Data processing agreement
Concluded between the Data Controller (the User) and MB „Debit vs credit“, company code 307536548 (the Data Processor).
Updated: May 2026
1. Subject of the agreement
This agreement governs the processing of personal data carried out by MB „Debit vs credit“ when providing the “Buhalterio Kalendorius” service.
2. Purpose of processing
Data is processed solely in order to:
- Provide the “Buhalterio Kalendorius” software service
- Ensure the operation and security of the system
- Comply with legal requirements
3. Categories of data processed
- User identification data (name, email)
- Client company data (names, VAT codes, company codes)
- Employee data (names, positions) entered into the system by the user
- Activity log data
4. Obligations of the data processor
- Process data only on the controller's instructions
- Ensure appropriate technical and organisational security measures
- Not disclose data to third parties without the controller's consent
- Assist the controller in ensuring data subjects' rights
- Report personal data breaches within 72 hours
- Delete or return the data when the agreement ends
5. Sub-processors
MB „Debit vs credit“ uses the following sub-processors:
- Supabase Inc. (database, EU region)
- Stripe Inc. (payments, where applicable)
6. Data security
The following security measures are applied:
- Encryption in transit (SSL/TLS)
- Access control (authentication)
- Row-level security (RLS) in the database
- Regular backups
7. Retention period
Data is kept for as long as the account exists. After the account is deleted, data is erased within 30 days.
8. Ensuring data subjects' rights
The data processor undertakes to help the data controller respond to data subjects' requests to exercise their rights within 30 days.
9. Term of the agreement
The agreement remains in force for as long as the user uses the “Buhalterio Kalendorius” service.
10. Contacts
MB „Debit vs credit“, company code: 307536548, email: info@debitvscredit.lt