Data Processing Agreement
The template we sign. It is published rather than sent on request, for the same reason the price is on the page: you should be able to read it before deciding whether to talk to us.
Last updated 2026-09-08.
Status of this document
1. What this covers
This Data Processing Agreement supplements the agreement between DTech SIA ("Processor") and the customer ("Controller") for the use of AEOI Reporting. It applies to personal data the Processor processes on the Controller's behalf under Article 28 of Regulation (EU) 2016/679.
Where the Processor determines its own purposes — the Controller's account data, billing, product communications — it acts as a controller and this agreement does not apply to that processing.
2. Subject matter, duration, nature and purpose
Subject matter: collection, validation, storage and formatting of information required for automatic exchange of tax information, and the evidence trail supporting it.
Duration: for as long as the Controller holds an account, plus the retention period the Controller configures.
Nature and purpose: enabling the Controller to meet its reporting obligations under the Crypto-Asset Reporting Framework, DAC8 and equivalent national law.
3. Categories of data subject and personal data
Data subjects: the Controller's account holders (individuals and the controlling persons of entity account holders), and the Controller's own personnel who use the platform.
- Identification data: name, address, date and place of birth, entity legal name and identifiers.
- Tax data: jurisdictions of tax residence, tax identification numbers, and reportable transaction aggregates.
- Correspondence and process data: the address a self-certification request was sent to, and the timestamps of requests, reminders, restrictions and completions.
4. Processor obligations
The Processor processes personal data only on documented instructions from the Controller, including for transfers to third countries, unless required otherwise by Union or Member State law — in which case it informs the Controller before processing, unless that law prohibits it.
The Processor ensures that persons authorised to process the personal data are bound by confidentiality.
The Processor implements the technical and organisational measures set out in the privacy notice, including encryption in transit and at rest, hashed credentials, role-based access control, and an append-only audit log with per-entry hash chaining.
The Processor assists the Controller in responding to data-subject requests and, taking into account the nature of processing, in meeting its obligations under Articles 32 to 36.
On termination, the Processor deletes or returns the personal data at the Controller's election, except where Union or Member State law requires storage. Export is available at any time and without charge.
5. Subprocessors
The Controller gives general authorisation for the subprocessors listed in the privacy notice. The Processor informs the Controller of any intended addition or replacement at least 30 days in advance, and the Controller may object on reasonable data-protection grounds.
The Processor imposes the same data-protection obligations on each subprocessor and remains fully liable to the Controller for their performance.
6. Personal data breaches
The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the information the Controller needs for its own Article 33 notification.
7. Audit
The Processor makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. In practice, the Controller can verify the integrity of its own audit log at any time from within the product, and export it with its hash chain.
8. International transfers
Personal data is hosted in the European Union. Where a subprocessor processes data outside the EEA, the Processor ensures an adequacy decision or the Standard Contractual Clauses apply, together with any supplementary measures required.
9. Liability
Liability under this agreement is subject to the limitations in the main agreement, which cap the Processor's aggregate liability at the fees paid in the twelve months preceding the claim. Nothing limits liability that cannot be limited by law.
Signing it
Write to info@aeoireporting.com and we will send it as a countersignable document. If your own DPA template is a condition of buying, send it — we would rather read yours than lose a customer over whose paper it is.