Data processing agreement
1. Parties and scope
This annex forms part of the terms when a user acting for a business or organization is a data controller or is authorized to appoint a further processor. The processor is Pat Dimension Patryk Olędzki, a sole proprietorship operated by Patryk Olędzki, Polish tax ID (NIP) 7221621767, REGON 382606442, Stokowisko 8, 18-212 Nowe Piekuty, Poland. Acceptance of the terms by an authorized representative includes this annex. It does not cover information for which the provider acts as an independent controller.
2. Processing and instructions
Processing lasts for the service and backup-deletion period. It includes receiving, storing, organizing, displaying, synchronizing, exporting, backing up and deleting board content on the customer’s documented instructions. Instructions arise from the terms, access settings and authorized users’ actions. The purpose is collaboration on customer materials, not the provider’s independent purposes.
Data subjects include users, collaborators, customers and others lawfully described in materials. Data includes names, contact details, comments, assignments and ordinary data in documents or images. The beta does not cover special-category data or criminal-conviction/offence data. The customer ensures a lawful basis, required notices and lawful instructions.
3. Confidentiality and security
Personnel access is limited to people bound by confidentiality and to what is needed for their work. Measures include HTTPS, individual sessions, board/file access controls, request limits, separation of privileges, recovery copies, encrypted offsite backups, updates and error/availability monitoring. This is not end-to-end encryption: the server processes content to provide the service. We adapt measures to risk without reducing the agreed level of protection.
4. Subprocessors and transfers
The customer generally authorizes OVHcloud for hosting and active data and Cloudflare for connection protection, infrastructure and R2 backups. We impose appropriate data-protection obligations on subprocessors and remain responsible to the customer for their performance as required by GDPR Article 28. Normal instructed processing does not send board content to Gmail.
We give at least 14 days’ durable notice before adding or replacing a subprocessor. The customer may raise a reasoned data-protection objection. We seek a solution; if none is possible, the customer may end the affected service and export data before the change. Transfers outside the EEA require the customer’s instructions inherent in using the described infrastructure and a GDPR Chapter V mechanism, such as standard contractual clauses or an applicable adequacy decision. We notify the customer of legally required transfers unless prohibited by law.
5. Assistance, incidents and audits
Taking account of the processing and information available, we assist with individual rights, security, impact assessments, supervisory consultations and GDPR Articles 32–36 obligations. We notify the customer without undue delay after becoming aware of a personal-data breach, describing known circumstances, effects and mitigating action and supplementing information as it becomes available. Contact: PatDimension@gmail.com.
We provide information needed to demonstrate compliance and permit audits by the customer or its authorized auditor. Arrangements protect other customers, security and confidentiality without excluding effective audit rights. We promptly inform the customer if, in our opinion, an instruction infringes data-protection law.
6. End of processing
At the customer’s choice, we return entrusted data through export or delete it after service termination, except where law requires retention of specific data. Backups expire within 30 days, remain protected and are not used for other purposes. Following recovery, prior deletions are reapplied. Resolving shared-content ownership does not remove the duty to delete where the customer is entitled to instruct deletion.