Prepare your organization for tomorrow's digital threats! Get report

DATA PROCESSING AGREEMENT (“DPA”)

  1. GENERAL PROVISIONS
    1. This Data Processing Agreement (“DPA”), together with our Terms of Service, our Data Protection Policy and any other specific framework agreement related to the cooperation between the parties (collectively, the “Main Agreement”), is entered into by and between XOPERO SOFTWARE S.A., with its registered office in Gorzów Wielkopolski, Poland, at 3 Franciszka Walczaka Street, 66-400 Gorzów Wielkopolski, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0000684240, Tax ID (NIP): 5993066603, Statistical ID (REGON): 080285693, represented by Łukasz Jesis – CEO (referred to as “XOPERO”, “we” or “us”, the “Company” or the “Processor”), and any person or entity being a Client (referred to as the “Client”, “you” or the “Controller”), each referred to individually as a “Party” and collectively as the “Parties”.
    2. This DPA supplements and forms an integral part of the Terms of Service and/or any other specific framework agreement related to the cooperation between the Parties – collectively referred to as the “Main Agreement.”
    3. This DPA shall be effective as of the date of execution of the Main Agreement. If this DPA is entered into after the date on which the Processor began processing Personal Data pursuant to the Main Agreement, its provisions shall apply mutatis mutandis to the processing performed from the date on which the Services began to be provided and/or the Software became available.
    4. Capitalized terms not otherwise defined in this DPA shall have the meanings assigned to them in the Main Agreement.
    5. In the event of any conflict between this DPA and the Main Agreement, the provisions of this DPA shall prevail with respect to the protection of personal data. In the event of any conflict between this DPA and the Standard Contractual Clauses referred to in Section 8.3, those clauses shall prevail with respect to the transfer of Personal Data to third countries.
    6. This DPA does not cover the processing of personal data in respect of which the Processor acts as an independent controller, in particular data processed for the purpose of entering into and settling the Main Agreement, maintaining accounting records, managing the Controller’s account and verifying the permissions of its users, ensuring the security and operational continuity of the Software and/or Services, including security telemetry and diagnostic data, handling service requests, and fulfilling the legal obligations incumbent upon the Processor. In this regard, the Processor acts on the basis of its own legal grounds, and the rules for processing are set forth in the Processor’s privacy policy.
    7. The Processor is authorized to generate and use anonymized and aggregated data created in connection with the provision of the Services and/or the provision of the Software for statistical purposes and for the maintenance, development, and improvement of the Software and Services, provided that such data does not allow for the identification of the Controller, its end users, or any other natural person. Anonymized data does not constitute Personal Data and is not subject to this DPA.
  2. SUBJECT MATTER OF THE AGREEMENT
    1. The Parties enter into this DPA, pursuant to which the Controller entrusts the Processor with the processing of all personal data. The entrustment of personal data to the Processor is made for the purpose of performing the Main Agreement, in particular with respect to the Controller’s use of the Processor’s Services and/or Software under the Main Agreement.
    2. The Processor may process the provided data only to the extent and for the purpose specified in the Main Agreement and to the extent and for the purpose necessary to provide the services specified in the Main Agreement.
    3. The Processor shall not store, use, sell, or disclose the Controller’s Personal Data for any purpose other than that necessary to fulfill the Main Agreement and as set forth in the instructions provided by the Controller.
    4. Categories of Data Subjects Whose Personal Data is Transferred – The Controller may transfer Personal Data during the use of the Services and/or Software, the scope of which is determined and controlled by the Controller at its sole discretion, which may include, but is not limited to, Personal Data relating to the following categories of data subjects:
      1. The Controller’s end users, including the Controller’s customers and business partners.
      2. Persons affiliated with the Controller, including representatives, advisors, and employees.
    5. Categories of Personal Data Transferred – The Controller may transfer or authorize other third parties to transfer Personal Data to the Processor, the scope of which is determined and controlled by the Controller at its sole discretion, and which may include, but is not limited to, the following categories of Personal Data:
      1. first name, last name, phone number, email address, shipping and billing addresses of customers, information about customer orders, purchase history, products purchased, store credit (trade credit), labels, and notes;
      2. employees’ first and last names, employment details such as job title;
      3. title, phone number, business address, and email address;
      4. any other Personal Data submitted by, sent to, or received by the Controller and/or its end users.
    6. A significant portion of the Personal Data entrusted to the Processor is contained in backup copies, which are subject to encryption. The Processor does not have access to the content of the encrypted backup copies nor the technical capability to determine which categories of Personal Data and which categories of data subjects they concern.
    7. The Parties do not anticipate the transfer of special categories of personal data as defined in Article 9 of the GDPR or of the data referred to in Article 10 of the GDPR. The Controller declares that it will not include such data in the Software or transfer it to the Processor without first notifying the Processor and agreeing on additional security measures with the Processor. Due to the nature of the Services and the encryption of backup copies, the Processor does not verify and is unable to verify the scope of the data included by the Controller.
    8. The frequency of data transfers (e.g., whether data is transferred on a one-time basis or continuously) depends on the use of the Software and/or Services under the Main Agreement.
    9. Nature of Processing – Personal Data will be processed in accordance with the Main Agreement (including this DPA) and may be subject to the following Processing activities:
      1. creating copies of content for storage and backup purposes;
      2. enabling the restoration of such copies at the Controller’s discretion;
      3. as necessary to ensure access to the Services and/or Software and in accordance with the Main Agreement, as well as otherwise in accordance with the Controller’s instructions; and
      4. disclosing such data in accordance with the Main Agreement (including this DPA) and/or as required by applicable law.
    10. Purpose of Data Transfer and Further Processing – The Processor shall process Personal Data to the extent necessary to provide access to the Software and/or Services in accordance with the Main Agreement and in accordance with the Controller’s further instructions regarding the Controller’s use of the Software and/or Services.
    11. Period for which personal data will be retained – The Processor will process Personal Data for the duration specified in the Main Agreement, unless otherwise agreed upon on a case-by-case basis; Subprocessors will process Personal Data to the extent necessary to provide access to the Software and/or Services in accordance with the Main Agreement and in accordance with further instructions from the Controller.
    12. The Controller’s instructions regarding the processing of Personal Data must be in documentary form, including via email sent to the contact address specified in the Main Agreement. Instructions that go beyond the standard functionality of the Software and/or the scope of Services specified in the Main Agreement require a separate agreement between the Parties and may be carried out for a fee, according to the Processor’s rates. The Processor is entitled to refuse to carry out an instruction if its execution is technically impossible, contrary to the Main Agreement, or would violate the law.
  3. DECLARATIONS AND OBLIGATIONS
    1. The Processor declares that it possesses the infrastructure, resources, experience, expertise, and well-qualified personnel capable of performing its duties in accordance with applicable law. In particular, the Processor declares that it is familiar with the rules governing the processing and protection of personal data set forth in Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as “GDPR”).
    2. Each Party shall comply with applicable data protection laws, in particular the GDPR.
    3. The Processor is obligated to:
      1. process the personal data provided solely pursuant to the Main Agreement and this DPA, except where required to do so by law; where the Processor’s processing of personal data is required by law, the Processor shall notify the Controller electronically – prior to commencing processing – of such legal obligation, unless the law prohibits the disclosure of such information on the grounds of an important public interest;
      2. process the personal data provided in accordance with the GDPR and this DPA;
      3. ensure that persons authorized to process the data maintain its confidentiality;
      4. implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk posed by a breach of the rights or freedoms of natural persons whose personal data will be processed;
      5. assist the Controller in fulfilling its obligation to respond to a request from a data subject regarding the exercise of the rights set forth in Chapter III of the GDPR. The assistance referred to in the preceding sentence shall be provided within a reasonable timeframe, to the best of the Processor’s ability, taking into account the nature of the processing and the information available to the Processor. The Controller shall first use the tools made available to it as part of the Software and/or Services;
      6. assist the Controller in:
        • ensuring the security of personal data processing by implementing appropriate technical and organizational measures;
        • reporting any personal data breaches to the supervisory authority and notifying the data subjects of such breaches;
        • conducting the data protection impact assessment referred to in Article 35 of the GDPR, and prior consultations with the supervisory authority referred to in Article 36 of the GDPR.
      7. immediately notify the Controller if, in the Processor’s assessment, an instruction issued to it constitutes a violation of the GDPR or other personal data protection regulations; in such a case, the Processor is entitled to suspend compliance with the instruction until it is confirmed or amended by the Controller.
    4. The assistance and support referred to in Section 3.3(e) and (f) shall be provided to a reasonable extent, taking into account the nature of the processing and the information available to the Processor. Activities that go beyond the standard functionality of the Software and the scope of Services specified in the Main Agreement may be performed for a fee, in accordance with the Processor’s rates.
  4. TECHNICAL AND ORGANIZATIONAL MEASURES
    1. The Processor shall implement and apply appropriate technical and organizational measures to ensure a level of security appropriate to the risk posed by a breach of the rights or freedoms of natural persons whose personal data will be processed on the basis of and within the scope of this DPA.
    2. When assessing whether the level of security referred to above is appropriate, the Processor is required to take into account the risks associated with the processing, in particular those resulting from accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure, or any unlawful access to personal data that is transmitted, stored, or processed.
    3. When implementing technical and organizational measures, the Processor:
      1. shall comply with the Controller’s guidelines regarding security measures for the processing of personal data in accordance with applicable law – within the limits of the Software’s functionality and the scope of Services specified in the Main Agreement; the implementation of measures exceeding this functionality requires a separate agreement in documentary form (incl. e-mail) between the Parties and may be provided for a fee, according to the Processor’s rates;
      2. takes into account current technical knowledge, the context, nature, scope, and purposes of the processing, as well as the risk of infringing upon the rights or freedoms of natural persons whose personal data will be processed on the basis of and within the scope of this DPA.
  5. SUB-PROCESSING
    1. The Controller consents to the Processor further entrusting the processing of personal data to other entities to the extent and for the purpose consistent with the Main Agreement.
    2. The Processor shall ensure that it will use services provided exclusively by processors that offer sufficient guarantees regarding the implementation of appropriate technical and organizational measures so that the processing complies with the requirements of the GDPR, as well as current laws regarding the protection of personal data.
    3. If the Controller elects for the Services to be provided exclusively using infrastructure located within the European Union/European Economic Area, only entities identified as being located within the EU/EEA for the given Controller shall be used.
    4. The list of subprocessors is available on the Processor’s website and is divided into IT Infrastructure Subprocessors and Service Subprocessors, as well as by the location of the respective Subprocessor.
    5. The Controller acknowledges that the use of the Software and/or Services requires the Processor to collaborate with IT Infrastructure Subprocessors as a key element of the performance of the Main Agreement.
    6. The Processor has the right to make changes to the list of IT Infrastructure Subprocessors who provide services directly related to the Controller, provided that the Controller is notified in advance – at a minimum via email – 30 days prior to the change, specifying the scope and reasons for the change. The Controller has the right to object within 7 days of receiving the notice; such an objection must be justified. Failure to object within this period constitutes the Controller’s implied consent to the change.
    7. The Processor has the right to make changes to the list of Service Subprocessors by modifying the list on the Processor’s website, with at least 14 days’ advance notice. The Controller has the right to raise a reasoned objection within 7 days of the date the change is published or the date of receipt of the notice – whichever occurs first. Failure to object within this period constitutes the Controller’s implied consent to the change.
    8. If the Controller raises a reasoned objection as referred to in Section 5.6 or 5.7, the Parties shall engage in good-faith negotiations to agree on an alternative solution within 30 days of the Processor’s receipt of the objection. If the Parties fail to agree on a solution within this period, either Party is entitled to terminate the Main Agreement with respect to the Services and/or Software to which the objection relates, subject to a 30-day notice period, without either Party being liable for damages in this regard. The Controller is then entitled to a refund of fees paid in advance for the unused period of provision of such Services.
    9. The Processor shall be fully liable to the Controller for compliance with the contractual obligations under the GDPR entered into between the Processor and the Subprocessors. If a Subprocessor fails to fulfill its obligations regarding the protection of personal data, the Processor shall be liable to the Controller for such failure to comply with these contractual obligations.
  6. AUDITS
    1. The Controller is entitled to verify the Processor’s compliance with this DPA, the Main Agreement, and applicable laws regarding the processing of personal data, in accordance with the rules set forth in this section, no more than once every twelve (12) consecutive months; in particular, the Controller may verify the compliance and adequacy of the technical and organizational measures implemented by the Processor to secure the processing of personal data. The limitation on frequency referred to in the preceding sentence shall not apply in the event of a confirmed breach of the protection of personal data entrusted by the Controller, or where the verification is conducted at the request of the competent supervisory authority.
    2. The verification referred to in Section 6.1 is carried out, first and foremost, by the Controller issuing a request to the Processor to provide the necessary explanations within 30 days.
    3. As part of the request referred to above, the Controller is entitled to require the Processor to provide internal documentation regarding the protection of personal data, as well as to submit relevant certificates or reports and the results of audits conducted by independent third parties – provided that this is permissible. The Processor’s submission of current certificates or reports from independent auditors covering the scope of the request shall be deemed sufficient to fulfill the obligation referred to in Article 28(3)(h) of the GDPR.
    4. If the Processor fails to respond within the specified time limit, provides an incomplete response, or if the documents submitted do not demonstrate compliance within the scope of the request, the Controller shall be entitled to conduct a direct audit in accordance with the rules set forth below.
    5. The Controller shall notify the Processor of its intention to conduct the direct audit at least 14 days prior to the scheduled date of the audit. If, in the Processor’s assessment, the audit cannot be conducted on the specified date for valid reasons, the Processor shall notify the Controller of this fact, providing justification for such assessment. In such a case, the Parties shall jointly agree on an alternative date for the audit.
    6. A direct audit may be conducted only by the Controller or by an independent external auditor who is neither a competitor of the Processor nor an entity affiliated with such a competitor, and who, prior to the commencement of the audit, enters into a confidentiality agreement with the Processor under terms no less restrictive than those binding on the Parties. The Processor has the right to raise a reasoned objection to the auditor; in such a case, the Controller shall designate another auditor.
    7. A direct audit may be conducted by the Controller or by third parties commissioned by the Controller to perform the audit, exclusively on business days between 8:00 a.m. and 4:00 p.m., for a period not exceeding three (3) consecutive business days.
    8. The Processor is obligated to cooperate with the auditors, in particular by providing them with access to premises and documents containing personal data and information regarding the methods of processing personal data, ICT infrastructure, and IT systems, as well as to individuals with knowledge of the personal data processing operations carried out by the Processor. The obligation referred to in the preceding sentence does not apply to: (a) personal data, documents, systems, and environments relating to the Processor’s other clients, including shared (multi-tenant) environments, to the extent that providing access to them would lead to the disclosure of data or information concerning those clients; (b) information constituting trade secrets of the Processor or third parties not covered by the scope of the audit; (c) the facilities and infrastructure of third parties, including data processing centers of IT Infrastructure Subprocessors, with respect to which the Processor has neither the right of access nor the authority to grant such access – in this regard, the Processor shall provide the certificates and audit reports it holds for such entities. The audit may not include penetration tests or other active security tests of production environments without the prior, separate consent of the Processor.
    9. Following the audit, a representative of the Controller shall prepare an audit report, which shall be signed by representatives of both Parties; the Processor has the right to include comments and reservations in the report. The Processor undertakes, within a reasonable timeframe agreed upon with the Controller, to comply with the reasonable post-audit recommendations contained in the report, aimed at rectifying deficiencies and improving the security of personal data processing.
    10. The costs associated with conducting the audit shall be borne by the Controller, including the costs of the external auditor. The Processor shall perform activities related to supporting the audit free of charge for up to sixteen (16) work hours in any period of twelve (12) consecutive months; support exceeding this limit, as well as support for any subsequent audit conducted during the same period, shall be provided for a fee, in accordance with the Processor’s rates. The preceding sentences do not apply if the audit reveals a material breach of this DPA by the Processor – in such a case, the Processor shall bear the reasonable costs of the audit.
  7. DATA BREACH DETECTION
    1. The Processor is obligated to implement and comply with procedures for detecting data breaches and to implement appropriate remedial measures.
    2. Upon discovering a breach involving personal data entrusted to the Processor by the Controller, the Processor shall, without undue delay and, if possible, no later than 48 hours after the breach is discovered, notify the Controller of the situation.
    3. If, and to the extent that, it is not possible to provide full information about the breach within the timeframe specified in Section 7.2, the Processor shall provide the information in stages, as it becomes available, without undue delay. The notification of the breach, as well as the actions taken by the Processor to investigate it or mitigate its effects, do not constitute an admission of liability or fault on the part of the Processor.
    4. The Processor shall, without undue delay, take all reasonable measures to minimize and remedy the adverse effects of the breach.
    5. The Processor is required to document every breach of the personal data entrusted to it, including the circumstances of the breach, its effects, and the corrective measures that have been taken.
  8. POSSIBLE TRANSFER OF DATA TO THIRD COUNTRIES
    1. Any Personal Data transferred by the Controller from the territory of the European Union/European Economic Area will, as a general rule, be processed exclusively within that territory and will not be transferred to third countries.
    2. The Controller has the right to choose a location outside the European Union/European Economic Area for the storage of its Personal Data – in such a case, the Controller acknowledges that such a choice shall be tantamount to an instruction to transfer Personal Data to a third country.
    3. The Processor shall ensure that any potential transfers of Personal Data to third countries will be carried out based on appropriate legal mechanisms (e.g., Standard Contractual Clauses or adequacy decisions, such as the Data Privacy Framework).
  9. TERM OF THE AGREEMENT AND LIABILITY PROVISIONS
    1. This DPA is entered into for a fixed term and expires upon termination of the Main Agreement.
    2. In the event of termination of the Main Agreement, this DPA shall expire concurrently with it.
    3. Within 30 days of the termination or expiration of the Main Agreement, the Processor – in accordance with the Controller’s choice, which must be communicated no later than the date of termination or expiration of the Main Agreement – shall return all Personal Data to the Controller or delete it. Failure to communicate a choice within the aforementioned timeframe shall constitute an instruction to delete the Personal Data.
    4. The return of Personal Data shall be carried out using the export functionality provided in the Software. Returning the data by any other means, as well as providing access to the Software solely for the purpose of downloading data following the termination or expiration of the Main Agreement, requires a separate agreement between the Parties and may be subject to a fee, in accordance with the Processor’s rates.
    5. The Processor is entitled to continue storing Personal Data to the extent and for the period required by law; in such a case, the Processor shall limit processing solely to the purpose arising from such provisions, while continuing to apply the provisions of this DPA. The Parties agree that the deletion of Personal Data from the Processor’s backup and archive copies shall take place in accordance with the retention and overwriting cycle adopted by the Processor for such copies, no later than 30 days from the date of deletion of the data from the production environment.
    6. Upon the Controller’s request, submitted within 30 days of the date of deletion of the Personal Data, the Processor shall provide documentary (incl. e-mail) confirmation of such deletion.
    7. The Controller has the right to terminate this DPA with immediate effect solely for good cause, including a breach by the Processor or Subprocessor of the provisions of the GDPR and other mandatory legal provisions or the terms of this DPA, in particular if:
      1. the competent supervisory authority determines in a final decision that the Processor or Subprocessor is in violation of the rules governing the processing of personal data;
      2. a final judgment by a court of general jurisdiction establishes that the Processor or Subprocessor is not complying with the rules governing the processing of personal data.
    8. Termination of this DPA shall be deemed to constitute termination of the Main Agreement to the extent that its performance requires the entrusting of Personal Data for processing.
    9. In the event of a breach of mandatory legal provisions or the provisions of this DPA due to fault on the part of the Processor, resulting in the Controller being required to pay damages or an administrative fine, the Processor shall be obligated to reimburse such expenses – to the extent corresponding to the degree to which the Processor is liable for the damage caused by the processing, as determined in accordance with Article 82(5) of the GDPR. The obligation referred to in the preceding sentence arises provided that: (a) the obligation to pay results from a final decision by a supervisory authority or a final court judgment; (b) the Controller promptly notified the Processor of the initiation of the proceedings, enabled the Processor to participate in such proceedings, and coordinated its procedural position with the Processor; and (c) the Controller did not acknowledge the claim or enter into a settlement without the Processor’s prior consent expressed in documentary form (incl. e-mail). The Processor shall not be liable to the extent that the obligation to pay arises from the Controller’s instructions, from the Controller’s violation of personal data protection regulations or the provisions of the Main Agreement, or from data entered by the Controller into the Software in violation of Section 2.7.
  10. LIABILITY AND FINAL PROVISIONS
    1. The total liability of each Party for non-performance or improper performance of this DPA, regardless of the legal basis for the claim, is subject to the limitations of liability set forth in the Main Agreement. Liability under this DPA and liability under the Main Agreement are subject to a single, combined monetary limit set forth in the Main Agreement, and amounts paid under this DPA shall be credited against that limit.
    2. Neither Party shall be liable for indirect damages, lost profits, loss of anticipated savings, or loss of reputation.
    3. The limitations referred to in Sections 10.1 and 10.2 do not apply to damages caused intentionally or to liability that cannot be excluded or limited under mandatory provisions of law. These limitations do not affect the Parties’ liability toward data subjects and supervisory authorities arising from Article 82 of the GDPR.
    4. If any part of this DPA is held to be invalid or unenforceable, this shall not affect the validity of the remaining provisions of this DPA, which shall remain valid and enforceable in accordance with their terms.
    5. Any amendments to this DPA must be made in the same (or a higher) form, failing which they shall be null and void.
    6. This DPA may be entered into in writing or in electronic form using qualified electronic signatures, as well as through the Controller’s acceptance of the Main Agreement incorporating the terms of this DPA.
    7. This DPA shall be governed by Polish law. Any disputes arising out of or in connection with this DPA shall be settled by the common court having jurisdiction over the Processor’s registered office, unless the Main Agreement provides otherwise.