Data Processing Agreement
This document is a data processing agreement under Article 28 of the General Data Protection Regulation (GDPR). It is concluded between the customer as controller and the provider as processor, and forms part of the terms of service.
In force from 31 July 2026
1. The parties
The controller is the customer, namely the business entity that runs its organization in Terenska naročila and enters data into it.
The processor is Nejc Gergič s.p., Adamičeva 52D, 2000 Maribor, Slovenia, registration number 9857125000.
This agreement is concluded in electronic form and takes effect when the customer accepts the terms of service. A separately signed contract is not required; if the customer needs one, we will provide it on request with identical content.
2. Subject matter, nature and purpose
The processor processes personal data solely to provide the controller with field order capture and management: storing and displaying customer data, creating orders and order sheets, sending email notifications, maintaining backups, and providing technical support.
Processing lasts for the duration of the subscription relationship, plus the period set out in clause 9.
3. Types of personal data
- contact data of the controller's customers: contact person's name, company or branch name, email address, phone number, address and town,
- content data: notes about a customer, order history, granted rewards and benefits,
- data about the controller's users: name, email address, role, profile picture (optional), sign-in records.
The service is not intended for processing special categories of personal data under Article 9 GDPR (health data, biometrics and the like). The controller undertakes not to enter such data into free-text fields.
4. Categories of data subjects
- contact persons at the controller's customers and business partners,
- employees and contractors of the controller who use the service.
5. Obligations of the processor
- 1.Processes personal data only on documented instructions from the controller. Use of the service in accordance with the terms of service constitutes such an instruction. Where processing is required by EU or Slovenian law, the processor informs the controller before processing, unless that law prohibits it.
- 2.Ensures that persons authorised to process the data are bound by confidentiality.
- 3.Implements the technical and organisational measures required by Article 32 GDPR, described in clause 7.
- 4.Engages sub-processors under the conditions in clause 6.
- 5.Assists the controller with data subject requests under Chapter III GDPR, taking into account the nature of the processing.
- 6.Assists the controller in meeting the obligations in Articles 32 to 36 GDPR, including breach notification and impact assessments.
- 7.Deletes or returns the personal data when the service ends, as set out in clause 9.
- 8.Makes available all information necessary to demonstrate compliance with this clause and allows for audits under clause 10.
- 9.Immediately informs the controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
6. Sub-processors
The controller gives the processor general written authorisation to engage sub-processors. The processor concludes a contract with each of them imposing data protection obligations at least equivalent to those in this agreement, and remains liable for their performance as for its own.
As at the effective date of this agreement, the sub-processors are:
| Sub-processor | Purpose | Data location |
|---|---|---|
| Supabase, Inc. | database, authentication, file storage, backups | Frankfurt, Germany (EU) |
| Vercel, Inc. | hosting and running the application | Frankfurt, Germany (EU) |
| Resend (Plus Five Five, Inc.) | transactional email (sign-in codes, notifications, order sheets) | EU and USA |
| Google Ireland Ltd. | Google sign-in, where a user chooses that option | EU |
The processor gives the controller at least 30 days' notice by email of any intended replacement or addition of a sub-processor. Within that period the controller may object on reasonable data protection grounds. If no solution can be found, the controller may terminate the subscription and receive a pro rata refund of the unused part of the paid period.
7. Technical and organisational measures
- Encryption in transit: all traffic runs over HTTPS/TLS.
- Encryption at rest: the database and backups are encrypted.
- Tenant separation: data is separated at the database level using row-level security, so one customer's query cannot reach another customer's data.
- Passwordless sign-in: access is confirmed with a short-lived one-time code, so there are no stored passwords to expose.
- Access control: only the provider has access to the production environment, on a least-privilege basis.
- Backups: automatic daily backups stored within the EU, with point-in-time recovery.
- Logging: access and changes are logged to the extent needed to investigate an incident.
- Patching: dependencies and platform are updated with security fixes on a regular basis.
8. Personal data breach
The processor notifies the controller of any personal data breach without undue delay and no later than 48 hours after becoming aware of it. The notification describes the nature of the breach, the categories and approximate number of records and data subjects concerned, the likely consequences, and the measures taken or proposed.
Notifying the supervisory authority and the data subjects is the controller's obligation; the processor supports it with all available information.
9. Deletion and return of data
After the subscription relationship ends, the processor keeps the data for a further 90 days so the controller can renew or request an export. The processor prepares the export on request, in a machine-readable format. After the 90 days the data is permanently deleted, including from backups as part of their regular rotation cycle.
The controller may request immediate deletion earlier. The only exception is data the processor must retain by law, such as issued invoices.
10. Audits and demonstrating compliance
On request, the processor provides the controller with the information needed to demonstrate compliance with this agreement. The controller may carry out an audit once a year, with at least 30 days' notice and during business hours; the parties agree the scope so that the audit does not disrupt the service or expose other customers' data. Where the controller requests the audit itself, it bears the cost.
11. Transfers to third countries
Data is stored in the European Union. Where support or maintenance involves access from a third country, that transfer relies on the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework, together with additional technical measures.
12. Relationship to other documents
This agreement forms part of the terms of service and prevails over them on questions of personal data processing. Processing where the provider is itself the controller is governed by the privacy policy.
Need a signed copy or want to use your own DPA template? Write to info@terenskanarocila.si and we will sort it out.