Data Processing Agreement
This Data Processing Agreement (the "Data Processing Agreement") constitutes Annex No. 2 to the Boostra Terms and Conditions and is concluded between:
the Service Recipient using the Boostra Application, hereinafter the "Controller",
and
BOOSTRA Sp. z o.o. with its registered office in Wrocław, ul. Sudecka 153, 53-128 Wrocław, KRS 0001172942, NIP 8993025273, REGON 541730975, hereinafter the "Processor".
The Data Processing Agreement is concluded upon acceptance of the Terms and Conditions, without the need to submit separate statements. The Controller may download its content from the Application's website at any time.
§ 1. Precedence and Definitions
1. With regard to the processing of personal data, this Data Processing Agreement takes precedence over the Terms and Conditions and the other documents binding the parties. In all other respects, the Terms and Conditions apply.
2. The terms "personal data", "processing", "controller", "processor", "personal data breach" and "data subject" have the meaning given to them in Article 4 GDPR.
3. "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
4. "Entrusted Data" means personal data processed by the Processor on behalf of the Controller, described in Annex No. 1.
§ 2. Subject Matter, Nature, Purpose, and Duration of Processing
1. The Controller entrusts the Processor with the processing of the Entrusted Data to the extent and for the purposes specified in Annex No. 1, which forms an integral part of this Data Processing Agreement.
2. The Processor processes the Entrusted Data for the term of the service agreement, and after its termination only to the extent and for the period specified in § 11.
3. The Processor does not process the Entrusted Data for its own purposes. The rules arising from this prohibition are set out in § 4.
§ 3. Documented Instructions of the Controller
1. The Processor processes the Entrusted Data solely on the documented instructions of the Controller, including with regard to the transfer of data to a third country, unless the obligation to process is imposed by Union law or the law of a Member State. In such a case, the Processor informs the Controller of that legal requirement before processing begins, unless the law prohibits such information on important grounds of public interest.
2. This Data Processing Agreement, the Terms and Conditions, and the actions taken by the Controller and its users in the Application, in particular connecting integrations, selecting the scope of authorization, and accepting proposed actions, constitute the documented instructions of the Controller.
3. Any instructions going beyond the scope indicated in the preceding paragraph shall be issued by the Controller in writing or electronically to kontakt@boostra.pl. If the execution of such an instruction requires effort exceeding the standard scope of the Service, the parties shall agree on the terms of its performance.
4. The Processor shall promptly inform the Controller if, in its assessment, an instruction of the Controller infringes the GDPR or other provisions on the protection of personal data of the European Union or a Member State. Until the matter is clarified, the Processor may suspend the execution of the instruction.
§ 4. Prohibition on Using Data for Own Purposes and for Training Models
1. The Processor does not use the Entrusted Data for its own purposes, in particular for marketing, sales, building its own data sets, or disclosure to third parties, except for further entrustment in accordance with § 7.
2. The Processor does not use the Entrusted Data to train, fine-tune, or validate artificial intelligence models, whether its own or those of third parties. The prohibition also covers pseudonymized data.
3. The Processor uses the available settings and contractual terms that exclude the use of the Entrusted Data for training artificial intelligence models and that limit the retention period of queries to the necessary minimum. The Processor does not use a model provider that does not allow for such an exclusion. If a provider breaches these terms, the Processor shall promptly inform the Controller and take action to bring the breach to an end.
4. The Processor may use data that is fully and irreversibly anonymized, including in aggregate compilations and industry comparisons, solely on condition that it does not allow the data subject or the Controller to be identified, that it relates to a group of an adequate minimum size, and that it does not allow the source data to be reconstructed. Data meeting these conditions does not constitute personal data and is not covered by this Data Processing Agreement.
§ 5. Confidentiality of Personnel
1. The Processor ensures that only authorized persons have access to the Entrusted Data, to the extent necessary to perform their duties.
2. Authorized persons are obliged to keep the Entrusted Data confidential, also after the end of their cooperation with the Processor.
3. The Processor maintains a register of authorized persons and makes it available to the Controller upon request, to the extent not containing personal data of personnel beyond what is necessary for verification.
§ 6. Security of Processing
1. The Processor implements technical and organizational measures appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of infringing the rights and freedoms of natural persons, in accordance with Article 32 GDPR.
2. The list of measures applied is set out in Annex No. 2. The Processor may develop and change the security measures, provided that the level of protection is not reduced.
3. The Processor regularly tests, measures, and evaluates the effectiveness of the measures applied.
§ 7. Further Entrustment of Processing
1. The Controller gives general authorization for the Processor to use further processing entities ("Subprocessors") listed in Annex No. 3.
2. The Processor shall inform the Controller of an intended change consisting of the addition of a Subprocessor or the replacement of an existing one at least 30 days in advance, by means of a notice in the Application or an e-mail to the address indicated in the Controller's Account. Publication of the change on the website does not replace this notification.
3. The Controller may object to the intended change within 14 days of receiving the notification, indicating justified grounds relating to data protection. In the event of an objection, the parties shall make a good-faith attempt to agree on an alternative solution. If agreement is not possible, the Controller may terminate the service agreement in the part affected by the change, with effect at the end of the current Billing Period, without negative financial consequences.
4. The Processor concludes an agreement with each Subprocessor imposing on it data protection obligations no less onerous than those arising from this Data Processing Agreement, in particular the obligations referred to in Article 28(3) GDPR.
5. The Processor is liable to the Controller for the performance of data protection obligations by a Subprocessor as for its own acts and omissions.
6. Store, advertising, and analytics platforms to which the Controller independently grants the Processor access are not Subprocessors of the Processor. The rules for processing data on the part of those platforms are governed by the Controller's relationship with their providers.
§ 8. Assistance in Exercising the Rights of Data Subjects
1. If the Processor receives a request from a data subject relating to the Entrusted Data, it shall forward it to the Controller promptly, no later than within 3 Business Days of receipt, and shall not respond to it independently, unless the Controller instructs otherwise or an obligation to act independently arises from the law.
2. The Processor assists the Controller in fulfilling its obligations under Chapter III of the GDPR, in particular by providing information on the scope of the data processed and, on the Controller's instructions, carrying out the export, rectification, restriction of processing, or erasure of data.
3. Assistance with the standard handling of requests is provided without additional remuneration. For requests requiring effort significantly exceeding standard handling, the parties shall agree on the terms of performance before commencing work.
4. Self-service functions for exporting data and deleting the Account from the panel are not currently available. Requests are fulfilled upon application submitted to support@boostra.pl.
§ 9. Assistance with Obligations under Articles 32-36 GDPR and Personal Data Breaches
1. The Processor assists the Controller in fulfilling its obligations relating to the security of processing, notification of breaches, data protection impact assessments, and prior consultation with the supervisory authority, to the extent corresponding to the nature of the processing and the information available to the Processor.
2. The Processor shall notify the Controller of a breach of protection of the Entrusted Data without undue delay, no later than within 48 hours of becoming aware of the breach. The time limit runs from the moment the breach is identified, not from the completion of its analysis.
3. The notification shall contain at least:
a description of the nature of the breach, including the type of incident and how it was detected;
the categories and approximate number of data subjects concerned, and the categories and approximate number of data records concerned;
the likely consequences of the breach;
the measures taken and proposed to address the breach and mitigate its possible adverse effects;
the contact point details on the part of the Processor.
4. If it is not possible to provide all the information at the time of notification, the Processor shall provide it in phases, without undue delay, as the facts are established.
5. The Processor does not independently notify a breach to the supervisory authority or notify the data subjects concerned, with respect to the Entrusted Data. The decision in this regard rests with the Controller.
6. The Processor maintains internal documentation of breaches relating to the Entrusted Data and makes it available to the Controller upon request.
§ 10. Transfer of Data Outside the European Economic Area
1. The production environment, database, and backups are maintained at an infrastructure provider within the territory of the European Economic Area. System administration is carried out from the territory of Poland.
2. Some Subprocessors, in particular providers of artificial intelligence models, may process the Entrusted Data outside the European Economic Area. The basis for the transfer is a European Commission adequacy decision or Standard Contractual Clauses adopted by the European Commission, in the appropriate module, depending on the Subprocessor.
3. The basis for the transfer applicable to individual Subprocessors is indicated in Annex No. 3. The Processor makes a copy of the safeguards applied available to the Controller upon request.
4. The Processor does not transfer the Entrusted Data outside the European Economic Area to Subprocessors not included in Annex No. 3 without first informing the Controller in the manner set out in § 7(2).
§ 11. Deletion or Return of Data after the Termination of Services
1. After the termination of the provision of services, in particular after the Controller closes its Account, the Processor makes access to the Entrusted Data available to the Controller in Read-Only Mode, enabling its export, for a period of 30 days from that event. If the Controller submits a request to change providers, the periods set out in § 15a of the Terms and Conditions shall apply instead of the period referred to in the preceding sentence.
2. Upon the expiry of the period indicated in the preceding paragraph, the Processor shall permanently delete the Entrusted Data from the production environment or irreversibly anonymize it, at the Controller's choice notified before the expiry of that period. In the absence of such notification, the Processor shall delete the data.
3. Entrusted Data contained in backups is deleted in the natural backup rotation cycle, no later than within 30 days of deletion from the production environment. During this period, the Processor does not use the backups for purposes other than restoring the environment after a failure.
4. Upon the Controller's request, the Processor confirms the deletion of the Entrusted Data in writing or electronically.
5. The Processor may store the Entrusted Data for longer only to the extent and for the period required by Union law or the law of a Member State, informing the Controller of the legal basis and scope of such storage.
§ 12. Information and Audit
1. The Processor makes available to the Controller, upon request, the information necessary to demonstrate compliance with the obligations arising from Article 28 GDPR, in particular a current description of the security measures, the list of Subprocessors, and information on breaches relating to the Entrusted Data.
2. The Controller has the right to conduct an audit or inspection at the Processor's premises, itself or through an authorized auditor, no more than once per calendar year, after notifying the Processor at least 30 days in advance, on Business Days and during the Processor's working hours, in a manner that does not unreasonably hinder its business.
3. The limitations on frequency and advance notice do not apply to an audit conducted following a breach of protection of the Entrusted Data or to an audit conducted at the request of the supervisory authority.
4. The auditor is obliged to maintain confidentiality. The audit may not cover the data of the Processor's other clients, its data constituting a trade secret unrelated to the processing of the Entrusted Data, or personal data of the Processor's personnel beyond what is necessary to verify authorizations.
5. If the Processor obtains a certificate or an independent audit report concerning information security, it may present it in lieu of an on-site audit. As of the date of conclusion of this Data Processing Agreement, the Processor does not hold such a certificate or report.
6. The costs of an on-site audit are borne by the Controller, except for an audit conducted following a breach for which the Processor is responsible.
§ 13. Special Category Data
1. The Controller does not entrust the Processor with the processing of data referred to in Articles 9 and 10 GDPR, unless the parties have agreed otherwise separately in writing, together with a specification of additional security measures.
2. The Controller represents that the sales it conducts do not belong to a category in which the mere information about a completed purchase reveals data concerning the health or sex life of the data subject, in particular that it does not include the sale of pharmacy and medicinal products, herbal products, dietary supplements, medical devices and rehabilitation equipment, optical products, products intended for persons with specific medical conditions, or products from the erotic industry.
3. In the event of a change in the circumstances covered by the representation, the Controller shall promptly inform the Processor thereof. Until additional security measures are agreed, the Processor may suspend processing to the extent affected by the change.
§ 14. Obligations and Representations of the Controller
1. The Controller represents that:
it has a legal basis for processing the Entrusted Data for the purposes for which it entrusts it to the Processor;
it has fulfilled, towards data subjects, the information obligations arising from Articles 13 and 14 GDPR, to the extent covering the use of the Application and the categories of recipients corresponding to the Processor's Subprocessors;
the data was obtained lawfully, and the scope of the authorization granted to the Processor for integrations corresponds to the scope necessary to provide the Service.
2. The Controller is responsible for the lawfulness of the Entrusted Data and for the content of the instructions issued to the Processor.
3. The Controller ensures that the persons to whom it grants access to the Account in the Application are authorized to do so and are bound to maintain confidentiality.
§ 15. Liability
1. Each party is liable for a breach of obligations arising from the GDPR to the extent that the breach results from its act or omission.
2. The Processor is liable to the Controller for the acts and omissions of Subprocessors as for its own.
3. The limitations of liability arising from the Terms and Conditions apply to this Data Processing Agreement, excluding damage caused intentionally and cases in which a limitation of liability is impermissible by operation of law.
4. The provisions of this paragraph do not limit the parties' liability towards data subjects or the supervisory authority.
§ 16. Term, Amendments, and Termination
1. The Data Processing Agreement is in force for the period during which the Processor processes the Entrusted Data, and expires upon performance of the obligations set out in § 11.
2. The Processor may amend the content of the Data Processing Agreement if this is necessary due to a change in the law, guidelines of supervisory authorities, or a material change in the scope of the Service. It shall inform the Controller of the change at least 14 days in advance. The absence of an objection within this period shall be deemed acceptance. In the event of an objection, the Controller may terminate the service agreement with effect at the end of the current Billing Period.
3. The Controller may terminate the service agreement with immediate effect if the Processor materially breaches its obligations arising from this Data Processing Agreement and does not remedy the breach within 14 days of being called upon to do so, or if the supervisory authority orders the cessation of processing.
§ 17. Governing Law and Dispute Resolution
1. The Data Processing Agreement is governed by Polish law.
2. Disputes arising from the Data Processing Agreement shall be resolved by the court having jurisdiction over the Processor's registered office, unless mandatory provisions of law provide for a different jurisdiction.
§ 18. Contact
Notifications of breaches of protection of the Entrusted Data and other matters relating to this Data Processing Agreement should be directed to kontakt@boostra.pl. Requests from data subjects, and notifications concerning the export and deletion of data, are received at support@boostra.pl, in accordance with § 8(4).
ANNEX NO. 1 - DESCRIPTION OF PROCESSING
| ELEMENT | DESCRIPTION |
|---|---|
| Subject matter of processing | Processing of personal data contained in data retrieved from the Controller's systems connected to the Application and data of users of the Controller's Account, to the extent that they constitute the Controller's data, in particular records of the log of actions performed in the connected systems, to the extent necessary to provide the service of analyzing sales and marketing data, generating recommendations and content, and performing actions accepted by the user in the connected systems. |
| Nature of processing | Retrieval of data through the application programming interfaces of the connected systems, storage, organization, analysis, compilation, transfer to artificial intelligence model providers to the extent necessary to provide a response, excluding data identifying buyers, unless the user enters it into the query content themselves, generation of content, and performance of write operations in external systems after the user's acceptance. |
| Purpose of processing | Provision of the Service to the Controller in accordance with the Terms and Conditions. The Processor does not process the Entrusted Data for its own purposes. |
| Duration of processing | The period of use of the Account in the Application. After the Controller closes its Account, 30 days for data export, counted from the closure of the Account. After this period, deletion or irreversible anonymization, taking into account backup rotation of up to 30 days. |
| Categories of data subjects | Buyers and persons placing orders in the Controller's Store. Persons using the Controller's Account in the Application - only to the extent that their data is processed on the Controller's instructions; in other respects, in particular with regard to account, authentication, and billing data, the controller of that data is the Processor, in accordance with the Privacy Policy. Persons whose data is found in the systems connected by the Controller, to the extent covered by the authorization granted. |
| Categories of personal data | Identification and contact data: first and last name, e-mail address, phone number. Order data: order identifier, date, status, amount, currency, item lines and product indexes, quantity, returns. Product and sales data related to the order. Technical data and account identifiers in the connected systems. Data from advertising and analytics accounts is retrieved only at an aggregate level and does not constitute personal data. |
| Special category data | Not entrusted. The rules are set out in § 13 of the Data Processing Agreement. |
| Processing operations | Collection, recording, storage, organization, consultation, use for analysis, disclosure to Subprocessors to the extent specified in Annex No. 3, deletion, and anonymization. |
ANNEX NO. 2 - TECHNICAL AND ORGANIZATIONAL MEASURES
| AREA | MEASURES APPLIED |
|---|---|
| Access control | Access to the production environment and the Controller's data only for authorized persons, to the extent resulting from the assigned role. Two-factor authentication for accounts with access to the production environment. Role-based permission management. On the Controller's side, the roles of administrator, editor, and viewer are available. |
| Integration authentication data | Authentication data and access tokens for the Controller's connected systems stored in encrypted form. Access to cryptographic material limited to persons responsible for maintaining the environment. Accounts in the connected systems remain the property of the Controller; the Processor does not open accounts in its own name. |
| Encryption | Encryption of data in transit. Encryption of authentication data at rest. |
| Event logging | Logging of security events. Logging of the Processor's personnel access to the Controller's data. A log of actions performed in the connected systems, containing the user, time, platform, object, state before and after the change, operation identifier, and the result returned by the external interface. The log serves to reconstruct the course of actions; a completed action cannot be undone, and can only be superseded by a subsequent action. |
| Support access | Access of technical and support personnel to the Controller's data only to the extent necessary to handle a request or incident, time-limited and logged. |
| Backups and business continuity | Regular backups maintained within the European Economic Area, with rotation not exceeding 30 days. Backups used solely to restore the environment after a failure. |
| Change and vulnerability management | Regular updates to the environment. Infrastructure monitoring. Testing the effectiveness of the measures applied. |
| Personnel | Named authorizations to process data. Confidentiality obligations applicable also after the end of cooperation. Training in data protection and security. |
| Location of processing | Production environment, database, and backups within the European Economic Area. System administration from the territory of Poland. Transfer of data outside the European Economic Area only to the extent specified in Annex No. 3. |
ANNEX NO. 3 - LIST OF SUBPROCESSORS
The list covers providers and platforms that have contact with data processed in connection with the Application, divided into three blocks. Block A comprises Subprocessors within the meaning of § 7, i.e., entities processing the Entrusted Data on the Processor's instructions; these include infrastructure and artificial intelligence model providers, as well as the provider of the request-handling tool, because the Entrusted Data may be contained in the content of a request or its attachment. Block B comprises the Processor's own providers, which do not have access to the Entrusted Data and process only data for which the Processor is the controller; they are indicated for the sake of transparency. Block C comprises store, advertising, and analytics platforms to which the Controller independently grants access; in accordance with § 7(6), these are not Subprocessors of the Processor, and the rules for processing data on their part are governed by the Controller's relationship with their providers. The columns concerning the region of processing and the basis for transferring data outside the European Economic Area require confirmation by Boostra against the current data processing agreements of the individual providers.
| SUBPROCESSOR | FUNCTION | REGION | TRANSFER BASIS | NOTES |
|---|---|---|---|---|
| A. SUBPROCESSORS PROCESSING THE ENTRUSTED DATA (§ 7 OF THE DATA PROCESSING AGREEMENT) | ||||
| Hetzner Online GmbH | Hosting, infrastructure, database, backups | EEA | Not applicable | |
| Anthropic | Language model: chat, analytics, content generation | Germany (EEA) | To be confirmed - see notes | Training opt-out and limited query retention |
| OpenAI | Language model: chat, analytics, content generation; image editing and modification | United States | Standard Contractual Clauses | Training opt-out and limited query retention |
| Stability AI | Image generation | United States | Standard Contractual Clauses | |
| Atlassian (Jira Service Management) | Request and support handling | Poland (EEA) | To be confirmed - see notes | Implementation planned. Remote access by personnel outside the EEA requires the transfer basis to be indicated |
| B. PROCESSOR'S PROVIDERS WITHOUT ACCESS TO THE ENTRUSTED DATA | ||||
| Google (Workspace, corporate services) | The Processor's e-mail, documents, and internal tools | United States | Standard Contractual Clauses | Not applicable to the Controller's advertising and analytics accounts |
| GetResponse | Sending of the Processor's marketing messages | Poland (EEA) | Standard Contractual Clauses | Does not handle service or transactional messages |
| Resend | Sending of service and transactional messages | United States | EU-US Data Privacy Framework Standard Contractual Clauses |
Scope of data limited to the e-mail address, message content, and necessary delivery metadata. |
| Calendly | Scheduling of consultations | United States | Standard Contractual Clauses | Scope of data limited to contact details |
| Stripe | Payments and subscriptions | United States | Standard Contractual Clauses | Acts as a separate controller with respect to payment data |
| Google Analytics 4 | Traffic analytics on the boostra.pl website | United States | Standard Contractual Clauses | The controller of the data collected on the website is the Processor |
| Google Tag Manager | Management of tags on the boostra.pl website (GTM-MTNN9TGP, GTM-5ZZ9WJ4B) | United States | Standard Contractual Clauses | Activation requires the website user's consent; see the Cookie Policy |
| C. PLATFORMS CONNECTED BY THE CONTROLLER (§ 7(6)) - NOT SUBPROCESSORS | ||||
| Shoper | E-commerce integration: synchronization of Store and order data | As per the platform's documents | Not applicable - no sub-entrustment | The Controller's account; authorization is granted by the Controller |
| WooCommerce | E-commerce integration: synchronization of Store and order data | As per the platform's documents | Not applicable - no sub-entrustment | The Controller's account; authorization is granted by the Controller |
| Shopify | E-commerce integration: synchronization of Store and order data | As per the platform's documents | Not applicable - no sub-entrustment | The Controller's account; authorization is granted by the Controller |
| Meta Ads | Advertising account: campaign management | As per the platform's documents | Not applicable - no sub-entrustment | The Controller's account; authorization is granted by the Controller |
| Google Ads | Advertising account: campaign management | As per the platform's documents | Not applicable - no sub-entrustment | The Controller's account; authorization is granted by the Controller |
| TikTok Ads | Advertising account: campaign management | As per the platform's documents | Not applicable - no sub-entrustment | The Controller's account; authorization is granted by the Controller |