concluded under Art. 28 GDPR in connection with the use of the booksero system
The date the document is downloaded = the date the Agreement is concluded.
Processor (Operator)
Entrusting party (Tenant) — to be completed by the Tenant
jointly referred to as the Parties, and each separately as a Party.
Whereas the Parties are bound by a separate Main Agreement (Acceptance of the booksero System Terms), the subject of which is the provision of IT services in the Processor's application, the performance of which requires the processing of personal data, the Parties have agreed as follows:
§ 1 Definitions
Terms used in the Agreement have the following meaning:
Controller – a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data,
Entrusting party – a natural or legal person, public authority, agency or other body which, as a Controller or jointly with other Controllers, determines the purposes and means of the processing of personal data and transfers them for processing to the Processor,
Processor – an entity that receives data for processing from the Entrusting party or the Controller,
Personal data – information relating to an identified or identifiable natural person (a "data subject"); an identifiable natural person is one who can be identified, directly or indirectly,
Business Days – days from Monday to Friday, excluding public holidays,
Breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data,
Sub-processing – further entrustment of the processing of Personal data by the Processor,
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data,
Main Agreement – a separate agreement between the Entrusting party and the Processor, the subject of which is the provision of IT services, the performance of which requires the processing of Personal data.
§ 2 Subject of the Agreement
The Entrusting party entrusts the Processor with the processing of Personal data on the terms set out in the Agreement.
For performing the services set out in the Agreement, the Processor is not entitled to any additional remuneration beyond that specified in the Main Agreement.
§ 3 Subject and duration of processing
The subject of processing is the Personal data entrusted for processing in connection with the performance of the Main Agreement, specified in Annex 1 to the Agreement.
The scope of entrustment may at any time be changed, extended or limited by the Entrusting party, which shall take place by sending the Processor a new version of Annex 1 electronically.
The entrustment of the processing of Personal data takes place for the duration of the performance of the Main Agreement.
§ 4 Purpose and nature of processing
Personal data is processed for the purpose of performing the Main Agreement.
The processing of the entrusted Personal data is of a continuous nature and takes place in the Processor's application. The processing of the entrusted Personal data covers the following processing operations carried out on the express instruction of the controller: modifying, collecting, recording, organising, structuring, storing, adapting, viewing, deduplication.
§ 5 Instruction to process
By concluding the Agreement, the Entrusting party instructs the Processor, and any person acting under the authority of the Processor who has access to the Personal data, to process the Personal data, which constitutes a documented instruction within the meaning of Art. 28(3)(a) in conjunction with Art. 29 GDPR.
§ 6 Statements of the Parties
The Processor acts in accordance with the obligations arising from the GDPR and the generally applicable provisions of Polish law.
The Entrusting party declares that it is entitled to entrust the processing of the Personal data.
The Entrusting party entrusts for processing Personal data for which it is the Controller or which it processes on behalf of another Controller or Controllers.
Where the Entrusting party entrusts for processing Personal data which it processes on behalf of another Controller or Controllers, it indicates those entities in Annex 2.
The Entrusting party is entitled to grant authorisations and issue instructions within the meaning of Art. 29 GDPR to the Processor.
§ 7 Obligations of the Parties
The Processor declares that it provides sufficient guarantees to implement appropriate technical and organisational measures to ensure a level of data security appropriate to the risk.
The Processor is obliged to:
process the Personal data in accordance with the GDPR,
process the Personal data only on the documented instruction of the Entrusting party,
allow access to the processing of Personal data only to persons whom it authorises and who have undertaken to maintain confidentiality,
take all technical and organisational measures required under Art. 32 GDPR,
where necessary and at the Entrusting party's request, assist in fulfilling the obligation to respond to requests from data subjects,
without undue delay, but no later than within 2 Business Days, inform the Entrusting party that a data subject has made a request,
make available to the Entrusting party, at its request, all information necessary to demonstrate compliance with its obligations.
Upon detecting a Breach, the Processor shall, without undue delay but no later than within 24 hours of detecting the Breach, report it to the Entrusting party. The report is made to the Entrusting party's email address, using the template set out in Annex 3.
The Processor may use only the services of such further processors as provide sufficient guarantees to implement appropriate technical and organisational measures.
The Processor is entitled to carry out sub-processing to the entities listed in Annex 4 to the Agreement. The Entrusting party further gives general consent to further sub-processing of data to the entities by means of which the Processor provides the service (subcontractors).
The Processor shall inform the Entrusting party of any intended changes concerning the addition or replacement of the entities listed in Annex 4 no later than 2 days before their introduction, and the Entrusting party may object within that period. Raising an objection means a lack of consent to the addition or replacement of such entity, which may result in a limitation of the functionality of the service.
§ 8 Right of audit
The Processor allows the Entrusting party or an authorised auditor to conduct audits, including inspections, and contributes to them.
The Entrusting party shall notify the Processor of its intention to conduct an audit in traditional written form. The Processor shall set possible audit dates within 21 business days of receiving the notification. The audit may not disrupt the Processor's operations.
The Processor shall immediately inform the Entrusting party if an issued instruction constitutes an infringement of the GDPR.
§ 9 Liability
Each Party is liable for damage caused to the other Party and to third parties in connection with the performance of the Agreement, in accordance with the provisions of the Civil Code.
The Processor is liable for the actions of its employees and other persons by means of whom it processes Personal data, as for its own action and omission.
The Processor is liable for damage caused by processing Personal data in a manner infringing the GDPR, where it has failed to fulfil the obligations imposed on it by the provisions.
§ 10 Duration and termination of the Agreement
This Agreement is concluded for a definite period, i.e. for the duration of the processing carried out in connection with the performance of the Main Agreement, and remains in force until the data is deleted.
Personal data stored in the System's production database is kept for the entire term of the Main Agreement (active subscription) and is not automatically deleted with the passage of time. The Processor protects the data with two independent layers: point-in-time recovery of the database within a 7-day window, and a copy of the whole database taken once a day and kept for 60 days with an independent provider, away from the application infrastructure. These are security mechanisms, not a data retention period. At the Controller's request, made during the term of the Main Agreement or within 30 days after it ends, the Processor shall provide a copy of the Personal data covering End-client records, appointments and sales, in CSV or XLSX format, without undue delay and no later than within 14 business days of receiving the request. Permanent deletion of Personal data occurs in particular in the event of: manual deletion of the data or database by the Controller, shutdown and deletion of the project (deployment), or expiry or non-payment of the subscription for a prolonged period. Deleting Personal data from the production database does not remove it from backups immediately. The data remains in backups until their retention period expires, i.e. for up to 60 days, after which it is deleted together with the expiring backup. During that period the backups are not used for any purpose other than disaster recovery.
The Entrusting party is entitled to terminate the Agreement without notice if the Processor fails to fulfil the obligations set out in the GDPR or the Agreement. The occurrence of grounds for termination of the Agreement without notice constitutes grounds for termination of the Main Agreement.
§ 11 Contact details of the Parties
In matters related to the performance of the Agreement, the Parties specify their contact details in Annex 5.
Deliveries and notifications are made electronically to the Parties' email addresses.
Each Party shall promptly notify the other Party electronically of any change to the data contained in Annex 5. A change of data does not constitute an amendment to the Agreement.
§ 12 Final provisions
The Agreement is governed by Polish law and enters into force on the day it is concluded by the Parties.
The annexes form an integral part of the Agreement:
Annex 1: Subject of processing
Annex 2: List of Controllers
Annex 3: Personal data Breach notification template
Annex 4: List of entities to which the Processor sub-entrusts processing
Annex 5: Contact details
The court competent to resolve disputes arising in connection with the performance of the Agreement is the court competent for the seat of the claimant.
Entrusting party (Tenant) signature of authorised person
Processor (Operator) Izabela Sadowska — President of the Management Board VIVI ESTETIC Sp. z o.o.
Annex 1 — Subject of processing
1. Categories of data subjects: Clients and prospective clients booking appointments at the Tenant's salon, the Tenant's employees.
2. Type of Personal data:
Ordinary data (e.g. first name, surname, phone number, email) — Applies
Special categories of personal data (e.g. health data, if collected by the salon) — tick if applicable (to be completed by the Tenant)
Personal data relating to criminal convictions — Does not apply
Annex 2 — List of Controllers on whose behalf processing takes place
If you are the sole controller of the data entrusted to us, this annex may be left blank.
No.
Controller name
Identifying data (Tax ID / address)
1
2
3
Annex 3 — Personal data Breach notification template
Annex 4 — List of entities to which the Operator sub-entrusts processing
Categories of processors: server rooms and Data Centres (hosting, database, backups), file storage, SMS service providers, email service providers, payment operators, AI assistant provider, technical notification channel.
No.
Provider name
Scope of services
Area
1
Neon, Inc. (on Amazon Web Services infrastructure)
Hosting of the System database
USA, Oregon region (outside EEA — SCC / DPF)
2
Replit, Inc.
Application hosting (runtime environment)
North America (outside EEA — SCC)
3
Cloudflare, Inc. (R2 storage)
Storage of files uploaded to the System and of database backups
Eastern Europe; provider established in the USA (SCC / DPF)
4
SerwerSMS.pl
Sending SMS (system login, notifications)
Poland (EEA)
5
Resend, Inc.
Sending email (confirmations, reminders)
USA (outside EEA — SCC)
6
Stripe Payments Europe, Ltd.
Online payment handling
EEA (Ireland) / USA — SCC
7
Anthropic PBC
AI assistant in the Panel — content of conversations with the assistant and account context
USA (outside EEA — SCC / DPF)
8
Telegram
Technical notifications for the Operator's team (company names, support ticket subjects; no End-client contact details)
outside EEA — SCC
Annex 5 — Contact details
On the Entrusting party's side (Tenant) — to be completed