Saltar al contenido
← Inicio

Data Processing Agreement

Última actualización: 2026-06-25

This Data Processing Agreement ("DPA") forms part of the Terms between advixory s.r.o., operator of Townproof (the "Processor"), and each customer (the "Controller") that uses Townproof to process contact personal data. It is concluded in electronic form in accordance with Article 28(9) GDPR.

1. Parties and roles

The customer is the controller of personal data about its own contacts and customers. advixory s.r.o. is the processor that processes that personal data on the customer's documented instructions to provide Townproof. For payment, billing and tax data, our Merchant of Record (Polar) acts as an independent controller, and its own terms and privacy policy apply to that processing.

2. Subject-matter, nature, purpose and duration

The subject-matter is the processing needed to provide review-request workflows, consent records, suppressions, auditability, analytics and support. The nature and purpose of the processing is to store, organize, import, validate, transmit, log, delete, export and secure personal data so that customers can send lawful review requests, honor opt-outs, keep audit trails and handle contact-rights requests. Processing lasts for the term of the customer's use of Townproof and any post-termination retention period required for legal, security, suppression or audit purposes.

3. Types of personal data

  • Contact email address, normalized email, first name and phone number.
  • Review-request metadata, including the request, message, delivery, unsubscribe, suppression and interaction records.
  • Compliance metadata, such as the consent-attestation actor, IP address, timestamps and audit events.

4. Categories of data subjects

Data subjects are the customer's own contacts, customers or business recipients whose information the customer uploads or manages in Townproof.

5. Controller obligations and instructions

The customer determines the purposes and legal basis for processing, ensures contact data is accurate and lawfully collected, provides the privacy notices required by Articles 13–14 GDPR (including the source of the data), handles data-subject requests as controller, ensures a valid legal basis for each send (including any consent or soft opt-in required under §116 of Act No. 452/2021 Coll.), and instructs us only to process data in ways permitted by law and this DPA. The customer's use of Townproof, together with its in-product configuration, constitutes its documented instructions.

6. Processor obligations

We will: (a) process personal data only on the controller's documented instructions, including for transfers to a third country, unless required by Union or Member-State law, in which case we will inform the controller before processing unless that law prohibits it; (b) ensure that persons authorized to process the data are bound by confidentiality; (c) take all security measures required by Article 32 GDPR; (d) respect the conditions in Sections 7 and 8 for engaging sub-processors; (e) assist the controller, by appropriate technical and organizational measures, in responding to data-subject requests; (f) assist the controller in ensuring compliance with Articles 32–36 GDPR, including security, breach notification and data-protection impact assessments; (g) at the controller's choice, delete or return personal data after the end of the services and delete existing copies unless storage is required by law; and (h) make available all information necessary to demonstrate compliance and allow for and contribute to audits. We will immediately inform the controller if, in our opinion, an instruction infringes the GDPR or other data-protection law.

7. Security measures

Taking into account the state of the art and the risk, we implement appropriate technical and organizational measures, including: encryption of personal data in transit; access controls and least-privilege access; isolation of each customer's data (multi-tenant separation); pseudonymization and tombstoning of purged identifiers; audit logging; secure backups; and procedures to detect, assess and respond to personal data breaches.

8. Sub-processors

The controller gives general written authorization for us to engage the sub-processors listed below for the stated purposes. We impose data-protection obligations on each sub-processor that are, in substance, the same as those in this DPA, and we remain fully liable to the controller for each sub-processor's performance. We will give the controller at least 30 days' prior notice of any intended addition or replacement of a sub-processor by email to the account administrator (this page remains the canonical sub-processor list), during which the controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the controller may terminate the affected part of the service.

  • Postmark (AC PM, LLC) Entrega de correos de solicitud de reseña y transaccionales.
    Ubicación: Estados Unidos · Garantía de transferencia: Cláusulas Contractuales Tipo de la UE; EU–US Data Privacy Framework.
  • Polar (Polar Software, Inc.) Merchant of Record para suscripciones, pagos, facturación e impuestos. Polar es el vendedor registrado y actúa como responsable independiente respecto a los datos de pago, facturación e impuestos de los compradores. Consulta la política de privacidad de Polar en https://polar.sh/legal/privacy-policy.
    Ubicación: Estados Unidos · Garantía de transferencia: Cláusulas Contractuales Tipo de la UE.
  • Neon (Neon, Inc.) Alojamiento gestionado de PostgreSQL para la base de datos principal de la aplicación.
    Ubicación: Unión Europea (Fráncfort, Amazon Web Services); empresa matriz en Estados Unidos · Garantía de transferencia: Datos almacenados en la UE; EU–US Data Privacy Framework y Cláusulas Contractuales Tipo para cualquier acceso de la matriz.
  • Sentry (Functional Software, Inc.) Supervisión de errores y rendimiento, configurada para depurar datos personales; la repetición de sesiones está desactivada en producción.
    Ubicación: Unión Europea (Fráncfort); empresa matriz en Estados Unidos · Garantía de transferencia: Datos de eventos almacenados en la UE; EU–US Data Privacy Framework y Cláusulas Contractuales Tipo para cualquier acceso de la matriz.
  • PostHog (PostHog, Inc.) Analítica de producto opcional y repetición de sesiones enmascarada y muestreada. Desactivada por defecto y usada solo con consentimiento; la propia base de datos de Townproof sigue siendo el registro analítico autorizado.
    Ubicación: Unión Europea (Fráncfort) · Garantía de transferencia: Datos alojados en la UE.
  • Google (Google Ireland Limited) Consultas a Google Maps y Places para datos del perfil de empresa, información de competidores y auditorías, y el widget de mapa opcional.
    Ubicación: Entidad contratante europea; el tratamiento puede producirse a escala mundial · Garantía de transferencia: EU–US Data Privacy Framework; Cláusulas Contractuales Tipo de la UE.
  • Cloudflare (Cloudflare, Inc.) DNS autoritativo para los dominios de Townproof.
    Ubicación: Estados Unidos · Garantía de transferencia: EU–US Data Privacy Framework; Cláusulas Contractuales Tipo de la UE.
  • OpenRouter (OpenRouter, Inc.) y proveedores de modelos alojados seleccionados Enrutamiento opcional de solicitudes de borradores de respuesta asistidos por IA a través de OpenRouter hacia proveedores de modelos alojados seleccionados cuando la función de IA está habilitada. OpenRouter y el proveedor de inferencia seleccionado reciben solo el texto de la reseña y el contexto del prompt necesarios para generar el borrador; el enrutamiento de producción se limita a proveedores aprobados y se configura para denegar la recopilación de datos por el proveedor o exigir retención cero de datos cuando esté soportado.
    Ubicación: Estados Unidos; la ubicación del proveedor de inferencia seleccionado depende de la configuración de enrutamiento · Garantía de transferencia: Acuerdo de Tratamiento de Datos de OpenRouter y Cláusulas Contractuales Tipo de la UE; salvaguardas específicas del proveedor confirmadas antes del uso en producción.
  • Vercel (Vercel, Inc.) Alojamiento de la aplicación y entrega de contenido.
    Ubicación: Estados Unidos (existe una región de la UE disponible) · Garantía de transferencia: Cláusulas Contractuales Tipo de la UE; EU–US Data Privacy Framework.

9. International transfers

Where advixory transfers personal data outside the European Economic Area to a sub-processor, it relies, in order of preference, on: (a) a European Commission adequacy decision for the recipient country, including the EU–US Data Privacy Framework where the sub-processor is certified under it; or (b) the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), incorporated into this DPA by reference. advixory concludes those clauses with each sub-processor using Module Three (processor-to-processor), and the controller authorizes advixory to enter into and manage them on the controller's behalf; where the controller itself transfers personal data to advixory from outside the EEA, Module Two (controller-to-processor) applies and is likewise incorporated by reference.

Before relying on the Standard Contractual Clauses, advixory carries out a transfer impact assessment consistent with EDPB Recommendations 01/2020, taking into account the limited and non-sensitive nature of the personal data (business contact details), the safeguards in the recipient country's law (including, for the United States, the necessary-and-proportionate limits and independent redress mechanism introduced by Executive Order 14086), and the supplementary technical and organizational measures advixory applies, including encryption of personal data in transit and at rest, access controls, data minimization and pseudonymization. advixory keeps this assessment under review and will suspend the transfer and notify the controller if it can no longer ensure an adequate level of protection.

In case of conflict between the Standard Contractual Clauses and this DPA or the Terms, the Standard Contractual Clauses prevail. The location and transfer safeguard for each sub-processor are shown in the list above, and the controller may request a copy of the relevant clauses at [email protected].

10. Personal data breach

We will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's personal data, and will provide the information the controller reasonably needs to meet its own obligations under Articles 33 and 34 GDPR. The 72-hour notification deadline under Article 33 applies to the controller, not to us as processor; our duty is to inform the controller without undue delay so that the controller can meet that deadline.

11. Assistance with data-subject rights

We will assist the controller with access, rectification, erasure, restriction, portability and objection requests where the request relates to personal data processed in Townproof. Contact exports are produced as a JSON and CSV bundle for the relevant contact, scoped to the customer's organization.

12. Deletion and return of data on termination

On termination or a valid deletion request, we delete or return the controller's personal data according to product capabilities and legal requirements. Contact personal data is purged by default 365 days after the contact's last interaction. Suppression records, audit logs without personal data, retained message metadata with personal data removed, and records required for legal compliance may be retained.

13. Audit rights

We will make available the information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, by the controller or an auditor it mandates. Audits must be limited to what is necessary, avoid disrupting the service, protect other customers' data, and respect our confidentiality and security controls; we may satisfy audit requests through documentation, summaries or equivalent evidence where appropriate.

14. Liability

As between the parties, the limitation of liability in the Terms of Service applies to this DPA. Nothing in this DPA limits any liability that cannot be limited under mandatory law, including a processor's liability toward data subjects under Article 82 GDPR.

15. Successors and assignment

This DPA binds and benefits each party and its respective successors and permitted assigns. We may assign or novate this DPA, together with the underlying Terms, to a successor or affiliated entity in connection with a merger, reorganization, sale of the business or its assets, or other corporate transaction. On written notice to the controller identifying the successor and the effective date, the successor assumes our rights and obligations, the controller's instructions and authorizations continue in favor of the successor, and this DPA continues without re-execution. Where applicable law requires the successor to be separately bound, the successor will execute a deed of adherence to this DPA, and the controller agrees in advance to such adherence. If the controller objects on reasonable data-protection grounds to the identity of the successor within 30 days of our notice, and we cannot resolve the objection, the controller may terminate the affected part of the service. Any onward transfer of personal data under this Section will comply with Articles 28 and 44–49 and the transparency requirements of Articles 13–14 GDPR.

16. Governing law and order of precedence

This DPA is governed by the laws of the Slovak Republic and any mandatory data-protection law that applies; the Standard Contractual Clauses keep their own governing law for transfers they cover. The courts competent for the seat of advixory s.r.o. in Košice have jurisdiction unless mandatory law requires a different forum. In case of conflict regarding the processing of personal data, this DPA prevails over the Terms of Service. This DPA is concluded in electronic form; acceptance is logged when a customer creates or accesses an organization and may be confirmed again in-product before review-request sending is enabled. Acceptance logs include the DPA version and related legal-document versions.

17. California (CCPA) terms

This Section applies where the customer is a business and the personal data is personal information under the California Consumer Privacy Act (CCPA). With respect to that data, advixory acts as a service provider and processes it only on the customer's behalf for the limited and specified business purpose of providing Townproof. advixory will not: (a) sell or share the personal information; (b) retain, use or disclose it for any purpose other than the business purposes specified in this DPA, for any commercial purpose other than providing the service, or outside the direct business relationship with the customer; or (c) combine it with personal information from another source, except as the CCPA permits. advixory certifies that it understands and will comply with these restrictions, will provide the same level of privacy protection as the CCPA requires, will notify the customer if it can no longer meet its obligations, will allow the customer to take reasonable steps to ensure its data is used appropriately, and will impose these same terms on any sub-processor.