Umowa powierzenia przetwarzania danych osobowych (DPA)
Umowa zawarta pomiędzy: WG Elements, ul. Teatralna 24/7, 11-600 Węgorzewo, NIP 8451865930 – „Podmiotem przetwarzającym”, a Klientem („Administratorem”), w związku z umową dotyczącą korzystania z aplikacji Fire Protocol, zgodnie z art. 28 RODO.
§ 1. Przedmiot i cel
- Administrator powierza Podmiotowi przetwarzającemu przetwarzanie danych osobowych w zakresie i celu określonym w Załączniku A.
- Powierzenie następuje wyłącznie w celu świadczenia usług w ramach Aplikacji.
- Podmiot przetwarzający przetwarza dane wyłącznie na udokumentowane polecenie Administratora.
§ 2. Czas trwania
Umowa obowiązuje przez czas obowiązywania umowy głównej; jej rozwiązanie powoduje rozwiązanie niniejszej Umowy.
§ 3. Obowiązki Podmiotu przetwarzającego
- przetwarzanie danych wyłącznie na udokumentowane polecenie Administratora;
- zobowiązanie osób upoważnionych do zachowania poufności;
- wdrożenie środków technicznych i organizacyjnych z art. 32 RODO (Załącznik C);
- przestrzeganie zasad podpowierzenia (§ 5);
- pomoc Administratorowi w realizacji praw osób, których dane dotyczą, oraz obowiązków z art. 32–36 RODO;
- usunięcie lub zwrot danych po zakończeniu usług (§ 7);
- udostępnienie informacji niezbędnych do wykazania zgodności i umożliwienie audytów (§ 8).
§ 4. Obowiązki Administratora
Administrator oświadcza, że jest uprawniony do przetwarzania powierzanych danych i wydaje polecenia zgodne z prawem.
§ 5. Podpowierzenie (subprocesorzy)
- Administrator wyraża ogólną zgodę na korzystanie z subprocesorów wymienionych w Załączniku B.
- Podmiot przetwarzający nakłada na subprocesorów obowiązki ochrony danych odpowiadające niniejszej Umowie i informuje o ich zmianach, umożliwiając sprzeciw w terminie 14 dni.
- Podmiot przetwarzający odpowiada wobec Administratora za działania subprocesorów.
§ 6. Naruszenia ochrony danych
Podmiot przetwarzający zgłasza naruszenie bez zbędnej zwłoki, nie później niż w ciągu 48 godzin od jego stwierdzenia, przekazując informacje umożliwiające realizację obowiązków z art. 33–34 RODO.
§ 7. Usunięcie lub zwrot danych
Po zakończeniu usług Podmiot przetwarzający usuwa lub zwraca dane (zależnie od decyzji Administratora) oraz usuwa kopie, chyba że prawo nakazuje ich przechowywanie. Decyzję Administrator przekazuje w terminie 30 dni; brak decyzji uprawnia do usunięcia danych.
§ 8. Audyt
Podmiot przetwarzający umożliwia audyt po zawiadomieniu z 14-dniowym wyprzedzeniem, w sposób niezakłócający działalności i z poszanowaniem poufności innych klientów.
§ 9. Postanowienia końcowe
Zmiany wymagają formy pisemnej lub dokumentowej. W sprawach nieuregulowanych stosuje się RODO i prawo polskie.
Załącznik A — Opis przetwarzania
| Rodzaj danych | Imię i nazwisko, służbowy e-mail, nazwa pracodawcy, rola, dane zadań i kontroli, adresy i nazwy obiektów, treść protokołów, zdjęcia, token push, dane techniczne urządzenia. |
|---|---|
| Kategorie osób | Pracownicy i współpracownicy Administratora; osoby wskazane w protokołach i zadaniach. |
| Cel i czas | Świadczenie usługi SaaS przez czas obowiązywania umowy. |
| Lokalizacja GPS | Aplikacja nie pobiera danych o lokalizacji GPS. |
Załącznik B — Subprocesorzy
| Subprocesor | Usługa | Lokalizacja |
|---|---|---|
| Google Cloud Platform (Google Cloud EMEA / Google Ireland) | Hosting i przechowywanie danych | EOG (regiony UE) |
| Expo (650 Industries, Inc.) | Wysyłka powiadomień push (Expo Push Service; dostarczanie przez Apple APNs i Google FCM) | USA — na podstawie standardowych klauzul umownych (art. 46 RODO) |
Załącznik C — Środki bezpieczeństwa (art. 32 RODO)
- szyfrowanie transmisji (HTTPS/TLS);
- kontrola dostępu oparta na rolach, uwierzytelnianie kont;
- hasła przechowywane w postaci zahaszowanej;
- logiczna separacja danych między organizacjami (multi-tenancy);
- kopie zapasowe i procedury odtwarzania;
- infrastruktura GCP w regionach UE; monitorowanie zdarzeń bezpieczeństwa;
- procedura zgłaszania i obsługi naruszeń.
Data Processing Agreement (DPA)
Agreement concluded between: WG Elements, ul. Teatralna 24/7, 11-600 Węgorzewo, Poland, VAT ID (NIP) 8451865930 – the “Processor”, and the Client (the “Controller”), in connection with the agreement on the use of the Fire Protocol app, pursuant to Art. 28 GDPR.
§ 1. Subject and purpose
- The Controller entrusts the Processor with processing personal data to the extent and for the purpose set out in Appendix A.
- The entrustment is made solely for the purpose of providing services within the App.
- The Processor processes data only on the documented instructions of the Controller.
§ 2. Duration
The Agreement remains in force for the term of the main agreement; its termination terminates this Agreement.
§ 3. Processor’s obligations
- processing data only on the documented instructions of the Controller;
- committing authorised persons to confidentiality;
- implementing technical and organisational measures under Art. 32 GDPR (Appendix C);
- complying with the rules on sub-processing (§ 5);
- assisting the Controller in fulfilling data subjects’ rights and the obligations under Art. 32–36 GDPR;
- deleting or returning data after the end of the services (§ 7);
- making available the information necessary to demonstrate compliance and allowing audits (§ 8).
§ 4. Controller’s obligations
The Controller declares that it is entitled to process the entrusted data and issues instructions that comply with the law.
§ 5. Sub-processing (sub-processors)
- The Controller gives general consent to the use of the sub-processors listed in Appendix B.
- The Processor imposes on sub-processors data protection obligations equivalent to this Agreement and informs of any changes, allowing an objection within 14 days.
- The Processor is liable to the Controller for the actions of sub-processors.
§ 6. Personal data breaches
The Processor reports a breach without undue delay, no later than within 48 hours of becoming aware of it, providing the information necessary to fulfil the obligations under Art. 33–34 GDPR.
§ 7. Deletion or return of data
After the end of the services, the Processor deletes or returns the data (depending on the Controller’s decision) and deletes copies, unless the law requires their retention. The Controller communicates its decision within 30 days; failure to decide entitles the Processor to delete the data.
§ 8. Audit
The Processor allows an audit after 14 days’ prior notice, in a manner that does not disrupt operations and respects the confidentiality of other clients.
§ 9. Final provisions
Amendments require written or documentary form. Matters not covered are governed by the GDPR and Polish law.
Appendix A — Description of processing
| Type of data | First and last name, business email, employer name, role, task and inspection data, property addresses and names, report contents, photos, push token, technical device data. |
|---|---|
| Categories of persons | The Controller’s employees and associates; persons named in reports and tasks. |
| Purpose and duration | Providing the SaaS service for the term of the agreement. |
| GPS location | The App does not collect GPS location data. |
Appendix B — Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Google Cloud Platform (Google Cloud EMEA / Google Ireland) | Hosting and data storage | EEA (EU regions) |
| Expo (650 Industries, Inc.) | Sending push notifications (Expo Push Service; delivery via Apple APNs and Google FCM) | USA — on the basis of standard contractual clauses (Art. 46 GDPR) |
Appendix C — Security measures (Art. 32 GDPR)
- encryption of transmission (HTTPS/TLS);
- role-based access control, account authentication;
- passwords stored in hashed form;
- logical separation of data between organisations (multi-tenancy);
- backups and recovery procedures;
- GCP infrastructure in EU regions; security event monitoring;
- breach reporting and handling procedure.