VORKIVO

Data Processing Agreement

Effective September 15, 2026 · Version 1.0

This DPA forms part of the VORKIVO Terms between the VORKIVO user (“Customer”) and Dawid Tomaszewicz, operator of VORKIVO (“Processor”), where Processor processes personal data on Customer's behalf.

1. Instructions

Processor processes Customer Personal Data only to provide, secure, maintain and support VORKIVO in accordance with the Terms, this DPA, Customer's configuration and other documented lawful instructions. Processor will inform Customer if an instruction appears to infringe applicable data-protection law unless prohibited.

2. Processing details

ItemDetails
Subject/durationHosting and processing business records for the service term plus limited deletion/backup and legal-retention periods.
Nature/purposeCollection, storage, organization, retrieval, display, transmission and deletion needed for CRM, quotes, jobs, scheduling, invoices, expenses and follow-ups.
Data subjectsCustomer's clients, prospects, contacts, personnel and other persons lawfully entered.
Data typesNames, contact details, addresses, service/job details, quotes, invoices, notes and related records. Special-category data should not be intentionally uploaded unless necessary and lawful.

3. Customer duties

Customer is responsible for lawful, fair and transparent processing, notices, legal bases, data-subject rights, data minimization and lawful instructions.

4. Confidentiality and security

Authorized persons are subject to confidentiality. Processor maintains appropriate measures proportionate to risk, including access controls, authentication, encrypted transport and application/database security controls.

5. Subprocessors

Customer gives general authorization for necessary subprocessors: Supabase (database/auth/backend), Cloudflare (delivery/network/security), Resend (transactional email) and OpenAI (AI processing when VorkiBot is used). Processor will impose required data-protection obligations and remains responsible for its DPA obligations. Material changes will be notified where required.

6. Rights assistance

Taking account of processing, Processor will reasonably assist Customer with data-subject requests and may direct requests concerning Customer Personal Data to Customer.

7. Breaches

Processor will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide reasonably available information needed for applicable notification duties.

8. DPIAs

Processor will provide reasonable assistance with required data-protection impact assessments and prior consultations, taking account of processing and information available.

9. Deletion/return

On termination, Processor will delete or return Customer Personal Data as required by applicable law and available functionality, subject to backups, legal retention and legal claims.

10. Audits

Processor will provide information reasonably necessary to demonstrate compliance. Audits must be proportionate, protect security and other customers, and use existing documentation/remote review where sufficient.

11. Transfers

Restricted international transfers will use an applicable lawful mechanism, including relevant Standard Contractual Clauses where required.

12. Contact

Processor: Dawid Tomaszewicz, ul. Kasztanowa 10/10, 55-010 Święta Katarzyna, Poland.
support@vorkivo.com