DPA — Data Processing Agreement
2026-05-17 · v1.0 / maj 2026
IMPORTANT NOTICE: This Data Processing Agreement (hereinafter: DPA) constitutes a binding legal addendum to the Main Agreement (General Terms of Business or specific B2B contract) between the Client (Controller) and Findes Group (Processor). This document ensures full compliance with Regulation (EU) 2016/679 (GDPR), the Personal Data Protection Act (ZVOP-2), and Regulation (EU) 2024/1689 (EU AI Act). By using our IT, marketing, or SaaS services, the Client automatically accepts this DPA.
In this DPA, the following terms have a specific legal meaning:
- Controller (Client): A B2B partner (agency, developer, franchise, company) that engages services from Findes Group and independently determines the purposes and means of processing personal data of its customers or employees.
- Processor (Findes Group): Depending on the nature of the service, this role is assumed by either Investra International Ltd (for IT platform, SaaS, CRM, Marketplace infrastructure) or Findes Marketing d.o.o. (for marketing services, Master Franchise operations in Slovenia).
- Sub-processor: A third party authorized by the Processor to carry out specific data processing tasks (e.g., AWS for hosting, OpenAI for artificial intelligence).
- Main Agreement: Any service agreement, SLA (Service Level Agreement), or General Terms under which the Processor provides services to the Controller.
- Personal data: Any information relating to an identified or identifiable natural person (the data subject) that the Processor processes on behalf of the Controller.
Legal nature
Where the Findes platform operates as a marketplace (Marketplace) for end users (B2C), Findes may act as a Joint Controller. However, this DPA specifically addresses situations where Findes provides IT/SaaS/Marketing infrastructure to B2B partners and acts strictly as a Processor.
The Processor shall process Personal data solely for the purpose of performing the services specified in the Main Agreement. The subject matter of processing includes the following parameters:
2.1 Categories of data subjects
- Customers and prospective customers (leads) of the Controller.
- Employees, agents and external collaborators of the Controller (SaaS platform users).
- Business partners and suppliers of the Controller.
2.2 Types of personal data
| Type of data | Examples | Purpose of processing |
|---|---|---|
| Identification data | Name, surname, username, tax number | Profile creation, CRM management |
| Contact details | Email, telephone number, address | Communication, sending offers, automation |
| Financial data | Transaction data, IBAN (partial) | Payment processing, affiliate commission models |
| Digital and IT data | IP address, log files, cookies, location | System security, analytics, audit trails |
| Communication content | Chat history, email messages | Customer support, AI analytics (if enabled) |
2.3 Nature of processing
Processing includes collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission (within the platform), restriction, deletion and destruction of data using automated IT and AI systems.
The Processor undertakes to comply strictly with the following obligations when processing Personal data:
- Written instructions: Processes Personal data solely on the basis of documented instructions from the Controller (including the use of functions within the SaaS platform). If the Processor believes that an instruction violates GDPR, it shall immediately notify the Controller.
- Confidentiality: Ensures that persons authorized to process data (employees, external collaborators) are bound by strict legal confidentiality obligations.
- Assistance to Controller: Subject to the nature of the processing and the information available to it, provides the Controller with assistance in fulfilling security obligations, breach notification and conducting Data Protection Impact Assessments (DPIA).
- Limitation of use: Shall never use the Controller's Personal data for its own marketing purposes, sale to third parties, or data monetization.
The Controller, as the data owner, bears primary responsibility for the lawfulness of processing. The Controller undertakes to:
- Have a valid legal basis (e.g., consent, contract, legitimate interest) for collecting and transferring Personal data to the Processor.
- Have provided data subjects with all necessary information (Privacy Policy) in a timely manner in accordance with Articles 13 and 14 of GDPR.
- Shall not enter special categories of personal data (health data, biometrics, political beliefs) into the Processor's systems unless expressly agreed in writing and safeguarded by additional TOMs.
- Shall ensure the security of access passwords (using 2FA/MFA) and API keys for accessing the Findes platform.
The Processor implements the highest industry standards for data protection. Standard TOMs (Technical and Organisational Measures) include:
5.1 Technical measures
- Encryption: All data is encrypted in transit (TLS 1.3 / HTTPS) and at rest (AES-256 database encryption).
- Access control: A strict role-based access control system (RBAC) is implemented. Production database access is limited to authorized senior engineers via secure VPN connections and MFA.
- Backups: Automated daily backups stored in separate geographic locations with backup integrity verification.
- Network monitoring: Use of Web Application Firewall (WAF), DDoS protection and intrusion detection systems (IDS/IPS).
5.2 Organisational measures
- Password policies: Mandatory use of strong passwords and multi-factor authentication (MFA) for all Processor employees.
- Training: Regular annual employee training on information security and GDPR compliance.
- Clean Desk Policy: Clean desk policy and screen lock requirements in company offices.
- Incident management: Documented procedure for rapid response to security incidents.
The Controller grants general written authorization to the Processor to engage Sub-processors. The Processor currently uses the following key Sub-processors:
| Sub-processor | Service / Purpose | Data location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, databases, file storage | EU (Frankfurt / Ireland) |
| Cloudflare / Netlify | CDN, WAF, static file hosting | Global (Edge), primarily EU |
| SendGrid / Mailgun | Infrastructure for sending transactional and marketing emails | EU / USA (DPF certified) |
| OpenAI, L.L.C. | AI text processing and analytics (Zero-Data Retention for API) | USA (DPF certified) |
| Stripe / PayPal | Payment and subscription processing | EU / USA (DPF certified) |
6.1 Change of Sub-processors
The Processor shall notify the Controller of any intended change or addition of new Sub-processors (typically via dashboard notification or email) at least 14 days before implementation. The Controller has the right to object on grounds related to data protection. If the dispute cannot be resolved, the Controller has the right to terminate the Main Agreement.
6.2 Responsibility for Sub-processors
The Processor shall enter into a binding agreement (DPA) with each Sub-processor that imposes the same or stricter data protection obligations as set out in this DPA. The Processor remains fully responsible to the Controller for the performance of Sub-processor obligations.
The primary location for data processing and storage is within the European Economic Area (EEA). If a service requires data transfer outside the EEA (e.g., to USA-based providers), the Processor shall ensure that the transfer is carried out exclusively on one of the following legal bases:
- Adequacy decision: Transfer to countries for which the European Commission has determined an adequate level of protection (including EU-US Data Privacy Framework for certified US companies).
- Standard Contractual Clauses (SCCs): Conclusion of the latest SCCs approved by the European Commission with additional technical measures (Transfer Impact Assessment - TIA) if necessary.
In the event of a confirmed breach of security of personal data processed by the Processor (e.g., unauthorized access, loss, destruction or disclosure of data), the Processor shall:
- Without undue delay, but no later than 48 hours after becoming aware of the breach, notify the Controller in writing (at the email address of the Controller's administrator or DPO).
- Include in the notification: the nature of the breach, categories and approximate number of affected data subjects, likely consequences of the breach and measures taken or to be taken to mitigate harm.
- Provide all reasonable assistance to the Controller in fulfilling its obligation to notify the supervisory authority (e.g., the Information Commissioner) and affected data subjects within the 72-hour timeframe required by GDPR.
Warning
The Processor shall not independently notify supervisory authorities or individuals of a breach unless explicitly required to do so by law or expressly requested in writing by the Controller.
If a data subject (e.g., a customer of the Controller) makes a request to exercise its rights (access, rectification, erasure/right to be forgotten, restriction, portability) directly to the Processor, the Processor shall:
- Immediately forward the request to the Controller and shall not respond to it independently.
- Provide the Controller with tools within the IT platform functionality to independently fulfill the request (e.g., profile deletion button, data export in JSON/CSV).
- If the tools are insufficient, the Processor shall provide technical assistance to the Controller upon written request in carrying out the request. Any substantial manual work may be charged to the Controller according to the applicable IT services price list.
Because Findes Group integrates AI functionality into its platforms (e.g., support automation, document analysis), the following strict rules apply in accordance with the Artificial Intelligence Regulation (EU AI Act):
- Zero-Data Retention for AI training: The Controller's Personal data is never used for training (fine-tuning) public or foundational models (Foundation Models) of the Processor or its AI Sub-processors (e.g., OpenAI). API calls to AI providers are configured so that data is not stored or used for training.
- Transparency: Where an AI system directly communicates with end customers of the Controller (e.g., AI chatbot), the customer must be clearly informed that they are communicating with a machine.
- Prohibition of high-risk systems: The Processor shall not perform AI processes for the Controller that would fall into the category of 'unacceptable risk' (e.g., social scoring) or 'high risk' (e.g., automated recruitment, remote biometric identification) unless a special annex has been concluded with an appropriate assessment of risk (Fundamental Rights Impact Assessment).
The Controller has the right to verify the Processor's compliance with this DPA and GDPR. An audit shall be conducted under the following conditions:
- The Controller shall first request documentation and certificates from the Processor (e.g., ISO 27001 reports, SOC 2, security statements). If this documentation demonstrates compliance, no further physical audit is necessary.
- If the documentation is insufficient or in case of a serious security incident, the Controller (or an independent external auditor who is not a competitor of the Processor) may conduct an audit upon at least 30 days' prior notice.
- The audit shall be conducted during normal working hours in a manner that minimally disrupts the Processor's operations. The audit costs shall be borne by the Controller, unless the audit discovers serious breaches by the Processor.
Upon termination of the Main Agreement or upon explicit request from the Controller, the Processor shall:
- Enable the Controller to export all Personal data in a standard machine-readable format (e.g., CSV, JSON) within 30 days of contract termination.
- After the expiry of the 30-day transition period, securely and permanently delete all Personal data of the Controller from all production systems.
- Data in backups will be automatically overwritten and destroyed in accordance with the regular backup rotation cycle (typically 90 days), remaining fully encrypted and inaccessible for processing.
An exception to deletion is data that the Processor must retain on the basis of legal obligations (e.g., tax and accounting legislation), but such data is retained exclusively for that purpose.
Parties' liability for damage to individuals due to GDPR violations is assessed in accordance with Article 82 of GDPR. In the mutual relationship (B2B), the following applies:
- The Processor is liable for damage only if it has not fulfilled obligations under GDPR that are expressly imposed on processors, or if it has acted outside or contrary to the lawful instructions of the Controller.
- The Processor's total liability for damages (including supervisory authority fines) under this DPA is strictly capped at the amount specified in the Main Agreement as the maximum liability limitation (Liability Cap). If not specified, liability is limited to the amount of fees paid by the Controller to the Processor in the 12 months prior to the event causing the damage.
- Neither party is liable for indirect damage, loss of profit, loss of data (if the Controller has neglected its own backups) or reputational harm.
This DPA enters into force simultaneously with the Main Agreement (or with confirmation of the General Terms) and remains in force as long as the Processor retains or processes any Personal data on behalf of the Controller.
In the event of a conflict between the provisions of this DPA and the provisions of the Main Agreement, the provisions of this DPA shall prevail, insofar as they relate to personal data protection and GDPR compliance.
This DPA shall be governed by the law specified in the Main Agreement. If not specified, the law of the Republic of Slovenia (for Findes Marketing d.o.o.) or the law of England and Wales (for Investra International Ltd) shall apply. All disputes arising from this DPA shall be resolved before the competent court as specified in the Main Agreement.
The Processor reserves the right to unilaterally amend this DPA if necessary due to changes in legislation (e.g., new EDPB guidelines, updates to the EU AI Act). The Controller shall be notified of any material changes at least 30 days in advance.
Findes Marketing d.o.o.
Master Franchise & Marketing
Company number: 8674639000
Litostrojska cesta 44A, 1000 Ljubljana, SI
info@findes.si
Investra International Ltd
Marketplace & IT Platform
Company No. 16626956
128 City Road, London EC1V 2NX, UK
legal@findes.si