Data Processing Agreement
This DPA forms part of the VORKIVO Terms between the VORKIVO user (“Customer”) and Dawid Tomaszewicz, operator of VORKIVO (“Processor”), where Processor processes personal data on Customer's behalf.
1. Instructions
Processor processes Customer Personal Data only to provide, secure, maintain and support VORKIVO in accordance with the Terms, this DPA, Customer's configuration and other documented lawful instructions. Processor will inform Customer if an instruction appears to infringe applicable data-protection law unless prohibited.
2. Processing details
| Item | Details |
|---|---|
| Subject/duration | Hosting and processing business records for the service term plus limited deletion/backup and legal-retention periods. |
| Nature/purpose | Collection, storage, organization, retrieval, display, transmission and deletion needed for CRM, quotes, jobs, scheduling, invoices, expenses and follow-ups. |
| Data subjects | Customer's clients, prospects, contacts, personnel and other persons lawfully entered. |
| Data types | Names, contact details, addresses, service/job details, quotes, invoices, notes and related records. Special-category data should not be intentionally uploaded unless necessary and lawful. |
3. Customer duties
Customer is responsible for lawful, fair and transparent processing, notices, legal bases, data-subject rights, data minimization and lawful instructions.
4. Confidentiality and security
Authorized persons are subject to confidentiality. Processor maintains appropriate measures proportionate to risk, including access controls, authentication, encrypted transport and application/database security controls.
5. Subprocessors
Customer gives general authorization for necessary subprocessors: Supabase (database/auth/backend), Cloudflare (delivery/network/security), Resend (transactional email) and OpenAI (AI processing when VorkiBot is used). Processor will impose required data-protection obligations and remains responsible for its DPA obligations. Material changes will be notified where required.
6. Rights assistance
Taking account of processing, Processor will reasonably assist Customer with data-subject requests and may direct requests concerning Customer Personal Data to Customer.
7. Breaches
Processor will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide reasonably available information needed for applicable notification duties.
8. DPIAs
Processor will provide reasonable assistance with required data-protection impact assessments and prior consultations, taking account of processing and information available.
9. Deletion/return
On termination, Processor will delete or return Customer Personal Data as required by applicable law and available functionality, subject to backups, legal retention and legal claims.
10. Audits
Processor will provide information reasonably necessary to demonstrate compliance. Audits must be proportionate, protect security and other customers, and use existing documentation/remote review where sufficient.
11. Transfers
Restricted international transfers will use an applicable lawful mechanism, including relevant Standard Contractual Clauses where required.
12. Contact
Processor: Dawid Tomaszewicz, ul. Kasztanowa 10/10, 55-010 Święta Katarzyna, Poland.
support@vorkivo.com