DATA PROCESSING AGREEMENT (DPA)

This Data Processing Agreement ("DPA") is concluded between:

VHN Sp. z o.o. ul. Gliwicka 35 42-600 Tarnowskie Góry Poland

NIP: 6452561131

hereinafter referred to as:

"Processor"

and

the User using Rezulo services,

hereinafter referred to as:

"Controller".

Acceptance of the Rezulo Terms of Service or commencement of using the Service means conclusion of this Agreement.

§1. SUBJECT MATTER OF THE AGREEMENT

  1. The Controller entrusts the Processor with the processing of personal data to the extent necessary for the provision of Rezulo services.

  2. The Processor undertakes to process personal data in accordance with:

a) Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"),

b) this Agreement,

c) documented instructions from the Controller.

  1. This Agreement constitutes an integral part of Rezulo's legal documentation.

§2. NATURE AND PURPOSE OF PROCESSING

  1. Processing takes place solely for the purpose of providing services available in the Rezulo system.

  2. The Processor does not use data entrusted by the Controller for its own marketing purposes.

  3. Data is not used by the Processor for data sales, marketing profiling, or disclosure to third parties for advertising purposes.

  4. The Processor processes data solely for the period necessary to provide the Service and in accordance with the retention principles specified in the Terms of Service.

§3. DURATION OF PROCESSING

  1. Data is processed for the period during which the Controller uses Rezulo services.

  2. Upon termination of the Service, the retention principles specified in the Terms of Service and this Agreement apply.

  3. This Agreement remains in force throughout the period of use of Rezulo.

§4. DATA CATEGORIES

The Controller may entrust, among others:

Customer data

  • first name,
  • surname,
  • email address,
  • phone number,
  • visit history,
  • reservation history,
  • information regarding services,
  • payment information,
  • notes regarding customers.

Employee data

  • first name,
  • surname,
  • email address,
  • phone number,
  • work schedule,
  • data related to the use of employee accounts.

Other data

Any data entered by the Controller into the Rezulo system.

§5. CATEGORIES OF DATA SUBJECTS

Data may concern:

  • customers,
  • potential customers,
  • persons making online reservations,
  • employees,
  • collaborators,
  • contractors,
  • other persons whose data was entered by the Controller.

§6. SPECIAL CATEGORY DATA

  1. The Controller may entrust special category data as defined in Article 9 GDPR.

  2. These may include, among others:

  • allergies,
  • contraindications to procedures,
  • health information,
  • other information necessary to perform services provided by the Controller.
  1. The Controller is responsible for possessing the appropriate legal basis for processing such data.

  2. The Processor does not verify the legality of the Controller's legal bases.

§7. PROCESSOR'S OBLIGATIONS

The Processor undertakes to:

a) process data only on the instruction of the Controller,

b) ensure the confidentiality of persons having access to data,

c) apply appropriate technical and organisational measures,

d) assist the Controller in fulfilling obligations arising from the GDPR,

e) inform the Controller of personal data breaches,

f) maintain the required documentation under applicable law.

§8. SECURITY MEASURES

The Processor applies security measures adequate to the risk.

These may include, among others:

  • encryption of data transmission,
  • access control,
  • permission system,
  • event logging,
  • security monitoring,
  • regular backups,
  • server infrastructure protection.

The Processor may update the applied security measures as technology develops.

§9. SUB-PROCESSORS

  1. The Controller gives general consent for the Processor to use Sub-processor services.

  2. Sub-processors may include, among others, providers of:

  • hosting,
  • cloud infrastructure,
  • payment services,
  • SMS services,
  • analytics services,
  • security services,
  • IT services.
  1. The current list of Sub-processors may include, among others:
  • OVHcloud,
  • Stripe,
  • Twilio,
  • Google,
  • Meta.
  1. The Processor may add new Sub-processors if this is necessary for the provision of the Service.

  2. The Controller may be informed of significant changes concerning Sub-processors via the website, the Rezulo system, or email.

§10. INTERNATIONAL TRANSFERS

  1. Some Sub-processors may process data outside the European Economic Area.

  2. In such cases, the Processor ensures appropriate safeguards required by the GDPR.

  3. These may include:

  • Standard Contractual Clauses of the European Commission (SCC),
  • adequacy decisions,
  • other mechanisms provided for by applicable law.

§11. PERSONAL DATA BREACHES

  1. If the Processor discovers a breach of personal data protection, the Processor will inform the Controller without undue delay after obtaining confirmed information about the incident.

  2. The information may include:

  • nature of the breach,
  • possible consequences,
  • scope of data affected by the breach,
  • remedial actions taken by the Processor.

§12. SUPPORT FOR THE CONTROLLER

The Processor, to the extent technically and organisationally possible, assists the Controller in fulfilling obligations arising from the GDPR, in particular regarding:

  • exercising the rights of data subjects,
  • reporting breaches,
  • data protection impact assessments,
  • consultations with supervisory authorities.

§13. AUDITS AND SECURITY INFORMATION

  1. The Controller may request information from the Processor concerning the applied data protection measures.

  2. The Processor may fulfill information obligations through:

  • security documentation,
  • responses to inquiries,
  • security reports,
  • other reasonable means.
  1. Audits should be conducted in a manner that does not compromise the security of other customers or the trade secrets of the Processor.

  2. The Processor may refuse to conduct an audit if its scope would be disproportionate, would lead to disclosure of trade secrets, or could compromise the security of other customers.

§14. DELETION OR RETURN OF DATA

  1. The Controller may download data available in Rezulo before terminating the use of the Service.

  2. Data may be stored for a period of up to 90 days from account deletion, in particular in backups.

  3. After the expiry of retention periods, data is deleted or anonymized, unless the law requires further storage.

§15. LIABILITY OF THE PARTIES

  1. Each party is liable for breach of obligations arising from the GDPR to the extent provided for by applicable law.

  2. The Processor is not liable for:

  • the legality of data entered by the Controller,
  • the absence of a legal basis for data processing by the Controller,
  • acts or omissions of the Controller.

§16. LANGUAGE VERSIONS

This Agreement may be published in various language versions.

Translations are for reference purposes only.

In case of discrepancies between language versions, the version indicated by the Processor for a given market or user shall be binding.

§17. FINAL PROVISIONS

  1. For matters not regulated herein, the provisions of the GDPR and Polish law apply.

  2. This Agreement constitutes an integral part of Rezulo's legal documentation.

  3. The current version of the DPA is published on the Rezulo website.

  4. Acceptance of the Rezulo Terms of Service means simultaneous acceptance of this Data Processing Agreement.

  5. The Agreement becomes effective on the date of commencement of Service use or acceptance of the Terms of Service.