Data processing agreement
Version of 29 September 2026 (reference 2026-10)
This page is a translation. The Spanish original at holacasilla.com/encargo/ is the binding text; if the two differ, the Spanish text prevails.
When you record in Casilla an invoice from a client or a supplier, you are processing personal data of third parties for which you are the controller. Casilla processes it on your behalf, to provide you with the service, and only for that. Article 28 of Regulation (EU) 2016/679 requires that relationship to be in writing: this is the writing.
Parties
| Data controller | The holder of the book: the person or entity that accepts this agreement when signing in to the application, identified by their account email and the NIF of their profile. |
|---|---|
| Data processor | Indieline, S.L.. Contact: acceso@holacasilla.com. |
Subject matter, nature and purpose
The processor processes the data that the controller records in the application for the sole purpose of providing the service described in the terms: keeping the ledger, computing the figures for modelos 130, 303 and 349 and showing their breakdown. The processing consists of storing, organising, consulting, cross-checking and, at the controller's request, exporting or deleting.
Data and data subjects affected
| Categories of data | Identification of clients and suppliers (name or company name, NIF, address, email); invoice and payment data; concepts and counterparties of bank movements; attached documents the controller decides to upload. |
|---|---|
| Categories of data subjects | The controller's clients, suppliers and other counterparties; contact persons at them. |
| Data not processed | Special categories under art. 9 GDPR. If an uploaded document contained them, the controller is the one who decides to upload it and who must have a basis for doing so. |
Duration
For as long as the controller has access to the service. On termination, the "Return and deletion" section applies.
Processor's obligations
In accordance with article 28.3 GDPR, the processor:
- Processes the data only on the controller's instructions, which are those of this agreement and those given by using the application. If a Union or Member State law obliged it to a different processing, it would notify the controller beforehand, unless that law prohibits it.
- Ensures that the people authorised to process data have committed to confidentiality. Today there is one: the owner of the processor. Any extension will be stated here.
- Applies the security measures in the next section.
- Does not engage another processor without authorisation. The sub-processors authorised by this agreement are those in the table below; a change will be communicated thirty days in advance so the controller can object.
- Helps the controller attend to data subjects' rights (access, rectification, erasure, restriction, portability, objection): the application allows locating, correcting and exporting a counterparty's data, and deleting it when no retention obligation prevents it.
- Helps the controller comply with its obligations on security, breach notification and impact assessment, with the information it has available.
- On termination of the service, returns or deletes the data as set out in "Return and deletion".
- Makes available to the controller the information necessary to demonstrate compliance and allows audits, with reasonable notice, without accessing other controllers' data.
Security measures
- Encryption in transit (TLS) across the whole service; the application does not answer unencrypted.
- Data and backups in the European Union (region eu-central-1, Frankfurt), in encrypted storage.
- Daily backup, verified before it counts, with fourteen days of rotation.
- Isolation by holder: every query from the application is limited to the controller's book; no parameter can widen it.
- Operational access to the server through an authenticated, logged channel, without shared keys or passwords.
- Request logging with no personal data (technical identifiers, not names or concepts).
Sub-processors
| Amazon Web Services EMEA SARL (Luxembourg) | Hosting, storage, backups and transactional email. Region eu-central-1. |
|---|---|
| Google Ireland Limited (Ireland) | The controller's identity provider (sign-in). Does not process this agreement's data subjects' data. |
Security breaches
If the processor becomes aware of a security breach affecting the controller's data, it will notify the controller without undue delay and in any case within seventy-two hours of becoming aware of it, with the information required by article 33.3 GDPR and whatever becomes known afterwards.
Return and deletion
On termination of the service, the controller can download their book in full from the application. Thirty days after closing the account, the processor deletes the data and its backups, except what a law obliges it to keep (art. 30 of the Código de Comercio; art. 29 of Ley 58/2003, General Tributaria), which remains blocked until the period ends.
Version
The current version is the one shown in the header. The application records which version each controller accepted and when; when something substantial changes, acceptance of the new one will be requested before continuing.