This Data Processing Addendum ("DPA") forms part of the agreement between Inovit d.o.o. ("Managd", "Processor") and the customer ("Controller") for use of the Managd Services. It applies to the extent Managd processes personal data on behalf of the Controller within the meaning of Regulation (EU) 2016/679 ("GDPR") or equivalent legislation.
1. Subject matter and duration
Managd processes personal data on the Controller's behalf solely to provide and support the Services, for as long as the Services are provided plus any period required by law.
2. Nature, purpose and types of data
- Nature & purpose: hosting, storage, backup, network transit, support.
- Categories of data subjects: the Controller's end users, customers, and staff whose data is processed via the Services.
- Types of personal data: determined by the Controller; may include identifiers, contact data, content, and any other data the Controller chooses to store.
3. Controller instructions
Managd will process personal data only on the Controller's documented instructions, including those set out in the main agreement and this DPA, unless required to do so by law.
4. Confidentiality
Managd ensures that personnel authorised to process personal data are bound by appropriate confidentiality obligations.
5. Security measures
Managd implements appropriate technical and organisational measures to protect personal data, including: encryption in transit (TLS), encryption of secrets at rest, role-based access controls, audit logging, least-privilege access, MFA for administrative access, vulnerability management, and physical security at hosting facilities operated by our infrastructure subprocessors.
6. Subprocessors
The Controller authorises Managd to engage subprocessors to provide the Services. Managd imposes equivalent data protection obligations on each subprocessor by contract and remains liable for their performance. A current list of subprocessors is available in the Privacy Policy. We will provide at least 30 days' prior notice of new subprocessors and give the Controller a chance to object on reasonable data protection grounds.
7. Data subject rights
Taking into account the nature of the processing, Managd will assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to data subject requests.
8. Personal data breaches
Managd will notify the Controller without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting the Controller's data, and will provide information reasonably required for the Controller's own notifications.
9. International transfers
Where personal data is transferred outside the EEA, Managd relies on adequacy decisions or, where none applies, the European Commission's Standard Contractual Clauses (2021/914), which are incorporated by reference into this DPA.
10. Audits
Managd makes available to the Controller information necessary to demonstrate compliance with Article 28 GDPR. Audits may be conducted on reasonable notice, at the Controller's cost, no more than once per year, subject to confidentiality and minimal disruption to operations. Independent third-party audit reports may be provided in lieu of on-site audits.
11. Deletion or return
On termination of the Services, the Controller may export its data within 30 days, after which Managd will delete or anonymise personal data, except where retention is required by law.
12. Liability
Liability under this DPA is subject to the limitations of liability set out in the main agreement.
13. Signing the DPA
By accepting the Managd Terms of Service and continuing to use the Services, the Controller is deemed to have accepted this DPA. A countersigned copy is available on request from legal@managd.net.