Data Processing Addendum (DPA)

    This Data Processing Addendum ("DPA") forms an integral part of the Terms of Service ("Principal Agreement") between Paweł Zawadzki Webowy.com Aplikacje Internetowe (doing business as Usecoord), hereinafter referred to as the "Processor", and the business entity using the Services, hereinafter referred to as the "Controller".

    1. Definitions

    • Controller: The Client who determines the purposes and means of the processing of Personal Data.
    • Processor: Paweł Zawadzki Webowy.com Aplikacje Internetowe (Usecoord).
    • Personal Data: Any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller.
    • Services: The hot-desking application for booking desks and meeting rooms as defined in the Terms of Service.

    2. Subject Matter and Duration

    Subject Matter: The Processor shall provide resource booking services (desks, rooms) and office management tools to the Controller.

    Duration: The processing shall continue for the duration of the Controller's subscription to the Services.

    3. Nature and Purpose of Processing

    The Processor will process Personal Data to:

    • Enable employees of the Controller to book office resources.
    • Provide administrative tools for the Controller to manage office space.
    • Authenticate users via Google Account integration.

    4. Categories of Data and Data Subjects

    Based on the Services provided:

    Data Subjects: Employees, contractors, and authorized users of the Controller.

    Categories of Personal Data:

    • Identification Data: Name and surname.
    • Contact Data: Professional email address.
    • Technical Data: IP addresses, device identifiers, and system logs.
    • Usage Data: Booking history (location, date, and time of reservations).

    5. Obligations of the Processor

    The Processor agrees to:

    • Process Personal Data only on documented instructions from the Controller.
    • Ensure that persons authorized to process the data have committed themselves to confidentiality.
    • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (pursuant to Article 32 GDPR).
    • Assist the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights.

    6. Sub-processors

    The Controller grants a general authorization to the Processor to engage sub-processors. The current list includes:

    • Vercel Inc.: Hosting and infrastructure (Data location: Ireland, EU).
    • Database Provider: Managed database services (Data location: Ireland, EU).
    • Google LLC: Authentication services (Google OAuth).
    • Paddle: Payment processing and billing.

    7. International Transfers

    Data is primarily stored and processed within the European Economic Area (EEA) in Ireland. For any transfers to third countries (e.g., to US-based sub-processors), the Processor ensures compliance via the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs).

    8. Audits and Deletion

    Audits: The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 of the GDPR.

    Deletion: Upon termination of the Services, the Processor shall delete all Personal Data, unless mandatory law requires further storage.