Legal · GDPR Art. 28

Data Processing Agreement

This agreement governs how Fiscana processes personal data on behalf of its B2B clients in compliance with Regulation (EU) 2016/679 (GDPR).

Effective date 1 June 2026
Legal basis GDPR Article 28
Governing law Portuguese law / EU law
Contact legal@fiscana.pt

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

Data Controller

The B2B client ("Client") who has subscribed to a Fiscana Business plan via business.fiscana.pt and whose identity is recorded in the Fiscana account database.

Data Processor

Innovate360 Lda, a company registered in Portugal, operating the Fiscana platform at fiscana.pt ("Fiscana").

This DPA forms part of and is incorporated into the Fiscana Business Terms of Service. By subscribing to a Fiscana Business plan, the Client agrees to this DPA.

2. Definitions

3. Nature, Purpose, and Duration of Processing

Nature

Fiscana processes Personal Data solely to deliver the Services — answering tax queries submitted through the Client's embedded widget and providing the Client with usage analytics via the Fiscana dashboard.

Purpose

The purpose of processing is the provision of AI-assisted Portuguese tax information as instructed by the Client. Fiscana will not process Personal Data for any purpose beyond delivery of the Services without the Client's prior written consent.

Duration

Processing continues for the duration of the Client's active subscription. Upon termination, Fiscana will delete or anonymise all Personal Data within 90 days, in accordance with Fiscana's data retention policy.

4. Categories of Data Processed

Fiscana processes the following categories of Personal Data on behalf of the Client:

Fiscana does not collect names, email addresses, NIF numbers, or any other directly identifying information from Data Subjects using the widget. The widget is designed to accept tax questions only.

5. Obligations of Fiscana as Processor

Fiscana agrees to:

6. Sub-processors

The Client grants Fiscana general authorisation to engage the following sub-processors. Fiscana will notify the Client of any intended changes to this list, giving the Client the opportunity to object.

All sub-processors are required by contract to provide the same level of data protection as set out in this DPA.

7. International Data Transfers

Fiscana stores all Personal Data within the European Union. Where sub-processors may process data outside the EU (for example, during AI inference via the Anthropic API), such transfers are governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission, or an equivalent adequacy mechanism.

8. Security Measures

Fiscana implements the following technical and organisational measures to protect Personal Data:

9. Obligations of the Client as Controller

The Client agrees to:

10. Data Retention and Deletion

Fiscana retains conversation content (query text and AI response text) for a maximum of 90 days from the date of submission. After 90 days, content is automatically anonymised — the query and response text are permanently deleted and replaced with anonymised metadata.

The following metadata is retained indefinitely as an anonymised statistical record and does not constitute Personal Data: intent category, language, plan type, timestamp, and anonymised session identifier.

Upon termination of the Client's subscription, all Personal Data associated with the Client's account will be deleted within 90 days of the termination date.

11. Liability

Each party shall be liable for any damages caused to Data Subjects or third parties resulting from its own breach of GDPR obligations. Where both parties are responsible for the same damage, liability shall be apportioned according to the degree of fault of each party.

Fiscana's total liability under this DPA shall not exceed the total fees paid by the Client to Fiscana in the three months preceding the event giving rise to the claim.

12. Governing Law and Jurisdiction

This DPA is governed by Portuguese law and the laws of the European Union. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Porto, Portugal.

13. Contact

For questions about this DPA, data subject requests, or to exercise your audit rights, contact:

Innovate360 Lda — operating as Fiscana
Email: legal@fiscana.pt
Website: fiscana.pt

Questions about this DPA?

Reach out and we will respond within 30 days.

legal@fiscana.pt