← Back

Data Processing Agreement (DPA)

Effective from March 26, 2026

§1Parties

Controller (Client) – the entity using the Service. Processor (Service Provider) – R4_TECH Rafał Jurek, Al. Ks.K.S. Wyszyńskiego 76/7, 94-047 Łódź, Poland. VAT ID: PL7282787249.

§2Subject Matter

The Controller entrusts the Processor with processing personal data in connection with the use of the Service. Processing takes place solely for the purpose of providing the Service.

§3Categories of Data

Processed data may include: • identification data, • contact data, • accounting data (KSeF), • system logs.

§4Nature of Processing

• storing data, • organising data, • making data available to the user, • processing in an information system.

§5Processor Obligations

The Processor undertakes to: • process data in compliance with the GDPR, • ensure confidentiality, • apply appropriate security measures, • not use the data for its own purposes.

§6Sub-processors

The Processor uses the following sub-processors: • OVH • Stripe • Cloudflare • Google • Zoho Corporation Pvt. Ltd. The Controller consents to their use.

§7International Transfers

Data may be transferred outside the EEA in accordance with the GDPR (Standard Contractual Clauses).

§8Security

The Processor applies: access controls, encrypted transmission (HTTPS), and infrastructure security measures.

§9Data Breaches

The Processor undertakes to notify the Controller of any data breach without undue delay.

§10Duration

This Agreement remains in force for the duration of the Service.

§11Data Deletion

Upon termination of the Service, data may be deleted or returned to the Controller.

§12Audit

The Controller has the right to audit the Processor's compliance with this Agreement.