Centrum prawne · wersja 2026-08-26.1
Data Processing Agreement (DPA)
Processing terms for customer data in hosted services.
Data obowiązywania: DO UZUPEŁNIENIA
Przed uruchomieniem sprzedaży należy uzupełnić dane przedsiębiorcy i uzyskać przegląd prawnika właściwy dla rynków sprzedaży.
1. Roles and instructions
For personal data submitted by the Customer to hosting or managed services, the Customer is controller and HOSTUVO — środowisko wdrożeniowe is processor. Processing follows documented Customer instructions unless required by law.
2. Confidentiality, security and incidents
Authorised personnel are bound by confidentiality. Risk-based measures include access control, segmentation, transport encryption, backups, logging and vulnerability management.
After confirming a breach affecting entrusted data, we notify the Customer without undue delay and provide available information needed for the Customer’s obligations.
3. Sub-processors and transfers
The Customer gives general authorisation for sub-processors listed in the current register. Material planned changes are notified in advance so a reasoned objection can be made. Equivalent data-protection duties are imposed on sub-processors.
4. Assistance, audit and termination
We reasonably assist with data-subject rights, impact assessments and consultations and provide information needed to demonstrate compliance. Audits must not compromise security or other customers’ confidentiality.
At service end, data is deleted or returned according to instructions, retention schedules and law. Backup copies expire through the normal rotation cycle.