Data Processing Agreement

Data Processing Agreement (DPA)

Version: 1.0 Effective from: [DATE — e.g. 1 July 2026] Processor: Ing. Tomáš Dejmek


This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms of Service between the Operator and the User. It governs the processing of personal data carried out by the Operator on behalf of the User in accordance with Article 28 GDPR.

It applies whenever a User, through a Tool created on the Platform, collects or otherwise processes personal data of Visitors or other persons. In that case:

The User acknowledges that, by accepting the Terms of Service and ticking the GDPR data-processing opt-in at registration, the User concludes this DPA with the Operator.


1. Parties

| Role | Party | |---|---| | Controller | The User / Organisation (identified by the billing e-mail in its account) | | Processor | Ing. Tomáš Dejmek, IČO 06798713, Habarticka 503, Prague, Czech Republic, dejmektomas@gmail.com |


2. Subject-matter and duration (čl. 28(3) GDPR)

2.1. Subject-matter: processing of personal data by the Processor on behalf of the Controller to the extent necessary to host, store, back up, transmit, render and operate the Controller's Tools on the Platform, and to provide related support.

2.2. Duration: for as long as the Controller uses the Platform, ending with deletion or return of the data under Article 11.


3. Nature and purpose of processing

3.1. Nature: storage, hosting, transmission, rendering, execution of Tool logic in a sandbox, storage of Tool version history and of AI Agent conversation history as part of a Tool, backup, and — only with the Controller's one-time consent — technical support or reproduction in a test environment.

3.2. Purpose: to provide the Platform service to the Controller so that the Controller's Tools function for Visitors.

3.3. The Processor processes personal data only on documented instructions of the Controller (čl. 28(3)(a) GDPR). The Controller's instructions are constituted by the Terms of Service, this DPA, and the configuration the Controller makes in the Platform (e.g. the inputs a Tool collects). The Processor does not determine the purposes or means of processing the Visitor data within Tools, and does not read Tool content except under the support provision.


4. Types of personal data and categories of data subjects

4.1. Categories of data subjects: Visitors and any other persons whose data the Controller chooses to collect or process through its Tools; the Controller's own Members.

4.2. Types of personal data: determined solely by the Controller through the design of its Tools. Typically: data entered into Tool inputs (which may include names, contact details, financial figures or other identifiers chosen by the Controller), and technical data such as Visitor IP addresses contained in server access logs, retained for a short technical period. The embedded widget does not set cookies in Visitors' browsers.

4.3. Special categories (čl. 9 GDPR). The Platform is not intended for special-category data (e.g. health, biometric, racial/ethnic data). If the Controller chooses to process such data through a Tool, the Controller is solely responsible for having a valid legal basis under čl. 9 GDPR and for any heightened obligations; the Controller must inform the Processor in advance so that adequate measures can be agreed.

4.4. The Processor does not know the precise content of the data, because it does not read Tool content (Article 3.3).


5. Obligations of the Processor (čl. 28(3) GDPR)

The Processor shall:

(a) process personal data only on documented instructions of the Controller, including as regards transfers to third countries, unless required by EU or Member-State law (in which case it informs the Controller, unless prohibited);

(b) ensure that persons authorised to process the data are bound by confidentiality;

(c) implement the technical and organisational measures in Annex 2 (čl. 32 GDPR);

(d) respect the conditions for engaging sub-processors in Article 7;

(e) assist the Controller, taking into account the nature of processing, in responding to data-subject requests (čl. 12–23 GDPR);

(f) assist the Controller in ensuring compliance with čl. 32–36 GDPR (security, breach notification, data-protection impact assessments), taking into account the information available to the Processor;

(g) at the Controller's choice, delete or return all personal data after the end of the provision of services (Article 11);

(h) make available to the Controller the information necessary to demonstrate compliance with čl. 28 and allow for and contribute to audits under Article 8;

(i) notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information the Processor reasonably has, so the Controller can meet its čl. 33/34 obligations.


6. Obligations of the Controller

The Controller shall:

(a) ensure it has a valid legal basis (čl. 6 GDPR, and čl. 9 where applicable) for all data it processes through its Tools;

(b) provide all required information notices to its Visitors/data subjects and obtain any required consents;

(c) issue instructions that are lawful; and

(d) be solely responsible for the content, lawfulness and accuracy of the data processed through its Tools.

The Processor is entitled to assume that the Controller's instructions are lawful and that the Controller complies with its obligations as controller.


7. Sub-processors (čl. 28(2),(4) GDPR)

7.1. The Controller gives the Processor general written authorisation to engage sub-processors. The current sub-processors are listed in Annex 1.

7.2. The Processor will inform the Controller of any intended addition or replacement of a sub-processor (by e-mail and/or in the Platform), giving the Controller the opportunity to object on reasonable data-protection grounds within 14 days. If the Controller objects and the matter cannot be resolved, the Controller may terminate the affected service.

7.3. The Processor imposes on each sub-processor, by contract, data-protection obligations equivalent to those in this DPA, and remains fully liable to the Controller for the sub-processor's performance.


8. Audit (čl. 28(3)(h) GDPR)

8.1. The Processor makes available, on the Controller's reasonable written request, the information necessary to demonstrate compliance with this DPA.

8.2. Audits or inspections take place no more than once per year (unless required by a supervisory authority or following a breach), on at least 30 days' prior written notice, during business hours, without unreasonable disruption, and subject to confidentiality. The Processor may satisfy audit requests by providing relevant documentation or third-party reports where available.


9. International transfers

9.1. The Processor does not transfer the Controller's data outside the EU/EEA except via the sub-processors in Annex 1 and under appropriate safeguards (čl. 46 GDPR), in particular Standard Contractual Clauses.

9.2. The Controller acknowledges that use of the AI Agent transmits the text submitted by the Controller (or its Members) to Anthropic in the USA, under the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. The Controller must not submit personal data into AI Agent prompts unless it has a lawful basis and accepts that transfer. This use is at the Controller's instruction. AI Agent conversations are stored as part of the relevant Tool and deleted together with it.


10. Data breach

The Processor notifies the Controller without undue delay (and where feasible within 72 hours of becoming aware) of any personal-data breach affecting the Controller's data, with the nature of the breach, likely consequences and measures taken or proposed, to the extent known. The Controller is responsible for any notification to the supervisory authority and data subjects.


11. Return and deletion of data (čl. 28(3)(g) GDPR)

11.1. Upon termination of the service, or on the Controller's request, the Processor deletes the Controller's personal data — including Tool version history and AI Agent conversations stored with Tools — subject to the 30-day grace period for reactivation stated in the Terms.

11.2. Encrypted backups containing the data are purged on a rolling basis within 30 days thereafter. During that window backups are not restored except for disaster recovery.

11.3. The Processor may retain data where required by EU or Member-State law, for the period and purpose so required.


12. Liability and final provisions

12.1. Each party's liability under this DPA is subject to the limitations agreed in the Terms of Service, to the extent permitted by čl. 82 GDPR and applicable law.

12.2. This DPA is governed by the law of the Czech Republic and forms an integral part of the Terms of Service. In case of conflict between this DPA and the Terms on data-protection matters, this DPA prevails.

12.3. This DPA enters into force on acceptance of the Terms / the GDPR opt-in and remains in force for the duration of the service.


Annex 1 — List of sub-processors

| Sub-processor | Purpose | Location | Transfer safeguard | |---|---|---|---| | Amazon Web Services EMEA SARL (AWS) | Hosting, storage, daily backups of Tools and data — region eu-north-1 (Stockholm, Sweden) | EU/EEA | Data stored within EU/EEA; AWS GDPR Data Processing Addendum; SCC / EU-U.S. DPF for any ancillary transfers | | Anthropic, PBC | AI Agent — generation of Tools from text prompts | USA | EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses |

The Processor will keep this Annex current and notify the Controller of changes under Article 7.2.

Note: Google (OAuth login, website analytics) and the payment provider process platform account and billing data for which the Operator is the controller — they are recipients listed in the Privacy Policy, not sub-processors of Visitor data under this DPA.


Annex 2 — Technical and organisational measures (čl. 32 GDPR)

The Processor maintains, as appropriate to the risk:

  1. Access control — restricted, authenticated access to systems; the Operator does not read Tool content except with the Controller's one-time support consent.
  2. Encryption — encryption of backups; encryption of data in transit (TLS).
  3. Sandboxed execution — Tool logic (Python) runs in an isolated sandbox, separating execution from other tenants and from the host.
  4. Tenant isolation — Organisations/Users are logically isolated on the shared infrastructure.
  5. Backups & recovery — daily backups; restoration procedures for service continuity.
  6. Confidentiality — persons with access are bound by confidentiality obligations.
  7. Resilience & monitoring — measures to maintain availability, with monitoring of operational metrics (not content).
  8. Data minimisation — the Operator observes only aggregate operational metrics and does not collect Tool content for its own purposes. The embedded widget sets no cookies in Visitors' browsers; Visitor IP addresses appear only in server access logs retained for a short technical period.
  9. Incident response — procedures to detect, handle and notify personal-data breaches.

These measures may be updated to reflect technical developments, provided the level of protection is not reduced.


⚠️ Legal notice: This DPA template should be reviewed by a qualified Czech lawyer, in particular Annexes 1 and 2 (which must reflect the actual infrastructure) and the transfer safeguards for Anthropic (USA). The safeguards must actually be concluded: accept Anthropic's Commercial Terms incl. DPA and AWS's GDPR Data Processing Addendum — referencing them in this document does not create them.