Skip to main content
pileform
  • FeaturesReview the full path from capture to posted books.
  • IntegrationsPost to your ledger and keep the workbook.
  • Use casesWorkflows for practices, finance teams, and businesses.
  • DownloadUse Pileform on Windows or in your browser.
PricingFor businesses
  • Free toolsFree calculators and checks for everyday finance work.
  • GuidesPractical guides for VAT and bookkeeping workflows.
  • BlogProduct notes and accounting explainers.
  • Help CenterAnswers for setup, capture, review, and posting.
  • FAQQuick answers about Pileform and your data.
ΕλληνικάSign in↗Start free Start free
Legal

Data Processing Agreement.

This DPA forms part of the agreement between you (the “Customer”, acting as data controller for the personal data processed through Pileform) and Encelyte Ltd (“Pileform”, acting as data processor). It implements GDPR Article 28 obligations.

Version 1.3 · 18 August 2026. This DPA reflects how we actually process Customer data today. If your compliance team has specific clauses to negotiate before counter-signature, email contact@pileform.com. We’ll work with you.

1. Parties

Processor: Encelyte Ltd, a Cyprus-registered company, operating the service known as Pileform. Registered office: Makariou III & Vyronos, P. Lordos Center, Block B, 2nd Floor, Office 203, 3105 Limassol, Cyprus. Contact: contact@pileform.com.

Controller: you, the Customer entering into the Pileform service terms.

2. Subject matter and duration

Subject matter: (a) processing of personal data contained in receipts, invoices, and accounting documents the Customer uploads to Pileform, for the purpose of extracting structured data and producing per-supplier Excel workbooks; and (b) where the Customer's users choose to use Pileform's in-app AI assistant, processing of personal data already held in the Customer's own Pileform account (for example supplier names, invoice references, account codes, and amounts) that the assistant includes in its request to the AI provider in order to answer the user's question.

Duration: for the term of the Customer’s service agreement with Pileform, plus the retention periods set out in section 7.

3. Nature and purpose of processing

Pileform performs two distinct kinds of processing. First, on documents the Customer uploads: optical character recognition, language detection, supplier grouping, VAT-rate inference, and structured data extraction, returned to the Customer as Excel workbooks with the original documents embedded for audit traceability. Second, only when a Customer's user sends a message to the in-app AI assistant: retrieval of, and question-answering over, the Customer's own accounting records already held in Pileform (for example supplier ledger balances, VAT return status, spend-by-account summaries, chart-of-accounts mappings, and document lookups), so the assistant can compose a natural-language answer. The assistant cannot access payroll, billing/payment-card data, or team/account-administration data.

4. Categories of personal data

Personal data processed may include, depending on the content of the uploaded documents:

  • Names of payees, customers, suppliers, and signatories appearing on receipts and invoices
  • Postal addresses, email addresses, and phone numbers appearing on commercial documents
  • VAT registration numbers and tax identifiers
  • Monetary amounts, dates, and reference numbers
  • Occasionally, identification numbers (e.g. national IDs printed on certain receipts in some jurisdictions)

No special-category data (Article 9) is intentionally processed. The Customer represents that they will not knowingly upload special-category data.

5. Categories of data subjects

  • End customers of the Customer’s clients (i.e. people whose names appear on receipts)
  • Employees and contractors of the Customer’s clients
  • Suppliers and merchants whose details are printed on receipts

6. Sub-processors

Pileform engages a vetted set of sub-processors, each bound by data protection obligations equivalent to those in this DPA. This is the current, named list as of the date at the top of this page:

  • Cloudflare, Inc. Edge network, application compute (Workers), the primary database (D1), object storage for uploaded documents and generated workbooks (R2), rate-limit and session storage (KV), the in-app assistant's knowledge-base vector index (Vectorize), and Workers AI (the embedding/rerank model that processes the text of a user's question to the assistant when it searches Pileform's own product documentation). Location: the storage and database bindings that hold Customer data carry a Western-Europe location hint — Cloudflare's own term for a best-effort, non-guaranteed placement, not a jurisdiction guarantee (see the Data security page). Transfer mechanism: Cloudflare's Data Processing Addendum, incorporating the EU Standard Contractual Clauses for any processing outside the EEA (see section 12).
  • Mistral AI SAS (Paris, France). The AI provider behind (a) OCR and categorisation of the documents you upload, and (b) the in-app assistant's language model, including composing an answer from the results of queries over your own accounting records already held in Pileform (for example supplier ledger balances, VAT return status, spend-by-account summaries, chart-of-accounts mappings, and document lookups). The assistant cannot reach payroll, billing/payment-card data, or team/account-administration data. Location: headquartered in France (EU); Pileform's own engineering documentation describes its processing as EU-based, but Pileform has not yet obtained Mistral's written confirmation of the exact processing region, data-retention period, or a zero-data-retention commitment, and makes no representation on those specific points until it has. Transfer mechanism: processing understood to remain within the EU/EEA; Standard Contractual Clauses would apply only if that changes (see section 12).
  • Hetzner Online GmbH (Germany, EU). Hosts the capture-pipeline server that receives uploaded documents, orchestrates OCR and categorisation, and runs Pileform's deterministic money and VAT calculations before the result is written to Cloudflare storage; the server does not retain your documents on its own disk beyond the processing run. Transfer mechanism: intra-EU processing (see section 12).
  • Stripe. Payment processing: Checkout, subscription billing, invoicing, and the self-serve customer portal. Receives your billing name, billing address and country, email, and card details (Stripe holds the card details; Pileform only ever sees the last 4 digits). Transfer mechanism: Stripe's own Data Processing Agreement, incorporating the EU Standard Contractual Clauses for any transfer outside the EEA.
  • Resend. Sends transactional email: account verification, job and notification links, billing and compliance reminders. Receives the recipient's email address, name where provided, and the notification content itself (for example a link to a completed job, or the name of a document being requested) — never receipt images or the full extracted ledger data. Location: Pileform's own DNS configuration routes Resend's bounce handling through Amazon SES in the eu-west-1 (Ireland) region; Resend's primary processing region for message content beyond that has not been independently confirmed. Transfer mechanism: Standard Contractual Clauses under Resend's own Data Processing Agreement, where applicable.
  • Sentry (error monitoring). Captures unhandled application errors, tagged with the affected route, error stage, and the user's email address; engineering practice strips passwords, tokens, and receipt content from the error context before it reaches Sentry. Transfer mechanism: Sentry's own Data Processing Agreement and Standard Contractual Clauses, where applicable.

Pileform will notify the Customer in writing (via the email address on the Customer account) of any intended addition or replacement of a sub-processor at least 30 days before the change takes effect. The Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected service with a pro-rata refund of pre-paid fees.

7. Data return and deletion

  • Source PDFs (uploaded files): deleted from primary storage 30 days after upload.
  • Generated workbooks: retained 90 days from generation, then deleted unless the Customer downloads or archives earlier.
  • In-app assistant conversations: the text of your questions and the assistant's answers is retained for 90 days from creation, then deleted automatically by a daily housekeeping job. A separate, content-free record of daily spend per company (a company id, a calendar day, and a running total — no conversation text) is kept for up to 24 months for billing and abuse-prevention purposes.
  • Tax-record retention: the period configured by the Customer in the in-app Settings → Data & exports section (default 7 years system-wide; range 6–30 years with country presets: Cyprus / UK / Ireland / Malta / Spain / Greece 6 years, Netherlands 7, Germany / France / Italy / Lebanon 10), held in encrypted cold storage, to satisfy applicable tax-compliance requirements. The Customer may request earlier deletion of any individual job at any time; Pileform will honour within 30 days unless legally required to retain (e.g. an active tax-audit notice).
  • On termination of the service agreement: the Customer may export all data via the in-app archive download. Pileform will then delete all personal data within 30 days of termination, subject to the configured tax-record retention period.
  • Backups: encrypted, retained 30 days, in a separate region from production. Backups are overwritten on the rolling 30-day cycle.

8. Security measures

  • TLS 1.3 in transit, AES-256 at rest, on all persistence layers
  • Primary storage and processing in an EU-region cloud, without a pinned legal jurisdiction
  • Per-account row-level isolation in the database; no cross-tenant data visibility
  • Salted PBKDF2 (210,000 iterations) for password hashing
  • HTTP-only, Secure, SameSite=Lax session cookies
  • Rate limiting on all endpoints, especially upload and authentication
  • Per-action audit log retained 90 days for sign-in attempts, available to the Customer on request
  • No third-party scripts on the workspace (app.pileform.com): no tag managers, analytics, or session-replay tools
  • Encrypted nightly backups, retained 30 days in a separate region
  • Vendor security review on each sub-processor before onboarding
  • Documented incident response plan with named contact

9. Audit rights

The Customer may, no more than once per twelve months, request a written summary of Pileform’s technical and organisational measures and the SOC2 / ISO 27001 attestations of named sub-processors. Pileform will respond within 30 days. On-site audits are not standard given Pileform’s size; an external auditor under NDA may be substituted at the Customer’s cost where the Customer has a demonstrable regulatory requirement.

10. Data subject requests

Pileform will assist the Customer in responding to data-subject requests under GDPR Articles 15–22. If a data subject contacts Pileform directly, Pileform will forward the request to the Customer within 7 business days and will not respond substantively unless instructed by the Customer.

11. Personal data breach

Pileform will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Customer’s data. The notification will include the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

12. International transfers

Where personal data is transferred outside the European Economic Area to a sub-processor, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 3 (processor-to-processor), with appropriate supplementary measures (encryption, access controls, contractual opt-out from any training on Customer content where the sub-processor offers machine-learning capabilities).

13. Confidentiality

All Pileform personnel with access to personal data are bound by confidentiality obligations and have received GDPR-aware training.

14. Liability

The liability cap and exclusions set out in the Pileform service terms apply to this DPA, save where GDPR or applicable law mandates otherwise.

15. Term and termination

This DPA takes effect when the Customer accepts the Pileform service terms and continues until the service agreement terminates. On termination, the obligations in section 7 (Data return and deletion) survive.

16. Governing law

This DPA is governed by the laws of the Republic of Cyprus and is read together with the Pileform Terms of Service.


Acceptance. The Customer’s use of the Pileform service after the date above constitutes acceptance of this DPA. A counter-signed PDF copy is available on request. Email contact@pileform.com with the subject line “DPA counter-signature.”

Questions or red-line proposals: contact@pileform.com.

pileform

Get product updates

Occasional emails when something meaningful ships. No spam, unsubscribe any time.

We will only email you about Pileform. Unsubscribe any time.

Product

FeaturesPricingFAQDownloadFor businessesPayroll (Cyprus)IntegrationsUse cases

Resources

All guidesCyprus VAT essentialsFiling VAT on TFACyprus VAT ratesGreece myDATA e-invoicing guideROI calculatorCompare PileformFrom the blogHelp Center

Free tools

VAT calculatorInvoice generatorReverse-charge checkerVAT return deadlinesSalary calculatorPAYE calculatorLoan calculatorCurrency converterAll free tools

Company

AboutContactChangelog

Legal

Privacy policyTermsCookiesDPAData security
© 2026 Encelyte Ltd. Pileform is a product of Encelyte Ltd.
Proudly crafted in Europe by Encelyte