Zum Inhalt springen
← Startseite

Data Processing Agreement

Zuletzt aktualisiert: 2026-06-25

This Data Processing Agreement ("DPA") forms part of the Terms between advixory s.r.o., operator of Townproof (the "Processor"), and each customer (the "Controller") that uses Townproof to process contact personal data. It is concluded in electronic form in accordance with Article 28(9) GDPR.

1. Parties and roles

The customer is the controller of personal data about its own contacts and customers. advixory s.r.o. is the processor that processes that personal data on the customer's documented instructions to provide Townproof. For payment, billing and tax data, our Merchant of Record (Polar) acts as an independent controller, and its own terms and privacy policy apply to that processing.

2. Subject-matter, nature, purpose and duration

The subject-matter is the processing needed to provide review-request workflows, consent records, suppressions, auditability, analytics and support. The nature and purpose of the processing is to store, organize, import, validate, transmit, log, delete, export and secure personal data so that customers can send lawful review requests, honor opt-outs, keep audit trails and handle contact-rights requests. Processing lasts for the term of the customer's use of Townproof and any post-termination retention period required for legal, security, suppression or audit purposes.

3. Types of personal data

  • Contact email address, normalized email, first name and phone number.
  • Review-request metadata, including the request, message, delivery, unsubscribe, suppression and interaction records.
  • Compliance metadata, such as the consent-attestation actor, IP address, timestamps and audit events.

4. Categories of data subjects

Data subjects are the customer's own contacts, customers or business recipients whose information the customer uploads or manages in Townproof.

5. Controller obligations and instructions

The customer determines the purposes and legal basis for processing, ensures contact data is accurate and lawfully collected, provides the privacy notices required by Articles 13–14 GDPR (including the source of the data), handles data-subject requests as controller, ensures a valid legal basis for each send (including any consent or soft opt-in required under §116 of Act No. 452/2021 Coll.), and instructs us only to process data in ways permitted by law and this DPA. The customer's use of Townproof, together with its in-product configuration, constitutes its documented instructions.

6. Processor obligations

We will: (a) process personal data only on the controller's documented instructions, including for transfers to a third country, unless required by Union or Member-State law, in which case we will inform the controller before processing unless that law prohibits it; (b) ensure that persons authorized to process the data are bound by confidentiality; (c) take all security measures required by Article 32 GDPR; (d) respect the conditions in Sections 7 and 8 for engaging sub-processors; (e) assist the controller, by appropriate technical and organizational measures, in responding to data-subject requests; (f) assist the controller in ensuring compliance with Articles 32–36 GDPR, including security, breach notification and data-protection impact assessments; (g) at the controller's choice, delete or return personal data after the end of the services and delete existing copies unless storage is required by law; and (h) make available all information necessary to demonstrate compliance and allow for and contribute to audits. We will immediately inform the controller if, in our opinion, an instruction infringes the GDPR or other data-protection law.

7. Security measures

Taking into account the state of the art and the risk, we implement appropriate technical and organizational measures, including: encryption of personal data in transit; access controls and least-privilege access; isolation of each customer's data (multi-tenant separation); pseudonymization and tombstoning of purged identifiers; audit logging; secure backups; and procedures to detect, assess and respond to personal data breaches.

8. Sub-processors

The controller gives general written authorization for us to engage the sub-processors listed below for the stated purposes. We impose data-protection obligations on each sub-processor that are, in substance, the same as those in this DPA, and we remain fully liable to the controller for each sub-processor's performance. We will give the controller at least 30 days' prior notice of any intended addition or replacement of a sub-processor by email to the account administrator (this page remains the canonical sub-processor list), during which the controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the controller may terminate the affected part of the service.

  • Postmark (AC PM, LLC) Zustellung von Bewertungsanfrage- und Transaktions-E-Mails.
    Standort: Vereinigte Staaten · Garantie für die Übermittlung: EU-Standardvertragsklauseln; EU–US Data Privacy Framework.
  • Polar (Polar Software, Inc.) Merchant of Record für Abonnements, Zahlungen, Rechnungsstellung und Steuern. Polar ist der Verkäufer (Seller of Record) und handelt für die Zahlungs-, Abrechnungs- und Steuerdaten der Käufer als eigenständiger Verantwortlicher. Siehe die Datenschutzerklärung von Polar unter https://polar.sh/legal/privacy-policy.
    Standort: Vereinigte Staaten · Garantie für die Übermittlung: EU-Standardvertragsklauseln.
  • Neon (Neon, Inc.) Verwaltetes PostgreSQL-Hosting für die primäre Anwendungsdatenbank.
    Standort: Europäische Union (Frankfurt, Amazon Web Services); US-Muttergesellschaft · Garantie für die Übermittlung: Daten in der EU gespeichert; EU–US Data Privacy Framework und Standardvertragsklauseln für etwaigen Zugriff der Muttergesellschaft.
  • Sentry (Functional Software, Inc.) Fehler- und Leistungsüberwachung, konfiguriert zum Entfernen personenbezogener Daten; Session Replay ist in der Produktion deaktiviert.
    Standort: Europäische Union (Frankfurt); Muttergesellschaft in den Vereinigten Staaten · Garantie für die Übermittlung: Ereignisdaten werden in der EU gespeichert; EU–US Data Privacy Framework und Standardvertragsklauseln für etwaige Zugriffe der Muttergesellschaft.
  • PostHog (PostHog, Inc.) Optionale Produktanalyse und maskierte, gesampelte Sitzungswiedergabe. Standardmäßig deaktiviert und nur mit Einwilligung genutzt; die eigene Datenbank von Townproof bleibt das maßgebliche Analyseprotokoll.
    Standort: Europäische Union (Frankfurt) · Garantie für die Übermittlung: Daten in der EU gehostet.
  • Google (Google Ireland Limited) Google-Maps- und Places-Abfragen für Unternehmensprofildaten, Wettbewerbs- und Audit-Informationen sowie das optionale Karten-Widget.
    Standort: Europäische Vertragspartei; die Verarbeitung kann weltweit erfolgen · Garantie für die Übermittlung: EU–US Data Privacy Framework; EU-Standardvertragsklauseln.
  • Cloudflare (Cloudflare, Inc.) Autoritatives DNS für die Domains von Townproof.
    Standort: Vereinigte Staaten · Garantie für die Übermittlung: EU–US Data Privacy Framework; EU-Standardvertragsklauseln.
  • OpenRouter (OpenRouter, Inc.) und ausgewählte gehostete Modellanbieter Optionale Weiterleitung von Anfragen für KI-gestützte Antwortentwürfe über OpenRouter an ausgewählte gehostete Modellanbieter, wenn die KI-Funktion aktiviert ist. OpenRouter und der ausgewählte Inferenzanbieter erhalten nur den Bewertungstext und den Prompt-Kontext, die zur Erstellung des Entwurfs erforderlich sind; das Produktionsrouting ist auf freigegebene Anbieter beschränkt und so konfiguriert, dass Datenerhebung durch Anbieter verweigert oder Zero Data Retention verlangt wird, soweit unterstützt.
    Standort: Vereinigte Staaten; der Standort des ausgewählten Inferenzanbieters hängt von der Routing-Konfiguration ab · Garantie für die Übermittlung: OpenRouter Data Processing Agreement und EU-Standardvertragsklauseln; anbieterspezifische Schutzmaßnahmen werden vor dem Produktionseinsatz bestätigt.
  • Vercel (Vercel, Inc.) Anwendungshosting und Content-Auslieferung.
    Standort: Vereinigte Staaten (eine EU-Region ist verfügbar) · Garantie für die Übermittlung: EU-Standardvertragsklauseln; EU–US Data Privacy Framework.

9. International transfers

Where advixory transfers personal data outside the European Economic Area to a sub-processor, it relies, in order of preference, on: (a) a European Commission adequacy decision for the recipient country, including the EU–US Data Privacy Framework where the sub-processor is certified under it; or (b) the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), incorporated into this DPA by reference. advixory concludes those clauses with each sub-processor using Module Three (processor-to-processor), and the controller authorizes advixory to enter into and manage them on the controller's behalf; where the controller itself transfers personal data to advixory from outside the EEA, Module Two (controller-to-processor) applies and is likewise incorporated by reference.

Before relying on the Standard Contractual Clauses, advixory carries out a transfer impact assessment consistent with EDPB Recommendations 01/2020, taking into account the limited and non-sensitive nature of the personal data (business contact details), the safeguards in the recipient country's law (including, for the United States, the necessary-and-proportionate limits and independent redress mechanism introduced by Executive Order 14086), and the supplementary technical and organizational measures advixory applies, including encryption of personal data in transit and at rest, access controls, data minimization and pseudonymization. advixory keeps this assessment under review and will suspend the transfer and notify the controller if it can no longer ensure an adequate level of protection.

In case of conflict between the Standard Contractual Clauses and this DPA or the Terms, the Standard Contractual Clauses prevail. The location and transfer safeguard for each sub-processor are shown in the list above, and the controller may request a copy of the relevant clauses at [email protected].

10. Personal data breach

We will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's personal data, and will provide the information the controller reasonably needs to meet its own obligations under Articles 33 and 34 GDPR. The 72-hour notification deadline under Article 33 applies to the controller, not to us as processor; our duty is to inform the controller without undue delay so that the controller can meet that deadline.

11. Assistance with data-subject rights

We will assist the controller with access, rectification, erasure, restriction, portability and objection requests where the request relates to personal data processed in Townproof. Contact exports are produced as a JSON and CSV bundle for the relevant contact, scoped to the customer's organization.

12. Deletion and return of data on termination

On termination or a valid deletion request, we delete or return the controller's personal data according to product capabilities and legal requirements. Contact personal data is purged by default 365 days after the contact's last interaction. Suppression records, audit logs without personal data, retained message metadata with personal data removed, and records required for legal compliance may be retained.

13. Audit rights

We will make available the information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, by the controller or an auditor it mandates. Audits must be limited to what is necessary, avoid disrupting the service, protect other customers' data, and respect our confidentiality and security controls; we may satisfy audit requests through documentation, summaries or equivalent evidence where appropriate.

14. Liability

As between the parties, the limitation of liability in the Terms of Service applies to this DPA. Nothing in this DPA limits any liability that cannot be limited under mandatory law, including a processor's liability toward data subjects under Article 82 GDPR.

15. Successors and assignment

This DPA binds and benefits each party and its respective successors and permitted assigns. We may assign or novate this DPA, together with the underlying Terms, to a successor or affiliated entity in connection with a merger, reorganization, sale of the business or its assets, or other corporate transaction. On written notice to the controller identifying the successor and the effective date, the successor assumes our rights and obligations, the controller's instructions and authorizations continue in favor of the successor, and this DPA continues without re-execution. Where applicable law requires the successor to be separately bound, the successor will execute a deed of adherence to this DPA, and the controller agrees in advance to such adherence. If the controller objects on reasonable data-protection grounds to the identity of the successor within 30 days of our notice, and we cannot resolve the objection, the controller may terminate the affected part of the service. Any onward transfer of personal data under this Section will comply with Articles 28 and 44–49 and the transparency requirements of Articles 13–14 GDPR.

16. Governing law and order of precedence

This DPA is governed by the laws of the Slovak Republic and any mandatory data-protection law that applies; the Standard Contractual Clauses keep their own governing law for transfers they cover. The courts competent for the seat of advixory s.r.o. in Košice have jurisdiction unless mandatory law requires a different forum. In case of conflict regarding the processing of personal data, this DPA prevails over the Terms of Service. This DPA is concluded in electronic form; acceptance is logged when a customer creates or accesses an organization and may be confirmed again in-product before review-request sending is enabled. Acceptance logs include the DPA version and related legal-document versions.

17. California (CCPA) terms

This Section applies where the customer is a business and the personal data is personal information under the California Consumer Privacy Act (CCPA). With respect to that data, advixory acts as a service provider and processes it only on the customer's behalf for the limited and specified business purpose of providing Townproof. advixory will not: (a) sell or share the personal information; (b) retain, use or disclose it for any purpose other than the business purposes specified in this DPA, for any commercial purpose other than providing the service, or outside the direct business relationship with the customer; or (c) combine it with personal information from another source, except as the CCPA permits. advixory certifies that it understands and will comply with these restrictions, will provide the same level of privacy protection as the CCPA requires, will notify the customer if it can no longer meet its obligations, will allow the customer to take reasonable steps to ensure its data is used appropriately, and will impose these same terms on any sub-processor.