Skip to main content

Data Processing Agreement

Last updated: August 1, 2026

The terms on which the Salon entrusts the processing of personal data to DOKUMENT.PL sp. z o.o. in accordance with Article 28 GDPR, covering the subject matter and duration of processing, categories of data, security measures, sub-processors, assistance with data subject rights, transfers outside the EEA, audits and the rules for deletion or return of data.

This translation is provided for convenience. The EN version is the binding one.

Parties, subject matter and nature of the agreement

This data processing agreement (the "DPA") forms an integral part of the Terms of Service for the subscription service for salons and is concluded between:

The Controller, which is the Salon, that is the business using the Meeti Me platform under the Agreement, and

The Processor, which is:

  • Legal name: DOKUMENT.PL sp. z o.o.
  • Address: Aleja Stanow Zjednoczonych 51 lok. 222, 04-028 Warszawa, Poland
  • Tax identification number (NIP): 5242982251
  • Company register number (KRS): 0001055336
  • Statistical number (REGON): 526237551
  • Share capital: 5 000,00 PLN

Contact for matters covered by this DPA: meetime.company@gmail.com. Contact for the data protection officer, where one has been appointed: meetime.company@gmail.com. Contact for contractual matters: meetime.company@gmail.com.

This DPA is concluded in performance of the obligation arising from Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and sets out the subject matter, duration, nature and purpose of the processing, the type of personal data, the categories of data subjects, and the obligations and rights of the Controller.

This DPA is concluded at the moment the Salon accepts the Terms of Service and remains in force for the entire term of the Agreement and, with respect to the obligations concerning the return, deletion and confidentiality of data, also after its termination.

In the event of any conflict between this DPA and the Terms of Service or any other contractual document, this DPA prevails in matters concerning the processing of the entrusted personal data.

Document version: 2026-08-01. Effective from: 2026-08-01.

Roles of the parties and allocation of responsibility

The Salon is the controller of the personal data of its clients and of its employees and contractors that is entered into the Meeti Me platform or generated as a result of the Salon's use of the platform's features, in particular the client records, notes about a client, the history of visits to that Salon, arrangements concerning the service, the staff schedule, and the content of communications sent by the Salon to its clients.

The Salon, as controller, independently and exclusively determines the purposes and means of processing this data, and is responsible for having a valid legal basis for the processing, for fulfilling the information obligation towards data subjects, for ensuring that the scope of data collected complies with the principle of data minimisation, and for the lawfulness of the instructions issued to the Processor.

DOKUMENT.PL sp. z o.o. is the processor with respect to the data referred to above. It processes such data solely on behalf of and on the documented instructions of the Salon, to the extent necessary to provide the Service.

DOKUMENT.PL sp. z o.o. is a separate controller with respect to: the Salon's registration and billing data, the account data of the Salon's Users to the extent of their authentication and security, the platform's technical logs and security logs, product analytics data concerning use of the platform, and the data of marketplace Clients to the extent of operating their accounts, intermediating in bookings and sending transactional notifications. This DPA does not apply to that scope; the rules of processing are described in the Meeti Me Privacy Policy.

The Salon becomes a separate controller with respect to a Client's data transmitted to it by the platform for the purpose of performing a Booking, from the moment of receipt, and is responsible for the further processing of that data on its own account.

Neither Party is a joint controller within the meaning of Article 26 GDPR in the scope covered by this DPA.

Scope, nature and purpose of the processing

Subject matter of the processing. The processing of personal data entrusted by the Salon in connection with the provision of the Service in the SaaS model.

Nature of the processing. Operations performed by automated means in an IT system: collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, alignment or combination, restriction, erasure or destruction.

Purpose of the processing. Solely the provision of the Service to the Salon, that is:

  1. maintaining the appointment calendar and the staff schedule,
  2. maintaining the Salon's client records (CRM), including notes and visit history,
  3. accepting, confirming, changing and cancelling bookings on behalf of the Salon,
  4. sending notifications on behalf of the Salon to its clients via the email, SMS, push and Telegram channels,
  5. maintaining the Salon's internal settlements and reports,
  6. providing the Salon with data export and copy functions,
  7. providing technical support at the Salon's request,
  8. maintaining, securing, backing up and restoring the environment in which the data is stored.

Duration of the processing. For the term of the Agreement, extended by the data export and deletion period described in the section "Deletion or return of data after the end of cooperation".

Categories of data subjects and categories of data

Categories of data subjects:

  • clients of the Salon, including persons making bookings via the marketplace and persons entered into the client records by the Salon,
  • employees and contractors of the Salon to whom the Salon has granted access to the Account or whose data it has entered into the schedule,
  • contact persons designated by the Salon,
  • legal guardians booking an appointment on behalf of a minor.

Categories of personal data:

| Category | Indicative scope | | --- | --- | | Identification data | First name, surname or display name, gender if provided by the Salon | | Contact data | Email address, phone number, Telegram chat identifier if linked | | Booking data | Date and time of the appointment, selected service, assigned staff member, booking status, history of changes and cancellations | | Client record data | Notes entered by the Salon, service preferences, history of visits to that Salon, value and frequency of visits | | Staff data | First name and surname, position or role, range of services, working hours, holidays and absences, work email address | | Communication data | Content of messages exchanged in connection with a booking, notification delivery status | | Technical data | Session and device identifiers, IP address, access logs for the Salon's Account |

Special categories of data. The platform is not intended for the processing of data referred to in Articles 9 and 10 GDPR, including health data. The Salon undertakes not to enter such data into the system, in particular into note fields, without a separate, valid legal basis, without prior written agreement with DOKUMENT.PL sp. z o.o. on additional security measures, and without informing the data subject. Entering such data in breach of the above undertaking is at the sole responsibility of the Salon.

Children's data. The platform is intended for persons who are at least 16 years old or, where the law applicable under law of Poland, without prejudice to the mandatory consumer rules of your country of residence provides for a lower threshold, for persons who have reached the age resulting from that law, not lower than 13 years. An appointment for a minor is booked by their legal guardian.

Documented instructions of the Controller

The Processor processes the entrusted personal data only on documented instructions from the Controller, including with regard to transfers of data to a third country or an international organisation.

The following are deemed to be documented instructions of the Controller:

  1. this DPA together with the Terms of Service and the price list,
  2. the configuration and settings of the Account made by the Salon or the Salon's Users in the dashboard, including enabling or disabling notification channels, integrations and data-processing features,
  3. actions performed by the Salon's Users in the platform interface or through the available API,
  4. requests and applications submitted by persons authorised by the Salon to meetime.company@gmail.com or meetime.company@gmail.com.

The Processor does not use the entrusted data for its own purposes; in particular, it does not use it to train machine learning models, to build marketing profiles, or to sell or disclose it to third parties beyond the scope described in this DPA.

If the Processor is required to process the data under Union or Member State law, it informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

If, in the Processor's opinion, an instruction of the Controller infringes the GDPR or other data protection provisions, the Processor immediately informs the Controller and may suspend the execution of the instruction until it is confirmed or amended. Suspending the execution of an instruction on this ground does not constitute a breach of the Agreement.

Executing instructions that go beyond the scope of the Service covered by the Plan, in particular non-standard migration operations, may require a separate arrangement and may involve a reasonable fee corresponding to the costs incurred, of which the Processor notifies the Controller before commencing the work.

Confidentiality of personnel

The Processor ensures that persons authorised to process the entrusted personal data:

  • have been expressly authorised to do so within the scope corresponding to their role, in accordance with the principle of least privilege,
  • have committed themselves to confidentiality in written or documented form or are under a statutory obligation of secrecy,
  • have been trained in the principles of personal data protection and information security before being granted access to the data and periodically thereafter, at least once a year,
  • have access only to the data necessary to perform their assigned tasks.

The obligation of confidentiality continues after the end of employment or cooperation with the Processor.

The Processor maintains a register of persons authorised to process the entrusted data and periodically, at least once every six months, reviews the currency of the granted authorisations and revokes those that are no longer needed.

Security measures (Article 32 GDPR)

The Processor implements and maintains appropriate technical and organisational measures ensuring a level of security appropriate to the risk, in particular:

Encryption.

  • Encryption of data in transit using TLS version 1.2 or higher, with HTTPS enforcement and the HSTS mechanism for all public connections.
  • Encryption of data at rest, covering the database, the file storage in Amazon S3 and all backups, using the AES-256 algorithm.
  • Storage of passwords exclusively as salted cryptographic hashes, using a modern hashing function resistant to dictionary attacks.
  • Encryption of internal connections between application components and of administrative connections.

Access control.

  • Role-based access control, with separation of the permissions of the Salon owner, manager and staff member, and with the principle of least privilege.
  • Strict isolation of data between Salons at the application level, preventing one Salon from accessing another Salon's data.
  • Multi-factor authentication mandatory for all administrative accounts and for access to the production infrastructure.
  • Short-lived access tokens, session invalidation on logout and on password change, detection of logins from new devices.
  • Access by the Processor's personnel to production data only on a justified-need basis, subject to approval, logged and time-limited.

Backups and business continuity.

  • Automatic backups performed at least once a day, stored in encrypted form in at least two separate availability zones within the European Economic Area.
  • A backup retention period of 30 days, with rotation allowing restoration of the state from a selected point in time.
  • Periodic backup restoration tests, carried out at least once a quarter, with documentation of their results.
  • A recovery time objective (RTO) of 8 hours and a recovery point objective (RPO) of 24 hours.
  • A business continuity plan and an incident response plan, reviewed at least once a year.

Logging and monitoring.

  • Logging of security events and data access events, including logins, failed login attempts, permission changes, data exports and administrative operations.
  • Retention of security logs for 12 months, in a manner preventing their unauthorised modification.
  • Availability and anomaly monitoring, automatic alerts, rate limiting, and protection against denial-of-service attacks.

Security of the development process.

  • Separation of the production, testing and development environments. We do not use real personal data in non-production environments; test data is synthetic or anonymised.
  • Code review before deployment, automated testing, scanning of dependencies for known vulnerabilities and regular security updates.
  • Secrets management in a dedicated vault, with no credentials placed in source code.
  • Periodic application security testing, at least once a year.

Organisational measures.

  • A data protection policy and an information security policy, reviewed at least once a year.
  • A record of categories of processing activities maintained in accordance with Article 30(2) GDPR.
  • A personal data breach management procedure, with designated roles and an escalation path.
  • Vetting of sub-processors before entrusting data to them and periodic assessment of their compliance.
  • The principle of data protection by design and by default (Article 25 GDPR), including pseudonymisation where possible without loss of functionality.

The Processor may modify the measures applied, provided that the level of security is not reduced. We provide the current description of the technical and organisational measures upon request sent to meetime.company@gmail.com.

Sub-processors

The Controller grants the Processor general authorisation to engage sub-processors, on the terms set out in this section.

The Processor concludes with each sub-processor an agreement imposing on it data protection obligations no less stringent than those arising from this DPA. The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.

Current list of sub-processors:

| Sub-processor | Role and scope of processing | Location of processing | | --- | --- | --- | | Amazon Web Services EMEA SARL | Hosting of the application and database, Amazon S3 file storage, storage of backups. Access to the full scope of entrusted data in encrypted form | European Union regions | | Amazon SES | Delivery of email messages sent on behalf of the Salon to its clients. Recipient's email address, first name or name, message content, delivery status | European Union regions | | SMS service provider | Delivery of SMS notifications sent on behalf of the Salon. Phone number, message content, delivery status | European Economic Area | | PostHog | Product analytics concerning use of the Salon dashboard, only after consent has been given. Pseudonymised identifier of the Salon's User, product events, device data, truncated IP address. Does not include client records or notes | Infrastructure hosted in the European Union | | Telegram | Delivery of notifications via the Telegram channel, only after the recipient has linked their account themselves. Chat identifier, notification content | Outside the European Economic Area, with the safeguards described in the transfers section |

Stripe handles only the Salon's subscription payments to DOKUMENT.PL sp. z o.o.. In that respect DOKUMENT.PL sp. z o.o. acts as a controller, not as a processor, and Stripe is therefore not a sub-processor within the meaning of this DPA. Stripe has no access to the data of the Salon's clients.

The current list of sub-processors is published at business.meeti.me and forms part of this DPA.

Change mechanism and right to object.

  1. The Processor informs the Controller of its intention to add a new sub-processor or replace an existing one at least 30 days in advance, by email to the address assigned to the Account and by a notice in the Salon dashboard. The notification includes the name of the sub-processor, the scope and purpose of the processing, and the location of the processing.
  2. The Controller may lodge a reasoned objection within 30 days of receiving the notification, by sending it to meetime.company@gmail.com. The objection should indicate the specific data protection circumstances on which it is based.
  3. Upon receipt of an objection, the Parties will engage in good-faith discussions aimed at resolving it. The Processor may in particular propose an alternative provider, additional safeguards, or a limitation of the scope of processing that removes the grounds for the objection.
  4. If the Parties do not reach agreement within 30 days of the objection being lodged, and the use of the sub-processor concerned is necessary for the provision of the Service, the Controller has the right to terminate the Agreement with effect on the day preceding the commencement of processing by the new sub-processor, with a pro-rata refund of the Subscription Fee for the unused period and with retention of the right to export the data.
  5. Until the deadline for lodging an objection has passed and, if an objection is lodged, until it has been resolved, the new sub-processor does not begin processing the entrusted data.

In exceptional situations requiring immediate action, in particular in the event of a failure of an existing provider or a threat to the continuity of the Service, the Processor may use a replacement sub-processor before the notice period has expired, informing the Controller without delay and stating the reasons. The right to object and the right of termination remain in force in such a case.

Assistance with the exercise of data subject rights

The Processor, taking into account the nature of the processing, assists the Controller insofar as possible in fulfilling its obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR: access, rectification, erasure, restriction of processing, data portability, objection, and the right not to be subject to decisions based solely on automated processing.

Assistance is provided primarily through the features available in the Salon dashboard, which allow the Controller to independently: search for a person's data, view and export it in CSV and JSON formats, rectify, delete or anonymise a client record, and generate a report on the scope of the data processed.

If a data subject's request is received directly by the Processor, the Processor does not respond to it on the merits but forwards it to the Controller without delay, and no later than within 3 business days, together with the information in its possession enabling the request to be handled, and informs the person making the request that the matter has been forwarded to the controller.

If fulfilling a request goes beyond the features available in the dashboard, the Processor provides technical assistance at the Controller's request, within a timeframe enabling the Controller to meet the one-month deadline under Article 12(3) GDPR, and no later than within 10 business days of receiving the request. For assistance that goes beyond the standard features of the Service and requires substantial effort, the Processor may charge a reasonable fee corresponding to the costs incurred, after informing the Controller in advance and obtaining its acceptance.

Assistance with the obligations under Articles 32 to 36 GDPR

The Processor assists the Controller in fulfilling the obligations set out in Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it.

Security of processing (Article 32). The Processor provides the Controller with the current description of the implemented technical and organisational measures, to the extent enabling the Controller to assess the adequacy of those measures, subject to the protection of trade secrets and the security of the platform.

Notification of breaches to the supervisory authority (Article 33). After becoming aware of a breach concerning the entrusted personal data, the Processor notifies the Controller without undue delay, and no later than within 24 hours of becoming aware of the breach. To the extent of the information in its possession, the notification includes: a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects and data records concerned; a description of the likely consequences of the breach; a description of the measures taken or proposed to remedy and mitigate the breach; the contact details of a point from which further information can be obtained; and the moment at which the breach was identified. If it is not possible to provide full information at once, the Processor provides it in phases, without undue delay, and maintains ongoing communication with the Controller until the matter is closed.

The Processor does not notify a breach to the supervisory authority on behalf of the Controller unless the Controller expressly requests this and the Parties agree the scope of such action. The decision to notify a breach to the supervisory authority rests with the Controller.

Communication to data subjects (Article 34). The Processor provides the Controller with the technical and informational support necessary to communicate a breach to the data subjects, including providing a list of the persons affected by the breach, and may, on the Controller's instruction and on its behalf, send the communication through the channels available in the platform.

Data protection impact assessments and prior consultation (Articles 35 and 36). At the Controller's request, the Processor provides the information necessary to carry out a data protection impact assessment and to conduct prior consultation with the supervisory authority, to the extent relating to the entrusted processing, in particular a description of the processing operations, the safeguards applied, the location of the processing, and the list of sub-processors.

The Processor maintains a register of all data breaches concerning the entrusted data, together with a description of the circumstances, effects and remedial actions taken, and makes it available to the Controller upon request to the extent relating to the Controller's data.

Transfers of data outside the European Economic Area

As a rule, the entrusted personal data is processed exclusively within the territory of the European Economic Area. The application infrastructure, database, file storage, backups and product analytics are located in European Union regions.

A transfer of the entrusted data outside the EEA may take place only:

  1. within the scope of the optional Telegram notification channel, activated by the notification recipient themselves,
  2. within the scope of any technical support provided by provider teams located outside the EEA, on an ad hoc, logged and time-limited access basis,
  3. on the documented instruction of the Controller.

Any such transfer takes place only with the use of an instrument ensuring an adequate level of protection in accordance with Chapter V GDPR, that is:

  • a European Commission adequacy decision (Article 45 GDPR), where such a decision covers the country or certification mechanism concerned, or
  • the standard contractual clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914, in the module appropriate to the relationship processor - processor (module three) or controller - processor (module two), depending on the roles of the parties.

The standard contractual clauses are deemed incorporated into this DPA by reference. For the purposes of their application, it is agreed that: the data exporter is the Controller, and the Processor concludes the clauses on behalf of and for the benefit of the Controller in its relationship with the sub-processor; the description of the transfer corresponds to the sections "Scope, nature and purpose of the processing" and "Categories of data subjects and categories of data"; the technical and organisational measures correspond to the section "Security measures"; the competent supervisory authority is the data protection authority of your country of residence; the law governing the clauses is law of Poland, without prejudice to the mandatory consumer rules of your country of residence, and the competent courts are courts competent for the seat of the operator, without prejudice to the consumer right to sue at their place of residence.

Before any transfer based on the SCCs, we carry out a transfer impact assessment taking into account the law and practice of the destination country, and we apply supplementary measures, including encryption of data in transit and at rest, minimisation of the scope of data transferred, and a procedure for challenging requests from third-country authorities.

If a third-country authority addresses a binding request to the Processor for disclosure of the entrusted data, the Processor notifies the Controller, unless legally prohibited from doing so, attempts to challenge the request, and limits the disclosure to the necessary minimum.

We provide a copy of the safeguards applied, including the text of the standard contractual clauses with trade secret information redacted, upon request sent to meetime.company@gmail.com.

Deletion or return of data after the end of cooperation

After the end of the provision of the Service, the Processor, at the choice of the Controller, deletes the entrusted personal data or returns it to the Controller, and deletes existing copies, unless Union or Member State law requires further storage of the data.

We apply the following schedule:

  1. Days 1 to 30 from the end of the Agreement: export period. The Controller retains read-only access and may independently export the full scope of the entrusted data in CSV and JSON formats. The export is free of charge and does not require the Processor's involvement. Upon a request submitted during this period to meetime.company@gmail.com, we extend the export period once by a further 30 days.
  2. Up to 90 days from the end of the Agreement: deletion from production systems. After the export period has expired, the Processor deletes or irreversibly anonymises the entrusted data in the production systems, no later than within 90 days of the end of the Agreement.
  3. Up to 90 days: deletion from backups. Data contained in backups is deleted in line with the backup rotation cycle, which does not exceed 90 days from the end of the Agreement. Until their deletion, the backups remain encrypted, and access to them is limited solely to disaster recovery purposes and remains subject to this DPA.

Upon the Controller's request submitted during the export period, the Processor carries out the deletion earlier than provided in the above schedule, within 14 days of receiving the request, subject to the backup rotation cycle.

After the process is complete, the Processor confirms the deletion of the data in writing or in documented form, upon request sent to meetime.company@gmail.com.

The above does not apply to data whose retention is required by law, in particular accounting and tax documentation relating to the subscription and data necessary for the establishment, exercise or defence of legal claims. In that respect, DOKUMENT.PL sp. z o.o. processes the data as a controller, for the period resulting from the applicable provisions, applying the principle of restricting access solely to the purpose for which the data was retained.

Audits and information obligations

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

First level: documentation. Upon a request sent to meetime.company@gmail.com, the Processor provides, no later than within 20 business days: the current description of the technical and organisational measures, the current list of sub-processors together with the locations of processing, a completed security questionnaire, information on incidents concerning the Controller's data, as well as available security test reports and certificates, to the extent that their disclosure does not endanger the security of the platform or breach obligations towards third parties.

Second level: audit. If the information provided at the first level proves insufficient, the Controller may conduct an audit on the following terms:

  • the audit is announced at least 30 days in advance, in writing or in documented form, stating its scope, purpose and planned duration,
  • the audit is conducted on business days, during working hours, in a manner minimising disruption to the Processor's operations, and lasts no longer than 3 business days,
  • the audit is conducted no more than once per calendar year, unless it is justified by an identified data breach, a binding instruction of the supervisory authority, or a material change in the manner of processing,
  • an external auditor may not be a competitor of the Processor and, before the audit begins, signs a confidentiality undertaking,
  • the audit may not cover data of the Processor's other customers, source code, details of the security architecture whose disclosure would endanger the security of the platform, or data constituting the trade secrets of third parties,
  • the audit may not consist of penetration testing or load testing of the production environment without the Processor's separate written consent and agreement on the conditions for carrying them out,
  • the costs of the audit are borne by the Controller; the Processor's own costs exceeding a reasonable effort may be settled at rates agreed before the audit begins, provided that the first audit in a given year, of a standard scope, is conducted without charging the Controller those costs.

The Processor remedies any irregularities identified in the audit without delay, within a timeframe agreed with the Controller and appropriate to the seriousness of the irregularity.

The Processor cooperates with the supervisory authority in the performance of its tasks and informs the Controller without delay of any action of the supervisory authority concerning the entrusted data.

Liability

Each Party is liable for damage caused by the processing of personal data in accordance with the rules set out in Article 82 GDPR and in the provisions applicable under law of Poland, without prejudice to the mandatory consumer rules of your country of residence.

The Processor is liable for damage caused by processing only where it has not complied with the obligations of the GDPR specifically directed at processors, or where it has acted outside or contrary to the lawful instructions of the Controller.

The Controller is responsible in particular for: the absence or defectiveness of the legal basis for the processing, failure to fulfil the information obligation towards data subjects, entering excessive data or special categories of data into the platform contrary to the provisions of this DPA, the content and lawfulness of the instructions issued, and the processing of data after it has been downloaded from the platform.

Limitation of liability. The limitations of liability set out in the Terms of Service, including the monetary cap, apply to the Parties' liability under this DPA, provided that these limitations do not apply in the case of wilful misconduct, gross negligence, death, bodily injury or damage to health, or to any extent to which a limitation of liability is impermissible under mandatory provisions of law, including with respect to liability towards data subjects and administrative liability towards the supervisory authority.

Recourse claims. If one Party satisfies in full a claim of a data subject, it has a recourse claim against the other Party for the part corresponding to that Party's share in the damage, in accordance with Article 82(5) GDPR. The Parties cooperate in the defence against such claims and inform each other without delay when such claims are brought.

Administrative fines imposed by the supervisory authority are borne by the Party whose act or omission constituted the basis for their imposition.

Final provisions

Amendments to the DPA. The provisions of the Terms of Service on amendments to standard terms apply mutatis mutandis to amendments to this DPA, including the notice period of at least 15 days and the Controller's right to terminate the Agreement. Amendments resulting directly from changes in the law or from guidance of the supervisory authority are introduced within the timeframe resulting from those provisions or that guidance.

Invalidity of provisions. If any provision of this DPA proves invalid or ineffective, the remaining provisions remain in force, and the invalid provision is replaced by a lawful provision that comes closest to the purpose of the invalid one.

Governing law and jurisdiction. This DPA is governed by law of Poland, without prejudice to the mandatory consumer rules of your country of residence. Disputes arising out of or in connection with this DPA are resolved by courts competent for the seat of the operator, without prejudice to the consumer right to sue at their place of residence, without prejudice to the right of data subjects to lodge a complaint with the supervisory authority the data protection authority of your country of residence (edpb.europa.eu, see edpb.europa.eu for the list of national authorities) and to seek judicial remedies before the competent court in accordance with Article 79 GDPR.

Precedence. With respect to the processing of the entrusted personal data, this DPA takes precedence over the Terms of Service, the price list and any prior arrangements between the Parties.

Binding version

This document has been drawn up in the following language versions: Polish (pl) and English (en).

For the PL (Poland) region, the Polish (pl) language version of this document is binding. For the EU (other states of the European Economic Area) region, the English (en) language version is binding. In the event of any discrepancy, the version binding for the given region prevails.