This Data Processing Addendum (the “DPA”) forms part of, and is incorporated into, the agreement between EvenHelm and the Customer for use of the Service (the “Agreement”). It applies wherever EvenHelm processes personal data on the Customer’s behalf — in particular the client, invoice, and expense information the Customer and its users upload into their workspace. Capitalised terms not defined here have the meaning given in the Agreement; “personal data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given in the GDPR.
01Parties, roles & how this DPA applies
This DPA is entered into between Meta Mine OOD (EIK 208222364), a limited liability company incorporated in the Republic of Bulgaria, of Zornitsa 42, Apt. 3, Burgas 8018, Bulgaria (“EvenHelm”, the “Processor”) and the Customer identified in the Agreement (the “Controller”).
In respect of the personal data described in section 04, the Customer is the controller and EvenHelm is the processor, processing that personal data only on the Customer’s documented instructions, which include the Agreement, this DPA, and the Customer’s lawful use of the Service’s features. Where the Customer is itself a processor for an upstream controller, EvenHelm acts as a sub-processor and this DPA applies accordingly.
EvenHelm separately acts as a controllerfor account, authentication, session, and billing data about the Customer’s users; that processing is governed by the Privacy Policy, not by this DPA.
02Subject-matter & duration
Subject-matter.The provision of the EvenHelm Service — a multi-tenant platform for cloud and AI cost and usage tracking and for invoicing — which requires EvenHelm to process personal data contained in the Customer Data on the Controller’s behalf.
Duration. Processing continues for the term of the Agreement, plus any period during which EvenHelm retains Customer Data in accordance with section 13 (return and deletion) and the limited periods for which EvenHelm is required to retain certain records by law.
03Nature & purpose of processing
EvenHelm processes the Customer’s personal data only to provide, secure, and support the Service. Processing operations include:
- Hosting and storing client, invoice, and expense records the Customer enters into its workspace.
- Generating and storing invoice PDFs in a private, access-controlled storage bucket, freezing an immutable snapshot of client details into each invoice.
- Organising, retrieving, displaying, aggregating, and computing totals over that data to render dashboards, lists, and documents back to the Customer.
- Transmitting transactional email (such as invitations) on the Customer’s instruction.
- Backing up, securing, and deleting the data as part of operating the Service.
EvenHelm does not use Customer Data for its own purposes, does not sell it, and does not use it to train any AI model. No Customer Data, client data, or prompts are sent to any AI provider — see the Sub-processors page.
04Categories of data subjects & personal data
Categories of data subjects
- The Customer’s own clients and customers (billed parties).
- Individual contacts, payers, and representatives named on invoices or in client records.
- Vendors and payees recorded in expenses.
- The Customer’s personnel insofar as their details appear within Customer Data.
Categories of personal data
| Category | What it includes |
|---|---|
| Client & contact identity | Client and contact names, billing addresses, email addresses, VAT/tax numbers, and payer details entered by the Customer. |
| Invoice content | Invoice line items, subject matter, notes, amounts, currency, and an immutable client snapshot frozen into each invoice, plus generated PDFs. |
| Expense & vendor records | Vendor names, expense descriptions, amounts, and payment logs the Customer records. |
The Service is not intended for special-category (sensitive) personal data within the meaning of Article 9 GDPR, and the Customer must not submit such data. EvenHelm does not knowingly process it.
05Controller (Customer) obligations
The Customer, as controller, warrants and undertakes that it will:
- Have a valid lawful basis, and provide all required notices and obtain all required consents, for the personal data it submits to the Service.
- Issue only lawful instructions for processing, and ensure its instructions do not require EvenHelm to breach the GDPR or other applicable law.
- Not upload special-category or otherwise excessive personal data into the Service.
- Be responsible for the accuracy of Customer Data and for managing its own users’ access and roles.
- Handle, as controller, requests it receives directly from data subjects, using EvenHelm’s assistance under section 10.
06Processor (EvenHelm) obligations
EvenHelm, as processor, undertakes to:
- Process on instructions only — process Customer personal data solely on the Customer’s documented instructions, including for transfers, unless required to do otherwise by law (in which case it will inform the Customer, where legally permitted).
- Confidentiality — ensure that personnel authorised to process the data are bound by appropriate confidentiality obligations.
- Security — implement the technical and organisational measures described in section 09.
- Sub-processors — engage sub-processors only on the terms in section 07.
- Assistance — assist the Customer with data-subject requests (section 10), security, breach notification (section 11), data-protection impact assessments, and prior consultations, taking into account the nature of processing and the information available to EvenHelm.
- Deletion / return — at the Customer’s choice, delete or return the personal data at the end of the Service per section 13.
- Demonstrate compliance — make available the information necessary to demonstrate compliance with Article 28 and allow for audits under section 12.
07Sub-processors
The Customer provides a general authorisationfor EvenHelm to engage sub-processors to support the provision of the Service. EvenHelm maintains a current list of sub-processor categories — together with each category’s role, the data it processes, and its location — on its Sub-processors page; a current list is also available on request via our contact form.
EvenHelm imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.
Change notice. Before adding or replacing a sub-processor, EvenHelm will give the Customer at least 30 days’ prior notice (by updating the Sub-processors page and/or email), during which the Customer may object on reasonable, documented data-protection grounds. If an objection cannot be resolved, the Customer may terminate the affected part of the Service as its sole remedy.
08International transfers
Where processing under this DPA involves a transfer of personal data outside the EEA or the UK to a country without an adequacy decision, the parties incorporate the European Commission’s Standard Contractual Clauses (the “SCCs”), and the UK International Data Transfer Addendum where the UK GDPR applies, by reference into this DPA.
For such transfers, the relevant module of the SCCs applies (EvenHelm as data importer where it acts as processor, and as exporter towards its onward sub-processors). For each recipient, EvenHelm relies on the EU–US Data Privacy Framework and/or the SCCs (with the UK Addendum where the UK GDPR applies), or an adequacy decision where one applies. Where this DPA and the SCCs conflict, the SCCs prevail in respect of the transfer.
09Security measures (Article 32)
Taking account of the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, EvenHelm implements appropriate technical and organisational measures, including:
- Encryption — encryption of personal data in transit and at rest.
- Access controls and tenant isolation — strict, least-privilege access controls and logical isolation of each workspace from every other workspace.
- Authentication — secure storage of credentials and support for two-factor authentication.
- Confidentiality, integrity, availability, and resilience — measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- Accountability — logging of workspace actions for accountability (labels and identities, never secrets).
EvenHelm reviews these measures periodically and may update them, provided the level of security is not materially reduced.
10Assistance with data-subject requests
Taking into account the nature of the processing, EvenHelm will assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer’s obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, and objection).
If EvenHelm receives a request directly from a data subject relating to Customer Data, it will not respond substantively (except to confirm the request relates to the Customer) and will, where permitted, promptly forward the request to the Customer. A self-service request flow is being developed; until then EvenHelm assists on request via our contact form.
11Personal-data breach notification
EvenHelm will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting the Customer’s personal data. The notification will, to the extent available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
EvenHelm will cooperate with, and reasonably assist, the Customer in meeting the Customer’s own breach notification obligations to supervisory authorities and affected data subjects under Articles 33 and 34 GDPR. As processor, EvenHelm will not itself notify a supervisory authority or data subjects on the Customer’s behalf unless instructed or legally required.
12Audit rights
EvenHelm will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates.
- The Customer will give reasonable prior notice — at least 30 days’ — and audits will occur during business hours, no more than once per 12 months except where required by a supervisory authority or following a breach.
- Audits must not unreasonably disrupt EvenHelm’s business or compromise the confidentiality or security of other customers’ data.
- EvenHelm may satisfy audit requests by providing existing reports, certifications, or summaries of its security measures where these reasonably address the request.
- Each party bears its own audit costs unless an audit reveals a material breach by EvenHelm.
13Return & deletion on termination
On termination or expiry of the Service, and at the Customer’s choice, EvenHelm will return or delete the Customer’s personal data, and delete existing copies, within 30 days, unless EU/UK law requires storage of the personal data.
The Customer acknowledges that invoices are immutable financial records: sent or paid invoices are voided rather than deleted, and deleted financial records are retained as soft-deleted entries. EvenHelm may therefore retain such records, and any data it is required to keep by law, for the legally required period, during which it remains protected under this DPA and is processed only for that retention purpose.
14Liability & order of precedence
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference to a party’s liability means aggregate liability under the Agreement and this DPA combined.
Order of precedence. In the event of a conflict, the following order applies in respect of the processing of personal data: (1) the Standard Contractual Clauses (where incorporated, for the relevant transfer); (2) this DPA; (3) the Agreement (including the Terms of Service); and (4) the Privacy Policy. Except as expressly amended here, the Agreement remains in full force.
15Acceptance & signature
This DPA may be accepted by signature or by the Customer’s acceptance of the Agreement that incorporates it. The fields below are completed at signing.
| Processor — EvenHelm | Controller — Customer |
|---|---|
| Entity: Meta Mine OOD (EIK 208222364, VAT BG208222364) | Entity: |
| Address: Zornitsa 42, Apt. 3, Burgas 8018, Bulgaria | Address: |
| Signatory / title: | Signatory / title: |
| Signature & date: | Signature & date: |
Governing law for this DPA: the laws of the Republic of Bulgaria. Processor contact for data-protection matters is via our contact form.