DATA PROCESSING AGREEMENT (“DPA”)
- GENERAL PROVISIONS
- This Data Processing Agreement (“DPA”), together with our Terms of
Service, our Data Protection Policy and any other specific framework agreement related to the
cooperation between the parties (collectively, the “Main Agreement”), is entered into by and
between XOPERO SOFTWARE S.A., with its registered office in Gorzów Wielkopolski, Poland, at 3
Franciszka Walczaka Street, 66-400 Gorzów Wielkopolski, entered in the Register of Entrepreneurs of
the National Court Register under KRS number 0000684240, Tax ID (NIP): 5993066603, Statistical ID
(REGON): 080285693, represented by Łukasz Jesis – CEO (referred to as “XOPERO”, “we” or “us”, the
“Company” or the “Processor”), and any person or entity being a Client (referred to as the
“Client”, “you” or the “Controller”), each referred to individually as a “Party” and collectively
as the “Parties”.
- This DPA supplements and forms an integral part of the Terms of Service and/or any other
specific framework agreement related to the cooperation between the Parties – collectively
referred to as the “Main Agreement.”
- This DPA shall be effective as of the date of execution of the Main Agreement. If this DPA is
entered into after the date on which the Processor began processing Personal Data pursuant to the
Main Agreement, its provisions shall apply mutatis mutandis to the processing performed from the
date on which the Services began to be provided and/or the Software became available.
- Capitalized terms not otherwise defined in this DPA shall have the meanings assigned to them in
the Main Agreement.
- In the event of any conflict between this DPA and the Main Agreement, the provisions of this
DPA shall prevail with respect to the protection of personal data. In the event of any conflict
between this DPA and the Standard Contractual Clauses referred to in Section 8.3, those clauses
shall prevail with respect to the transfer of Personal Data to third countries.
- This DPA does not cover the processing of personal data in respect of which the Processor acts
as an independent controller, in particular data processed for the purpose of entering into and
settling the Main Agreement, maintaining accounting records, managing the Controller’s account and
verifying the permissions of its users, ensuring the security and operational continuity of the
Software and/or Services, including security telemetry and diagnostic data, handling service
requests, and fulfilling the legal obligations incumbent upon the Processor. In this regard, the
Processor acts on the basis of its own legal grounds, and the rules for processing are set forth
in the Processor’s privacy policy.
- The Processor is authorized to generate and use anonymized and aggregated data created in
connection with the provision of the Services and/or the provision of the Software for statistical
purposes and for the maintenance, development, and improvement of the Software and Services,
provided that such data does not allow for the identification of the Controller, its end users,
or any other natural person. Anonymized data does not constitute Personal Data and is not subject
to this DPA.
- SUBJECT MATTER OF THE AGREEMENT
- The Parties enter into this DPA, pursuant to which the Controller entrusts the Processor with
the processing of all personal data. The entrustment of personal data to the Processor is made for
the purpose of performing the Main Agreement, in particular with respect to the Controller’s use
of the Processor’s Services and/or Software under the Main Agreement.
- The Processor may process the provided data only to the extent and for the purpose specified in
the Main Agreement and to the extent and for the purpose necessary to provide the services
specified in the Main Agreement.
- The Processor shall not store, use, sell, or disclose the Controller’s Personal Data for any
purpose other than that necessary to fulfill the Main Agreement and as set forth in the
instructions provided by the Controller.
- Categories of Data Subjects Whose Personal Data is Transferred – The Controller may transfer
Personal Data during the use of the Services and/or Software, the scope of which is determined and
controlled by the Controller at its sole discretion, which may include, but is not limited to,
Personal Data relating to the following categories of data subjects:
- The Controller’s end users, including the Controller’s customers and business partners.
- Persons affiliated with the Controller, including representatives, advisors, and
employees.
- Categories of Personal Data Transferred – The Controller may transfer or authorize other third
parties to transfer Personal Data to the Processor, the scope of which is determined and
controlled by the Controller at its sole discretion, and which may include, but is not limited to,
the following categories of Personal Data:
- first name, last name, phone number, email address, shipping and billing addresses of
customers, information about customer orders, purchase history, products purchased, store
credit (trade credit), labels, and notes;
- employees’ first and last names, employment details such as job title;
- title, phone number, business address, and email address;
- any other Personal Data submitted by, sent to, or received by the Controller and/or its end
users.
- A significant portion of the Personal Data entrusted to the Processor is contained in backup
copies, which are subject to encryption. The Processor does not have access to the content of the
encrypted backup copies nor the technical capability to determine which categories of Personal
Data and which categories of data subjects they concern.
- The Parties do not anticipate the transfer of special categories of personal data as defined in
Article 9 of the GDPR or of the data referred to in Article 10 of the GDPR. The Controller
declares that it will not include such data in the Software or transfer it to the Processor
without first notifying the Processor and agreeing on additional security measures with the
Processor. Due to the nature of the Services and the encryption of backup copies, the Processor
does not verify and is unable to verify the scope of the data included by the Controller.
- The frequency of data transfers (e.g., whether data is transferred on a one-time basis or
continuously) depends on the use of the Software and/or Services under the Main Agreement.
- Nature of Processing – Personal Data will be processed in accordance with the Main Agreement
(including this DPA) and may be subject to the following Processing activities:
- creating copies of content for storage and backup purposes;
- enabling the restoration of such copies at the Controller’s discretion;
- as necessary to ensure access to the Services and/or Software and in accordance with the
Main Agreement, as well as otherwise in accordance with the Controller’s instructions;
and
- disclosing such data in accordance with the Main Agreement (including this DPA) and/or as
required by applicable law.
- Purpose of Data Transfer and Further Processing – The Processor shall process Personal Data to
the extent necessary to provide access to the Software and/or Services in accordance with the
Main Agreement and in accordance with the Controller’s further instructions regarding the
Controller’s use of the Software and/or Services.
- Period for which personal data will be retained – The Processor will process Personal Data for
the duration specified in the Main Agreement, unless otherwise agreed upon on a case-by-case
basis; Subprocessors will process Personal Data to the extent necessary to provide access to the
Software and/or Services in accordance with the Main Agreement and in accordance with further
instructions from the Controller.
- The Controller’s instructions regarding the processing of Personal Data must be in documentary
form, including via email sent to the contact address specified in the Main Agreement.
Instructions that go beyond the standard functionality of the Software and/or the scope of
Services specified in the Main Agreement require a separate agreement between the Parties and may
be carried out for a fee, according to the Processor’s rates. The Processor is entitled to refuse
to carry out an instruction if its execution is technically impossible, contrary to the Main
Agreement, or would violate the law.
- DECLARATIONS AND OBLIGATIONS
- The Processor declares that it possesses the infrastructure, resources, experience, expertise,
and well-qualified personnel capable of performing its duties in accordance with applicable law.
In particular, the Processor declares that it is familiar with the rules governing the processing
and protection of personal data set forth in Regulation (EU) 2016/679 of April 27, 2016, on the
protection of natural persons with regard to the processing of personal data and on the free
movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation,
hereinafter referred to as “GDPR”).
- Each Party shall comply with applicable data protection laws, in particular the GDPR.
- The Processor is obligated to:
- process the personal data provided solely pursuant to the Main Agreement and this DPA,
except where required to do so by law; where the Processor’s processing of personal data is
required by law, the Processor shall notify the Controller electronically – prior to
commencing processing – of such legal obligation, unless the law prohibits the disclosure of
such information on the grounds of an important public interest;
- process the personal data provided in accordance with the GDPR and this DPA;
- ensure that persons authorized to process the data maintain its confidentiality;
- implement appropriate technical and organizational measures to ensure a level of security
appropriate to the risk posed by a breach of the rights or freedoms of natural persons whose
personal data will be processed;
- assist the Controller in fulfilling its obligation to respond to a request from a data
subject regarding the exercise of the rights set forth in Chapter III of the GDPR. The
assistance referred to in the preceding sentence shall be provided within a reasonable
timeframe, to the best of the Processor’s ability, taking into account the nature of the
processing and the information available to the Processor. The Controller shall first use
the tools made available to it as part of the Software and/or Services;
- assist the Controller in:
- ensuring the security of personal data processing by implementing appropriate technical
and organizational measures;
- reporting any personal data breaches to the supervisory authority and notifying the
data subjects of such breaches;
- conducting the data protection impact assessment referred to in Article 35 of the GDPR,
and prior consultations with the supervisory authority referred to in Article 36 of the
GDPR.
- immediately notify the Controller if, in the Processor’s assessment, an instruction issued
to it constitutes a violation of the GDPR or other personal data protection regulations; in
such a case, the Processor is entitled to suspend compliance with the instruction until it is
confirmed or amended by the Controller.
- The assistance and support referred to in Section 3.3(e) and (f) shall be provided to a
reasonable extent, taking into account the nature of the processing and the information available
to the Processor. Activities that go beyond the standard functionality of the Software and the
scope of Services specified in the Main Agreement may be performed for a fee, in accordance with
the Processor’s rates.
- TECHNICAL AND ORGANIZATIONAL MEASURES
- The Processor shall implement and apply appropriate technical and organizational measures to
ensure a level of security appropriate to the risk posed by a breach of the rights or freedoms of
natural persons whose personal data will be processed on the basis of and within the scope of
this DPA.
- When assessing whether the level of security referred to above is appropriate, the Processor is
required to take into account the risks associated with the processing, in particular those
resulting from accidental or unlawful destruction or accidental loss, alteration, unauthorized
disclosure, or any unlawful access to personal data that is transmitted, stored, or processed.
- When implementing technical and organizational measures, the Processor:
- shall comply with the Controller’s guidelines regarding security measures for the
processing of personal data in accordance with applicable law – within the limits of the
Software’s functionality and the scope of Services specified in the Main Agreement; the
implementation of measures exceeding this functionality requires a separate agreement in
documentary form (incl. e-mail) between the Parties and may be provided for a fee, according
to the Processor’s rates;
- takes into account current technical knowledge, the context, nature, scope, and purposes of
the processing, as well as the risk of infringing upon the rights or freedoms of natural
persons whose personal data will be processed on the basis of and within the scope of this
DPA.
- SUB-PROCESSING
- The Controller consents to the Processor further entrusting the processing of personal data to
other entities to the extent and for the purpose consistent with the Main Agreement.
- The Processor shall ensure that it will use services provided exclusively by processors that
offer sufficient guarantees regarding the implementation of appropriate technical and
organizational measures so that the processing complies with the requirements of the GDPR, as
well as current laws regarding the protection of personal data.
- If the Controller elects for the Services to be provided exclusively using infrastructure
located within the European Union/European Economic Area, only entities identified as being
located within the EU/EEA for the given Controller shall be used.
- The list of subprocessors is available on the Processor’s website and is divided into IT
Infrastructure Subprocessors and Service Subprocessors, as well as by the location of the
respective Subprocessor.
- The Controller acknowledges that the use of the Software and/or Services requires the Processor
to collaborate with IT Infrastructure Subprocessors as a key element of the performance of the
Main Agreement.
- The Processor has the right to make changes to the list of IT Infrastructure Subprocessors who
provide services directly related to the Controller, provided that the Controller is notified in
advance – at a minimum via email – 30 days prior to the change, specifying the scope and reasons
for the change. The Controller has the right to object within 7 days of receiving the notice; such
an objection must be justified. Failure to object within this period constitutes the Controller’s
implied consent to the change.
- The Processor has the right to make changes to the list of Service Subprocessors by modifying
the list on the Processor’s website, with at least 14 days’ advance notice. The Controller has the
right to raise a reasoned objection within 7 days of the date the change is published or the date
of receipt of the notice – whichever occurs first. Failure to object within this period
constitutes the Controller’s implied consent to the change.
- If the Controller raises a reasoned objection as referred to in Section 5.6 or 5.7, the Parties
shall engage in good-faith negotiations to agree on an alternative solution within 30 days of the
Processor’s receipt of the objection. If the Parties fail to agree on a solution within this
period, either Party is entitled to terminate the Main Agreement with respect to the Services
and/or Software to which the objection relates, subject to a 30-day notice period, without either
Party being liable for damages in this regard. The Controller is then entitled to a refund of fees
paid in advance for the unused period of provision of such Services.
- The Processor shall be fully liable to the Controller for compliance with the contractual
obligations under the GDPR entered into between the Processor and the Subprocessors. If a
Subprocessor fails to fulfill its obligations regarding the protection of personal data, the
Processor shall be liable to the Controller for such failure to comply with these contractual
obligations.
- AUDITS
- The Controller is entitled to verify the Processor’s compliance with this DPA, the Main
Agreement, and applicable laws regarding the processing of personal data, in accordance with the
rules set forth in this section, no more than once every twelve (12) consecutive months; in
particular, the Controller may verify the compliance and adequacy of the technical and
organizational measures implemented by the Processor to secure the processing of personal data.
The limitation on frequency referred to in the preceding sentence shall not apply in the event of
a confirmed breach of the protection of personal data entrusted by the Controller, or where the
verification is conducted at the request of the competent supervisory authority.
- The verification referred to in Section 6.1 is carried out, first and foremost, by the
Controller issuing a request to the Processor to provide the necessary explanations within 30
days.
- As part of the request referred to above, the Controller is entitled to require the Processor
to provide internal documentation regarding the protection of personal data, as well as to submit
relevant certificates or reports and the results of audits conducted by independent third parties
– provided that this is permissible. The Processor’s submission of current certificates or
reports from independent auditors covering the scope of the request shall be deemed sufficient to
fulfill the obligation referred to in Article 28(3)(h) of the GDPR.
- If the Processor fails to respond within the specified time limit, provides an incomplete
response, or if the documents submitted do not demonstrate compliance within the scope of the
request, the Controller shall be entitled to conduct a direct audit in accordance with the rules
set forth below.
- The Controller shall notify the Processor of its intention to conduct the direct audit at least
14 days prior to the scheduled date of the audit. If, in the Processor’s assessment, the audit
cannot be conducted on the specified date for valid reasons, the Processor shall notify the
Controller of this fact, providing justification for such assessment. In such a case, the Parties
shall jointly agree on an alternative date for the audit.
- A direct audit may be conducted only by the Controller or by an independent external auditor
who is neither a competitor of the Processor nor an entity affiliated with such a competitor, and
who, prior to the commencement of the audit, enters into a confidentiality agreement with the
Processor under terms no less restrictive than those binding on the Parties. The Processor has the
right to raise a reasoned objection to the auditor; in such a case, the Controller shall designate
another auditor.
- A direct audit may be conducted by the Controller or by third parties commissioned by the
Controller to perform the audit, exclusively on business days between 8:00 a.m. and 4:00 p.m.,
for a period not exceeding three (3) consecutive business days.
- The Processor is obligated to cooperate with the auditors, in particular by providing them with
access to premises and documents containing personal data and information regarding the methods
of processing personal data, ICT infrastructure, and IT systems, as well as to individuals with
knowledge of the personal data processing operations carried out by the Processor. The obligation
referred to in the preceding sentence does not apply to: (a) personal data, documents, systems,
and environments relating to the Processor’s other clients, including shared (multi-tenant)
environments, to the extent that providing access to them would lead to the disclosure of data or
information concerning those clients; (b) information constituting trade secrets of the Processor
or third parties not covered by the scope of the audit; (c) the facilities and infrastructure of
third parties, including data processing centers of IT Infrastructure Subprocessors, with respect
to which the Processor has neither the right of access nor the authority to grant such access –
in this regard, the Processor shall provide the certificates and audit reports it holds for such
entities. The audit may not include penetration tests or other active security tests of
production environments without the prior, separate consent of the Processor.
- Following the audit, a representative of the Controller shall prepare an audit report, which
shall be signed by representatives of both Parties; the Processor has the right to include
comments and reservations in the report. The Processor undertakes, within a reasonable timeframe
agreed upon with the Controller, to comply with the reasonable post-audit recommendations
contained in the report, aimed at rectifying deficiencies and improving the security of personal
data processing.
- The costs associated with conducting the audit shall be borne by the Controller, including the
costs of the external auditor. The Processor shall perform activities related to supporting the
audit free of charge for up to sixteen (16) work hours in any period of twelve (12) consecutive
months; support exceeding this limit, as well as support for any subsequent audit conducted
during the same period, shall be provided for a fee, in accordance with the Processor’s rates.
The preceding sentences do not apply if the audit reveals a material breach of this DPA by the
Processor – in such a case, the Processor shall bear the reasonable costs of the audit.
- DATA BREACH DETECTION
- The Processor is obligated to implement and comply with procedures for detecting data breaches
and to implement appropriate remedial measures.
- Upon discovering a breach involving personal data entrusted to the Processor by the Controller,
the Processor shall, without undue delay and, if possible, no later than 48 hours after the
breach is discovered, notify the Controller of the situation.
- If, and to the extent that, it is not possible to provide full information about the breach
within the timeframe specified in Section 7.2, the Processor shall provide the information in
stages, as it becomes available, without undue delay. The notification of the breach, as well as
the actions taken by the Processor to investigate it or mitigate its effects, do not constitute an
admission of liability or fault on the part of the Processor.
- The Processor shall, without undue delay, take all reasonable measures to minimize and remedy
the adverse effects of the breach.
- The Processor is required to document every breach of the personal data entrusted to it,
including the circumstances of the breach, its effects, and the corrective measures that have
been taken.
- POSSIBLE TRANSFER OF DATA TO THIRD COUNTRIES
- Any Personal Data transferred by the Controller from the territory of the European
Union/European Economic Area will, as a general rule, be processed exclusively within that
territory and will not be transferred to third countries.
- The Controller has the right to choose a location outside the European Union/European Economic
Area for the storage of its Personal Data – in such a case, the Controller acknowledges that such
a choice shall be tantamount to an instruction to transfer Personal Data to a third country.
- The Processor shall ensure that any potential transfers of Personal Data to third countries
will be carried out based on appropriate legal mechanisms (e.g., Standard Contractual Clauses or
adequacy decisions, such as the Data Privacy Framework).
- TERM OF THE AGREEMENT AND LIABILITY PROVISIONS
- This DPA is entered into for a fixed term and expires upon termination of the Main
Agreement.
- In the event of termination of the Main Agreement, this DPA shall expire concurrently with
it.
- Within 30 days of the termination or expiration of the Main Agreement, the Processor – in
accordance with the Controller’s choice, which must be communicated no later than the date of
termination or expiration of the Main Agreement – shall return all Personal Data to the
Controller or delete it. Failure to communicate a choice within the aforementioned timeframe
shall constitute an instruction to delete the Personal Data.
- The return of Personal Data shall be carried out using the export functionality provided in
the Software. Returning the data by any other means, as well as providing access to the Software
solely for the purpose of downloading data following the termination or expiration of the Main
Agreement, requires a separate agreement between the Parties and may be subject to a fee, in
accordance with the Processor’s rates.
- The Processor is entitled to continue storing Personal Data to the extent and for the period
required by law; in such a case, the Processor shall limit processing solely to the purpose
arising from such provisions, while continuing to apply the provisions of this DPA. The Parties
agree that the deletion of Personal Data from the Processor’s backup and archive copies shall
take place in accordance with the retention and overwriting cycle adopted by the Processor for
such copies, no later than 30 days from the date of deletion of the data from the production
environment.
- Upon the Controller’s request, submitted within 30 days of the date of deletion of the Personal
Data, the Processor shall provide documentary (incl. e-mail) confirmation of such deletion.
- The Controller has the right to terminate this DPA with immediate effect solely for good
cause, including a breach by the Processor or Subprocessor of the provisions of the GDPR and
other mandatory legal provisions or the terms of this DPA, in particular if:
- the competent supervisory authority determines in a final decision that the Processor or
Subprocessor is in violation of the rules governing the processing of personal data;
- a final judgment by a court of general jurisdiction establishes that the Processor or
Subprocessor is not complying with the rules governing the processing of personal data.
- Termination of this DPA shall be deemed to constitute termination of the Main Agreement to the
extent that its performance requires the entrusting of Personal Data for processing.
- In the event of a breach of mandatory legal provisions or the provisions of this DPA due to
fault on the part of the Processor, resulting in the Controller being required to pay damages or
an administrative fine, the Processor shall be obligated to reimburse such expenses – to the
extent corresponding to the degree to which the Processor is liable for the damage caused by the
processing, as determined in accordance with Article 82(5) of the GDPR. The obligation referred
to in the preceding sentence arises provided that: (a) the obligation to pay results from a final
decision by a supervisory authority or a final court judgment; (b) the Controller promptly
notified the Processor of the initiation of the proceedings, enabled the Processor to participate
in such proceedings, and coordinated its procedural position with the Processor; and (c) the
Controller did not acknowledge the claim or enter into a settlement without the Processor’s prior
consent expressed in documentary form (incl. e-mail). The Processor shall not be liable to the
extent that the obligation to pay arises from the Controller’s instructions, from the Controller’s
violation of personal data protection regulations or the provisions of the Main Agreement, or
from data entered by the Controller into the Software in violation of Section 2.7.
- LIABILITY AND FINAL PROVISIONS
- The total liability of each Party for non-performance or improper performance of this DPA,
regardless of the legal basis for the claim, is subject to the limitations of liability set forth
in the Main Agreement. Liability under this DPA and liability under the Main Agreement are
subject to a single, combined monetary limit set forth in the Main Agreement, and amounts paid
under this DPA shall be credited against that limit.
- Neither Party shall be liable for indirect damages, lost profits, loss of anticipated savings,
or loss of reputation.
- The limitations referred to in Sections 10.1 and 10.2 do not apply to damages caused
intentionally or to liability that cannot be excluded or limited under mandatory provisions of
law. These limitations do not affect the Parties’ liability toward data subjects and supervisory
authorities arising from Article 82 of the GDPR.
- If any part of this DPA is held to be invalid or unenforceable, this shall not affect the
validity of the remaining provisions of this DPA, which shall remain valid and enforceable in
accordance with their terms.
- Any amendments to this DPA must be made in the same (or a higher) form, failing which they
shall be null and void.
- This DPA may be entered into in writing or in electronic form using qualified electronic
signatures, as well as through the Controller’s acceptance of the Main Agreement incorporating
the terms of this DPA.
- This DPA shall be governed by Polish law. Any disputes arising out of or in connection with
this DPA shall be settled by the common court having jurisdiction over the Processor’s registered
office, unless the Main Agreement provides otherwise.
View the archived Data Processing Agreement