← Powrót na stronę główną

Umowa powierzenia przetwarzania danych osobowych (DPA)

Wzór zawierany z Klientem zgodnie z art. 28 RODO  •  WG Elements, ul. Teatralna 24/7, 11-600 Węgorzewo, NIP 8451865930

Poniższy dokument stanowi wzór umowy powierzenia zawieranej pomiędzy Klientem (Administratorem) a WG Elements (Podmiotem przetwarzającym) w związku z korzystaniem z aplikacji Fire Protocol. Umowa zawierana jest w formie dokumentowej wraz z umową główną. W celu podpisania prosimy o kontakt: info@fireprotocol.pl.

Umowa zawarta pomiędzy: WG Elements, ul. Teatralna 24/7, 11-600 Węgorzewo, NIP 8451865930 – „Podmiotem przetwarzającym”, a Klientem („Administratorem”), w związku z umową dotyczącą korzystania z aplikacji Fire Protocol, zgodnie z art. 28 RODO.

§ 1. Przedmiot i cel

  1. Administrator powierza Podmiotowi przetwarzającemu przetwarzanie danych osobowych w zakresie i celu określonym w Załączniku A.
  2. Powierzenie następuje wyłącznie w celu świadczenia usług w ramach Aplikacji.
  3. Podmiot przetwarzający przetwarza dane wyłącznie na udokumentowane polecenie Administratora.

§ 2. Czas trwania

Umowa obowiązuje przez czas obowiązywania umowy głównej; jej rozwiązanie powoduje rozwiązanie niniejszej Umowy.

§ 3. Obowiązki Podmiotu przetwarzającego

  • przetwarzanie danych wyłącznie na udokumentowane polecenie Administratora;
  • zobowiązanie osób upoważnionych do zachowania poufności;
  • wdrożenie środków technicznych i organizacyjnych z art. 32 RODO (Załącznik C);
  • przestrzeganie zasad podpowierzenia (§ 5);
  • pomoc Administratorowi w realizacji praw osób, których dane dotyczą, oraz obowiązków z art. 32–36 RODO;
  • usunięcie lub zwrot danych po zakończeniu usług (§ 7);
  • udostępnienie informacji niezbędnych do wykazania zgodności i umożliwienie audytów (§ 8).

§ 4. Obowiązki Administratora

Administrator oświadcza, że jest uprawniony do przetwarzania powierzanych danych i wydaje polecenia zgodne z prawem.

§ 5. Podpowierzenie (subprocesorzy)

  1. Administrator wyraża ogólną zgodę na korzystanie z subprocesorów wymienionych w Załączniku B.
  2. Podmiot przetwarzający nakłada na subprocesorów obowiązki ochrony danych odpowiadające niniejszej Umowie i informuje o ich zmianach, umożliwiając sprzeciw w terminie 14 dni.
  3. Podmiot przetwarzający odpowiada wobec Administratora za działania subprocesorów.

§ 6. Naruszenia ochrony danych

Podmiot przetwarzający zgłasza naruszenie bez zbędnej zwłoki, nie później niż w ciągu 48 godzin od jego stwierdzenia, przekazując informacje umożliwiające realizację obowiązków z art. 33–34 RODO.

§ 7. Usunięcie lub zwrot danych

Po zakończeniu usług Podmiot przetwarzający usuwa lub zwraca dane (zależnie od decyzji Administratora) oraz usuwa kopie, chyba że prawo nakazuje ich przechowywanie. Decyzję Administrator przekazuje w terminie 30 dni; brak decyzji uprawnia do usunięcia danych.

§ 8. Audyt

Podmiot przetwarzający umożliwia audyt po zawiadomieniu z 14-dniowym wyprzedzeniem, w sposób niezakłócający działalności i z poszanowaniem poufności innych klientów.

§ 9. Postanowienia końcowe

Zmiany wymagają formy pisemnej lub dokumentowej. W sprawach nieuregulowanych stosuje się RODO i prawo polskie.

Załącznik A — Opis przetwarzania

Rodzaj danychImię i nazwisko, służbowy e-mail, nazwa pracodawcy, rola, dane zadań i kontroli, adresy i nazwy obiektów, treść protokołów, zdjęcia, token push, dane techniczne urządzenia.
Kategorie osóbPracownicy i współpracownicy Administratora; osoby wskazane w protokołach i zadaniach.
Cel i czasŚwiadczenie usługi SaaS przez czas obowiązywania umowy.
Lokalizacja GPSAplikacja nie pobiera danych o lokalizacji GPS.

Załącznik B — Subprocesorzy

SubprocesorUsługaLokalizacja
Google Cloud Platform (Google Cloud EMEA / Google Ireland)Hosting i przechowywanie danychEOG (regiony UE)
Expo (650 Industries, Inc.)Wysyłka powiadomień push (Expo Push Service; dostarczanie przez Apple APNs i Google FCM)USA — na podstawie standardowych klauzul umownych (art. 46 RODO)

Załącznik C — Środki bezpieczeństwa (art. 32 RODO)

  • szyfrowanie transmisji (HTTPS/TLS);
  • kontrola dostępu oparta na rolach, uwierzytelnianie kont;
  • hasła przechowywane w postaci zahaszowanej;
  • logiczna separacja danych między organizacjami (multi-tenancy);
  • kopie zapasowe i procedury odtwarzania;
  • infrastruktura GCP w regionach UE; monitorowanie zdarzeń bezpieczeństwa;
  • procedura zgłaszania i obsługi naruszeń.

Data Processing Agreement (DPA)

A template concluded with the Client in accordance with Art. 28 GDPR  •  WG Elements, ul. Teatralna 24/7, 11-600 Węgorzewo, Poland, VAT ID (NIP) 8451865930

This is an English translation provided for convenience. In the event of any discrepancy, the Polish version is legally binding.
The document below is a template data processing agreement concluded between the Client (Controller) and WG Elements (Processor) in connection with the use of the Fire Protocol app. The agreement is concluded in documentary form together with the main agreement. To sign it, please contact: info@fireprotocol.pl.

Agreement concluded between: WG Elements, ul. Teatralna 24/7, 11-600 Węgorzewo, Poland, VAT ID (NIP) 8451865930 – the “Processor”, and the Client (the “Controller”), in connection with the agreement on the use of the Fire Protocol app, pursuant to Art. 28 GDPR.

§ 1. Subject and purpose

  1. The Controller entrusts the Processor with processing personal data to the extent and for the purpose set out in Appendix A.
  2. The entrustment is made solely for the purpose of providing services within the App.
  3. The Processor processes data only on the documented instructions of the Controller.

§ 2. Duration

The Agreement remains in force for the term of the main agreement; its termination terminates this Agreement.

§ 3. Processor’s obligations

  • processing data only on the documented instructions of the Controller;
  • committing authorised persons to confidentiality;
  • implementing technical and organisational measures under Art. 32 GDPR (Appendix C);
  • complying with the rules on sub-processing (§ 5);
  • assisting the Controller in fulfilling data subjects’ rights and the obligations under Art. 32–36 GDPR;
  • deleting or returning data after the end of the services (§ 7);
  • making available the information necessary to demonstrate compliance and allowing audits (§ 8).

§ 4. Controller’s obligations

The Controller declares that it is entitled to process the entrusted data and issues instructions that comply with the law.

§ 5. Sub-processing (sub-processors)

  1. The Controller gives general consent to the use of the sub-processors listed in Appendix B.
  2. The Processor imposes on sub-processors data protection obligations equivalent to this Agreement and informs of any changes, allowing an objection within 14 days.
  3. The Processor is liable to the Controller for the actions of sub-processors.

§ 6. Personal data breaches

The Processor reports a breach without undue delay, no later than within 48 hours of becoming aware of it, providing the information necessary to fulfil the obligations under Art. 33–34 GDPR.

§ 7. Deletion or return of data

After the end of the services, the Processor deletes or returns the data (depending on the Controller’s decision) and deletes copies, unless the law requires their retention. The Controller communicates its decision within 30 days; failure to decide entitles the Processor to delete the data.

§ 8. Audit

The Processor allows an audit after 14 days’ prior notice, in a manner that does not disrupt operations and respects the confidentiality of other clients.

§ 9. Final provisions

Amendments require written or documentary form. Matters not covered are governed by the GDPR and Polish law.

Appendix A — Description of processing

Type of dataFirst and last name, business email, employer name, role, task and inspection data, property addresses and names, report contents, photos, push token, technical device data.
Categories of personsThe Controller’s employees and associates; persons named in reports and tasks.
Purpose and durationProviding the SaaS service for the term of the agreement.
GPS locationThe App does not collect GPS location data.

Appendix B — Sub-processors

Sub-processorServiceLocation
Google Cloud Platform (Google Cloud EMEA / Google Ireland)Hosting and data storageEEA (EU regions)
Expo (650 Industries, Inc.)Sending push notifications (Expo Push Service; delivery via Apple APNs and Google FCM)USA — on the basis of standard contractual clauses (Art. 46 GDPR)

Appendix C — Security measures (Art. 32 GDPR)

  • encryption of transmission (HTTPS/TLS);
  • role-based access control, account authentication;
  • passwords stored in hashed form;
  • logical separation of data between organisations (multi-tenancy);
  • backups and recovery procedures;
  • GCP infrastructure in EU regions; security event monitoring;
  • breach reporting and handling procedure.

© Fire Protocol · WG Elements

Regulamin Polityka prywatności DPA