Assoluto

Data Processing Agreement

under Article 28 of Regulation (EU) 2016/679 (GDPR)

Version 1.0 · effective from October 6, 2026

The Czech version of this Agreement is binding; other language versions are translations for convenience.

1. Parties and scope

Processor: Václav Mudra, Company ID (IČO) 09989978, with registered office at Lidická 2020/2, 405 02 Děčín. Contact: team@assoluto.eu (the "Processor").

Controller: the Customer — the entrepreneur who uses the Hosted Service at assoluto.eu under the Terms of Service (the "Controller").

This Agreement implements Article 28(3) GDPR. It supplements the Terms of Service and forms part of the contract for the Hosted Service; it applies to every Customer from the effective date of this version, or from the creation of the account if later. Terms not defined here have the meaning given to them in the Terms of Service and in the GDPR.

This Agreement does not apply to Self-Hosted installations, where the Customer runs the software on its own infrastructure and the Provider processes no personal data on its behalf.

On request, the Processor will provide a copy of this Agreement signed on its behalf. Write to team@assoluto.eu.

2. Subject matter and duration

Subject matter: processing of personal data that the Controller, its users and its customer contacts enter into the Hosted Service (the "Personal Data"), solely in order to provide the Hosted Service to the Controller.

Duration: for the term of the contract for the Hosted Service and, after it ends, until the Personal Data is deleted under Section 12.

3. Nature and purpose of processing

Nature of processing: storage and hosting, organisation, retrieval and display to authorised users, transmission (including e-mail notifications), backup, export and deletion.

Purpose: operating the Controller's customer portal — orders and their items, drawings and other attachments, comments, order status and notifications, records of customer-owned material, and communication between the Controller and its clients.

The Processor does not use the Personal Data for its own purposes, does not sell it and does not use it for marketing or profiling.

4. Categories of data subjects

  • the Controller's staff users — employees and other persons the Controller invites to the portal;
  • the Controller's customer contacts — persons at the Controller's clients who are invited to the portal;
  • other persons whose data appears in order content or attachments, for example a name in a drawing's title block or a delivery contact.

5. Categories of personal data

  • identification and contact data: name, work e-mail address, phone number (if entered), role, and the company the person belongs to;
  • client company records, which contain personal data where the client is a sole trader: name, company ID, tax ID, billing address;
  • account data: password hash (Argon2id), language, notification preferences, time of last sign-in;
  • order content: orders, items, quantities, prices, dates, comments, status history and records of customer-owned material;
  • drawings and other uploaded files, including their names and metadata;
  • records of actions in the portal (audit trail) and technical logs (IP address, browser identification) used for security.

The Service is not intended for special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR), and the Controller will not upload such data.

6. Instructions of the Controller

The Processor processes the Personal Data only on documented instructions from the Controller. The instructions are given by this Agreement, by the Terms of Service and by the Controller's configuration and use of the Hosted Service, including actions taken by its users. Further instructions can be given in writing by e-mail.

This also applies to transfers of Personal Data to a third country or an international organisation. The Processor and the subprocessors listed in Annex 2 process the Personal Data in the European Union.

If Union or Member State law requires the Processor to process the Personal Data otherwise, the Processor will inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

The Processor will immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

7. Confidentiality

The Processor ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

The Processor's operator account cannot browse the Controller's portal. Where support requires access, it is granted to that one portal only, and the grant and its revocation are recorded in the portal's audit log, which the Controller's administrators can view.

8. Security of processing

The Processor implements the technical and organisational measures listed in Annex 1 (Article 32 GDPR). It may replace them with measures that provide at least the same level of protection; Annex 1 is then updated accordingly.

9. Subprocessors

The Controller gives the Processor general written authorisation to engage the subprocessors listed in Annex 2.

The Processor will inform the Controller of any intended addition or replacement of a subprocessor at least 30 days in advance, by updating this page and the Privacy Policy and by e-mail to the Controller's administrators. The Controller may object; if the parties do not reach agreement, the Controller may terminate the subscription before the change takes effect.

The Processor imposes on each subprocessor, by contract, data protection obligations that provide at least the same level of protection as this Agreement, and remains fully liable to the Controller for the performance of the subprocessor's obligations.

Other service providers named in the Privacy Policy (payment processing, DNS) do not process the Personal Data on the Controller's behalf and are not subprocessors under this Agreement.

10. Assistance to the Controller

Data subject requests. Taking into account the nature of the processing, the Processor assists the Controller in responding to requests from data subjects under Chapter III GDPR, primarily through functions of the Service:

  • every staff user and customer contact can download their personal data (JSON) and delete their account from their own profile — the account is anonymised, while orders and their history are kept;
  • administrators can export all data of the portal at any time as a ZIP archive (business records as CSV plus all uploaded files);
  • administrators can correct or deactivate staff users, client companies and customer contacts.

If a request cannot be handled with these functions, the Processor will assist on the Controller's request sent by e-mail. If a data subject contacts the Processor directly about the Personal Data, the Processor will forward the request to the Controller without undue delay and will not respond to it on its own unless the Controller instructs it to.

Other obligations. The Processor assists the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment and prior consultation), taking into account the nature of processing and the information available to the Processor.

11. Personal data breach

The Processor will notify the Controller of a personal data breach affecting the Personal Data without undue delay after becoming aware of it, and in any case within 48 hours, by e-mail to the Controller's billing e-mail address of record and to its administrators.

The notification will describe, as far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Information that is not yet available will be provided in phases without further undue delay.

The Processor documents every breach and takes measures to contain it and to mitigate its possible adverse effects. Notifying the supervisory authority and the data subjects remains the Controller's responsibility; the Processor provides the information the Controller needs for it.

12. Return and deletion at the end of the service

Return. Until the account is deactivated — including the 3-day export period after cancellation under the Terms of Service — the Controller can download all data of the portal as a ZIP archive.

Deletion. After deactivation the data is kept for 30 days, during which the Controller may request manual recovery. After 30 days an automated daily job permanently deletes the Personal Data from the database and the file storage, including the copies of uploaded files in the backup storage.

Database backups are not altered; they are deleted automatically when their retention period in Annex 1 expires. Until then they are used only to restore the Service after an incident.

Accounting records about the Customer (such as invoices for the Service) are kept for the period required by Czech accounting law; they are not Personal Data processed on the Controller's behalf. On request, the Processor will confirm the deletion in writing.

13. Information and audits

The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR — in particular this Agreement, Annex 1, the security overview at assoluto.eu/security and, on request, further documentation.

The source code of the Service is public (AGPL-3.0), so the Controller or an auditor it mandates can verify how the software processes data.

The Processor allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by it. An audit beyond the documentation must be announced at least 30 days in advance, may take place at most once per calendar year unless prompted by a personal data breach or required by a supervisory authority, must not disrupt the Service or expose data of other customers, and the auditor must be bound by confidentiality. Each party bears its own costs of the audit.

14. Liability

Between the parties, liability under this Agreement is governed by the Terms of Service, including the limitation of liability in their Section 10. Nothing in this Agreement limits the rights of data subjects under Article 82 GDPR.

15. Final provisions

In matters of personal data protection this Agreement prevails over the Terms of Service.

The Processor may amend this Agreement in the same way as the Terms of Service, with at least 30 days' prior notice; a change required by law or by a supervisory authority may take effect sooner. The version number and effective date at the top of this page identify the current version.

This Agreement is governed by the law of the Czech Republic; jurisdiction follows the Terms of Service.

Annex 1 — Technical and organisational measures

Separation of customers

  • Each supplier's portal is a separate tenant. PostgreSQL Row-Level Security filters every query by tenant inside the database, and the application connects with a database role that cannot switch these policies off.
  • Each customer contact sees only the orders, drawings and material of their own company.

Access control and sign-in

  • Passwords are stored only as Argon2id hashes — never in readable form.
  • Sign-in, signup, password reset and the contact form are rate-limited against brute force.
  • Password-reset and invitation links work only once.
  • Changing a password signs out every existing session.
  • Session cookies are HttpOnly and SameSite=Lax, and sent only over HTTPS in production.
  • Every form is protected against cross-site request forgery (CSRF).
  • Access to the production server and storage is limited to the Processor; support access to a portal requires an explicit grant recorded in that portal's audit log.

Transmission and hosting

  • All traffic is encrypted with HTTPS (HSTS enabled); pages are served with a strict Content-Security-Policy.
  • The application, the database and uploaded files are hosted by Hetzner Online GmbH in Germany (EU) — a server for the application and database, Hetzner Object Storage for drawings and attachments.

Backups and recovery

  • The database is dumped daily and the dump is encrypted (GPG) as it is written; the private key needed to decrypt it is not kept on the server.
  • Encrypted dumps and copies of uploaded files are kept in a separate, private, versioned storage bucket in a different Hetzner location in Germany than the server and the primary file storage.
  • Retention: encrypted daily dumps 14 days on the server and 180 days in the backup location; database copies taken before each software deployment — the latest 10, on the server only.
  • A backup copy of an uploaded file is deleted at the latest 180 days after the file was deleted from the portal; all copies of a deleted portal are removed when the portal's data is purged.
  • Restoring from the off-site backup has been tested, and an automated check reports a failure when the newest off-site copy is older than 30 hours.

Accountability and data lifecycle

  • Administrative actions inside a portal are recorded in an audit trail that the portal's administrators can view.
  • Audit trail records of an active portal are kept for 3 years.
  • Data of a portal deactivated more than 30 days ago is permanently deleted by an automated daily job — from the database, the file storage and the file copies in the backup location.
  • Self-service export and erasure for every user; whole-portal ZIP export for administrators (Section 10).
  • The source code is open (AGPL-3.0), so anyone can check how it works.

Annex 2 — Subprocessors

The Controller authorises the following subprocessors (Section 9). The same list, together with providers that do not process the Personal Data, is published in the Privacy Policy.

Subprocessor Purpose Data categories Location
Hetzner Online GmbH Application hosting and database (VPS); Object Storage for uploaded files; database backups All Customer data, including drawings and other uploaded files DE (EU)
Brevo (Sendinblue SAS) Transactional email delivery Recipient email, name, message body FR (EU)