Vinnslusamningur (DPA)
Útgáfa 1.2 · Gildistaka: 17. september 2026
Athugið: Vinnslusamningurinn er birtur á ensku og enska útgáfan gildir sem hinn bindandi texti.
This Data Processing Addendum ("DPA") forms part of the brutto Terms & Conditions (the "Terms") between Quickstart ehf., kennitala 570823-0190, Borgartún 27, 105 Reykjavík, Iceland ("Quickstart", "we", "us") and the customer accepting the Terms ("Customer", "you").
By accepting the Terms you accept this DPA on your own behalf and on behalf of any company on whose instructions you submit Customer Data. No signature is required; acceptance is recorded electronically at the time you accept the Terms.
Where this DPA conflicts with the Terms in respect of the processing of personal data, this DPA prevails.
1. Definitions
1.1 "Applicable Data Protection Law" means Regulation (EU) 2016/679 ("GDPR"), the Icelandic Act on Data Protection and the Processing of Personal Data No. 90/2018, and any other data protection law applicable to a party's processing under the Terms.
1.2 "Customer Data" means documents, images, files, records and other content submitted to the Service by or on behalf of Customer, together with any text, values or metadata extracted from them by the Service.
1.3 "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
1.4 "Sub-processor" means any third party engaged by Quickstart to process Customer Data.
1.5 "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR.
1.6 Terms not defined here have the meaning given in the Terms.
2. Roles and scope
2.1 This DPA applies where Quickstart processes Personal Data on Customer's behalf. In respect of such Personal Data, Customer is the Controller and Quickstart is the Processor.
2.2 Quickstart acts as Controller in respect of account, authentication, billing, support and usage data processed to operate and secure the Service. That processing is described in the brutto Privacy Policy and is outside the scope of this DPA.
2.3 Where Customer is itself a Processor acting on behalf of a third-party Controller, Quickstart is a Sub-processor. Customer warrants that it has the authority of that Controller to appoint Quickstart on the terms of this DPA and to agree the SCCs on that Controller's behalf.
2.4 Each party shall comply with its own obligations under Applicable Data Protection Law.
3. Processing instructions
3.1 Quickstart shall process Customer Data only on documented instructions from Customer, including with regard to transfers to a third country, unless required to do so by Union or Member State law or by Icelandic law to which Quickstart is subject. In such a case Quickstart shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2 Customer instructs Quickstart to process Customer Data in order to:
- (a) receive, store and make available documents and records submitted by Customer;
- (b) perform automated processing, including optical character recognition and structured data extraction by artificial intelligence providers, on documents submitted by Customer;
- (c) return extracted results to Customer within the Service;
- (d) provide the features described in the Terms, including bookkeeping support, receipt and invoice management, contract handling and electronic signature workflows;
- (e) provide maintenance, security and support for the Service; and
- (f) comply with Quickstart's legal obligations.
3.3 The Terms, this DPA, and Customer's configuration and use of the Service constitute Customer's complete documented instructions. Any additional instruction requires the written agreement of the parties.
3.4 Quickstart shall immediately inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Customer obligations and warranties
4.1 Customer warrants and represents that, in respect of all Customer Data it submits:
- (a) it has a valid legal basis under Article 6 and, where applicable, Article 9 of the GDPR for the processing, including processing carried out by Quickstart and its Sub-processors on Customer's behalf;
- (b) it has the right and authority to disclose the Customer Data to Quickstart and to its Sub-processors, and to have that Customer Data processed by automated means, including by the artificial intelligence providers listed under clause 7;
- (c) no confidentiality obligation, contractual restriction or professional duty prevents disclosure of the Customer Data to Quickstart or to its Sub-processors;
- (d) it has provided all information required by Articles 13 and 14 of the GDPR to Data Subjects identified in submitted documents who are not Customer's own personnel or authorised users — including counterparties, signatories, named representatives, payees and merchant personnel — or has validly determined that an exemption under Article 14(5) applies; and
- (e) it shall not submit data falling within Article 9 or Article 10 of the GDPR except as expressly agreed in writing under clause 6.4.
4.2 Customer shall indemnify Quickstart against claims, fines, penalties and reasonable costs arising from a breach of clause 4.1.
5. Confidentiality
5.1 Quickstart shall ensure that persons authorised to process Customer Data are bound by an appropriate statutory obligation of confidentiality or have committed themselves to confidentiality in writing.
5.2 Quickstart shall limit access to Customer Data to those personnel who require access to perform their role, and shall maintain access controls enforcing that limitation.
6. Security
6.1 Quickstart shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. Those measures are described in Annex II.
6.2 Quickstart may update the measures in Annex II from time to time provided the level of security is not materially reduced.
6.3 Customer is responsible for the security of its own systems, credentials and authorised users' access, and for configuring the Service appropriately.
6.4 The Service is not designed for data falling within Article 9 or Article 10 of the GDPR. Quickstart applies no additional safeguards in respect of such data absent written agreement.
7. Sub-processors
7.1 Customer provides general written authorisation for Quickstart to engage Sub-processors to process Customer Data.
7.2 Quickstart maintains a current list of Sub-processors, including each Sub-processor's identity, role, processing location and transfer mechanism, at app.brutto.is/subprocessors. That list forms Annex III to this DPA.
7.3 Quickstart shall give Customer at least thirty (30) days' notice before adding or replacing a Sub-processor, by updating the list and notifying Customer's designated contact.
7.4 Customer may object to a proposed Sub-processor on reasonable data protection grounds within that period. The parties shall discuss the objection in good faith. If no resolution is reached, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the terminated portion.
7.5 Quickstart shall impose on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Sub-processor's obligations.
8. International transfers
8.1 Quickstart shall not transfer Customer Data outside the European Economic Area except in accordance with this clause.
8.2 Where Customer Data is transferred to a country that is not the subject of an adequacy decision, the transfer is governed by the SCCs, which are incorporated into this DPA by reference:
- (a) Module Two (Controller to Processor) applies where Customer is a Controller;
- (b) Module Three (Processor to Sub-processor) applies where Customer is itself a Processor.
8.3 For the purposes of the SCCs:
- (a) Annex I.A is completed by the parties' details in this DPA and Customer's account information;
- (b) Annex I.B is completed by Annex I to this DPA;
- (c) Annex I.C identifies the Icelandic Data Protection Authority (Persónuvernd) as competent Supervisory Authority, or such other authority as is competent under Clause 13 of the SCCs;
- (d) Annex II of the SCCs is completed by Annex II to this DPA;
- (e) the optional docking clause (Clause 7) applies;
- (f) in Clause 9, Option 2 (general written authorisation) applies, with the notice period in clause 7.3 above;
- (g) in Clause 11, the optional independent dispute resolution provision does not apply;
- (h) in Clause 17, the governing law is the law of Iceland;
- (i) in Clause 18(b), the forum is the courts of Iceland.
8.4 Where Applicable Data Protection Law of the United Kingdom applies, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the Information Commissioner's Office.
8.5 Quickstart has entered into a data processing agreement incorporating the SCCs with each Sub-processor that processes Customer Data outside the EEA, including its artificial intelligence provider.
9. Data Subject rights
9.1 Taking into account the nature of the processing, Quickstart shall assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR.
9.2 The Service provides functionality enabling Customer to access, correct, export and delete Customer Data. Customer shall use that functionality in the first instance.
9.3 Where Quickstart receives a request directly from a Data Subject relating to Customer Data, it shall not respond substantively but shall promptly forward the request to Customer, save where legally required to respond.
10. Personal Data Breach
10.1 Quickstart shall notify Customer without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a Personal Data Breach affecting Customer Data.
10.2 The notification shall describe, to the extent then known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information.
10.3 Quickstart shall provide reasonable further assistance to enable Customer to comply with its obligations under Articles 33 and 34 of the GDPR.
10.4 Notification under this clause is not an acknowledgement of fault or liability.
11. Data protection impact assessments
11.1 Quickstart shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with a Supervisory Authority under Articles 35 and 36 of the GDPR, taking into account the nature of the processing and the information available to Quickstart.
12. Deletion and return
12.1 On termination or expiry of the Terms, Customer may export Customer Data using the functionality of the Service for a period of ninety (90) days.
12.2 At the end of that period, Quickstart shall delete Customer Data, save that:
- (a) accounting material — including receipts, invoices and transaction records — is retained for seven (7) years where Quickstart is required to retain it under Icelandic bookkeeping law; and
- (b) Customer Data contained in routine backups is deleted in accordance with Quickstart's backup rotation, and in any event within one (1) day.
12.3 Where Customer requests deletion before the end of the period in clause 12.1, Quickstart shall comply, subject to clause 12.2(a) and (b).
12.4 Quickstart shall, on written request, certify deletion.
13. Audits and information
13.1 Quickstart shall make available to Customer the information necessary to demonstrate compliance with Article 28 of the GDPR and this DPA.
13.2 Quickstart may satisfy clause 13.1 by providing its then-current security documentation, third-party audit or certification reports, and completed security questionnaires.
13.3 Where the information provided under clause 13.2 is not sufficient, Customer may conduct an audit, including an inspection. Such audits shall be: limited to once in any twelve-month period, save where required by a Supervisory Authority or following a Personal Data Breach; on not less than thirty (30) days' written notice; conducted during business hours; subject to reasonable confidentiality obligations; conducted so as to minimise disruption; and at Customer's cost, save where the audit reveals material non-compliance by Quickstart.
14. Automated and AI-assisted processing
14.1 Quickstart uses third-party artificial intelligence providers to perform optical character recognition and structured data extraction on documents submitted by Customer. Those providers are identified in Annex III.
14.2 Quickstart shall ensure that Customer Data disclosed to such providers:
- (a) is not used to train, fine-tune or otherwise improve any provider's models;
- (b) is processed under a data processing agreement incorporating the SCCs where the provider processes outside the EEA; and
- (c) is not retained in provider logs accessible to Quickstart, Quickstart having disabled such logging.
14.3 Customer acknowledges that a provider may retain inputs and outputs for a limited period, currently up to thirty (30) days, solely for the purpose of detecting abuse or misuse of that provider's services, and that such data is not used for training and is not accessible to Quickstart. Quickstart shall update Annex III if this position changes.
14.4 Extracted information is generated automatically, is presented to Customer as a suggestion, and may be incomplete or incorrect. Quickstart does not carry out solely automated decision-making producing legal or similarly significant effects concerning a Data Subject. Customer is responsible for reviewing extracted information before relying on or acting on it.
15. Liability
15.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms.
15.2 Nothing in this DPA limits or excludes either party's liability to a Data Subject under Article 82 of the GDPR, or any liability that cannot be limited or excluded under Applicable Data Protection Law.
16. Term
16.1 This DPA takes effect when Customer accepts the Terms and continues while Quickstart processes Customer Data.
16.2 Quickstart may update this DPA. Where an update materially affects Customer's rights, Quickstart shall give notice in accordance with the change provisions of the Terms. The current version and its effective date are published at app.brutto.is/dpa.
17. Governing law
17.1 This DPA is governed by the law of Iceland. The District Court of Reykjavík has exclusive jurisdiction, save as provided in the SCCs.
Annex I — Description of the processing
- Subject matter: Provision of the brutto Service, including automated extraction of structured information from documents submitted by Customer.
- Duration: The term of the Terms, plus the retention periods in clause 12.
- Nature and purpose: Collection, recording, storage, structuring, automated extraction, retrieval, use, disclosure to Sub-processors, erasure.
- Categories of Data Subject: Customer's personnel and authorised users; individuals identified or identifiable in documents submitted by Customer, including counterparties, signatories, named representatives, payees and merchant personnel.
- Types of Personal Data: Name; kennitala; email address; telephone number; postal address; employer and job title; signature; bank account and payment card identifiers; transaction dates, amounts and line items; contract terms and values; and other Personal Data contained in documents submitted by Customer.
- Special categories: None requested or required. Not to be submitted absent written agreement (clause 6.4).
- Frequency: Continuous, on Customer submission.
- Retention: As set out in clause 12.
- Sub-processor processing: As set out in Annex III.
Annex II — Technical and organisational measures
Encryption. Customer Data is encrypted in transit using TLS 1.2 or above and encrypted at rest. Bank credentials are stored encrypted and are not displayed in full.
Access control. Role-based access on a least-privilege basis. Multi-factor authentication is required for administrative access. End-user authentication uses Icelandic electronic ID. Access rights are reviewed quarterly and on any change of personnel.
Pseudonymisation and minimisation. Personal Data is limited to what is necessary for the purposes in Annex I.
Network and application security. Network segmentation and isolation of production environments; secrets management; dependency and vulnerability monitoring; secure development practices including code review before deployment.
Logging and monitoring. Administrative access and configuration changes are logged. Logs are retained for 30 days.
Resilience. Automated backups with a one-day retention window, encrypted at rest.
Personnel. Confidentiality undertakings; access provisioned on role and revoked on departure; periodic security awareness training.
Sub-processor management. Sub-processors are assessed before engagement and bound by written data protection terms no less protective than this DPA.
Incident response. Documented incident response procedure including assessment, containment, notification and post-incident review.
AI provider configuration. Customer Data disclosed to artificial intelligence providers is excluded from model training; provider-side request logging is disabled; uploaded document objects are deleted after processing and carry a maximum time-to-live of one hour.
Annex III — Sub-processors
The current list of Sub-processors, including identity, role, processing location and transfer mechanism, is published at app.brutto.is/subprocessors and forms part of this DPA. Changes are notified in accordance with clause 7.3.