Concluded pursuant to Article 28(3) of the EU General Data Protection Regulation 2016/679 ("GDPR"), as an integral part of the User's collaboration with BID Grupa d.o.o. (hereinafter: Provider) for website creation and/or maintenance services. It is applied together with the corresponding signed Agreement and the General Terms of Collaboration.
In the relationship regulated by the Agreement, the User is the Data Controller, and the Provider is the Data Processor of personal data within the meaning of Article 4(7)–(8) of the GDPR.
Nature of Processing — Limited Scope: The Provider, through its own and partner technical infrastructure (CMS, hosting, CDN), enables the transmission and technical processing of personal data generated by the User's business operations. The Provider does not store, analyze, or use the personal data of data subjects beyond the scope of operational log/cache periods necessary for providing technical services and ensuring system security. A more detailed description is provided in Annex DPA-1.
The Provider processes personal data exclusively on the basis of documented instructions from the Controller, contained in the Agreement, General Terms, this DPA, Annex DPA-1, and subsequent written instructions. The Provider will inform the Controller if it considers that an instruction infringes the GDPR or other EU/RH regulations.
All processing activities take place within the EU/EEA. Transfer to a third country requires the written consent of the Controller and is carried out in accordance with Article 44 of the GDPR.
The Controller gives the Provider general written consent for the use of sub-processors, provided that the Provider imposes data protection obligations on the sub-processor that are equivalent to those in this DPA. The Provider will inform the Controller in advance of the intended replacement or addition of sub-processors, with a deadline of 14 days for a reasoned objection. The Provider submits the current list of sub-processors in writing upon request.
The Provider implements appropriate technical and organizational data protection measures suitable for the processing risk: access control (authentication, authorization based on the principle of "least privilege," logging), encryption in transit (TLS) and, where applicable, at rest, regular software updates and security patches, backups, documented change management and incident management processes, contractual confidentiality of all persons under its management. A more detailed description is provided in Annex DPA-2.
All persons processing data under the direction of the Provider have a legal or contractual obligation of confidentiality, which remains valid even after the termination of the Agreement.
If a data subject contacts the Provider directly to exercise their rights under the GDPR (Chapter III.), the Provider forwards the request to the Controller without delay and does not respond independently, except upon the explicit written instruction of the Controller. The Provider provides reasonable technical and organizational assistance to the Controller in fulfilling the data subject's requests.
The Provider shall notify the Controller without undue delay, no later than within 24 hours of becoming aware of a personal data breach, and provide the available information necessary for the Controller to report to the supervisory authority (nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, measures taken or proposed). Corrective measures are borne by the Provider to the extent that the breach occurred as a result of its failure.
The Provider cooperates with the Controller and the Personal Data Protection Agency (AZOP). The Controller has the right to verify compliance through written questionnaires and evidence of measures, and, with a prior notice of 30 days, conduct an audit (alone or through an independent auditor) in a manner that does not disrupt the Provider's operations; the cost of the audit is borne by the Controller.
The Provider designates the legal email address from the Agreement (section 1 — Provider) as the contact point for data protection issues. The Controller designates the DPO email address from the Agreement (section 2 — User) as the contact point. Changes to the contact point are submitted to the other Party in writing at least 14 days before implementation.
The DPA applies for the entire period during which the Provider processes personal data on behalf of the Controller for any active service (Creation or Maintenance). Upon termination of the Agreement, the Provider will, within 30 days, according to the Controller's written choice, return or delete all personal data to which it has access, and provide written confirmation of the execution, except for the part where legal regulations mandate further storage.
The Provider reserves the right to unilaterally amend this DPA in accordance with the development of data protection regulations and technological practices. The amended DPA applies to all Users, including those who signed the Agreement before the amendment. The URL where the DPA is published is not versioned — it always displays the currently valid version.
The Provider will notify the Controller of every amendment in writing at least 60 days before implementation. Material amendments give the Controller the right to object within 30 days and terminate the Agreement without notice; minor amendments apply automatically upon the expiration of the deadline from the first paragraph, unless the Controller objects in writing within that period. The Provider internally archives all versions of the DPA; the archive of previous versions is available upon written request.
Note: The Provider does not store the personal data of data subjects in permanent databases under its control outside the scope of operational logs and cache. Data entered through forms are forwarded to the User's systems according to the configuration.