Data Processing Agreement
Permanent address of this version: https://riadov.systems/en/data-processing-agreement/1-0/
1. Parties and what this agreement is
This is the template Data Processing Agreement (the "Processing Agreement") — the agreement required by Art. 28 GDPR where Riadov Systems processes personal data on behalf of a customer. It forms part of an Order under the Development and Hosting Terms and is concluded in writing or in electronic form (Art. 28(9) GDPR) — as a signed document or by confirmation of the completed text from the customer's e-mail address stated in the Order.
- Controller, "you" — [name or company name], [address], [NIP or other registration number], [who acts on behalf of the controller].
- Processor, "we" — Riadov Systems Vladyslav Riadov, NIP 6972395549, REGON 526790012, ul. Jana Ostroroga 1a/28, 64-100 Leszno, Polska; contact for data and incidents: support@riadov.systems, Telegram @Riadov_Systems.
The fields in square brackets here and in Annexes 1–4 are filled in for each agreement. The terms "personal data", "processing", "controller", "processor", "sub-processor" (another processor) and "personal data breach" have the meaning given in the GDPR. "Order", "Secrets" and "Managed Hosting" have the meaning given in the Development and Hosting Terms.
Earlier agreements are not changed. If a data processing agreement has already been concluded between us, it remains on its own terms. This template replaces it only by written agreement of both parties and does not apply retroactively.
2. Subject matter, nature and purpose of processing
The subject matter, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex 1. We process data only to perform the Order — development, Managed Hosting and Support — and to the extent necessary for that.
The Processing Agreement remains in force for the term of the Order and thereafter — until we have returned and deleted the data under section 12.
3. Processing only on instructions
- We process personal data only on your documented instructions — this Processing Agreement, the Order and written instructions from the contact stated in Annex 1 — including with regard to transfers of data outside the European Economic Area (EEA).
- If Union or Member State law requires us to process data otherwise, we inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- If, in our opinion, an instruction infringes the GDPR or other data protection provisions, we inform you immediately and do not follow that instruction until you reply.
- We do not use your personal data for our own purposes: we do not sell them or use them for advertising, for analytics of our own products, for training artificial intelligence models or as test data in other projects. Reuse of Our Code (Development and Hosting Terms, section 7) never covers your data or Secrets.
- For development and testing we use test or anonymised data. Production data are used only where this cannot be avoided (for example, to investigate a specific failure), and to the minimum extent.
- We use only the artificial intelligence development tools named in Annex 3, under their provider’s commercial terms with a data processing agreement. Production data reach them only to the minimum extent needed to investigate a specific failure. We never transfer health data to artificial intelligence development tools — to investigate such failures we use only synthetic or anonymised data.
4. Who has access
On our side, access to personal data is held only by persons who need it for the Order — those named in Annex 1. Each of them has committed to confidentiality or is under a statutory obligation of confidentiality, and processes data only on your instructions. We admit a new person only under the same obligation and inform you of this.
This applies to our people. Infrastructure providers (section 6) operate on their own terms and may have technical access to their equipment and network. We do not claim that no one other than us has the physical or technical ability to access the servers.
5. Security of processing
We apply the technical and organisational measures required by Art. 32 GDPR, taking into account the risk to the data subjects. The measures and the status of each of them on the date of conclusion are set out in Annex 2. We may change the measures only without lowering the overall level of protection.
We process special categories of data (Art. 9 GDPR), such as health data, and data relating to criminal convictions (Art. 10 GDPR) only if this is expressly stated in Annex 1 together with additional safeguards.
6. Sub-processors
- You give general written authorisation to engage the sub-processors listed in Annex 3, on the terms stated there.
- We inform you of an intended addition or replacement of a sub-processor at the e-mail address in Annex 1 at least within the period set in Annex 1 before it takes effect — stating the name, role, type of data and place of processing. Within that period you may object, giving a reason related to data protection. If we cannot accommodate the objection, you may terminate the Services affected by the change without penalty, with effect from the day the change takes effect.
- Each sub-processor is bound by contract to data protection obligations corresponding to Art. 28(3) GDPR, to the extent of its role. For large infrastructure providers these are their standard data processing agreements: we do not promise individual terms with them.
- We remain fully liable to you for the performance of a sub-processor's data protection obligations.
Who is not our sub-processor. Telegram is the platform through which bots operate: it processes its users' data as an independent controller on its own terms. Your accounts with third-party services (for example, e-mail, cloud storage, a payment provider or a key for an artificial intelligence service) to which the system connects using your access are your providers under your contracts with them.
7. Transfers outside the EEA
We transfer personal data outside the EEA only on your instructions and only on the grounds set out in Chapter V GDPR: on the basis of a European Commission adequacy decision or of standard contractual clauses adopted by the Commission (as at the date of this version, Decision (EU) 2021/914), with supplementary measures where needed. Sub-processors that may process data outside the EEA, and the transfer mechanism, are stated in Annex 3.
8. Data subject requests
- If a data subject contacts us with a request concerning their data in your system, we forward the request to you within the period set in Annex 1 and do not respond to it on the merits ourselves, unless you have instructed otherwise.
- We help you handle requests — access, rectification, erasure, restriction, portability, objection — using the system's tools (export and deletion tools, if the Deliverable includes them) or manually on your written instruction quoting the request number. You verify the data subject's identity and decide on the request.
- Assistance within the limits stated in Annex 1 is provided without separate charge; beyond them, at the rate set in the Order. Assistance needed because of our breach is free of charge.
- If the system's database has to be restored from a backup, we repeat the deletions already carried out before reopening the system.
9. Personal data breaches
- We notify you of a personal data breach affecting your data without undue delay after becoming aware of it — at the incident contact in Annex 1, no later than the time limit stated there.
- The notification contains what we know: what happened, the categories and approximate number of data subjects and records, the likely consequences, the measures taken and planned, and a contact for further information. Whatever we do not know straight away we send in phases, without undue delay.
- We take measures to limit the consequences, document the breach and help you notify the supervisory authority (Art. 33 GDPR) and data subjects (Art. 34 GDPR). Without your instruction we do not notify either the supervisory authority or data subjects in your place, unless the law requires it.
10. Other assistance and records
Taking into account the nature of processing and the information available to us, we help you comply with your obligations under Arts 32–36 GDPR: security of processing, breach notification, data protection impact assessment and prior consultation with the supervisory authority. We maintain a record of the categories of processing carried out on your behalf (Art. 30(2) GDPR) and cooperate with the supervisory authority on request.
11. Information and audits
- At your request we provide the information needed to demonstrate compliance with this Processing Agreement: a description of measures, the list of sub-processors, breach reports, confirmations of deletion.
- You, or an independent auditor mandated by you who is bound by confidentiality, may carry out an audit, including an on-site inspection — with notice and no more often than stated in Annex 1. The frequency limit does not apply after a personal data breach affecting your data or where requested by the supervisory authority.
- An audit gives no access to other clients' data or to infrastructure Secrets and must not endanger the security of systems: on shared infrastructure we show what relates to your data — by demonstration, sample evidence or reports.
- We cannot open the providers' data centres (section 6) to inspection: for them we provide their certificates, reports and data processing agreements — to the extent the provider makes them available.
- Each party bears its own audit costs.
12. End of processing: return and deletion of data
- After the end of the Services involving processing, at your choice we either return all personal data to you (export under the Development and Hosting Terms, section 10) and delete them, or only delete them — within the period set in Annex 1. If you have not told us your choice before the end, we first provide you with an export by a secure method and then delete the data.
- Deletion covers production databases, files, logs containing personal data that we control, and working copies on our devices. We confirm completion of deletion in writing.
- Backups. Data disappear from backups not immediately but when the retention period of the copy containing them expires — in accordance with Annex 4. Until then the copies are not used for any other purpose and are protected in the same way as production data. If a server backup has to be restored, we delete your data from the restored copy before returning the server to operation.
- We may retain data for longer only where Union or Member State law requires it. In that case we tell you which data are retained, on what legal basis and until when, and we process them only for that purpose.
- Deletion in third-party services to which the system is connected through your account (section 6) is your responsibility.
13. Liability, precedence and governing law
Liability between us is governed by the Development and Hosting Terms (section 14) and the Order. Limitations of liability between the parties do not change the liability of each of us towards data subjects (Art. 82 GDPR) and towards the supervisory authority, and do not apply to damage caused intentionally. If we ourselves determine the purposes and means of processing in breach of this Processing Agreement, we are considered a controller in respect of that processing (Art. 28(10) GDPR).
In matters of personal data protection this Processing Agreement takes precedence over the Order, the Development and Hosting Terms and the Terms of Service.
The Processing Agreement is governed by the law of the Republic of Poland; disputes are dealt with as in section 16 of the Terms of Service.
Annex 1. Description of processing and time limits
| Field | What to enter |
|---|---|
| System | [name, address] |
| Services involving data processing | [Managed Hosting / development with access to production data / Support] |
| Nature of processing | [storage and hosting, backup and recovery, export and deletion on instruction, viewing to investigate failures, changes on instruction] |
| Purpose | performance of the Order of [date]: [description] |
| Categories of data subjects | [clients, employees, drivers, community members, bot users…] |
| Types of data | [name, phone, e-mail, Telegram ID, address, documents, photos…] |
| Special categories and criminal conviction data | [none / which — and additional safeguards] |
| Controller's contact for instructions | [name, e-mail, Telegram] |
| Controller's contact for incidents | [name, phone, e-mail] |
| Controller's data protection officer | [if appointed] |
| Our persons with access | [name — role] |
| Notice of a new sub-processor | [days] before it takes effect |
| Forwarding a data subject request to you | within [working days] |
| Assistance with requests without separate charge | [number of requests or hours per month] |
| Notification of a personal data breach | no later than [hours] after we become aware |
| Audit | notice of [days]; no more often than [once a year] |
| Return and deletion after the end | within [days] |
Annex 2. Security measures
The status of each measure is entered as at the date of conclusion according to the actual state of the infrastructure: a measure that is only planned is marked as planned, not as in place.
| Measure | How | Status |
|---|---|---|
| Encryption in transit | HTTPS between users and the system | [in place / planned] |
| Server access | SSH keys only, no password login; firewall; blocking of password guessing | [in place / planned] |
| Separation of systems | separate containers, a separate database and a separate database user with the necessary privileges for each system | [in place / planned] |
| Secrets | in environment files on the server, outside code repositories | [in place / planned] |
| Backups | daily; encryption of copies before storage and transfer to the backup server, decryption keys kept off the servers | [in place / planned] |
| Recovery | restoration in an isolated environment, repeating completed deletions before opening the system | [in place / planned] |
| Monitoring | alerts to the administrator about backup and service failures | [in place / planned] |
| Minimisation | test data in development; tools to export and delete a data subject's data where the Deliverable includes them | [in place / planned] |
| Updates | updates of dependencies and images as part of Support | [in place / planned] |
| Organisational | confidentiality obligations, access only for persons who need it, logging of data subject requests and breaches | [in place / planned] |
Annex 3. Sub-processors
We do not engage other sub-processors for your data without the procedure in section 6. A row that does not apply to your system is marked "not engaged".
| Provider | Role | What data | Place of processing and transfer mechanism | When engaged |
|---|---|---|---|---|
| Contabo GmbH | Server (VPS) on which the system, its databases, files and backup archives run | All system data | EU (Germany) | Always with Managed Hosting |
| Cloudflare, Inc. | Delivery and protection network: requests to the system pass through it at addresses we serve via Cloudflare (including in the riadov.app domain) | Content of the system's requests and responses, IP addresses and technical request data | Cloudflare network, processing outside the EEA possible; mechanism: [under the Cloudflare data processing agreement as at the date of conclusion] | If the system's address is served via Cloudflare under our account |
| [Backup server provider] | Storage of backup snapshots off the main server | Copies of the system's databases and files | [country]; mechanism: [if outside the EEA] | From the day the backup server goes live — after notice under section 6 |
| OpenAI | The system's artificial intelligence features (for example, document parsing or message checking) | Texts and documents the system sends for parsing | [place of processing and mechanism — under OpenAI's terms as at the date of conclusion] | Only if such a feature is in the Order and runs on our API key |
| Google (Drive, Gmail) | Storage or e-mail the system works with | [data] | [place of processing and mechanism] | Only if the system works with Google under our account |
| Anthropic Ireland, Limited / Anthropic PBC | Artificial intelligence development tools (Claude, under Anthropic’s commercial terms with a data processing agreement): help with code and investigating failures | Code; personal data — only to the minimum extent needed to investigate a specific failure; health data — never | USA; mechanism: standard contractual clauses, Module 3 (Decision (EU) 2021/914) | During development and Support |
Annex 4. Backups and when data disappear
Data deleted from the system remain in backups until the retention period of the last copy containing them expires. The periods below are settings of our infrastructure; the actual status of each layer is entered as at the date of conclusion.
| Backup layer | Period | What this means for deleted data |
|---|---|---|
| Daily archives of databases and files on the system's server | [R] days (as at the date of this version set to 7) | They disappear when rotation removes the last archive containing them: up to R days plus the interval between runs |
| Copies of files (photos, documents) on the system's server | [M] days from confirmed disappearance of the original / [automatic clean-up not enabled — date of enabling] | A copy of a file is deleted M days after the backup process has confirmed that the original no longer exists |
| Snapshots on a backup server of another provider | [not used / up to 35 daily and 12 monthly snapshots, but no longer than S days, S = [400]] | They disappear when rotation removes the last snapshot containing them |
| Total | [for databases — up to R + S days, for files — up to M + S days, plus run intervals] | For example, with M = 30 and S = 400 a copy of a deleted file may exist for about 430 days |
If part of the backup process is not working, we keep the last successful copy of that part until the failure is fixed — so as not to be left without a usable copy; we learn of the failure from an alert and fix it. Encrypting a copy protects it but is not deletion. Copies in third-party services (for example, the Google Drive bin) disappear under their providers' rules.