DATA PROCESSING AGREEMENT

(hereinafter referred to as "Agreement")
concluded in accordance with Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR)

Last updated December 26, 2025

1. CONTRACTING PARTIES

Controller:
Ordering party of Craftorea service – natural or legal person using the Craftorea platform to operate their own e-shop
Data provided during registration in the Craftorea platform
(hereinafter referred to as "Controller")

Processor:
Name: Norbert Vígh
Address: Bajč 776, Bajč 946 54, Slovak Republic
Registered in the Trade Register of the District Office Komárno, no. 440-49417
Registration No.: 56301481
Tax ID: 1125013648
Not a VAT payer.
E-mail: craftorea@gmail.com
(hereinafter referred to as "Processor")

Controller and Processor hereinafter jointly referred to as "Contracting Parties" or individually as "Party".

2. SUBJECT MATTER OF THE AGREEMENT

2.1 This Agreement regulates the conditions for processing personal data in connection with the provision of the Craftorea service (hereinafter referred to as "Service") in accordance with GDPR and Act No. 18/2018 Coll. on the protection of personal data.

2.2 The Controller acts as the controller of personal data within the meaning of GDPR, the Processor acts as the processor of personal data within the meaning of GDPR.

2.3 This Agreement is an integral part of the Service Agreement concluded between the Contracting Parties and takes effect simultaneously with that agreement.

3. SCOPE OF PERSONAL DATA PROCESSING

3.1 Subject of processing:

The Processor processes personal data in connection with the provision of the Service, in particular:

  • personal data of the Controller's customers (name, surname, address, e-mail, phone, order data),
  • data on employees or collaborators of the Controller who have access to the platform,
  • payment and transaction data,
  • technical data related to platform usage (IP addresses, cookies, logs),
  • other personal data that the Controller enters into the platform in the course of operating the e-shop.

3.2 Categories of data subjects:

  • customers of the Controller,
  • employees or collaborators of the Controller,
  • other persons whose personal data the Controller processes in the course of their business activities.

3.3 Purposes of processing:

  • provision and operation of the Craftorea platform,
  • order and customer management,
  • payment processing,
  • technical support provision,
  • ensuring service security and availability,
  • fulfillment of legal obligations of the Processor.

3.4 Retention period of personal data:
Personal data will be processed during the term of the Service Agreement and after its termination for the period necessary to fulfill legal obligations or to defend legal claims, but no longer than 5 years from the termination of the agreement, unless the law provides for a longer retention period.

4. PROCESSOR OBLIGATIONS

4.1 The Processor undertakes:

  • to process personal data exclusively in accordance with the written instructions of the Controller and this agreement,
  • to implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction or alteration,
  • to maintain confidentiality of all personal data and information obtained in connection with the provision of the Service,
  • to enable the Controller to conduct audits and checks of compliance of personal data processing with this agreement and GDPR,
  • to immediately inform the Controller of any personal data security breach that the Processor discovers,
  • to assist the Controller in fulfilling requests of data subjects regarding their rights under GDPR (right of access, rectification, erasure, restriction of processing, data portability, right to object),
  • to assist the Controller in fulfilling obligations arising from GDPR, particularly in data protection impact assessments and consultations with the supervisory authority,
  • upon termination of service provision, to delete or return all personal data to the Controller and delete existing copies, unless the law requires data retention.

4.2 The Processor is authorized to process personal data exclusively within the scope and for the purposes specified in this agreement or in the written instructions of the Controller.

4.3 The Processor may not process personal data for its own purposes or provide them to third parties without the prior written consent of the Controller, except in cases required by law. If the Processor is bound by such obligations, the Processor is required to inform the Controller before processing the data, except in cases where such notification would be unlawful.

4.4 The Processor confirms that it is aware of the relevant data protection laws and must comply with the principles of proper data processing.

4.5 Persons who may have access to the processed data from the Controller must be bound by confidentiality in writing, unless they are already bound by another written agreement.

4.6 The Processor shall ensure that persons it employs and who process data are informed about the relevant data protection regulations, as well as about this agreement, before they begin processing data. Regular appropriate training and measures must be conducted. The Processor shall ensure that persons authorized to process data are properly instructed and continuously monitored for compliance with data protection requirements.

4.7 In connection with the mediated processing of data, the Processor must assist the Controller in designing and updating the list of processing operations and in creating data protection assessments. All requested data and documentation must be provided to the Controller upon request and immediately made available.

4.8 If the Controller were subject to inspection by supervisory authorities or other bodies, or if data subjects were to exercise any rights against the Controller, the Processor is required to assist the Controller to the required extent, if the affected data are processed on behalf of the Controller.

4.9 The Processor may provide information to third parties only with the prior consent of the Controller. Questions sent directly to the Processor will be immediately forwarded to the Controller.

5. CONTROLLER OBLIGATIONS

5.1 The Controller undertakes:

  • to ensure that all personal data provided to the Processor are obtained and processed in accordance with GDPR and applicable legal regulations,
  • to provide the Processor with written instructions regarding the processing of personal data,
  • to inform the Processor of all circumstances that may affect the processing of personal data,
  • to immediately inform the Processor of any changes regarding the processing of personal data,
  • to ensure that data subjects are informed about the processing of their personal data in accordance with GDPR,
  • to ensure that data subjects have the opportunity to exercise their rights under GDPR.

5.2 The Controller is responsible for the lawfulness of obtaining, processing and providing personal data to the Processor and for compliance of personal data processing with GDPR.

6. SECURITY MEASURES

6.1 The Processor implements and maintains appropriate technical and organizational measures to protect personal data, in particular:

  • encryption of data in transit and at rest,
  • regular data backup,
  • access control and restriction to personal data only to authorized persons,
  • regular updates of security systems and software,
  • monitoring and detection of security incidents,
  • regular training of employees in the field of data protection,
  • physical security of servers and data centers.

6.2 The Processor informs the Controller of all significant changes in security measures.

7. DATA SUBJECT RIGHTS

7.1 The Processor will assist the Controller in fulfilling requests of data subjects regarding their rights under GDPR:

  • right of access to personal data,
  • right to rectification of inaccurate personal data,
  • right to erasure of personal data ("right to be forgotten"),
  • right to restriction of processing of personal data,
  • right to data portability,
  • right to object to processing of personal data.

7.2 The Processor will provide the Controller with technical means to exercise these rights of data subjects.

7.3 If the Processor receives a direct request from a data subject regarding their rights under GDPR, it will immediately forward it to the Controller for processing.

8. INSTRUCTIONS

8.1 The Controller reserves the full right to issue instructions regarding the processing of data on its behalf.

8.2 The Processor immediately informs the Controller if, in its opinion, an instruction issued by the Controller violates legal requirements. The Processor has the right to refrain from executing the relevant instructions until they are confirmed or changed by the responsible party on behalf of the Controller.

8.3 The Controller must document issued instructions and their implementation.

9. NOTIFICATION OBLIGATIONS

9.1 The Processor immediately notifies the Controller of any personal data security breach. Any reasonably suspected case must also be reported. The notification must be delivered to one of the Controller's known addresses within 24 hours of the moment when the Processor discovers that the relevant event occurred.

9.2 The security breach notification must contain at least the following information:

  • description of the type of personal data breach and, if possible, the categories and approximate number of data subjects, as well as the relevant categories and approximate number of personal data records,
  • name and contact details of the data protection officer or other contact point for obtaining further information,
  • description of the likely consequences of the personal data breach,
  • description of measures taken or proposed by the Processor to remedy the personal data breach and, where possible, measures to mitigate adverse effects.

9.3 The Controller must also be immediately informed of any significant obstacles in fulfilling this task, as well as of violations of legal provisions on data protection or provisions of this agreement by the Processor or a person it employs.

9.4 The Processor immediately informs the Controller of any inspections or measures carried out by the supervisory authority or other third parties, if they relate to the mediated processing of data.

9.5 The Processor shall ensure that the Controller is supported in these obligations to the necessary extent in accordance with Articles 33 and 34 of the GDPR Regulation.

10. SUB-PROCESSORS

10.1 The Processor may involve third parties (sub-processors) in the processing of personal data only with the prior written consent of the Controller or in accordance with the general consent granted in this agreement.

10.2 The Processor may involve the following sub-processors without the prior consent of the Controller:

  • Vercel Inc. – cloud service provider for hosting and operation of the application,
  • Neon Database Inc. – database service provider for data storage and processing.

10.3 Consent is only possible if the sub-processor is subject to a contractual minimum of data protection obligations that are comparable to the obligations set out in this agreement. The Controller will, upon request, check the relevant agreements between the Processor and the sub-processor.

10.4 The Controller's rights must also be effectively enforceable against the sub-processor. The Controller must in particular have the right to conduct inspections or have inspections conducted by third parties to the extent set out in this agreement.

10.5 The responsibilities of the Controller and the sub-processor must be clearly distinguished.

10.6 Any further sub-processing by the sub-processor is not permitted.

10.7 The Processor shall select the sub-processor primarily on the basis of consideration of the suitability of technical and organizational measures adopted by the sub-processor.

10.8 Any transfer of data processed on behalf of the Controller by sub-processors is permitted only after the Processor submits convincing documentation that the sub-processor fully fulfills its obligations.

10.9 The appointment of sub-processors who process data on behalf of the Controller and who do not have their registered office and do not operate exclusively within the EU or EEA is only possible in accordance with the conditions set out in section 11 of this agreement. This is particularly only permissible if the sub-processor adopts appropriate data protection measures. The Processor informs the Controller of the specific data protection guarantees provided by the sub-processor and how they can be demonstrated.

10.10 The Processor must regularly check whether the sub-processor fulfills its obligations, but at least every 12 months. The inspection and its results are documented so that they are understandable to a qualified third party. The documentation must be provided to the Controller without request.

10.11 If the sub-processor fails to fulfill its data protection obligations, the Processor will be liable to the Controller for this.

10.12 For the purposes of this agreement, sub-processing is understood to mean only those services that directly relate to the provision of the primary service. It does not include supplementary services such as transport, maintenance and cleaning, or the use of telecommunications or user services. The Processor's obligation is to ensure that in these cases proper data protection is ensured and data security remains intact.

11. INTERNATIONAL DATA TRANSFER

11.1 The Processor may process personal data within the European Union or in countries with an adequate level of data protection according to the decision of the European Commission.

11.2 If the Processor needs to transfer personal data to a third country or international organization, it will ensure appropriate safeguards in accordance with GDPR, in particular:

  • standard contractual clauses approved by the European Commission,
  • certification or code of conduct in accordance with GDPR,
  • other safeguards recognized by the European Commission.

11.3 The Processor informs the Controller of all international data transfers and safeguards provided.

12. AUDIT AND CONTROL

12.1 The Processor will enable the Controller or an authorized third party to conduct audits and checks of compliance of personal data processing with this agreement and GDPR.

12.2 Audits are conducted after prior written notice to the Processor at least 30 days in advance and at a reasonable time that does not interfere with the normal operation of the Service.

12.3 The Processor will provide all necessary cooperation in conducting audits, including access to documentation and systems related to personal data processing.

12.4 The costs of the audit are borne by the Controller, unless the audit reveals a breach of this agreement or GDPR by the Processor.

13. CONFIDENTIALITY

13.1 The Processor and all its employees and collaborators are bound by an obligation of confidentiality regarding all personal data and information obtained in connection with the provision of the Service.

13.2 The confidentiality obligation continues even after the termination of this agreement and the Service Agreement.

13.3 The confidentiality obligation does not apply to information that:

  • were publicly known at the time of their provision,
  • became publicly known without breach of the confidentiality obligation,
  • must be disclosed on the basis of legal regulations or court decision.

14. TERMINATION OF THE AGREEMENT

14.1 Upon termination of the contractual relationship or at any time upon request of the Controller, the Processor must either destroy or hand over the data processed as part of the assignment to the Controller, depending on the Controller's decision. Any existing copies of the data must also be destroyed. Data must be destroyed in a manner that prevents recovery or recreation of the remaining information even with considerable effort.

14.2 The Processor is required to immediately ensure the return of data from sub-processors or deletion at sub-processors.

14.3 Any documentation that serves as evidence of proper data processing is retained by the Processor according to the relevant retention periods, including the statutory period after the expiration of the agreement. Once the Processor's contractual obligations end, it may submit the relevant documentation to the Controller.

14.4 The Processor may retain personal data only to the extent and for the period required by law, and during this period all obligations under this agreement apply.

15. REMUNERATION

15.1 The remuneration for the Processor is clearly specified in the Service Agreement. This agreement does not specify a separate remuneration or compensation.

16. RIGHT TO EXTRAORDINARY TERMINATION

16.1 The Controller may terminate this agreement at any time without prior notice ("extraordinary termination") if there is a serious breach of data protection regulations or provisions of this agreement on the part of the Processor, if the Processor cannot or does not execute the Controller's lawful instructions, or if the Processor, in violation of this agreement, refuses to accept the Controller's supervisory rights.

16.2 A serious breach means in particular if the Processor has substantially failed or been unable to fulfill the obligations set out in this agreement, especially regarding technical and organizational measures.

16.3 In case of a minor breach, the Controller will provide the Processor with reasonable time to remedy the situation. If the situation is not properly remedied, the Controller is entitled to extraordinary termination under the conditions set out here.

17. LIABILITY

17.1 The Controller is liable for compensation for damages to anyone for damages caused by any unauthorized party or for incorrect data processing under this agreement.

17.2 The Controller bears the burden of proof to demonstrate that the damage is a consequence of circumstances for which the Processor is responsible, if the given data were processed according to this agreement. If this proof is not submitted, then the Controller, if called upon, will release the Processor from all claims that were made against it in connection with data processing.

17.3 The Processor is liable to the Controller for any damages caused by the Processor, its employees, its sub-processors or an agency acting under contract in connection with the provision of the requested contractual service.

17.4 The Processor's liability is limited to the amount that the Controller paid to the Processor during the two years preceding the event that caused the liability.

17.5 Provisions 17.2 and 17.3 do not apply if the damage arose as a result of the correct realization of the requested service or instruction provided by the Controller.

17.6 The Processor is not liable for damages arising as a result of:

  • incorrect or incomplete instructions from the Controller,
  • breach of the Controller's obligations under this agreement or GDPR,
  • unauthorized processing of personal data by the Controller.

18. FINAL PROVISIONS

18.1 Both parties are required to treat confidentially all information about trade secrets and measures relating to data security that the other party obtained in the course of the contractual relationship, even after the termination of the agreement. If there are doubts as to whether information is subject to confidentiality, it must be treated confidentially until written consent of the other party is obtained.

18.2 In the event that the Processor's assets are threatened by measures of third parties (e.g., seizure or confiscation), bankruptcy or settlement proceedings or other events, the Processor will immediately notify the Controller of these facts.

18.3 This Agreement represents the complete agreement between the Contracting Parties regarding the processing of personal data and replaces all previous agreements and arrangements in this area.

18.4 Changes to this agreement are valid only in writing and must be signed by both Contracting Parties.

18.5 If any provision of this agreement is or becomes invalid or ineffective, the other provisions are not affected and remain in force.

18.6 This Agreement is governed by the law of the Slovak Republic and GDPR.

18.7 Disputes arising from this agreement or in connection with it will be resolved by the Contracting Parties primarily by conciliation. If conciliation is not reached, the court with subject matter and local jurisdiction according to the Processor's registered office is competent to decide disputes.

18.8 This Agreement takes effect on the day of its conclusion, i.e., on the day of acceptance by the Ordering Party within the registration in the Craftorea platform or by signing this agreement.

    Data Processing Agreement · Craftorea