Skip to content
Effective Date: 25/08/2026

Data Processing Agreement (DPA)

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Cristin Griu, trading as ZentraSnap (“ZentraSnap”, “Processor”, “we”, “us” or “our”) and the person or organisation using the ZentraSnap service (“Customer”, “you” or “your”).

This DPA applies where ZentraSnap processes Personal Data on behalf of the Customer in connection with the ZentraSnap service.

This DPA is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 (“GDPR”) and applicable Irish data-protection law, including the Data Protection Act 2018.

1. Definitions

1.1 Client Data

“Client Data” means Personal Data contained in, derived from or otherwise associated with financial documents submitted to ZentraSnap by or on behalf of the Customer, including bank statements, invoices, receipts, images and extracted document data.

Client Data may include names, addresses, financial account information, transaction information, invoice information, contact details and other Personal Data contained in submitted documents.

1.2 Customer

Depending on the circumstances, the Customer may act as either:

  • a Controller of Client Data; or
  • a Processor acting on behalf of another Controller.

Where the Customer acts as a Processor, ZentraSnap acts as a Subprocessor. References in this DPA to the Customer's instructions or responsibilities apply accordingly.

1.3 Subprocessor

“Subprocessor” means a third party engaged by ZentraSnap to process Client Data on behalf of the Customer in connection with providing the Service.

1.4 Applicable Data Protection Law

“Applicable Data Protection Law” includes the GDPR, the Irish Data Protection Act 2018 and any other applicable laws governing the processing of Personal Data under this DPA.

The terms Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Supervisory Authority have the meanings given to them under the GDPR.

2. Roles of the Parties

2.1 Customer: The Customer is the Controller of Client Data or, where applicable, a Processor acting on behalf of another Controller. The Customer determines the purpose for which Client Data is submitted to ZentraSnap and is responsible for establishing an appropriate lawful basis for that processing.

2.2 ZentraSnap: ZentraSnap acts as a Processor or Subprocessor in relation to Client Data. ZentraSnap processes Client Data only to provide the document-extraction functionality requested by the Customer, in accordance with:

  • this DPA;
  • the Terms of Service;
  • the Customer's use and configuration of the Service; and
  • any other lawful documented instructions agreed between the parties.

2.3 Account and Service Usage Data: This DPA does not govern Personal Data for which ZentraSnap independently acts as Controller, such as ZentraSnap account information, authentication data, support information, subscription information, business-administration records and service-usage or credit-accounting records. Such processing is governed by the ZentraSnap Privacy Policy.

Service-usage and credit-accounting records may include user identifiers, subscription and billing-cycle information, credit balances, credits used, document and page counts, OCR page counts, invoice and receipt counts, extracted transaction counts, usage-event identifiers, processing status and timestamps.

ZentraSnap's usage-accounting database is not intended to store Client Data such as transaction descriptions, transaction amounts, account balances, bank-account numbers, invoice contents or receipt contents.

3. Subject Matter, Nature and Purpose of Processing

3.1 Subject Matter

ZentraSnap processes Client Data in order to provide automated financial-document extraction and related functionality.

3.2 Bank Statements

When the Customer submits a bank statement, the document is temporarily uploaded to private object storage provided through Cloudflare R2. Supported image files may first be converted into PDF format locally within the user's browser. The document is then processed using cloud computing infrastructure supplied by Modal Labs.

Processing may include:

  • downloading the temporary document;
  • reading native PDF text;
  • rendering pages where required;
  • optical character recognition (“OCR”), including through Microsoft Azure AI Document Intelligence where OCR is required;
  • applying ZentraSnap's document-extraction machine-learning models;
  • identifying transaction dates, descriptions, debit values, credit values and balances;
  • generating document-coordinate information for review and highlighting;
  • temporarily storing extraction status and structured results; and
  • returning the extracted information to the Customer.

The original bank-statement upload is normally deleted from temporary Cloudflare R2 storage after the processing job completes or fails. As an additional safeguard, temporary bank-statement files, extraction results, processing status information and related temporary objects in Cloudflare R2 are subject to an automated lifecycle policy configured to expire them after one day.

Cloudflare's current DPA applies to customers using its services and expressly addresses processor/subprocessor obligations and international transfers.

3.3 Invoices and Receipts

Invoices and receipts submitted through ZentraSnap's invoice and receipt extraction functionality are transmitted to the paid Google Gemini API for automated analysis.

Processing may include identifying and extracting:

  • supplier or vendor information;
  • customer information;
  • invoice numbers;
  • document dates;
  • monetary totals;
  • VAT or other tax information;
  • line items; and
  • other structured information present in the document.

For paid Gemini services, Google's current terms provide that prompts, files and responses are not used to improve Google's products and are processed pursuant to Google's applicable Data Processing Addendum. Google may nevertheless retain limited information in accordance with its applicable security, abuse-prevention, logging, legal and regulatory requirements.

3.4 Vercel Application Infrastructure

ZentraSnap uses Vercel to host its web application and server-side API infrastructure. Certain Client Data, including extraction results, may transit through ZentraSnap's server-side application routes hosted on Vercel when results are delivered to the authenticated Customer.

3.5 No Sale of Client Data

ZentraSnap does not sell Client Data.

3.6 Machine-Learning Training

ZentraSnap will not use Client Data submitted through the production Service to train or fine-tune ZentraSnap's own machine-learning models unless the Customer has separately and expressly agreed to such use.

ZentraSnap will not intentionally enable optional Subprocessor functionality that permits Client Data to be contributed for general AI model training without the Customer's separate authorisation.

Modal's current contractual terms similarly state that Modal will not train AI models using Customer Data without prior written consent.

4. Documented Instructions

4.1 ZentraSnap shall process Client Data only on documented instructions from the Customer unless processing is required by European Union or Irish law. The Customer's use of ZentraSnap to upload documents, initiate extraction, retrieve results, delete information or configure Service functionality constitutes documented instructions for the purposes of this DPA.

4.2 If ZentraSnap is required by law to process Client Data other than on the Customer's instructions, ZentraSnap will inform the Customer before such processing unless legally prohibited from doing so.

4.3 If ZentraSnap reasonably believes that an instruction from the Customer infringes Applicable Data Protection Law, ZentraSnap shall inform the Customer without undue delay and may suspend the affected processing until the matter is resolved.

This reflects the processor obligations required by Article 28 GDPR.

5. Obligations of the Customer

The Customer shall:

5.1 Lawfulness: Ensure that its collection, use and submission of Client Data complies with Applicable Data Protection Law and that it has an appropriate lawful basis and authority to instruct ZentraSnap to process the data.

5.2 Transparency: Provide Data Subjects with any privacy information or notices required under applicable law.

5.3 Data Minimisation: Submit only Client Data reasonably necessary for the intended document-extraction purpose.

5.4 Customer Instructions: Ensure that its instructions to ZentraSnap comply with Applicable Data Protection Law.

5.5 Security: Take appropriate measures to secure its own accounts, devices, networks, browsers, credentials and downloaded extraction results.

6. Obligations of ZentraSnap

6.1 Confidentiality

ZentraSnap shall ensure that any person authorised to process Client Data is subject to an appropriate obligation of confidentiality. Access to Client Data by ZentraSnap personnel shall be limited to circumstances reasonably necessary for security, support, troubleshooting, legal compliance or operation of the Service.

6.2 Security

Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, ZentraSnap shall maintain technical and organisational measures appropriate to the risk of processing. Current measures are described in Annex 2.

6.3 Data Minimisation

ZentraSnap shall seek to process and retain only the Client Data reasonably necessary to provide and secure the Service.

6.4 Personnel Access

ZentraSnap shall restrict production infrastructure credentials and administrative access to authorised persons.

7. Subprocessors

7.1 General Authorisation: The Customer provides general written authorisation for ZentraSnap to engage the Subprocessors listed in Annex 3.

GDPR Article 28 permits general written authorisation provided that customers are informed of intended additions or replacements and have an opportunity to object.

7.2 Subprocessor Obligations: Where ZentraSnap engages a Subprocessor to process Client Data, ZentraSnap shall ensure through an appropriate written agreement that the Subprocessor is subject to data-protection obligations appropriate to the processing and consistent with applicable Article 28 requirements.

ZentraSnap remains responsible to the Customer for the performance of its Subprocessors' data-protection obligations to the extent required by Applicable Data Protection Law.

7.3 Changes: ZentraSnap shall provide reasonable advance notice of an intended addition or replacement of a Subprocessor that will materially process Client Data. Notice may be provided by email, in-app notification, publication through ZentraSnap's website or another reasonable mechanism.

Where reasonably practicable, ZentraSnap will provide at least 15 days' notice before a new Subprocessor begins processing Client Data. Where an urgent replacement is reasonably necessary for security, service continuity or legal compliance, ZentraSnap may provide notice as soon as reasonably practicable.

7.4 Objections: The Customer may object to a new Subprocessor on reasonable data-protection grounds. The parties shall attempt in good faith to resolve the objection. If no reasonable alternative is available, the Customer may discontinue the affected Service or terminate its use of ZentraSnap before the Subprocessor begins the relevant processing, subject to the applicable Terms of Service.

8. International Data Transfers

ZentraSnap and its Subprocessors may process Client Data outside Ireland or the European Economic Area. Where Client Data is transferred to a country that does not benefit from an applicable European Commission adequacy decision, ZentraSnap shall ensure that an appropriate transfer mechanism is used where required by law.

Such mechanisms may include:

  • the European Commission Standard Contractual Clauses;
  • the EU-U.S. Data Privacy Framework where applicable;
  • another safeguard permitted under Article 46 GDPR; or
  • another lawful transfer mechanism available under the GDPR.

Modal's current DPA expressly provides for the use of Standard Contractual Clauses and other GDPR-compliant transfer mechanisms. Google Cloud's current DPA similarly addresses SCCs and processor-to-processor transfers.

9. Data Subject Rights

9.1 Customer Responsibility: The Customer remains responsible for responding to requests from Data Subjects exercising rights under applicable data-protection law.

9.2 ZentraSnap Assistance: Taking into account the nature of the processing, ZentraSnap shall provide reasonable assistance to the Customer, including through appropriate technical and organisational measures, to enable the Customer to respond to Data Subject requests concerning:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • data portability;
  • objection; and
  • other applicable rights.

The Irish Data Protection Commission specifically identifies this assistance obligation as a mandatory Article 28 requirement.

9.3 Requests Received by ZentraSnap: If ZentraSnap directly receives a request from a Data Subject relating to Client Data processed on behalf of a Customer, ZentraSnap shall not independently respond to the substantive request unless authorised or legally required to do so. Where reasonably possible, ZentraSnap shall notify the relevant Customer or direct the Data Subject to the relevant Controller.

9.4 Temporary Data: Because bank-statement documents and extraction results are designed to have short retention periods, Client Data may already have been deleted by the time a Data Subject request is received. Where data remains within systems under ZentraSnap's control, ZentraSnap will provide reasonable assistance with identifying, deleting, restricting or returning the data where technically feasible and legally required.

10. Personal Data Breaches

10.1 Notification: ZentraSnap shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Client Data processed on the Customer's behalf.

10.2 Information: To the extent reasonably available, ZentraSnap shall provide information concerning:

  • the nature of the Personal Data Breach;
  • the categories of affected Client Data and Data Subjects;
  • the likely consequences;
  • measures taken or proposed to address the breach; and
  • information reasonably required for the Customer to meet its obligations under Articles 33 and 34 GDPR.

Information may be supplied in phases where all details are not immediately available.

10.3 Cooperation: ZentraSnap shall take reasonable steps to investigate, mitigate and remediate Personal Data Breaches affecting Client Data within ZentraSnap's processing environment.

10.4 Customer Systems: ZentraSnap is not responsible for security breaches caused solely by the compromise of systems, devices, credentials or networks controlled by the Customer, although ZentraSnap will provide reasonable assistance where the event also affects Client Data processed through the Service.

11. Security, DPIAs and Regulatory Assistance

Taking into account the nature of the processing and information reasonably available to ZentraSnap, ZentraSnap shall provide reasonable assistance to the Customer concerning its compliance with:

  • Article 32 GDPR — security of processing;
  • Articles 33 and 34 — Personal Data Breach notification;
  • Article 35 — Data Protection Impact Assessments; and
  • Article 36 — prior consultation with Supervisory Authorities.

This assistance is expressly part of the processor duties identified by the Irish Data Protection Commission.

12. Return and Deletion of Client Data

12.1 During Normal Processing: For bank statements, the uploaded source document is normally deleted from ZentraSnap's temporary Cloudflare R2 storage after the extraction completes or fails. Temporary source documents, extraction-result files, job-status records and related temporary R2 objects are additionally subject to an automated Cloudflare R2 lifecycle policy configured to expire them after one day.

12.2 Results: Extracted results are returned to the Customer through the ZentraSnap application. The Customer is responsible for downloading or otherwise retaining any results it wishes to keep beyond ZentraSnap's temporary retention period.

12.3 End of Processing: Upon termination of the processing relationship, or upon a valid instruction from the Customer, ZentraSnap shall delete or return Client Data under its control, unless retention is required by applicable law. Where data is stored only temporarily and has already been deleted in accordance with the Service's retention architecture, ZentraSnap will have no remaining copy to return.

12.4 Subprocessor Retention: Subprocessors may maintain temporary copies, security records, logs or backups for periods permitted under their applicable agreements and retention policies. ZentraSnap shall require its Subprocessors to delete Client Data in accordance with applicable contractual and legal obligations.

13. Audits and Demonstration of Compliance

13.1 Information: ZentraSnap shall make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR.

13.2 Audit Evidence: Where reasonably sufficient, compliance may initially be demonstrated through:

  • this DPA;
  • technical documentation;
  • security documentation;
  • Subprocessor DPAs;
  • independent certifications or audit reports made available by applicable providers; and
  • responses to reasonable security or data-protection questionnaires.

13.3 Audits: Where the information described above is insufficient to demonstrate compliance, or where an audit is required by Applicable Data Protection Law or a competent Supervisory Authority, ZentraSnap shall allow for and reasonably contribute to an audit relating to the processing covered by this DPA. Audits shall, where practicable:

  • take place on reasonable prior written notice;
  • occur during normal business hours;
  • avoid unreasonable disruption to the Service;
  • respect confidentiality and the security of other customers; and
  • be limited to systems and processing relevant to the Customer's Client Data.

Nothing in this section restricts audit rights that cannot lawfully be limited under the GDPR.

14. Records and Regulatory Cooperation

ZentraSnap shall maintain information concerning its processing activities where required under applicable data-protection law.

ZentraSnap shall reasonably cooperate with the Customer and competent Supervisory Authorities concerning processing covered by this DPA where required by law.

15. Liability

Liability arising from this DPA is subject to the limitation-of-liability provisions in the ZentraSnap Terms of Service except to the extent that such liability cannot lawfully be excluded or limited under the GDPR or other applicable law.

Nothing in this DPA limits the statutory powers of a Supervisory Authority or rights that cannot legally be restricted by contract.

16. Duration and Termination

This DPA becomes effective when the Customer becomes bound by the ZentraSnap Terms of Service and remains effective for as long as ZentraSnap processes Client Data on the Customer's behalf.

Provisions that by their nature are intended to survive termination, including confidentiality, deletion, audit, liability and international-transfer obligations, shall survive for as long as necessary to fulfil their purpose.

17. Order of Precedence

If there is a conflict concerning the processing of Client Data between:

  • this DPA; and
  • the ZentraSnap Terms of Service,

this DPA shall prevail to the extent of that conflict.

Where Standard Contractual Clauses apply to an international transfer and conflict with this DPA, the Standard Contractual Clauses shall prevail to the extent required by law.

DETAILS OF PROCESSING

A. Subject Matter

Provision of ZentraSnap's financial-document extraction service.

B. Nature and Purpose

The processing may include:

  • receipt and temporary storage of documents;
  • PDF and image processing;
  • OCR using Microsoft Azure AI Document Intelligence where required;
  • recognition of text, words, confidence information and document coordinates;
  • machine-learning inference;
  • AI-based document extraction;
  • parsing and classification of financial information;
  • creation of structured transaction or invoice data;
  • temporary processing-status storage;
  • delivery of results to authenticated users;
  • security and abuse prevention; and
  • deletion of temporary processing data.

C. Duration

Processing takes place for the duration necessary to provide the requested extraction functionality.

For bank-statement processing, Cloudflare R2 temporary files and extraction objects are subject to an automated lifecycle rule configured to expire them after one day, while the original source document is ordinarily deleted sooner after the processing job completes or fails.

Certain Subprocessors may maintain limited temporary logs, security information, backups or function-processing data according to their applicable contracts and retention policies.

Where Azure Document Intelligence is used, Microsoft may temporarily retain submitted OCR input and analysis results for up to 24 hours in accordance with its service retention policy.

D. Categories of Data Subjects

Client Data may relate to:

  • • the Customer's clients/customers
  • • account holders
  • • employees
  • • directors
  • • business owners
  • • sole traders
  • • suppliers and vendors
  • • customers of clients
  • • payees and payers
  • • representatives/contact persons
  • • other persons identified within financial documents

E. Categories of Personal Data

Client Data may include:

  • • names
  • • business names
  • • physical addresses
  • • email addresses
  • • telephone numbers
  • • account numbers
  • • IBANs
  • • sort codes
  • • bank identifiers
  • • transaction dates
  • • transaction descriptions
  • • debit/credit amounts
  • • account balances
  • • supplier/customer info
  • • invoice numbers
  • • receipt information
  • • VAT or tax identifiers
  • • VAT/tax amounts
  • • invoice line items
  • • payment information
  • • document metadata
  • • OCR-derived text
  • • document-coordinate info

• other Personal Data contained within submitted documents.

F. Special Categories of Personal Data

ZentraSnap is not specifically designed to collect Special Category Personal Data. However, financial documents may incidentally contain information from which sensitive characteristics could potentially be inferred, for example through transaction descriptions.

The Customer is responsible for avoiding the submission of unnecessary Special Category Personal Data and ensuring that any such processing is lawful. ZentraSnap shall process such information only insofar as it is contained in documents submitted for the requested extraction task.

TECHNICAL AND ORGANISATIONAL MEASURES

ZentraSnap currently employs measures including:

Access Control

Production infrastructure and administrative systems are restricted to authorised persons. Infrastructure credentials, API credentials, storage credentials and service secrets are maintained server-side and are not intentionally exposed to end users.

Authentication

Access to protected ZentraSnap functionality is restricted using authenticated user sessions. Paid document-processing functionality may additionally be restricted to users with an appropriate active subscription.

Encryption in Transit

Web application and API communications use HTTPS/TLS.

Encryption at Rest

ZentraSnap uses infrastructure providers that support encryption of stored data. Cloudflare states that R2 objects are automatically encrypted at rest. Modal states that its platform uses encryption for customer data in transit and at rest.

Private Storage

Temporary Cloudflare R2 storage used for bank statements is not configured as a public document repository.

Temporary Retention

Bank-statement processing uses short-lived temporary storage. R2 temporary processing objects are subject to a one-day lifecycle expiry rule.

Data Minimisation

ZentraSnap seeks to minimise the amount and duration of Client Data stored for processing.

Subprocessor Controls

ZentraSnap selects service providers that provide contractual data-protection and security commitments appropriate to their role.

Application Security

ZentraSnap uses server-side access controls for protected operations and maintains cloud-provider credentials outside client-side application code.

Security Monitoring

Reasonable security, rate-limiting and operational monitoring measures may be used to detect abuse and protect the availability and integrity of the Service.

AUTHORISED SUBPROCESSORS

SubprocessorPurposeClient Data potentially processed
Cloudflare, Inc. / applicable Cloudflare entityPrivate temporary R2 object storage for bank-statement processingSource bank statements, temporary results and processing/job metadata
Modal Labs, Inc.Cloud computing and GPU infrastructure for bank-statement extraction, machine-learning inference and OCRBank-statement content, rendered document data, OCR text and extracted transaction data
Google / applicable Google contracting entityPaid Gemini API processing for invoices and receiptsInvoice/receipt documents, images, prompts and extracted structured information
Microsoft Corporation / applicable Microsoft Azure contracting entityAzure AI Document Intelligence OCR for scanned, image-based or unsuccessful bank-statement extractionBank-statement pages/images, OCR-recognised text, document coordinates, confidence information and analysis results
Vercel, Inc.Hosting and server-side application/API infrastructureClient Data that transits ZentraSnap's server routes, including extraction requests/results where applicable