This Data Processing Agreement (DPA) governs the processing of personal data by Cortena B.V. on behalf of its customers, in connection with the Cortena platform and services. It forms part of the Subscription Agreement between Cortena and the Customer and is incorporated by reference into that agreement.
The version in effect at the Effective Date of each Subscription Agreement is binding. Cortena will notify customers of any material changes with at least 30 days prior written notice.
For questions: compliance@cortena.ai · DPO: Sharon Klaver · dpo@cortena.ai
1. Definitions
Agreement means this Data Processing Agreement and all annexes, forming part of the Subscription Agreement between Cortena and the Customer.
Controller means the Customer, who determines the purposes and means of processing personal data.
Processor means Cortena B.V., who processes personal data on behalf of the Controller.
Customer Personal Data means any personal data processed by Cortena on behalf of the Customer pursuant to or in connection with the Subscription Agreement.
Data Protection Laws means the General Data Protection Regulation (EU) 2016/679 (GDPR), and any applicable national implementing legislation, as amended or replaced from time to time.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
Sub-processor means any third party appointed by Cortena to process Customer Personal Data in connection with the provision of the Service.
Services means the AI Finance Operations platform and related services provided by Cortena under the Subscription Agreement.
EEA means the European Economic Area.
2. Processing of Customer Personal Data
2.1 Documented instructions
Cortena shall process Customer Personal Data only on documented instructions from the Customer, unless required to do so by applicable law. The Subscription Agreement, together with any written instructions provided by the Customer, constitutes the Customer's documented instructions for the purposes of this DPA.
2.2 Scope and purpose
Cortena processes Customer Personal Data solely for the purpose of providing and maintaining the Services as described in the Subscription Agreement. Cortena shall not process Customer Personal Data for any other purpose, including but not limited to training or improving AI models, benchmarking, or developing products or features for other customers.
2.3 Nature of processing
The processing activities carried out by Cortena include: receipt and storage of invoices and financial documents, extraction and classification of financial data, synchronisation with accounting systems, and associated operational support activities.
2.4 Categories of data
Customer Personal Data processed by Cortena may include: names and contact details of employees, contractors, and counterparties; invoice and payment data; vendor and supplier information; and other financial records uploaded to the Service.
2.5 Duration
Cortena processes Customer Personal Data for the duration of the Subscription Agreement, unless applicable law requires longer retention.
3. Processor personnel
Cortena shall ensure that all personnel with access to Customer Personal Data are subject to binding confidentiality obligations. Access to Customer Personal Data is strictly limited to those personnel who need access to perform the Services. Cortena shall take reasonable steps to ensure the reliability of any employee, contractor, or sub-processor with access to Customer Personal Data.
4. Security
4.1 Technical and organisational measures
Cortena implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures include:
- Encryption of data in transit (TLS) and at rest (AES-256)
- Private Kubernetes infrastructure hosted on bare-metal servers in Germany
- Strict access controls and multi-factor authentication for production systems
- Web application firewall and regular external penetration testing
- Automated code scanning and secure software development lifecycle practices
- Least-privilege access controls across all internal systems
4.2 Risk assessment
In determining the appropriate level of security, Cortena takes into account the risks presented by the processing, including the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
4.3 Updates
Security measures are reviewed and updated periodically as the platform evolves and as threats develop. See also Security and EU hosting.
5. Sub-processing
5.1 Authorised sub-processors
The Customer authorises Cortena to appoint sub-processors to assist in providing the Services. Cortena's current list of approved sub-processors is published in this Compliance Centre. See Sub-processors.
5.2 Sub-processor obligations
Cortena shall impose data protection obligations on each sub-processor that are materially equivalent to those set out in this DPA. Cortena remains fully liable to the Customer for the performance of any sub-processor's obligations under this DPA, to the extent that Cortena failed to exercise reasonable care in selecting or supervising that sub-processor.
5.3 Changes to sub-processors
Cortena will notify the Customer of any intended addition or replacement of a sub-processor with at least 30 days prior written notice. If the Customer objects to a new sub-processor on reasonable data protection grounds, the Customer may raise the objection in writing within 30 days of notification. The Parties shall negotiate in good faith to resolve the issue. If no resolution is reached, either Party may terminate the affected part of the Services on reasonable written notice.
6. Data subject rights
6.1 Assistance
Taking into account the nature of the processing, Cortena shall assist the Customer by implementing appropriate technical and organisational measures to enable the Customer to fulfil its obligations to respond to requests from data subjects exercising their rights under applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).
6.2 Notification of requests
Cortena shall promptly notify the Customer if it receives a request from a data subject in respect of Customer Personal Data. Cortena shall not respond to any such request except on the documented instructions of the Customer, or as required by applicable law.
7. Personal Data Breach
7.1 Notification
Cortena shall notify the Customer without undue delay, and in any event within 72 hours, upon becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall include, to the extent available: a description of the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences of the breach, and measures taken or proposed to address the breach.
7.2 Cooperation
Cortena shall cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of any Personal Data Breach.
8. Data Protection Impact Assessments
Cortena shall provide reasonable assistance to the Customer with any Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities that the Customer reasonably considers to be required by Article 35 or Article 36 of the GDPR, where such assessments relate to the processing of Customer Personal Data by Cortena.
9. Deletion and return of Customer Personal Data
9.1 On termination
Upon termination or expiry of the Subscription Agreement, Cortena shall, at the Customer's choice, delete or return all Customer Personal Data within 30 days of the date of termination. This obligation applies to all copies of Customer Personal Data processed by Cortena and its sub-processors.
9.2 Legal retention requirements
Cortena shall not be required to delete Customer Personal Data to the extent that applicable law requires its retention. In such cases, Cortena shall notify the Customer and shall ensure that the retained data is protected in accordance with this DPA.
See also Data deletion.
10. Audit rights
10.1 Information and cooperation
Cortena shall make available to the Customer, upon reasonable written request, all information necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR.
10.2 Audits and inspections
Cortena shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to: (a) reasonable prior written notice of at least 30 days; (b) audits during normal business hours that minimise disruption; (c) the Customer bears the costs unless the audit reveals material non-compliance by Cortena.
10.3 Alternative assurance
Where Cortena has obtained relevant third-party certifications or completed independent security assessments, Cortena may satisfy audit requests by providing the relevant reports or certifications, to the extent they cover the scope of the Customer's audit requirements.
11. International data transfers
11.1 EEA processing
Cortena stores and processes all Customer Personal Data within Germany and the EEA, using infrastructure operated by Hetzner Online GmbH (Germany). Customer Personal Data does not leave the EEA as part of Cortena's core hosting and processing operations.
11.2 Sub-processor transfers
Certain sub-processors may process limited data outside the EEA in the course of providing specific services (such as email reception via Postmark, based in the United States). Where such transfers occur, Cortena ensures that appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms approved by the European Commission.
11.3 No unauthorised transfers
Cortena shall not transfer Customer Personal Data to any country outside the EEA without the Customer's prior written consent, unless required by applicable law or covered by an approved transfer mechanism as described in Section 11.2.
12. Confidentiality
Each Party shall keep this DPA, and all information received from the other Party in connection with it, strictly confidential, except to the extent required by applicable law or already in the public domain through no breach of this DPA.
13. Governing law and jurisdiction
This DPA is governed by the laws of the Netherlands. Any disputes arising in connection with this DPA shall be submitted to the exclusive jurisdiction of the competent courts of Amsterdam, the Netherlands, consistent with the governing law provisions of the Subscription Agreement.
Contact and requests
Email: compliance@cortena.ai
DPO: Sharon Klaver · dpo@cortena.ai
Address: Cortena B.V., Stadhouderskade 5 - 6, 1054 ES Amsterdam, Netherlands · Imprint