Data Processing Agreement (DPA)
Effective from March 26, 2026
§1Parties
Controller (Client) – the entity using the Service.
Processor (Service Provider) – R4_TECH Rafał Jurek, Al. Ks.K.S. Wyszyńskiego 76/7, 94-047 Łódź, Poland. VAT ID: PL7282787249.
§2Subject Matter
The Controller entrusts the Processor with processing personal data in connection with the use of the Service. Processing takes place solely for the purpose of providing the Service.
§3Categories of Data
Processed data may include:
• identification data,
• contact data,
• accounting data (KSeF),
• system logs.
§4Nature of Processing
• storing data,
• organising data,
• making data available to the user,
• processing in an information system.
§5Processor Obligations
The Processor undertakes to:
• process data in compliance with the GDPR,
• ensure confidentiality,
• apply appropriate security measures,
• not use the data for its own purposes.
§6Sub-processors
The Processor uses the following sub-processors:
• OVH
• Stripe
• Cloudflare
• Google
• Zoho Corporation Pvt. Ltd.
The Controller consents to their use.
§7International Transfers
Data may be transferred outside the EEA in accordance with the GDPR (Standard Contractual Clauses).
§8Security
The Processor applies: access controls, encrypted transmission (HTTPS), and infrastructure security measures.
§9Data Breaches
The Processor undertakes to notify the Controller of any data breach without undue delay.
§10Duration
This Agreement remains in force for the duration of the Service.
§11Data Deletion
Upon termination of the Service, data may be deleted or returned to the Controller.
§12Audit
The Controller has the right to audit the Processor's compliance with this Agreement.