AEOI Reporting

Data Processing Agreement

The template we sign. It is published rather than sent on request, for the same reason the price is on the page: you should be able to read it before deciding whether to talk to us.

Last updated 2026-09-08.

Status of this document

Drafted in-house and not yet reviewed by external counsel. It describes what the product actually does — if you need a lawyer-reviewed version before signing, ask and we will tell you where the review has got to.

1. What this covers

This Data Processing Agreement supplements the agreement between DTech SIA ("Processor") and the customer ("Controller") for the use of AEOI Reporting. It applies to personal data the Processor processes on the Controller's behalf under Article 28 of Regulation (EU) 2016/679.

Where the Processor determines its own purposes — the Controller's account data, billing, product communications — it acts as a controller and this agreement does not apply to that processing.

2. Subject matter, duration, nature and purpose

Subject matter: collection, validation, storage and formatting of information required for automatic exchange of tax information, and the evidence trail supporting it.

Duration: for as long as the Controller holds an account, plus the retention period the Controller configures.

Nature and purpose: enabling the Controller to meet its reporting obligations under the Crypto-Asset Reporting Framework, DAC8 and equivalent national law.

3. Categories of data subject and personal data

Data subjects: the Controller's account holders (individuals and the controlling persons of entity account holders), and the Controller's own personnel who use the platform.

  • Identification data: name, address, date and place of birth, entity legal name and identifiers.
  • Tax data: jurisdictions of tax residence, tax identification numbers, and reportable transaction aggregates.
  • Correspondence and process data: the address a self-certification request was sent to, and the timestamps of requests, reminders, restrictions and completions.

4. Processor obligations

The Processor processes personal data only on documented instructions from the Controller, including for transfers to third countries, unless required otherwise by Union or Member State law — in which case it informs the Controller before processing, unless that law prohibits it.

The Processor ensures that persons authorised to process the personal data are bound by confidentiality.

The Processor implements the technical and organisational measures set out in the privacy notice, including encryption in transit and at rest, hashed credentials, role-based access control, and an append-only audit log with per-entry hash chaining.

The Processor assists the Controller in responding to data-subject requests and, taking into account the nature of processing, in meeting its obligations under Articles 32 to 36.

On termination, the Processor deletes or returns the personal data at the Controller's election, except where Union or Member State law requires storage. Export is available at any time and without charge.

5. Subprocessors

The Controller gives general authorisation for the subprocessors listed in the privacy notice. The Processor informs the Controller of any intended addition or replacement at least 30 days in advance, and the Controller may object on reasonable data-protection grounds.

The Processor imposes the same data-protection obligations on each subprocessor and remains fully liable to the Controller for their performance.

6. Personal data breaches

The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the information the Controller needs for its own Article 33 notification.

7. Audit

The Processor makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. In practice, the Controller can verify the integrity of its own audit log at any time from within the product, and export it with its hash chain.

8. International transfers

Personal data is hosted in the European Union. Where a subprocessor processes data outside the EEA, the Processor ensures an adequacy decision or the Standard Contractual Clauses apply, together with any supplementary measures required.

9. Liability

Liability under this agreement is subject to the limitations in the main agreement, which cap the Processor's aggregate liability at the fees paid in the twelve months preceding the claim. Nothing limits liability that cannot be limited by law.

Signing it

Write to info@aeoireporting.com and we will send it as a countersignable document. If your own DPA template is a condition of buying, send it — we would rather read yours than lose a customer over whose paper it is.