DATA PROCESSING AGREEMENT

Last update: November 4, 2025
1. GENERAL PROVISIONS

1.1. These terms and conditions constitute the Data Processing Agreement (“Agreement”) between the Controller and the Processor and define, in particular: the subject and duration of the entrustment of personal data processing, the nature and purpose of personal data processing, the types of personal data, the categories of data subjects, the conditions for subcontracting, and the obligations of both Parties under applicable data protection laws, including Regulation (EU) 2016/679 (“GDPR”).

1.2. This Agreement governs the processing of personal data under which the Controller entrusts the Processor with processing personal data of the Controller’s employees, contractors, and other authorized users in connection with the provision of services and access to the web application Oterion, operated at: https://oterion.com (“Application”).

1.3. For the purposes of this Agreement, the following definitions apply:

  • Processor: the Service Provider - Oterion sp. z o.o., with its registered office and contact details as provided in the Terms of Service.
  • Controller: the User - an entity that has entered into a service agreement with the Processor and uses the Application.
  • Employee / Authorized User: a natural person linked to the Controller (by employment or civil contract) who uses or has access to the Application (e.g., via an account created by the Controller).
  • Personal Data: any information relating to an identified or identifiable natural person as defined under the GDPR and relevant Polish data protection laws.
  • Sub-processor: a third party engaged by the Processor to process personal data on its behalf.
2. CONDITIONS FOR ENTRUSTING PERSONAL DATA PROCESSING

2.1. As the proper performance of the services provided by the Controller requires the processing of the Client’s and Employees’ personal data, the Controller entrusts the Processor with the processing of such personal data. The scope of the entrusted personal data depends on the person entering this data into the Application (the Controller or its authorized Employee) and may include, in particular: first name, last name, job title, branch address, email address, and phone number.

2.2. In connection with the performance of the agreement between the Controller and the Processor, the Processor undertakes to process the personal data specified in Section 2.1 solely to the extent necessary for the proper functioning of the Application and the fulfillment of the Agreement. The Processor shall not use the personal data for any other purpose.

2.3. The Processor undertakes to process and secure the personal data entrusted to it in accordance with the generally applicable laws in Poland and the European Union governing the protection of personal data of natural persons, including the GDPR.
The Processor shall apply appropriate technical and organizational measures to ensure an adequate level of security of personal data. Depending on the nature of the risk, such measures may include, among others: pseudonymization and encryption of personal data, ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services, restoring availability in case of physical or technical incidents, and regularly testing, assessing, and evaluating the effectiveness of security measures.

2.4. Except as provided in Sections 2.5–2.7, the Processor shall not copy (other than for backup purposes), distribute, disclose, or use for its own purposes any personal data entrusted to it.

2.5. The Processor may make the entrusted personal data available to entities supporting it in the performance of the Agreement, such as providers of email, hosting, monitoring, or technical support services, to the extent necessary for the proper provision of the Application.

2.6. The Controller hereby authorizes the Processor to entrust the processing of personal data to hosting service providers engaged by the Processor to ensure the availability, reliability, and security of the Application. In such cases, the Processor shall require such providers to process personal data in compliance with applicable data protection regulations and solely for the purpose of providing their respective services.

2.7. Use of Sub-processors

The Processor relies on affiliated entities and external service providers (“Sub-processors”) to support the operation, maintenance, and delivery of the Application. https://oterion.com/en/legal/subprocessorsThese Sub-processors perform functions such as data hosting, email delivery, monitoring, or technical support, and are engaged under written agreements that ensure an adequate level of protection for personal data in accordance with applicable data protection regulations, including the GDPR.
A current and regularly updated list of Sub-processors is available at: https://oterion.com/en/legal/subprocessors. By using the Application, the Controller acknowledges and accepts the Processor’s use of such Sub-processors as an essential part of the service.

2.8. The Processor shall ensure that persons authorized to process personal data are bound by confidentiality obligations or are subject to a statutory duty of confidentiality.

2.9. The Controller entrusts the Processor with the processing of personal data for the period corresponding to the limitation period for claims arising from the primary agreement between the Parties. After the expiration of that period, or in the event of the termination of the primary agreement by either Party, the Processor shall return or permanently delete all entrusted personal data and any copies thereof, taking appropriate measures to eliminate the possibility of further processing.

2.10. The Processor undertakes to promptly notify the Controller of:

  • Any legally binding request for disclosure of personal data by a competent public authority, unless prohibited by law (in particular criminal procedure provisions ensuring the confidentiality of an investigation);
  • Any unauthorized access to personal data;
  • Any request received from a data subject whose data the Processor is processing, while refraining from responding to such requests directly.

2.11. The Processor shall provide the Controller with all information necessary to demonstrate compliance with the obligations set forth in this Agreement and shall allow and cooperate in audits, including inspections, conducted by the Controller or an auditor authorized by the Controller.

3. DATA RETENTION AND TRANSFERS

3.1. The Processor shall store and process personal data primarily within the European Union (EU).

3.2. Where data is transferred outside the EU/EEA, the Processor shall ensure adequate protection through one or more of the following mechanisms:

  • the EU–US Data Privacy Framework (where applicable),
  • Standard Contractual Clauses (SCCs) adopted by the European Commission,
  • Binding Corporate Rules, or
  • equivalent contractual or technical safeguards (encryption, limited access, secure transmission).

3.3. The Processor maintains a Global Identification Database located in the EU for determining regional routing (e.g., EU vs. US infrastructure). This database stores only minimal identifiers (email, region, account status, metadata) and is processed under Article 6(1)(f) GDPR - legitimate interest in ensuring technical and regulatory compliance across regions.

3.4. Marketing-related personal data (e.g., newsletter subscriptions, website forms) may be processed by Sub-processors located in the United States. Such processing is based on consent and safeguarded by SCCs or participation in the EU–US Data Privacy Framework.

3.5. Support requests and access control logs are stored within the EU. Temporary access by authorized personnel outside the EU may occur solely to diagnose or resolve technical issues and only through secure, monitored connections.

3.6. Retention periods:

  • Account-related data: retained as long as the account remains active or until deletion is requested;
  • Marketing data: retained until consent withdrawal or request for deletion;
  • Support records: retained for up to 24 months after resolution;
  • Backup data: deleted automatically within standard retention cycles.

4. TERM AND TERMINATION

4.1. This Agreement remains in force for the duration of the main service agreement between the Controller and the Processor.

4.2. Termination of the main service agreement automatically terminates this Data Processing Agreement, unless retention of certain data is required by law or agreed for limited purposes (e.g., dispute resolution, billing reconciliation).


5. FINAL PROVISIONS

5.1. In matters not covered by this Agreement, the provisions of generally applicable Polish law and the GDPR shall apply.

5.2. The Controller shall provide the Processor, within 14 days from entering into this Agreement, with the details of its data protection officer (if appointed) and any co-controllers.

5.3. Any disputes arising from this Agreement shall be submitted to the court having jurisdiction over the Processor’s registered office.

5.4. This Agreement forms an integral part of the Terms of Service between the Controller and the Processor.