Appendix No. 1, Data Processing Agreement (DPA)

Data Processing Agreement (DPA) to the Terms of Service for the provision of RetJet services.

Last updated:

This is an informational translation. The legally binding version of this document is the Polish original, available at www.retjet.pl/zalacznik-nr-1. In case of any discrepancy between the language versions, the Polish version prevails.

§ 1. Parties to the agreement

  1. Data Controller: the Client (online store) using the RetJet Digital Service, who concludes the Agreement by creating an Account in the Application.

  2. Data Processor: RetJet sp. z o.o. ul. 1 Maja 22, 43-300 Bielsko-Biała KRS (National Court Register) number: 0001129805 NIP (Tax Identification Number): 5472248276 REGON (National Business Registry Number): 529760483 e-mail: [email protected]

  3. The Agreement is concluded at the moment the Controller accepts the Terms of Service and remains in force for the entire period of use of the RetJet Application.

§ 2. Subject of the entrustment

  1. Under this Agreement, the Controller entrusts the Processor with the processing of personal data to the extent necessary for the Processor to provide the Digital Service consisting of handling returns and complaints in the Controller’s online store.

  2. The processing of data takes place on behalf of the Controller and solely for the purpose of performing the Agreement.

§ 3. Scope, nature, and categories of data

  1. The Processor may process the following personal data:

    • first and last name (if included in the order),

    • e-mail address,

    • order number,

    • product data,

    • reasons for returns,

    • data concerning return shipments (numbers, tracking, carrier),

    • communications related to the return or complaint process.

  2. Categories of data subjects: customers of the Controller’s online store.

  3. Nature of processing: collecting, storing, organizing, accessing, analyzing, transmitting, deleting - within the framework of providing the Digital Service.

§ 4. Processor’s obligations

The Processor undertakes to:

  1. process data solely on the Controller’s documented instructions (contained in the Terms of Service, the Application, and instructions provided by electronic means),

  2. ensure that persons authorized to process data are bound to maintain confidentiality,

  3. apply technical and organizational measures in accordance with Art. 32 GDPR,

  4. not process data for its own purposes,

  5. keep a register of security breaches,

  6. provide the Controller with the information necessary to demonstrate compliance with Art. 28 GDPR.

§ 5. Security measures

The Processor implements and maintains personal data protection measures, including:

  1. encryption of data transmission (TLS),

  2. access control (authorization, roles, ACL),

  3. encrypted backup copies,

  4. security of server and network infrastructure,

  5. access registers and activity logs,

  6. regular updates of software and security systems.

The Controller accepts the level of security measures applied by the Processor as adequate to the risk.

§ 6. Sub-processing of data

  1. The Controller gives general consent to the Processor’s use of sub-processors necessary for the provision of the Digital Service.

  2. The Processor uses only sub-processors that provide security measures compliant with the GDPR.

  3. The list of sub-processors includes, among others:

    • providers of hosting and server infrastructure,

    • the payment system provider,

    • providers of e-mail and communication services. The current list of sub-processors is published by the Processor or is available at the Controller’s request.

§ 7. Processor’s assistance

The Processor, having regard to the nature of the processing and the resources available to it:

  1. assists the Controller in fulfilling obligations arising from data subjects’ requests (Art. 15-22 GDPR),

  2. supports the Controller in fulfilling obligations related to personal data breaches (Art. 33-34 GDPR),

  3. enables the Controller to carry out an audit or inspection, within reasonable limits and in a manner that does not disrupt the operation of the systems.

§ 8. Personal data breaches

  1. The Processor notifies the Controller of every personal data breach without undue delay, no later than 48 hours from the moment of its detection.

  2. The notification includes at least: the nature of the breach, its scale, the possible consequences, and the remedial measures taken.

§ 9. Retention and deletion of data

  1. The Processor stores personal data for the period of use of the Digital Service.

  2. After the provision of services ends, the data is:

    • deleted, or

    • anonymized - if further use is necessary for statistical purposes or to improve the operation of the Application.

  3. The maximum data retention period is 36 months, unless the Controller requests earlier deletion.

§ 10. Liability of the parties

  1. The parties are liable for damages arising from a breach of the GDPR to the extent that the breach occurred through their fault.

  2. The Processor’s liability is limited to actual, proven damages, excluding cases of intentional fault.

§ 11. Final provisions

  1. The Agreement constitutes an integral part of the Terms of Service for the provision of RetJet services.

  2. The Processor may update this Agreement, informing the Controller with 14 days’ notice.

  3. In matters not regulated herein, Art. 28 GDPR and Polish law shall apply.

Ask about progress

Tell us what you need. We’ll reply to the address you provide as soon as we have something concrete about this integration.