Draft — under legal review
Data Processing Agreement
Draft. This document is a draft prepared by the Solispec development team and is under review by a lawyer. It is not yet in force. Translations are provided for convenience; if a translation differs from the English version, the English version prevails.
1. Parties and scope
This Data Processing Agreement ("DPA") is between the customer using a Pro, Business or White Label plan ("Customer", the controller) and the operator of Solispec, a Ukrainian sole proprietor: [OPERATOR: full name, tax ID and address — to be provided by the owner] ("Solispec", the processor).
It applies when the Customer's projects or clients address book contain personal data of third parties, and it supplements the Terms of Service. It is intended to meet Article 28 GDPR. [LAWYER: confirm how the DPA is concluded, e.g. accepted in the account settings or with the Terms.]
2. Details of the processing
- Subject matter: hosting and processing of Customer data in the Solispec service.
- Duration: for as long as Solispec provides the Service to the Customer, plus the deletion period in section 10.
- Nature and purpose: storage, display, calculation, versioning, backup and, once available, export, only to provide the Service.
- Categories of data subjects: the Customer's clients and their contact persons, and other people the Customer records in projects.
- Categories of personal data: name, email, phone, address, notes, and installation locations or addresses in projects. The Customer should not store special categories of data (Article 9 GDPR).
3. Instructions
Solispec processes the personal data only on the Customer's documented instructions. These Terms, this DPA and the Customer's use of the Service's functions are the Customer's instructions. If Solispec is required by law to process the data otherwise, it will inform the Customer first unless the law forbids this. Solispec will tell the Customer if it believes an instruction breaches data protection law.
4. Confidentiality
Solispec ensures that everyone authorised to process the personal data is bound by confidentiality.
5. Security measures
Solispec implements appropriate technical and organisational measures, including:
- encryption in transit (TLS);
- access control based on accounts and roles;
- isolation of each organization's data from other organizations;
- password hashing;
- regular backups stored in the EU.
Solispec may update these measures if the level of protection is not reduced.
6. Sub-processors
The Customer gives general authorisation for the following sub-processors:
- OVH — hosting and backups (EU);
- Stripe — card payments (billing data of the Customer);
- Heleket — cryptocurrency payments (billing data of the Customer);
- an email delivery provider (SMTP) [to be named].
Google Analytics (only with consent) and map providers (OpenStreetMap/Nominatim, map tile providers, Mapbox with the user's own token) are requested by the visitor's browser directly or concern website use; they do not receive the Customer's client address book. [LAWYER: confirm this classification.]
Solispec will inform the Customer in advance of any new or replaced sub-processor [notice period to be set]. The Customer may object on reasonable data-protection grounds; if no solution is found, the Customer may terminate the affected plan. Solispec imposes data protection obligations on each sub-processor equivalent to this DPA and remains responsible for them.
7. International transfers
Customer data is hosted and backed up in the EU, so standard contractual clauses are not needed for the hosting. Where Stripe, Heleket or Google process data outside the EU, the transfers rely on their own safeguards. [LAWYER: confirm Heleket's location and transfer basis.]
[LAWYER: Solispec is established in Ukraine and administers the Service remotely; assess whether this access requires safeguards under Chapter V GDPR.]
8. Assistance
Taking into account the nature of the processing, Solispec helps the Customer to:
- answer data subjects' requests (access, rectification, erasure, restriction, portability, objection); if a data subject contacts Solispec directly, Solispec will forward the request to the Customer;
- meet its obligations on security, breach notification, data protection impact assessments and prior consultation.
9. Personal data breaches
Solispec will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data. The notice will include the information available at the time, such as the nature of the breach, the likely consequences and the measures taken or proposed.
10. Deletion or return
At the end of the Service, the Customer can obtain a copy of its data: by self-service export once it is available, and until then on request to [email protected], provided within one month. Solispec will then delete the personal data, unless the law requires it to be kept. Copies in backups are deleted as the backups rotate, within up to 30 days [verify].
11. Audits
On request, Solispec will provide the information needed to show compliance with this DPA and will allow and contribute to audits by the Customer or an auditor it appoints, with reasonable notice and confidentiality. [LAWYER: set frequency and cost rules.]
12. Liability and precedence
Liability under this DPA is governed by the Terms of Service, subject to mandatory law. If this DPA conflicts with the Terms on data protection matters, this DPA prevails.