concluded under Art. 28 GDPR in connection with the use of the booksero system
The date the document is downloaded = the date the Agreement is concluded.
Processor (Operator)
Entrusting party (Tenant) — to be completed by the Tenant
jointly referred to as the Parties, and each separately as a Party.
Whereas the Parties are bound by a separate Main Agreement (Acceptance of the booksero System Terms), the subject of which is the provision of IT services in the Processor's application, the performance of which requires the processing of personal data, the Parties have agreed as follows:
§ 1 Definitions
Terms used in the Agreement have the following meaning:
Controller – a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data,
Entrusting party – a natural or legal person, public authority, agency or other body which, as a Controller or jointly with other Controllers, determines the purposes and means of the processing of personal data and transfers them for processing to the Processor,
Processor – an entity that receives data for processing from the Entrusting party or the Controller,
Personal data – information relating to an identified or identifiable natural person (a "data subject"); an identifiable natural person is one who can be identified, directly or indirectly,
Business Days – days from Monday to Friday, excluding public holidays,
Breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data,
Sub-processing – further entrustment of the processing of Personal data by the Processor,
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data,
Main Agreement – a separate agreement between the Entrusting party and the Processor, the subject of which is the provision of IT services, the performance of which requires the processing of Personal data.
§ 2 Subject of the Agreement
The Entrusting party entrusts the Processor with the processing of Personal data on the terms set out in the Agreement.
For performing the services set out in the Agreement, the Processor is not entitled to any additional remuneration beyond that specified in the Main Agreement.
§ 3 Subject and duration of processing
The subject of processing is the Personal data entrusted for processing in connection with the performance of the Main Agreement, specified in Annex 1 to the Agreement.
The scope of entrustment may at any time be changed, extended or limited by the Entrusting party, which shall take place by sending the Processor a new version of Annex 1 electronically.
The entrustment of the processing of Personal data takes place for the duration of the performance of the Main Agreement.
§ 4 Purpose and nature of processing
Personal data is processed for the purpose of performing the Main Agreement.
The processing of the entrusted Personal data is of a continuous nature and takes place in the Processor's application. The processing of the entrusted Personal data covers the following processing operations carried out on the express instruction of the controller: modifying, collecting, recording, organising, structuring, storing, adapting, viewing, deduplication.
§ 5 Instruction to process
By concluding the Agreement, the Entrusting party instructs the Processor, and any person acting under the authority of the Processor who has access to the Personal data, to process the Personal data, which constitutes a documented instruction within the meaning of Art. 28(3)(a) in conjunction with Art. 29 GDPR.
§ 6 Statements of the Parties
The Processor acts in accordance with the obligations arising from the GDPR and the generally applicable provisions of Polish law.
The Entrusting party declares that it is entitled to entrust the processing of the Personal data.
The Entrusting party entrusts for processing Personal data for which it is the Controller or which it processes on behalf of another Controller or Controllers.
Where the Entrusting party entrusts for processing Personal data which it processes on behalf of another Controller or Controllers, it indicates those entities in Annex 2.
The Entrusting party is entitled to grant authorisations and issue instructions within the meaning of Art. 29 GDPR to the Processor.
§ 7 Obligations of the Parties
The Processor declares that it provides sufficient guarantees to implement appropriate technical and organisational measures to ensure a level of data security appropriate to the risk.
The Processor is obliged to:
process the Personal data in accordance with the GDPR,
process the Personal data only on the documented instruction of the Entrusting party,
allow access to the processing of Personal data only to persons whom it authorises and who have undertaken to maintain confidentiality,
take all technical and organisational measures required under Art. 32 GDPR,
where necessary and at the Entrusting party's request, assist in fulfilling the obligation to respond to requests from data subjects,
without undue delay, but no later than within 2 Business Days, inform the Entrusting party that a data subject has made a request,
make available to the Entrusting party, at its request, all information necessary to demonstrate compliance with its obligations.
Upon detecting a Breach, the Processor shall, without undue delay but no later than within 24 hours of detecting the Breach, report it to the Entrusting party. The report is made to the Entrusting party's email address, using the template set out in Annex 3.
The Processor may use only the services of such further processors as provide sufficient guarantees to implement appropriate technical and organisational measures.
The Processor is entitled to carry out sub-processing to the entities listed in Annex 4 to the Agreement. The Entrusting party further gives general consent to further sub-processing of data to the entities by means of which the Processor provides the service (subcontractors).
The Processor shall inform the Entrusting party of any intended changes concerning the addition or replacement of the entities listed in Annex 4 no later than 2 days before their introduction, and the Entrusting party may object within that period. Raising an objection means a lack of consent to the addition or replacement of such entity, which may result in a limitation of the functionality of the service.
§ 8 Right of audit
The Processor allows the Entrusting party or an authorised auditor to conduct audits, including inspections, and contributes to them.
The Entrusting party shall notify the Processor of its intention to conduct an audit in traditional written form. The Processor shall set possible audit dates within 21 business days of receiving the notification. The audit may not disrupt the Processor's operations.
The Processor shall immediately inform the Entrusting party if an issued instruction constitutes an infringement of the GDPR.
§ 9 Liability
Each Party is liable for damage caused to the other Party and to third parties in connection with the performance of the Agreement, in accordance with the provisions of the Civil Code.
The Processor is liable for the actions of its employees and other persons by means of whom it processes Personal data, as for its own action and omission.
The Processor is liable for damage caused by processing Personal data in a manner infringing the GDPR, where it has failed to fulfil the obligations imposed on it by the provisions.
§ 10 Duration and termination of the Agreement
This Agreement is concluded for a definite period, i.e. for the duration of the processing carried out in connection with the performance of the Main Agreement, and remains in force until the data is deleted.
Personal data stored in the System's production database is kept for the entire term of the Main Agreement (active subscription) and is not automatically deleted with the passage of time. The Processor provides a point-in-time recovery function allowing the database to be restored to an earlier state within a time window depending on the selected plan (currently from 7 to 28 days back) — this is a security mechanism, not a data retention period. The Controller may at any time download (export) the data itself, including after the Main Agreement ends. Permanent deletion of Personal data occurs in particular in the event of: manual deletion of the data or database by the Controller, shutdown and deletion of the project (deployment), or expiry or non-payment of the subscription for a prolonged period.
The Entrusting party is entitled to terminate the Agreement without notice if the Processor fails to fulfil the obligations set out in the GDPR or the Agreement. The occurrence of grounds for termination of the Agreement without notice constitutes grounds for termination of the Main Agreement.
§ 11 Contact details of the Parties
In matters related to the performance of the Agreement, the Parties specify their contact details in Annex 5.
Deliveries and notifications are made electronically to the Parties' email addresses.
Each Party shall promptly notify the other Party electronically of any change to the data contained in Annex 5. A change of data does not constitute an amendment to the Agreement.
§ 12 Final provisions
The Agreement is governed by Polish law and enters into force on the day it is concluded by the Parties.
The annexes form an integral part of the Agreement:
Annex 1: Subject of processing
Annex 2: List of Controllers
Annex 3: Personal data Breach notification template
Annex 4: List of entities to which the Processor sub-entrusts processing
Annex 5: Contact details
The court competent to resolve disputes arising in connection with the performance of the Agreement is the court competent for the seat of the claimant.
Entrusting party (Tenant) signature of authorised person
Processor (Operator) Izabela Sadowska — President of the Management Board VIVI ESTETIC Sp. z o.o.
Annex 1 — Subject of processing
1. Categories of data subjects: Clients and prospective clients booking appointments at the Tenant's salon, the Tenant's employees.
2. Type of Personal data:
Ordinary data (e.g. first name, surname, phone number, email) — Applies
Special categories of personal data (e.g. health data, if collected by the salon) — tick if applicable (to be completed by the Tenant)
Personal data relating to criminal convictions — Does not apply
Annex 2 — List of Controllers on whose behalf processing takes place
If you are the sole controller of the data entrusted to us, this annex may be left blank.
No.
Controller name
Identifying data (Tax ID / address)
1
2
3
Annex 3 — Personal data Breach notification template
Annex 4 — List of entities to which the Operator sub-entrusts processing
Categories of processors: server rooms and Data Centres (hosting, colocation, backup), SMS service providers, email service providers, payment operators.
No.
Provider name
Scope of services
Area
1
Replit, Inc.
Application hosting, Data Centre, backups
EEA (Europe region)
2
SerwerSMS.pl
Sending SMS (system login, notifications)
Poland (EEA)
3
Resend, Inc.
Sending email (confirmations, reminders)
USA (outside EEA — SCC)
4
Stripe Payments Europe, Ltd.
Online payment handling
EEA (Ireland) / USA — SCC
Annex 5 — Contact details
On the Entrusting party's side (Tenant) — to be completed