Data Processing Agreement (DPA)
A personal-data processing agreement, concluded between the User (Controller) and the DoPusk Operator (Processor), accepted when the Account is created.
§1. Subject
The Controller entrusts the Processor with processing Employees' personal data to the extent and for the purpose arising from use of the DoPusk Service (keeping HR records).
§2. Nature and purpose
Processing to provide the Service's functions (storing profiles, generating documents, monitoring deadlines). Categories of persons: the Controller's employees and associates and their family members. Categories of data: identification, contact, PESEL/identity document, employment and pay data, data needed for insurance.
§3. Processor obligations
Processing only on the Controller's documented instructions; ensuring confidentiality; security measures (Art. 32 GDPR — encryption of sensitive data, access control, audit log); assisting the Controller in fulfilling data-subject rights and obligations under Arts. 32–36 GDPR; deleting or returning data on termination (accounting for statutory retention periods — export in a structured format).
§4. Sub-processing
The Processor may use infrastructure providers (hosting in the EEA) under a general authorisation; it informs of changes and ensures equivalent obligations.
§5. Rights and audit
The Processor makes available the information needed to demonstrate compliance and allows audits. Breach notification — without undue delay, no later than 24 h from detection.
§6. Term
The agreement is in force for the duration of using the Service. On termination — data is deleted or returned per §3, with export preserved.
Effective date: 01.08.2026