The agreement of article 28 GDPR, which governs our reading of your accounting. You accept it on the connection screen, before the first reading — not at payment.
Data Processing Agreement (article 28 GDPR)
Anthracite Brussels — accounting takeover and filing preparation · Version 1.5 — 7 August 2026
This agreement is the annex on personal data of the Terms of Service. It is self-contained: it refers to no other text.
⏱ You accept it on the connection screen — before you give us your key, and before we read anything at all. Not at payment, not at delivery.
Why that moment and not a more convenient one. What makes us a processor is the first reading of your data, which happens at the free diagnosis. An agreement accepted after that would leave the most sensitive step of the journey outside any written framework, and no text signed later repairs a permission collected after the fact. So we ask before, at the only moment where asking means anything.
Between
You, identified on the order, hereafter the Controller;
and
Charbon Cinéma SRL, a limited liability company incorporated in Belgium, rue Berthelot 172, 1190 Forest, Belgium, enterprise and VAT number BE 0669.654.643, RPM/RPR Brussels, trading as Anthracite Brussels, hereafter the Processor;
together, the Parties.
Article 1 — Purpose and definitions
1.1. This agreement governs the processing of personal data carried out by the Processor on behalf of the Controller in the context of the accounting takeover service described in the Terms of Service.
1.2. "Personal data", "processing", "controller", "processor", "personal data breach" and "data subject" have the meaning given to them by article 4 of Regulation (EU) 2016/679 ("GDPR").
1.3. This agreement is the single annex on data protection to the Terms of Service. Where the two texts contradict each other on a data-protection point, this agreement prevails.
Why that priority clause. It stops a sentence written to be readable in the Terms of Service from being used as a derogation from an obligation article 28 puts beyond the reach of the parties.
Article 2 — Which role each party has
2.1. You act as controller. You determine the purposes and means of the processing of your accounting, and you decide to have it migrated.
2.2. We act as processor. We exercise no control over your purposes, we do not determine the content of the data processed, and we use it for no purpose of our own.
2.3. Where you are an accounting professional. Where you are an accounting firm or any professional acting for your own clients, you are yourself a processor for them and we act as sub-processor within the meaning of article 28(4) GDPR. In that case you warrant that you hold your clients' written authorisation, or a documented general authorisation, allowing you to use us. This agreement then applies mutatis mutandis, with you exercising the controller's prerogatives.
2.4. An accounting professional remains bound by professional secrecy and by the duty of confidentiality, in particular under article 50 of the Act of 17 March 2019. This agreement, and article 5 in particular, exists among other things so that entrusting data to us is compatible with both.
Why this article. Accounting firms are a channel we sell to. Without this written qualification the chain of processors would be implicit, and the authorisation of the firm's own clients — which article 28(2) requires — would be impossible to check.
Article 3 — Processing on documented instructions (art. 28(3)(a))
3.1. We process personal data only on your documented instructions. The following, and nothing else, are those instructions:
- this agreement and its Annex 1;
- the Terms of Service you accepted;
- the order, including the identification of the company being taken over (name, enterprise number, VAT number, technical identifier of the source database and internal identifier of the company) and the level of takeover chosen;
- your own triggering of the build, from your browser, with your own API key;
- any later instruction sent in writing to
support@anthracite.brussels.
3.2. We transfer no data to a third country or to an international organisation, unless required to do so by a law we are subject to; in that case we inform you of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
3.3. We inform you immediately if, in our view, an instruction infringes the GDPR or another provision of Union or Belgian data-protection law, and we suspend that instruction until you confirm it in writing.
Why 3.3, in the words of the law itself. It is the last paragraph of article 28(3). It also heads off a temptation that runs the other way: getting a customer to sign a convenient statement both parties know to be inaccurate. Such a statement would have no effect towards the supervisory authority or the data subjects — it would only prove we knew.
Article 4 — Purpose, scope and duration
4.1. The purpose is narrow: to perform the service you ordered (the takeover, or the annual-accounts export under Annex C of the Terms of Service), to deliver the result, and where applicable to host the base for the agreed period. It includes determining the price where the price depends on a figure read at the diagnosis (volumes, weight of attached documents, turnover of the year concerned) — that figure is shown to you together with the price, before you order. No processing for any other purpose is authorised: not statistics, not improving our software, not training an automated system, not marketing.
Why price determination is named as a purpose. For a company, turnover is not personal data. For a sole trader, it is. Naming it covers the second case and costs the first nothing.
4.2. The nature of the operations, the categories of data, the categories of data subjects and the durations are set out in Annex 1.
4.3. We do not open, index or read the content of the attachments we carry. They are copied wholesale, without inspection.
Why say it that way. It is true, it can be checked in our code, and it is the only honest thing anyone can say about files whose content nobody can vouch for: a scanned receipt may carry health data or data about criminal convictions. Promising there is none would be unverifiable. Promising we do not open them is not.
4.4. The API key you supply is never stored: it is held in memory for the length of one reading and is written to no database, no file, no log and no notification. We send nothing but read operations to your source base, a restriction implemented as a whitelist of methods in the transport component.
4.5. You can revoke your key immediately after each operation. We remind you of that on screen.
Article 5 — Confidentiality (art. 28(3)(b))
5.1. We ensure that persons authorised to process the data have committed themselves to confidentiality, by a written undertaking or under an appropriate statutory obligation. That undertaking survives the end of their involvement.
5.2. Access is limited to the persons whose involvement is necessary to perform the service. The list of persons who had access is provided to you on written request.
Article 6 — Security of processing (art. 28(3)(c) and art. 32)
6.1. We implement the appropriate technical and organisational measures set out in Annex 2, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks involved.
6.2. We may change those measures provided the level of security is not lowered. Any substantial change is brought to your attention.
6.3. ⚠️ No backups — and what that means for you. No backup of the base we build is kept: only one copy exists. Resilience within the meaning of article 32(1)(c) GDPR is provided by the fact that the base can be rebuilt from the source, which stays with you. As a consequence, work you do yourself in the hosted base is not backed up; it is up to you to download a copy, which you can do at any time.
Why we chose that, and why we write it down. Keeping no second copy is a minimisation measure, not a gap — one copy fewer is one copy that cannot leak. But it would be dishonest to let you believe an incident could be undone. The flip side of minimisation is owed to you in writing.
Article 7 — Sub-processors (art. 28(2) and (4))
7.1. You give us a general written authorisation to use the sub-processors listed in Annex 3.
7.2. We inform you of any intended change concerning the addition or replacement of a sub-processor at least thirty days before it takes effect. You have that period to object. If you object on reasoned grounds, we look for a solution together; failing that, you may end the service in progress and be refunded pro rata for what was not performed.
7.3. We impose on any sub-processor, by contract, the same obligations as those in this agreement, and we remain fully liable to you for its performance of them.
7.4. Where the destination base is hosted by a platform of yours. Where you want the rebuilt books delivered into a platform you hold the subscription for (Odoo Online, odoo.sh), that platform is your processor, not ours, and it does not appear in Annex 3. This is the configuration we recommend.
Why we recommend it. In the opposite configuration the platform would become our sub-processor and article 28(4) would make us answerable for its failures. Your authorisation would be enough legally; it is not enough economically.
Article 8 — Helping you answer data subjects (art. 28(3)(e))
8.1. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests to exercise the rights laid down in Chapter III GDPR.
8.2. If a data subject writes to us directly, we do not answer on the merits: we forward the request to you without delay and tell you we have done so.
8.3. ⚠️ The copy does not update itself. What we hold is a snapshot of your source base. A rectification, an objection or an erasure carried out by you in your source base does not propagate to the copy. You instruct us in writing about what has to be repeated on the copy; failing that, the deletion of the copy at the agreed term (article 10) ends the matter.
Why say it so bluntly. It is the most counter-intuitive consequence of any migration, and the one a customer discovers at the worst possible moment: the day someone exercises a right to erasure. An unpleasant sentence in a contract beats an impossible answer inside a one-month deadline.
Article 9 — Assistance and breach notification (art. 28(3)(f) and art. 33(2))
9.1. We assist you in ensuring compliance with the obligations of articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to us.
9.2. We notify you of any personal data breach without undue delay and at the latest within forty-eight hours of becoming aware of it, by email to the address on your order.
9.3. The notification contains, as far as possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact details of a point of contact. Missing information follows as it becomes available.
Why forty-eight hours rather than "without delay". You have seventy-two hours to notify the supervisory authority. A shorter promise than yours would be one we could not verifiably keep; an open-ended one would put you in default with nothing you could do about it. Forty-eight hours leaves you the time you need and stays achievable without a night shift.
Article 10 — What happens to the data at the end (art. 28(3)(g))
10.1. At the end of the hosting, or on early termination of the service, we delete all personal data processed on your behalf, and any existing copies, unless a legal retention obligation applies or article 10.7 provides otherwise.
10.2. Before deletion you are warned, on the terms of article 16.3 of the Terms of Service — twice on a ninety-day term, at delivery on a seven-day one — and offered again every file produced together with a complete copy of the base.
10.3. Deletion is not carried out unless a hand-over took place after the last work you did in the hosted base.
10.4. Deletion is recorded in a timestamped erasure record listing what was deleted and the check made for each item. That record is provided to you on request.
10.5. There is no backup of the hosted base to erase (article 6.3): its deletion is therefore complete by construction. The one item that outlives it — the comparison report of article 10.7 — does not live in that base but on your order in our own system, and it is deleted at the term article 10.7 sets.
10.6. The API key, never having been stored, does not have to be deleted.
10.7. The one thing that outlives the hosting: the comparison report. The comparison report of article 11 of the Terms of Service is kept on your order for eighteen months from delivery, and deleted at that term. We tell you plainly why, because it is the only exception on this page:
- it is the acceptance document — article 11.2 makes the delivery deemed accepted against it, so a delivery whose report has vanished can no longer be shown to have been accepted, by either of us;
- it is the document a claim is measured against, and article 14.2 of the Terms of Service leaves you twelve months to bring one for any defect other than a defect in the faithfulness of the takeover. A copy we destroyed at the end of the hosting would remove your evidence as much as ours;
- it lets you read it again after the hosted base is gone — which is when you are most likely to need it.
Eighteen months is the twelve of article 14.2 plus a margin for a claim brought on the last day. It is not extended by a renewal of the hosting, and you can ask us to delete it earlier, at which point we do so and note it in the erasure record.
And what happens between the eighteenth month and the twenty-fourth. Article 14.2 of the Terms of Service gives you twenty-four months for a defect in the faithfulness of the takeover, because that kind of defect is only really discoverable at your next closing. This term is shorter than that one, and we would rather say so than round the difference away: past the eighteenth month our copy is gone, and the copies that carry your claim are yours — the PDF attached to your delivery e-mail and the
COMPARISON-REPORT.txtinside your parcel, which article 11.4 of the Terms of Service hands you precisely so that they sit outside our systems and we can never withdraw them. Keep them with the file.
10.8. What that report can contain, and what it cannot. It carries the findings of our checks: counts, account codes, aggregate figures, dates, document types, and — where a check found a difference — a limited sample of the lines concerned, which may include a supplier or customer name. It carries no attachment, no user account, no payroll data, and nothing from a document's contents. It is stored on the order it belongs to, readable only by you (through your order) and by us, and it is covered by the same measures as the rest (Annex 2).
Why a record rather than a promise. Article 28(3)(g) requires deletion; nothing requires proving it. A timestamped record turns an obligation to act into a document that can be checked — and it is the first thing an inspection would ask for.
And why 10.7 exists at all, rather than staying quiet. Making the comparison report survive the hosting was a deliberate choice, and it puts a small amount of your accounting data in our system for longer than everything else. An exception that is not written down is an exception that makes the rule false — and "we delete everything" is exactly the kind of sentence that is either true or worthless. Naming it, timing it, and saying what it can contain costs us a paragraph and keeps the rest of this article exact.
Article 11 — Information and audits (art. 28(3)(h))
11.1. We make available to you all information necessary to demonstrate compliance with the obligations of this agreement.
11.2. You may carry out audits, including inspections, or have them carried out by an auditor you mandate. Such audits take place once a year at most — without limit in the event of a confirmed data breach or an instruction from a supervisory authority — on thirty days' written notice, during working hours, without disrupting our activity, and subject to the auditor's confidentiality undertaking, the auditor not being a direct competitor.
11.3. The cost of the audit is yours, unless the audit reveals a substantial failure on our part.
Why these limits, and why they stop there. Framing how an audit happens is lawful. Removing it or making it impracticable is not — article 28(3)(h) is beyond the reach of the parties, and a clause that emptied it would fall, leaving the statutory regime bare.
Article 12 — Processor's record (art. 30(2))
We keep a record of the categories of processing activities carried out on your behalf, containing the information listed in article 30(2) GDPR. It is made available to the supervisory authority on request.
Article 13 — Where the data is, and transfers
13.1. Processing takes place on servers located in the European Union. No transfer outside the European Economic Area is made.
13.2. Should a transfer ever become necessary, it could only take place after informing you beforehand and on the basis of one of the instruments of Chapter V GDPR.
Article 14 — Your statements and warranties
You state and warrant:
- that you are the controller of the data in the source base, or that you hold its controller's authorisation (article 2.3);
- that you have a legal basis for that processing, in particular your accounting and tax obligations, and that you have informed the data subjects in accordance with articles 13 and 14 GDPR;
- that the source base contains neither special categories of data within the meaning of article 9, nor data relating to criminal convictions within the meaning of article 10, beyond what an accounting necessarily contains, and that you will not put any there while the service is running;
- that you authorise the sub-processors of Annex 3;
- that the key you supply is yours and that you are entitled to let us use it.
Why these statements, and not a statement that there is no personal data at all. Whether a processing exists is an objective question: it does not depend on what the parties agree to write. A statement that an accounting contains no personal data would be untrue as a matter of fact — bank statement lines carry the names of counterparties — and a clause both parties know to be false protects nobody. It only proves we knew.
Article 15 — Liability
15.1. Each Party bears the consequences of its own breaches of the GDPR. Article 82 GDPR applies in relations with data subjects; nothing here derogates from the liabilities it creates, which are beyond the reach of the Parties.
15.2. Between the Parties, and for contractual damage only, the limitation of liability set out in the Terms of Service applies, except for administrative fines and for compensation owed to data subjects under article 82 GDPR, which follow their own regime.
Why that carve-out. Purporting to cap a liability the GDPR attaches directly to the processor towards the data subject would have no effect towards that person, and would weaken the cap where it is valid.
Article 16 — Duration, amendment, governing law
16.1. This agreement takes effect when you accept it, on the connection screen, before the first reading of your base, and ends when all data has been deleted in accordance with article 10.
16.2. It is amended automatically to the extent necessary to comply with a change in applicable law or a decision of a supervisory authority.
16.3. It is governed by Belgian law. Any dispute falls under the exclusive jurisdiction of the courts of the judicial district of Brussels, without prejudice to the competences the GDPR reserves to data subjects and to supervisory authorities.
Annex 1 — Description of the processing (art. 28(3) and art. 30(2))
Subject matter — the takeover of an accounting kept in an Odoo system into an Odoo Community database built for the Controller, or the remote generation of an annual-accounts XBRL file.
Nature of the operations — reading the source base through its programming interface; copying; writing into a fresh base; storage; making available; hosting; deletion. For the annual-accounts offer: reading and computing only, with no hosting.
Purpose — the single purpose described in article 4.1. No purpose of the Processor's own.
Categories of data subjects — the processing bears overwhelmingly on data of legal persons, which recital 14 GDPR puts outside the Regulation. The natural persons who may appear are:
- suppliers, customers and providers trading as natural persons or as self-employed;
- representatives and contact persons of legal persons;
- counterparties named in bank statement lines;
- where applicable, persons mentioned in the supporting documents carried, whose content is not inspected (article 4.3).
Categories of data
| Level of takeover | What is processed |
|---|---|
| Balances | chart of accounts, balances, investment lines; labels of opening entries |
| + The figures | all entries and their labels, including bank statement labels carrying names |
| + Everything | partner records (name, address, VAT number, bank details, any contact details), attached documents |
Not processed: user accounts of the source base, HR and individual payroll data, prospecting and CRM files.
National register numbers. The documents carried may incidentally contain a national register number. The Processor uses it for no purpose whatsoever: it does not index that number, does not search for it, does not cross-reference it with any other data, and treats it only as the opaque content of the document that carries it, on behalf of the Controller.
Durations
| Phase | Duration |
|---|---|
| Diagnosis | aggregates only; no individual data retained |
| Build | the time of the copy |
| Hosting | 14 days from delivery on a paid order, 7 days on an order that cost nothing (art. 16.1 of the Terms of Service), extendable at the time of ordering in units of 7 days up to 53 units; reminders set at D-30 and D-7, which on the seven-day term both fall at delivery. A term already sold is not shortened by a later change to the grid |
| Annual-accounts generation | transient; data deleted on delivery of the file |
| Comparison report | 18 months from delivery, on the order — the one thing that outlives the hosting (art. 10.7) |
| Deletion | at the term, after the reminders of art. 10.2 and a hand-over; timestamped erasure record |
Annex 2 — Technical and organisational measures (art. 32)
- Dedicated, partitioned environment. Building and hosting take place on a machine dedicated
to that purpose, separate from workstations. One Odoo instance and one database per customer.
Each instance runs under its own PostgreSQL role (
LOGIN NOCREATEDB), owning only its own database, so that no customer can list, download, drop or connect to another customer's base — a partition enforced by the database engine itself, below the application. PostgreSQL listens on a local socket only, with password authentication (scram-sha-256). - No customer data on a workstation, and none in a folder synchronised to a third-party service.
- A master password of its own for each instance, randomly generated, stored in a restricted-access file — never a default value.
- The API key is never stored, and log and notification writes are filtered so that it can never appear in them, even truncated.
- Reads only on the source base, implemented as a whitelist of methods in the transport component. A generic dispatcher is refused as well. The list, and the SHA-256 fingerprint of the file that enforces it, are published live.
- No outgoing mail from customer instances: scheduled actions and mail servers are disabled there, so that no base can write to a real recipient.
- Encryption in transit (HTTPS with a recognised certificate) for every access to the instances and for the delivery of files.
- Signed download links, limited in use and expiring.
- Lifecycle journal of the operations that matter (build, making available, reminders, hand-over, destruction) in a register chained by hash.
- No backups: a single copy, rebuildable from the source (article 6.3).
- Proven deletion at end of life, item by item.
- Start-up checks: an instance refuses to start if one of its isolation invariants is not met.
Annex 3 — Authorised sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| OVH SAS, 2 rue Kellermann, 59100 Roubaix, France | supply and operation of the physical infrastructure hosting the servers (dedicated server) | France, European Union |
No other sub-processor is involved. In particular:
- no third-party backup, application monitoring or analytics service has access to the data;
- the payment provider is involved for the financial transaction alone, on your billing data, as an independent controller: it has access to no data from the migrated base and is not a sub-processor;
- where you choose to have your base delivered into a platform you hold the subscription for, that platform is your own processor (article 7.4).
Charbon Cinéma SRL, trading as Anthracite Brussels · rue Berthelot 172, 1190 Forest, Belgium ·
BE 0669.654.643 · RPM/RPR Brussels · support@anthracite.brussels
Data Processing Agreement — version 1.5, 7 August 2026. The version in force on the day you
accept it is the one that applies; earlier versions are archived and available on request.