← myocr.app

Data Processing Agreement (DPA)

Version 1.0 — September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between MAD.AI SRL, with registered office in Cremona, Italy, company details as published in the site footer ("Processor", "myocr.app") and the customer accepting these terms ("Controller"), and governs the processing of personal data carried out by the Processor on behalf of the Controller through the myocr.app service, pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR").

1. Subject matter and duration

1.1 The Processor provides automated data-extraction services: documents uploaded by the Controller (bank statements, invoices, receipts and similar) are converted into structured formats (Excel, CSV, OFX, JSON).

1.2 This DPA applies for as long as the Controller uses the service and until deletion of all personal data pursuant to Section 7.

2. Nature and purpose of processing

2.1 Processing consists of: receipt, temporary storage, automated text extraction (OCR/AI), format conversion, delivery of results to the Controller, and automatic deletion, for the sole purpose of providing the conversion service.

2.2 The Processor does not use the Controller's documents for any other purpose. In particular, document content is never used to train AI models, neither by the Processor nor by its sub-processors (contractually excluded).

3. Categories of data and data subjects

3.1 Personal data contained in the documents the Controller chooses to upload, typically: names, IBANs and account details, transaction descriptions and amounts, invoice data, contact details.

3.2 Data subjects: the Controller's clients, suppliers, employees and counterparties, as determined by the documents uploaded.

3.3 The Controller warrants it has a lawful basis for the processing and shall not upload special categories of data (Art. 9 GDPR) unless strictly necessary and lawful.

4. Obligations of the Processor

The Processor shall:

5. Sub-processors

5.1 The Controller gives general authorisation to the engagement of the following sub-processors:

Sub-processorPurposeLocation / safeguards
Hetzner Online GmbHHosting and storageGermany (EU)
Enterprise AI cloud providersAutomated text extraction EU/US — data-processing agreements with Standard Contractual Clauses, no-training and no-retention terms. Identity available to the Controller on request at info@myocr.app.
Stripe, Inc.Payment processing (account and billing data only — no document data)EU/US — SCCs
Cloudflare, Inc.DNS resolution (no document data)EU/US
SiteGround / SMTP2GOTransactional and product email (account data only)EU / EU-US

5.2 The Processor shall inform the Controller of intended changes to this list by updating the public page at myocr.app/security at least 15 days in advance; the Controller may object on reasonable data-protection grounds by terminating the service.

5.3 The Processor imposes on each sub-processor data-protection obligations equivalent to those in this DPA.

6. International transfers

6.1 Documents are received and stored exclusively on servers located in Germany. Where a sub-processor processes data outside the EEA, the transfer is covered by an adequacy decision or Standard Contractual Clauses (Art. 46 GDPR), with supplementary measures where required.

7. Retention and deletion

7.1 Deletion is automatic and built into the service:

7.2 Upon termination of the service or deletion of the account (which may be requested at info@myocr.app), the Processor deletes remaining personal data within 30 days, save for data whose retention is required by law (e.g. billing records).

8. Audits

8.1 The Processor makes available: this DPA, the myocr.app/security page, and summary documentation of its technical and organisational measures. On-site audits may be agreed for enterprise plans, at the Controller's expense, once per year, with 30 days' notice, without access to other customers' data.

9. Liability and final provisions

9.1 Liability is governed by the Terms of Service. This DPA prevails over the Terms in case of conflict regarding personal data. Italian law applies; exclusive jurisdiction of the competent court for the Processor's registered office, without prejudice to mandatory consumer provisions.

Annex 1 — Technical and organisational measures (summary)

For a countersigned copy of this DPA, or any data-protection question, contact info@myocr.app.