DATA PROCESSING AGREEMENT (DPA)

concluded on [DATE] in [CITY] between:

  1. [CLIENT COMPANY NAME], with its registered office at [ADDRESS], registered under number [REGISTRATION NUMBER, e.g., KRS/NIP], represented by [FULL NAME OF REPRESENTATIVE], hereinafter referred to as the „Data Controller”,

and

  1. Contractors.es sp. z o.o., registered in the Register of Entrepreneurs of the National Court Register maintained by the District Court in Bydgoszcz, 13th Commercial Division of the National Court Register, under KRS number 0001219274, NIP 5543043884, REGON 543878653, represented by the President of the Management Board, Paweł Bukowski, hereinafter referred to as the „Data Processor”.

§ 1. Subject of the Agreement

  1. Under this Agreement, the Data Controller entrusts the Data Processor with the processing of personal data in connection with the use of the Contractors.es service, in accordance with the terms specified in this Agreement and in the Terms of Service.
  2. The Data Processor undertakes to process personal data only to the extent and for the purposes necessary for the proper functioning of the Contractors.es application.
  3. The Data Controller declares that it has obtained consent from the data owners for further entrustment of data to the Data Processor in the case of data for which it is not the data controller.

§ 2. Scope of Personal Data Processing

  1. The scope of entrusted data includes personal data entered by the Data Controller in the Contractors.es application, e.g., names, surnames, email addresses, phone numbers, employee data, project data, etc.
  2. Categories of data subjects: employees, collaborators, and contractors of the Data Controller.

§ 3. Obligations of the Data Processor

  1. The Data Processor undertakes to: a) process personal data in an automated manner as part of the operation of the Contractors.es application and manually only when necessary for maintenance or development of the application; b) ensure that persons authorized to process personal data have committed to confidentiality; c) implement appropriate technical and organizational measures to ensure the security of personal data in accordance with Article 32 GDPR; d) cooperate with the Data Controller to ensure proper processing of personal data in accordance with applicable law and the Terms of Service; e) keep personal data and methods of securing it confidential, including after termination of this Agreement, and ensure that its employees and other persons authorized to process the entrusted personal data commit to confidentiality in this regard; f) inform the Data Controller of any personal data breaches within 48 hours of their detection.

§ 4. Obligations of the Data Controller

  1. The Data Controller undertakes to: a) ensure that the entrusted personal data have been collected in accordance with applicable law; b) cooperate with the Data Processor to ensure proper processing of personal data in accordance with applicable law, the Terms of Service, and this Agreement.

§ 5. Subprocessing of Data

  1. The Data Processor may entrust personal data to subcontractors (sub-processors) to provide the Contractors.es service. The list of subprocessors to whom data is entrusted is available at https://contractors.es/us/subprocesors/.
  2. The Data Controller consents to the subprocessing of data by the above entities. In the event of new entities being added, the Data Processor will inform the Data Controller of the changes. Lack of consent to such subprocessing may result in termination of the main agreement and discontinuation of the Contractors.es service.
  3. The Data Processor undertakes to ensure that the subcontractors meet technical and organizational requirements so that processing complies with this Agreement and legal requirements.

§ 6. Liability of the Parties

  1. The Data Processor is liable for damages resulting from violations of personal data protection regulations, provided it is proven that it failed to fulfill its obligations under this Agreement.
  2. In the event of a personal data breach resulting from unauthorized access (e.g., by third parties through the infrastructure of the Data Controller or the Data Processor), the Data Processor undertakes to: a) promptly inform the Data Controller of the incident, no later than 48 hours after detection; b) take all reasonable technical, organizational, and legal measures to mitigate the effects of the breach and minimize the risk of further damage. The Data Processor is not liable for damages caused by unauthorized access to personal data unless the damage resulted from gross negligence or willful misconduct of the Data Processor. The Data Controller undertakes to use the service as intended, including securing its own devices and user account access.
  3. The Data Controller is responsible for ensuring that the entrusted data comply with applicable law.

§ 7. Term of the Agreement

  1. The Agreement is concluded for the duration of the provision of the Contractors.es service by the Data Processor.
  2. After termination of the Agreement, the Data Processor undertakes to delete personal data within 30 days.

§ 8. Final Provisions

  1. Matters not regulated by this Agreement shall be governed by GDPR and Polish law.
  2. Disputes arising from this Agreement shall be resolved by the court having jurisdiction over the Data Processor’s registered office.

This Agreement is concluded electronically through electronic acceptance.