Wersja polska

Data Processing Agreement

Version 1.0 · effective 8 October 2026

This data processing agreement (the “Agreement”) sets out how SpaDesk processes, on a salon's behalf, the personal data the salon enters into the app – data about its clients, employees and other people. It is the contract referred to in Article 28(3) GDPR. This is an English translation of the Polish Umowa powierzenia; the Polish version is the binding one.

§ 1. Parties and conclusion of the Agreement

  1. The Agreement is concluded between:
    • the Company that uses SpaDesk under the Terms, as the controller (the “Controller”; this term does not refer to the Admin role in SpaDesk), and
    • the Provider as the processor (the “Processor”):

    Alex Maher Netskyes

    ul. Telefoniczna 23D, 91-728 Łódź, Poland

    NIP (tax ID) 7272820962

    Email: kontakt@spadesk.pl

  2. The Agreement is concluded electronically when a Company Account is created and the Owner, acting on the Controller's behalf, ticks the box accepting the Agreement. If the Company Account was created before the Agreement took effect, the Agreement is concluded when it is accepted in the app. Later versions of the Agreement are accepted in the app.
  3. The Agreement is concluded in electronic form, which meets the requirement of Article 28(9) GDPR.
  4. In matters of personal data protection, the Agreement takes precedence over the Terms; in all other respects the Terms apply.

§ 2. Definitions

Capitalised terms in the Agreement mean:

  1. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation);
  2. Terms – the SpaDesk Terms of Service (Regulamin), available at spadesk.pl/terms;
  3. Service Agreement – the agreement concluded between the Company and the Provider on the terms of the Terms (called the “Agreement” in the Terms);
  4. Data – the personal data entrusted to the Processor by the Controller, described in § 4;
  5. Sub-processor – another processor engaged by the Processor (Article 28(2) and (4) GDPR);
  6. Parties – the Controller and the Processor.

Other capitalised terms, such as SpaDesk, Service, Provider, Company, Company Account, Owner, User and Ad Platforms, have the meanings given in the Terms, and terms defined in the GDPR, such as processing and personal data breach, have the meanings given in the GDPR.

§ 3. Subject matter, nature and purpose of processing

  1. The Controller entrusts the Processor with processing the Data, and the Processor undertakes to process it solely to the extent and for the purpose set out in the Agreement, in accordance with the Agreement and the GDPR.
  2. Processing consists of storing, organising and compiling the Data (for example in reports), displaying, searching and exporting it, sending email and text messages on the Controller's instructions, making backups and deleting the Data. It takes place in IT systems, by means of SpaDesk.
  3. The sole purpose of processing is to provide the Service to the Controller in accordance with the Terms.
  4. The Data is processed for the term of the Agreement (§ 17).

§ 4. Categories of data subjects and types of data

  1. Processing concerns the following categories of data subjects:
    • the Controller's clients;
    • the Controller's employees and co-workers;
    • Users of the Controller's Company Account;
    • people who fill in the Controller's forms.
  2. Processing covers the following types of data:
    • identification and contact data: name, email address, phone number;
    • date of birth and gender;
    • notes and tags;
    • sales and services recorded with finance entries (for example the client's name), voucher purchases and redemptions, and the history of messages sent;
    • marketing consents and unsubscribes from messages;
    • answers given in forms, including signatures;
    • employee data: position, address, national ID number (PESEL) or ID card number, bank account number, emergency contact details, contracts – including employment contracts – and other documents, salary, work schedules and time off;
    • the change history of the Company Account, that is, information on which User entered or changed data and when;
    • other data the Controller enters into SpaDesk, including in free-text fields and attached files.
  3. The Data may include special categories of personal data (Article 9 GDPR), in particular health information in client notes and questionnaires, if the Controller enters or collects it.

§ 5. The Controller's instructions

  1. The Processor processes the Data only on documented instructions from the Controller – including with regard to transfers of Data to a third country or an international organisation – unless required to do so by European Union or Polish law. In such a case, it informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  2. The Controller's documented instructions are the Terms, the Agreement and the actions of the Controller and its Users in SpaDesk, such as adding or changing a client's details, sending a message, or exporting or deleting data.
  3. The Controller may give other instructions by email from the Owner's address to kontakt@spadesk.pl. If they cannot be carried out within the Service, the Processor informs the Controller without delay, and the Controller may then terminate the Service Agreement.
  4. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
  5. The Processor does not use the Data for its own purposes and does not sell it.

§ 6. The Controller's obligations and rights

  1. The Controller is responsible for the lawfulness of processing the Data, in particular for:
    • having a legal basis for processing the Data and for its instructions, including clients' consent to receive marketing messages required by the Polish Electronic Communications Law of 12 July 2024 (Prawo komunikacji elektronicznej) and, for health data, the data subject's explicit consent, unless it has another legal basis under Article 9(2) GDPR;
    • meeting its information obligations towards data subjects (Articles 13 and 14 GDPR) and handling their rights;
    • giving Users roles and permissions appropriate to their tasks and authorising them to process the Data;
    • entering into SpaDesk only the Data needed for the purposes for which it processes it.
  2. In particular, the Controller has the right to give instructions (§ 5), receive information and carry out audits (§ 15), object to new Sub-processors (§ 9), be notified of personal data breaches (§ 13) and decide on the return of the Data before it is deleted (§ 14).

§ 7. Confidentiality

  1. The Processor allows only persons it has authorised to process the Data, who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  2. These persons have access to the Data only to the extent necessary to provide the Service, for example to fix a fault or handle a request from the Controller, or to comply with a legal obligation.
  3. The confidentiality obligation continues after the Agreement ends.

§ 8. Security of processing

  1. The Processor applies the technical and organisational measures referred to in Article 32 GDPR to ensure a level of security appropriate to the risk, in particular:
    • encryption of connections to SpaDesk (HTTPS/TLS);
    • keeping the database and running the application servers in the European Union (Frankfurt), with stored data encrypted by the infrastructure providers;
    • strict separation of each Company's data, enforced in the database (row-level security);
    • User roles and permissions in the Company Account, including limiting access to selected locations;
    • a change history (audit log);
    • storing passwords only as hashes;
    • limits on sign-in attempts;
    • optional two-factor sign-in (a code from an authenticator app);
    • email address confirmation;
    • encryption in the database of access tokens for the Ad Platforms and of employees' national ID (PESEL) or ID card numbers and bank account numbers;
    • regular database backups made by the database provider;
    • limiting access to production systems to the Provider and protecting that access with strong authentication.
  2. The Processor may change these measures if this does not lower the level of protection of the Data.
  3. The Controller is responsible for security on its side, in particular for its devices, for its Users protecting their sign-in details, and for Data exports downloaded from SpaDesk.

§ 9. Sub-processors

  1. The Controller gives the Processor general written authorisation to engage Sub-processors (Article 28(2) GDPR).
  2. On the date the Agreement takes effect, the Processor uses the following Sub-processors:
    • Vercel Inc. – app hosting and file storage; the application servers run in Frankfurt (EU);
    • Neon Inc. – the database, in the Frankfurt region (EU);
    • Resend – sending email;
    • SMSAPI (LINK Mobility Poland) – sending text messages, when the Controller texts its clients;
    • OpenAI – preparing ad copy suggestions, when the Controller uses that feature; it receives a description of the advertised service, its price, the Company's name and its town – not client data;
    • Meta (Facebook, Instagram) and Google (Google Ads) – when the Controller connects its ad accounts to SpaDesk; they receive the content and settings of the ads, including targeting – not client data.
    The current list is also in the Privacy policy.
  3. The Processor informs the Controller by email or in the app at least 14 days in advance of any intended addition or replacement of a Sub-processor. During that time, the Controller may object by writing to kontakt@spadesk.pl. If the Parties do not agree on a solution, the Controller may terminate the Service Agreement before the change by deleting its Company Account.
  4. The Processor imposes on each Sub-processor, by contract, the same data protection obligations as in the Agreement, in particular providing sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of the GDPR. Where a Sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of those obligations.

§ 10. Transfers of Data outside the EEA

  1. The SpaDesk database and application servers are located in the European Union (Frankfurt).
  2. Some Sub-processors are based outside the European Economic Area, including in the United States. The Processor transfers Data to them only with the safeguards required by Chapter V GDPR (Article 44 et seq.) – on the basis of a European Commission adequacy decision, including the EU-U.S. Data Privacy Framework for organisations certified under it, or standard contractual clauses adopted by the European Commission. The Controller instructs the Processor to transfer Data on these terms.

§ 11. Assistance with data subjects' rights

  1. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR.
  2. For this purpose, SpaDesk lets the Controller view, correct, export and delete client data itself.
  3. If a data subject makes a request directly to the Processor, the Processor forwards it to the Controller without delay and – other than telling that person that the request has been forwarded – does not respond to it itself unless the Controller authorises it to do so.
  4. For matters the Controller cannot handle itself in SpaDesk, the Processor assists it on request sent by email.

§ 12. Assistance with obligations under Articles 32–36 GDPR

  1. Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations under Articles 32–36 GDPR, concerning the security of processing, notifying personal data breaches to the supervisory authority and communicating them to data subjects, data protection impact assessments and prior consultation with the supervisory authority.
  2. In particular, at the Controller's request, the Processor provides the information on the processing of the Data and the security measures in place that is needed for a data protection impact assessment or prior consultation.

§ 13. Personal data breaches

  1. The Processor notifies the Controller of a personal data breach concerning the Data without undue delay, and no later than 48 hours after becoming aware of it, by email to the Owner's address.
  2. The notification includes, as far as available, the information required by Article 33(3) GDPR:
    • a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
    • the name and contact details of the person from whom more information can be obtained;
    • a description of the likely consequences of the breach;
    • a description of the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
  3. Where not all the information is available at once, the Processor provides it in phases without undue further delay.
  4. The Processor promptly takes steps to limit the effects of the breach, documents breaches and cooperates with the Controller. The Controller decides whether to notify the breach to the supervisory authority and to communicate it to data subjects.

§ 14. Return and deletion of Data

  1. The Controller can retrieve the Data at any time: the Owner downloads a full export of the Data in JSON format in Settings → Company → Export all data.
  2. After the provision of the Service ends, the Processor deletes all the Data:
    • when the Owner deletes the Company Account – 30 days after the deletion request, in accordance with § 15 of the Terms; until then, the deletion can be cancelled;
    • when the Provider terminates the Service Agreement – 30 days after the termination date; until then, at the Controller's request, the Processor provides an export of the Data.
  3. Deleted Data disappears from database backups when those backups are overwritten in the normal backup cycle. Until then, it is protected like the rest of the Data and may be used only to restore SpaDesk after a failure; in that case, the Processor deletes again the Data that had been deleted before.
  4. The Processor may keep Data longer only where European Union or Polish law requires it.
  5. At the Controller's request, the Processor confirms the deletion of the Data by email.

§ 15. Information and audits

  1. The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, in particular by answering questions sent to kontakt@spadesk.pl.
  2. The Processor allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, on the following terms:
    • the Controller gives notice of the audit by email at least 14 days in advance, stating its scope;
    • the audit takes place on business days, during the Processor's business hours, in a way that does not disrupt SpaDesk;
    • an audit may take place no more than once a year, unless it follows a personal data breach concerning the Data or is requested by a supervisory authority;
    • the Controller bears the costs of the audit;
    • the auditor undertakes in writing to keep information confidential, and the audit does not cover other customers' data or the Processor's trade secrets beyond what the audit requires.

§ 16. Liability

  1. The Parties are liable to data subjects in accordance with Article 82 GDPR. The Processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to the Controller's lawful instructions.
  2. Between the Parties, the Processor's liability under the Agreement is subject to the rules and limitations in § 11 of the Terms, to the extent the law allows. These limitations do not affect the rights of data subjects.

§ 17. Term of the Agreement

  1. The Agreement remains in force for as long as the Service Agreement and, after it ends, until the Data is deleted in accordance with § 14.
  2. As providing the Service requires processing the Data, the Agreement cannot be terminated without terminating the Service Agreement; the Controller may terminate both as set out in the Terms.

§ 18. Changes and final provisions

  1. The Processor informs the Controller of changes to the Agreement by email or in the app at least 14 days before they take effect. A Controller that does not accept the changes may terminate the Service Agreement before that date by deleting its Company Account. The Owner accepts each new version of the Agreement in the app on the Controller's behalf.
  2. Matters not covered by the Agreement are governed by the GDPR, Polish law – in particular the Polish Personal Data Protection Act of 10 May 2018 and the Civil Code – and the Terms.
  3. The Agreement is governed by Polish law. Disputes arising from it are resolved by the court indicated in § 17(3) of the Terms.
  4. The English version of the Agreement (spadesk.pl/dpa) is a translation; in case of any discrepancy, the Polish version prevails.
  5. The Agreement is effective from 8 October 2026.