Back

Legal document

Appendix 1: Data Processing Terms

Data Processing Agreement forming Appendix 1 to the AnimalAdmin Platform Terms

Effective from 26 August 2026

These Data Processing Terms constitute the Data Processing Agreement.

Entrustment of personal data processing

  1. The Service Provider and Service Recipient cooperate under the Agreement for supply of Services based on the Terms (the Main Agreement).
  2. The Controller (Service Recipient) entrusts the Processor (Service Provider) with processing personal data under Article 28 GDPR.
  3. The Controller represents that it is controller of the entrusted data or a processor authorised to engage the Processor as a further processor.
  4. Processing is entrusted within the scope set out in § 2.
  5. Capitalised terms have the meanings given in the Terms or GDPR unless stated otherwise.

Subject matter, nature, purpose and duration

  1. The Processor processes entrusted personal data only on the Controller's documented instructions and solely to supply the Services. Entering into the Main Agreement constitutes a documented instruction.
  2. Categories of data and data subjects are listed in Appendix 1 to the Data Processing Agreement.
  3. The Controller must not entrust data under Articles 9 or 10 GDPR without prior agreement in documentary form and bears sole responsibility for breach.
  4. Processing uses ICT systems and is automated.

Processor obligations, rights and representations

  1. The Processor implements and maintains technical and organisational measures appropriate to the nature, scope, context and purpose of processing and required by law so processing complies with GDPR.
  2. Authorised persons must be bound by confidentiality or an appropriate statutory duty.
  3. Where justified and possible, the Processor assists the Controller in responding to data-subject requests under applicable law, including GDPR Chapter III.
  4. The Processor promptly informs the Controller of:
    1. each personal data breach involving entrusted data, meaning accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, no later than 48 hours after detection;
    2. each request received from a data subject, without responding until the Controller's instructions are received, no later than 48 hours after receipt;
    3. each legally authorised government request for disclosure, unless notification is prohibited by law to preserve investigation confidentiality;
    4. an audit by the President of the Polish Personal Data Protection Office or another supervisory authority, its results and other public-authority actions concerning the data.
  5. Within the justified scope and available information, the Processor assists with obligations under Articles 32-36 GDPR concerning security, breach notification, impact assessments and consultation.
  6. The Processor:
    1. provides information and documents necessary to demonstrate compliance within 14 days of request;
    2. allows and contributes to audits and inspections on terms agreed by the Parties and subject to this section.
  7. An audit may occur no earlier than 14 days after notice, on an agreed date, and after a confidentiality agreement is entered into with the Controller or authorised auditor.
  8. After an audit, the Parties prepare two signed copies of a report. The Processor may submit reservations within five working days.
  9. Where deficiencies affect security, the Processor implements recommendations made by the Controller or auditor.

Controller obligations

  1. Throughout the agreement, the Controller must have a legal basis and authority to entrust the data. If either is lost, it must promptly stop entrusting affected data and inform the Processor.
  2. The Controller must not issue instructions contrary to applicable law, the Data Processing Agreement or other contractual obligations.

Subprocessing

  1. The Controller gives general authorisation for the Processor to appoint subprocessors, including those in Appendix 2.
  2. The Processor ensures each subprocessor applies appropriate GDPR-compliant measures and equivalent data-protection obligations.
  3. For a new subprocessor or changed scope, the Processor gives email notice at least seven days in advance. The Controller may object by email within seven days of notice.
  4. If no objection is made in time, the Processor may proceed.
  5. If an objection is made, the Processor may terminate the Main Agreement immediately.
  6. Subprocessing under paragraph 3 does not amend the Data Processing Agreement.
  7. The subprocessor list is Appendix 2.

Confidentiality

The Parties use materials, data and information obtained from the other Party solely to perform the Data Processing Agreement and keep them confidential during and after its term.

Consequences of termination

Following termination, the Processor promptly, and no later than 14 working days after termination, returns to the Controller and deletes from its media all entrusted personal data, including electronic media. This does not apply to data that applicable law requires the Processor to retain for longer.

Final provisions

  1. Appendix 1 lists data and data-subject categories; Appendix 2 lists subprocessors.
  2. Changes are governed by the amendment provisions of the Terms.
  3. Matters not regulated are governed by the Terms, GDPR and applicable Polish law.

Attachments