audit rights
The Customer has the right, on prior written agreement (including by email) at a reasonable time and subject to confidentiality and the protection of other customers' data, to obtain from Numerio reasonable information and documentation demonstrating that the security measures set out in this Agreement are applied. Given that Numerio is a small processor at pilot stage, audits are carried out in a proportionate, pre-agreed manner (for example document review or a questionnaire) rather than a mandatory on-site inspection, unless the parties agree otherwise.
13. Relationship to other documents
This Agreement supplements the Terms of Service and the Privacy Policy. In the event of a conflict on data-processing matters, this Agreement prevails.
14. Contact
MB „Blue age lab", Saulėtekio al. 15-1, LT-10224 Vilnius, Lithuania
Tel. +370 5 208 0417 · email hello@numerio.ai