Legal

Data Processing Agreement

Effective 25 September 2026

This Data Processing Agreement ("DPA") is part of the Terms of Service between Liubomyr Manastyretskyi, a self-employed person (OSVČ) registered in the Czech Republic and trading as Vizitka ("Vizitka", "we"), and you, the customer, and applies whenever we process personal data on your behalf in providing the service. It sets out the terms Article 28 of the GDPR requires between a controller and its processor. No signature is needed: it takes effect when you accept the Terms of Service and use the service for a website that collects or shows personal data. If you need a signed copy, write to [email protected].

1. Roles

You are the controller of the personal data your site collects and holds: the details visitors enter into its forms, the people named in its content, the pictures of people you upload, and anything else about an identifiable person that you put into your site. We are your processor for that data. For the data about you as our customer, such as your account and sign-in details, we are the controller, and the Privacy Policy applies instead of this DPA.

2. What the processing is

Item

Description

Subject matter

Hosting, storing, publishing and processing your site and the data it collects, as the service does

Duration

For as long as you have an account with a site on it, plus the deletion period in Section 9

Nature and purpose

Storing content and form submissions, serving pages to visitors, showing submissions to you and the members you invite, sending you notifications, running the workflows you set up, keeping version history, and providing support

Types of personal data

Whatever your forms ask for (typically names, email addresses, phone numbers and messages); personal data in your pages, posts, tables and uploaded files; visitors' IP addresses and browser details in server logs

Data subjects

Visitors of your site; your customers and prospects; people named or shown in your content

3. Our obligations

We will:

  • process personal data only on your documented instructions, which are the Terms of Service, this DPA, and what you do in the dashboard and through an agent you authorized; we tell you if we believe an instruction breaks the law;

  • process it only for the purposes in Section 2, never for our own purposes, and never sell it or use it for advertising;

  • make sure the people who can access it are bound to confidentiality and access it only to run, secure and support the service;

  • keep the security measures in Section 6;

  • engage other processors only as Section 5 allows;

  • help you answer requests from data subjects, as Section 7 describes;

  • help you meet your obligations on security, breach notification and, where needed, data protection impact assessments, taking into account what we know and what the service can do;

  • delete the data when the agreement ends, as Section 9 describes;

  • make available the information needed to show that we keep this DPA, and allow audits as Section 8 describes.

4. Your obligations

You are responsible for the lawfulness of the processing you instruct: for having a legal basis to collect what your forms collect, for telling your visitors what you collect and why, for asking their consent where the law requires it (including for analytics and other tags you connect), for keeping your own privacy notice, and for answering data subjects who exercise their rights against you. You also instruct us, through the service, on what to collect and what to delete: the forms you build, the tags you connect, the workflows you set up and the rows you delete are your instructions.

5. Subprocessors

You authorize us to use the providers listed on the Subprocessors page, each of which is bound by a contract with data protection obligations no weaker than this DPA's. We may add or replace a provider; we will update that page and tell account holders in the dashboard or by email at least 30 days before a new provider processes your data. If you object on reasonable data protection grounds and we cannot resolve it, you may end the agreement for the affected site before the change takes effect, and we refund the unused part of any paid period. We remain responsible for our subprocessors.

6. Security

We keep technical and organizational measures appropriate to the risk, including:

  • encryption in transit, and at rest for secrets and workflow data;

  • separation of each site's data from every other site's;

  • access to submissions limited to the site's members, and denied to coding agents;

  • a version history of changes, so that a mistaken or malicious change can be undone;

  • hosting in data centres in the European Union with a provider certified to ISO 27001;

  • restriction of production access to the people who run the service.

We may change these measures as the service evolves, but not in a way that lowers the level of protection.

7. Data subjects' requests

If a visitor asks you to access, correct, delete or restrict their data, the dashboard lets you see and delete submissions and other content yourself, and that is the way to honour most requests. If a request reaches us instead of you, we will forward it to you without undue delay and will not answer it ourselves unless you ask us to or the law requires it. Where the dashboard is not enough, we help you at your request.

8. Personal data breaches and audits

If we become aware of a breach of security that affects personal data we process for you, we will notify you without undue delay, and within 48 hours where we can, with the information we have at the time and more as it becomes available, so that you can meet your own notification duties.

We make available, on request, the information reasonably necessary to show that we keep this DPA, including a description of our measures and the certifications of our hosting providers. Where that is not enough, you may audit us, or have an independent auditor bound to confidentiality do so, once in any 12 months, with 30 days' notice, during business hours, in a way that does not endanger the security of other customers' data, and at your cost.

9. Deletion at the end

When you delete a site, or your account, we delete the personal data we process for you from our live systems as the Privacy Policy describes, and the remaining traces (server logs, error reports and the change history of table rows) expire within the periods stated there. We may keep data the law requires us to keep, and only for as long as it requires. Export what you need before you delete.

10. Transfers

Our servers and database are in the European Union. Where a subprocessor is outside the European Economic Area, or may process data outside it (such as Cloudflare's global network), the transfer relies on an adequacy decision, including the EU-U.S. Data Privacy Framework for certified providers, or on the European Commission's Standard Contractual Clauses, as the Subprocessors page states for each provider. You may ask us for the documentation.

11. Liability and precedence

Liability under this DPA is governed by the liability terms in the Terms of Service. If this DPA and the Terms of Service conflict about the processing of personal data, this DPA prevails.