Umowa
Umowa o przetwarzaniu danych
Umowa regulująca nasze przetwarzanie danych osobowych w imieniu naszych klientów, na mocy art. 28 RODO. Pełny tekst, w tym załączniki I i II.
Ostatnia aktualizacja:
Niniejsze tłumaczenie ma charakter informacyjny. W przypadku jakichkolwiek rozbieżności wiążąca jest wersja angielska.
Niniejsza umowa jest w języku angielskim
Wersja angielska jest wiążąca. Tłumaczenia, o ile są dostępne, mają charakter informacyjny i nie są wiążące w przypadku rozbieżności. W celu uzyskania podpisanej kopii lub tłumaczenia prosimy o kontakt na adres privacy@beskos.com.
Spis treści
- 1. Definitions
- 2. Roles of the parties
- 3. Scope and instructions
- 4. Confidentiality
- 5. Security of processing
- 6. Sub-processors
- 7. International transfers
- 8. Assistance to the Controller
- 9. Personal data breaches
- 10. Return and deletion
- 11. Information and audits
- 12. Term, precedence and liability
- Annex I — Description of the processing
- Annex II — Technical and organisational measures
This Data Processing Agreement (the “DPA”) forms part of the Beskos Terms of Service between the customer (the “Controller”) and Open Solutions, established in Poznań, Poland, NIP PL7773457857 (the “Processor”). It applies whenever the Processor processes personal data on behalf of the Controller in the course of providing the Services.
This DPA is incorporated into the Terms of Service automatically. No separate signature is required. Where the Controller requires a signed copy for its own records, one is available on request at privacy@beskos.com.
1. Definitions
“GDPR” means Regulation (EU) 2016/679. “Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given to them in the GDPR.
“Services” means the Beskos workspace: email, calendar, contacts, files, documents, chat, meetings, wiki, boards and the assistant, together with the administration console.
“Customer Data” means all data the Controller or its users submit to, store in, or generate through the Services, including the content of messages, files and documents.
“Sub-processor” means a third party engaged by the Processor to process personal data on behalf of the Controller.
2. Roles of the parties
The Controller determines the purposes and means of the processing of Customer Data. The Processor processes Customer Data only on behalf of the Controller.
Where the Controller is itself a processor acting on behalf of a third-party controller, the Processor acts as a sub-processor, and this DPA applies accordingly.
The Processor acts as an independent controller in respect of account administration data (billing details, the identity of administrators, security and audit logs). That processing is described in the Privacy Policy and is not governed by this DPA.
3. Scope and instructions
The Processor processes Customer Data only on documented instructions from the Controller. The Terms of Service, this DPA and the Controller's use of the features of the Services constitute those instructions.
The Processor does not use Customer Data for its own purposes. In particular, the Processor does not sell Customer Data, does not use it for advertising, and does not use it to train artificial intelligence models, whether its own or those of any third party.
The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law. The Processor may suspend the execution of that instruction until it is confirmed or withdrawn.
Where the Processor is required by Union or Member State law to process Customer Data other than on the Controller's instructions, it informs the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
4. Confidentiality
The Processor ensures that persons authorised to process Customer Data are bound by an obligation of confidentiality, and that access is limited to those who need it to provide, secure or support the Services.
Administrative access to production systems is restricted to authorised personnel, granted on the principle of least privilege and reviewed as roles change.
5. Security of processing
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as required by Article 32 of the GDPR.
The measures in force are described in Annex II. The Processor may update them, provided the level of security is not reduced. Annex II describes measures that are in place; it does not describe planned measures.
6. Sub-processors
The Controller gives the Processor general written authorisation to engage sub-processors. The current list is published at beskos.com/sub-processors and forms part of this DPA.
The Processor gives at least 14 calendar days' notice before engaging a new sub-processor or replacing an existing one. Notice is given by email to the addresses registered for billing and administration and by updating the published list.
The Controller may object to a new sub-processor on reasonable data-protection grounds within those 14 days, by writing to privacy@beskos.com. The parties will discuss the objection in good faith. Where it cannot be resolved and the Processor nonetheless engages the sub-processor, the Controller may terminate the affected Services and receive a refund of any prepaid fees for the unused period.
The Processor imposes on each sub-processor data protection obligations no less protective than those set out in this DPA, and remains fully liable to the Controller for the performance of the sub-processor's obligations.
7. International transfers
Customer Data is processed and stored within the European Union. The application, database and mail servers are located in the European Union; files are held in storage under European jurisdiction; artificial-intelligence processing takes place in European data centres.
Certain sub-processors are companies established in the United States, notwithstanding that the data is processed within the European Union. Where personal data is transferred to, or is accessible from, a third country, the transfer is governed by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) or Module Three (processor to processor) as applicable, supplemented by the measures described in Annex II.
The Processor does not represent that no provider in its supply chain is subject to foreign legislation. The published sub-processor list states, for each provider, where the data is processed and which transfer mechanism applies.
If the Processor receives a legally binding request from a public authority for disclosure of Customer Data, it notifies the Controller before disclosure unless prohibited by law; where prohibited, it uses reasonable efforts to obtain a waiver of that prohibition and challenges the request where there are reasonable grounds to consider it unlawful.
8. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR. The administration console allows the Controller to access, export, correct and delete the data of its users without the Processor's involvement.
Where a data subject contacts the Processor directly in relation to Customer Data, the Processor does not respond to the substance of the request but refers the data subject to the Controller and informs the Controller without undue delay.
The Processor assists the Controller in ensuring compliance with Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to the Processor.
9. Personal data breaches
The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not available at once, it is provided in phases without undue further delay.
The Processor does not notify supervisory authorities or data subjects on the Controller's behalf unless the Controller instructs it to do so in writing.
10. Return and deletion
During the term of the Services the Controller may export Customer Data at any time and without the Processor's assistance: email over IMAP, calendars in iCalendar format, contacts in vCard or CSV, and files by download, including whole folders as archives.
On termination of the Services the Processor deletes Customer Data within 30 days, unless Union or Member State law requires its retention. Backups, where they exist, are deleted in accordance with their retention cycle.
The Processor certifies deletion in writing on request.
11. Information and audits
The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 of the GDPR, including this DPA, the published sub-processor list, the Security page and the answers to reasonable written questions.
The Processor holds no security certification at the date of this DPA. It does not claim conformity with ISO 27001, SOC 2 or any comparable standard.
The Controller may audit the Processor's compliance no more than once in any twelve-month period, on 30 days' written notice, during business hours, and in a manner that does not disrupt the Services or compromise the confidentiality of other customers' data. Where an audit is required by a supervisory authority, or follows a personal data breach, that limitation does not apply.
12. Term, precedence and liability
This DPA applies for as long as the Processor processes Customer Data on behalf of the Controller, and the obligations in clauses 4, 7 and 10 survive its termination.
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails in respect of the processing of personal data. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits any liability that cannot be limited under the GDPR.
This DPA is governed by Polish law. The English text is the authentic version; any translation is provided for convenience only and, in the event of a discrepancy, the English text prevails.
Annex I — Description of the processing
A. The parties
Data exporter (Controller): the customer identified in the billing account, at the address given there. Contact: the administrator and billing addresses registered in the account. Role: controller (or processor, where acting for a third-party controller).
Data importer (Processor): Open Solutions, Wawrzyńca Engeströma 10, 60-571 Poznań, Poland. NIP PL7773457857 · REGON 543340675. Contact: privacy@beskos.com. Role: processor.
B. Categories of data subjects
Employees, contractors, officers and other members of the Controller's organisation to whom accounts are issued.
Any natural person who corresponds with, or whose personal data is included in messages, files, calendars, contacts or documents created or received by, those account holders.
C. Categories of personal data
Account and identity data: name, email address, account identifiers, group and role membership, authentication credentials (stored as hashes) and, where enabled, multi-factor authentication secrets.
Communications content and metadata: the content, headers, attachments, recipients and timestamps of email, chat messages and calendar invitations.
Files and documents: the content and metadata of files stored in the drive, documents edited in the office suite, wiki pages and boards.
Meeting data: participant identifiers, connection metadata and, where a meeting is recorded at the Controller's instruction, the recording itself.
Technical and security data: IP addresses, device and client identifiers, and authentication and administration logs.
D. Sensitive data
The Services are not designed or marketed for the processing of special categories of personal data within the meaning of Article 9 of the GDPR, nor of data relating to criminal convictions and offences.
The Processor cannot prevent such data from being included in content the Controller chooses to store. Where it is, the Controller remains responsible for establishing a lawful basis for the processing and for any additional safeguards its own risk assessment requires.
E. Nature, purpose and frequency
The processing is continuous, for the duration of the subscription, and consists of the operations necessary to provide the Services: receiving, transmitting, storing, indexing, displaying, searching, editing, backing up and deleting Customer Data at the direction of the Controller and its users.
The assistant processes the content submitted to it in order to produce the requested output. That content is transmitted to the model-serving sub-processor identified in the published list and is not retained by it for training.
F. Retention
Customer Data is retained for as long as the Controller keeps it in the Services, and for 30 days after termination of the Services, after which it is deleted.
Data the Controller's users delete is removed from the Services when the deletion is confirmed, save that items in a trash or recycle folder are retained until that folder is emptied or the retention period configured by the Controller expires.
Meeting recordings are retained according to the retention setting chosen by the Controller. Security and administration logs are retained for 90 days.
G. Competent supervisory authority
The Processor is established in Poland. The competent supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
Where the Standard Contractual Clauses apply, the supervisory authority of the Member State in which the data exporter is established acts as competent supervisory authority in accordance with Clause 13 of those Clauses.
Annex II — Technical and organisational measures
The following measures are in force at the date stated above. This annex describes what is implemented, not what is planned; where a measure is absent, it is stated as such.
Encryption
All connections to the Services are encrypted in transit with TLS, using certificates issued by a public certification authority. This applies to the web application, the API, and the mail protocols (SMTP submission, IMAP and JMAP).
Files stored in Drive, documents and meeting recordings are encrypted by the Processor with AES-256-GCM before being written to object storage. The storage provider receives ciphertext only and holds no key capable of decrypting it. This measure does not extend to the content of email messages, which is held by the mail server and is protected by transit encryption, the storage provider's own encryption at rest, and the access controls described below.
Each Controller's data is encrypted under a distinct key, held by the Processor within the European Union and wrapped by a master key present only in the environment of the running service. Destruction of a Controller's key renders all of that Controller's files unreadable.
This measure protects the data from the storage provider and from disclosure of the stored objects. It is not end-to-end encryption: the Processor holds the keys and is technically able to read file content, as is necessary to provide previews, in-browser document editing and shared links.
Backups are encrypted before transmission using an asymmetric scheme. The production environment holds only the public key and cannot decrypt any backup it has written; the private key is held outside the production infrastructure.
Multi-factor authentication secrets are encrypted at rest in the database with a key held outside it.
The database volume and the mail server volume are not encrypted at the block-device level. They are protected by the access controls described below.
Access control
Passwords for accounts issued by the Processor are stored as bcrypt hashes; mailbox credentials are held by the mail server and are never stored in plaintext.
Password strength is measured and weak passwords are refused, both at the point of choosing one and by the mail server itself.
Multi-factor authentication (time-based one-time passwords) is available to all users and can be required by the Controller for its organisation.
Access to Customer Data within the Services is governed by roles and by per-resource permissions set by the Controller. Every query for customer data is restricted to the organisation of the authenticated user.
Administrative access to the production infrastructure is restricted to authorised personnel and protected by key-based authentication and multi-factor authentication.
Application security
Session cookies are transmitted only over HTTPS and are not accessible to scripts. State-changing requests require a header that a cross-site request cannot set.
Authentication endpoints are rate-limited to frustrate credential stuffing and brute-force attempts.
Secrets and credentials are supplied to the running system through the environment and are not stored in the source code.
The administration interface of the mail server is not exposed to the public internet.
Separation and isolation
The Services are multi-tenant. Data belonging to different customers is separated logically: every record carries the identifier of the organisation that owns it, and every query is constrained by the organisation of the authenticated user.
Mailboxes are separate accounts on the mail server, isolated from one another by the server's own access controls.
Availability and resilience
The availability of each component is monitored continuously from outside the infrastructure and published at status.beskos.com.
Backups are taken three times a day of both the application database and the mail database — the latter holding messages, attachments and mailbox configuration. They are written to object storage under European jurisdiction and retained for 30 days.
Each backup is verified as readable before it is stored, and its size is confirmed at the destination. The backup process reports each successful run to the monitoring system, so that a backup which silently stops running raises an alert rather than going unnoticed. Restoration has been tested end to end against production data.
Backups protect against loss of the infrastructure. They are not a retrieval service for data the Controller's own users delete; for that, the Controller should rely on the deletion and trash controls in the Services.
Governance
The Processor holds no security certification and does not claim conformity with any security standard.
Changes to the software are version-controlled, reviewed before release and deployed through an automated pipeline; the change history is retained.
Security vulnerabilities may be reported to security@beskos.com. The Processor acknowledges reports within five working days and does not pursue researchers who act in good faith and do not access, modify or retain other people's data.
Measures for transfers
Where a sub-processor established outside the European Economic Area is engaged, the Standard Contractual Clauses are in place, the data continues to be processed within the European Union, and the transfer is recorded in the published sub-processor list with the applicable mechanism.
The Processor maintains no arrangement granting any public authority direct or unmediated access to Customer Data, and has received no such request as at the date stated above.
Pytania
Prosimy pisać na adres privacy@beskos.com.