Duebira.
Duebira · Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") is incorporated into and forms part of the Duebira Terms of Service between Duebira, Inc. ("Duebira", "Processor") and the user of the Duebira platform ("Controller"). It governs Duebira's processing of personal data on the Controller's behalf in accordance with applicable data protection law, including the GDPR where applicable.

Effective date
June 2, 2026
Controller
You (the registered Duebira user)
Processor
Duebira, Inc.
01

Definitions

As used in this DPA:

Personal Data: Any information relating to an identified or identifiable natural person, as defined under applicable data protection law (including GDPR Article 4(1)).
Controller: The natural or legal person who determines the purposes and means of processing Personal Data — in this context, the Duebira user (you).
Processor: The entity that processes Personal Data on behalf of the Controller — in this context, Duebira, Inc.
Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
Data Subject: An identified or identifiable natural person whose Personal Data is processed — in this context, your clients and their contact information.
Sub-processor: A third party engaged by Duebira to process Personal Data in connection with providing the Service.
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data.
Service: The Duebira platform for invoice and proposal generation, as described in the Terms of Service.
02

Scope and Purpose

2.1 Subject Matter

This DPA applies to Personal Data that the Controller uploads, enters, or generates through the Service, including client names, email addresses, phone numbers, company names, and any other contact details entered into the Duebira platform.

2.2 Nature and Purpose of Processing

Duebira processes Personal Data solely to provide the Service — specifically to generate, send, and track invoices and proposals on the Controller's behalf. Duebira does not use Personal Data for its own commercial purposes, advertising, or analytics beyond what is necessary to operate the Service.

2.3 Categories of Data Subjects

The Data Subjects are the Controller's clients and prospective clients whose contact information is entered into the platform.

2.4 Categories of Personal Data

2.5 Duration

Processing continues for the duration of the Controller's active Duebira account, and is terminated as described in Section 12.

03

Processor Obligations

Duebira, as Processor, agrees to:

04

Sub-processors

4.1 Authorised Sub-processors

The Controller authorises Duebira to engage the following sub-processors, each of whom has agreed to data protection obligations consistent with this DPA:

Sub-processorPurposeLocationPrivacy Policy
Supabase, Inc.Database hosting and storageUSA (AWS us-west-2)Privacy Policy ↗
Clerk, Inc.Authentication and user managementUSAPrivacy Policy ↗
Stripe, Inc.Payment processingUSAPrivacy Policy ↗
Resend, Inc.Transactional email deliveryUSAPrivacy Policy ↗
Cloudflare, Inc.Application hosting and CDNGlobal edge infrastructurePrivacy Policy ↗
Anthropic, PBCAI-powered document generation (Claude)USAPrivacy Policy ↗
Sentry, Inc.Error monitoring and performance tracking (may capture stack traces)USAPrivacy Policy ↗
PostHog, Inc.Product analytics and user behaviour trackingUSAPrivacy Policy ↗
Telnyx LLCSMS payment-reminder delivery (processes client phone numbers)USAPrivacy Policy ↗
Voyage AI Innovations, Inc.Embeddings for voice personalization (processes user-submitted writing samples)USAPrivacy Policy ↗
Langfuse GmbHAI prompt/response tracing and evaluationUSAPrivacy Policy ↗
Upstash, Inc.Rate limiting and caching (Redis — request/IP identifiers)USAPrivacy Policy ↗
Better Stack, Inc.Uptime and infrastructure monitoringUSAPrivacy Policy ↗

4.2 Changes to Sub-processors

Duebira will notify the Controller of any intended addition or replacement of sub-processors by updating this DPA and, where feasible, by email notice. The Controller may object to a new sub-processor within 14 days of notification by contacting [email protected].

05

Data Subject Rights

Duebira will assist the Controller in fulfilling its obligations to respond to Data Subject requests (including access, rectification, erasure, restriction, portability, and objection rights) under applicable law. The Controller, as the primary relationship holder with its clients, is responsible for receiving and triaging such requests.

If a Data Subject contacts Duebira directly regarding their rights, Duebira will forward the request to the Controller within 5 business days and will not respond to the Data Subject on the Controller's behalf without the Controller's authorisation.

For requests involving the Controller's own personal data (i.e., data about the Controller as an individual), please use the account deletion flow in Settings or email [email protected].

06

Security Measures

Duebira implements and maintains the following technical and organisational measures to protect Personal Data:

Duebira continuously evaluates and improves its security posture. The specific measures described above reflect the state of the Service as of the effective date and may be updated to reflect improvements.

07

International Transfers

Duebira and its sub-processors operate primarily in the United States. Where Personal Data of EU/EEA residents is transferred to the United States, Duebira relies on one or more of the following transfer mechanisms:

A copy of applicable SCCs or transfer mechanism documentation is available upon request at [email protected].

08

Data Retention and Deletion

8.1 Retention During Service

Duebira retains Personal Data for as long as the Controller's account is active or as necessary to provide the Service.

8.2 Deletion on Request

The Controller may delete individual client records at any time through the Clients section of the dashboard. Deletion removes the record from Duebira's database. Residual copies in backups are purged on the applicable backup rotation cycle (typically 7–30 days depending on the sub-processor).

8.3 Account Deletion

Upon account deletion (via Settings → Danger Zone or by request to [email protected]), Duebira will delete all Personal Data associated with the account within 30 days, except where retention is required by law (e.g., financial records for tax or audit purposes, which may be retained for up to 7 years).

8.4 Return of Data

The Controller may request an export of their data by contacting [email protected] prior to account deletion. Duebira will provide a machine-readable export within 30 days of request.

09

Breach Notification

In the event of a Personal Data breach affecting data processed under this DPA, Duebira will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification will include, to the extent known at the time:

The Controller is responsible for notifying relevant supervisory authorities and Data Subjects as required by applicable law. Duebira will cooperate in providing information needed for such notifications.

Breach notifications will be sent to the email address associated with the Controller's Duebira account.

10

Audit Rights

Duebira will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. This includes:

More extensive audits (e.g., on-site inspections) may be conducted by the Controller or an independent third party, subject to at least 30 days' prior written notice to [email protected], during normal business hours, and at the Controller's expense. Duebira may require the auditor to sign a confidentiality agreement before granting access.

11

Liability

Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Duebira Terms of Service. Where applicable data protection law imposes liability that cannot be limited by contract, such mandatory provisions shall apply.

As between Duebira and the Controller, the Controller is responsible for ensuring it has a valid legal basis for processing the Personal Data of its clients and for providing any required notices to Data Subjects.

12

Term and Termination

This DPA takes effect on the date the Controller accepts the Duebira Terms of Service and remains in force for the duration of the Service relationship.

This DPA automatically terminates when the Terms of Service terminate. Sections 5, 6, 8, 9, 10, and 11 survive termination to the extent necessary to give them effect.

Upon termination, Duebira will delete or return Personal Data as described in Section 8.3, unless applicable law requires otherwise.

13

Governing Law

This DPA is governed by the laws of the State of Delaware, USA, without regard to conflict-of-law principles. Where GDPR applies, the parties acknowledge that the DPA is intended to satisfy Article 28 GDPR requirements, and any conflict between this DPA and GDPR shall be resolved in favour of GDPR compliance.

Disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.

Questions about this DPA?

For data protection enquiries, sub-processor documentation, or to exercise rights under this agreement, contact our privacy team.

[email protected]

Questions? [email protected]

Privacy PolicyTerms of ServiceCookie Notice

© 2026 Duebira, Inc.