ERP DLM
HomePricingBlogDocsStart free trial
ENES

Data Processing Agreement (DPA)

Last updated: September 2026

1. Parties and purpose

This Data Processing Agreement (hereinafter, "DPA") is entered into between the customer of the Service (hereinafter, the "Controller") and DATA LEAN MAKERS, S.L., tax ID (CIF) B93690386, registered office at Calle Conrado del Campo 6, planta 1, puerta B, 29620 Torremolinos (Málaga), as provider of the ERP DLM Service (hereinafter, the "Processor"), in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).

This DPA governs the processing of personal data of third parties (customers, suppliers, employees or other natural persons) that the Controller enters into the Service in the course of its activity, with respect to which the Processor acts as data processor.

2. Nature and purpose of processing

The Processor shall process personal data solely for the provision of the contracted Service (business management: invoicing, accounting, CRM, stock and other ERP features), in accordance with the Controller's documented instructions. The Processor shall not process the data for its own purposes or for purposes other than those instructed.

3. Duration

Processing shall continue while the contractual relationship between the parties is in force and, after its termination, during the period in which the Processor is required to retain the data under applicable law.

4. Categories of data and data subjects

The processed data are those the Controller enters into the Service: identifying and contact data of customers, suppliers and employees, as well as associated financial and invoicing data. The Controller guarantees that it has the necessary legal basis for their processing.

5. Processor's obligations

  • Documented instructions: process the data only in accordance with the Controller's instructions and this DPA.
  • Confidentiality: ensure that persons authorised to process the data commit to confidentiality.
  • Security: apply appropriate technical and organisational measures (encryption, access control, backups) to ensure a level of security appropriate to the risk.
  • Breach notification: notify the Controller, without undue delay, of any security breach affecting the processed data.
  • Assistance: assist the Controller, insofar as possible, so that it can address data subjects' rights (access, rectification, erasure, etc.) and its notification obligations.
  • Return and deletion: upon termination of the service, return or delete the data, unless a legal obligation requires their retention.

6. Sub-processors

The Processor may rely on the following sub-processors for the provision of the Service, who commit in writing to obligations equivalent to those of this DPA:

  • Stripe (payment processing).
  • OpenAI (AI document capture feature).
  • Hosting provider (infrastructure and databases).
  • Email provider (notification delivery).

The Processor shall inform the Controller of any intended change regarding the addition or replacement of sub-processors, giving it the opportunity to object.

7. International transfers

Some sub-processors (Stripe and OpenAI) are established outside the European Economic Area (USA). Processing by such sub-processors is based on appropriate safeguards under the GDPR (standard contractual clauses approved by the European Commission and/or the Data Privacy Framework, as applicable). More information in the Privacy Policy.

8. Audit

The Processor shall make available to the Controller the information necessary to demonstrate compliance with the obligations of this DPA and shall allow, with prior agreement and under confidentiality, the performance of reasonable audits.

ERP DLM

All-in-one business management.

Product

  • Features
  • Pricing
  • Documentation

Company

  • Blog
  • Privacy
  • Terms & conditions
  • DPA (GDPR)
  • Cookies
  • Legal notice

© 2026 ERP DLM. All rights reserved.