Salonivo
SALONIVOH&S Agnieszka Adamska • legal documents
← Legal documentsDownload binding Polish DOCXPLENUKRkontakt@salonivo.pl

DATA PROCESSING AGREEMENT

Appendix to the terms of use of “Salonivo” – Article 28 GDPR

Document date: 18 September 2026

Convenience translation. In case of any discrepancy or interpretative doubt, the Polish version is the governing and binding version.
This Agreement may be concluded electronically during registration/activation. The Customer is the Controller of data entered into the Salon, and the Service Provider is the Processor to the extent necessary to provide the service.

§ 1. Parties and subject matter

• The Controller is the Customer using Salonivo whose identifying details were provided during registration or purchase of the Subscription (“Controller”).

• The Processor is H&S Agnieszka Adamska, ul. Bażantów 24/9, 40-668 Katowice, Poland, NIP 2220930216 (“Processor”).

• The Controller entrusts the Processor with processing personal data to the extent necessary to provide, secure, synchronise, maintain and support the Application.

• The processing arrangement lasts for the term of the service agreement and for the technical period necessary to return/delete data after termination.

§ 2. Nature, purpose and scope of data

Nature of processing operationscollection (in the technical sense), recording, organisation, storage, retrieval, transmission, synchronisation, modification on User instruction, backup creation, deletion
Purposeproviding the functions of the “Salonivo” Application, synchronisation, reporting, team management, settlements and support
Categories of data subjectsemployees, contractors, salon owner; potentially salon clients only where the Controller itself enters their data
Categories of dataname/display name, user identifiers, operational data relating to work and services, payment data at method/amount level, employee settlements, notes entered by the Controller, technical and audit data
Special-category datanot intended as part of the standard scope; the Controller should not enter such data without a separate arrangement and assessment of safeguards
Frequencycontinuous/periodic while the service is being used

§ 3. Controller instructions

• The Processor processes data only on documented instructions from the Controller unless processing is required by Union or Polish law.

• Documented instructions include in particular: actions of the Controller and its authorised Users in the Application, function settings, support requests and this Agreement.

• If the Processor considers that an instruction infringes the GDPR or other data-protection law, it informs the Controller without undue delay and may suspend execution of that instruction until the matter is clarified.

§ 4. Confidentiality and authorised persons

• The Processor ensures that persons authorised to process data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.

• Administrative access to data should be limited to persons for whom it is necessary for maintenance, security, support or compliance with a legal obligation.

§ 5. Security of processing

• The Processor implements technical and organisational measures appropriate to the risk, taking into account the state of the art, costs, and the nature and scope of processing.

• The minimum set of measures is described in Appendix A. The Processor may replace them with equivalent or more effective measures provided that the overall level of protection is not reduced.

§ 6. Sub-processors

• The Controller grants the Processor general authorisation to use further processors necessary to provide the service.

• The current list of main sub-processors is contained in Appendix B or in an updated list made available in the service documentation.

• The Processor imposes on each sub-processor data-protection obligations at least equivalent to those arising from this Agreement to the extent required by Article 28 GDPR.

• The Processor will inform the Controller of a planned material change of sub-processor with appropriate advance notice, generally at least 14 days. The Controller may raise a reasoned objection relating to data protection; the parties will take reasonable steps to resolve the issue.

§ 7. Data-subject rights and Controller obligations

• The Controller is responsible for the lawfulness of the entrusted data, legal bases, information duties, minimisation, accuracy and retention periods within its own activity.

• Taking into account the nature of processing, the Processor assists the Controller, insofar as technically possible, in responding to data-subject requests concerning GDPR rights.

• If the Processor receives a request relating to data for which the Customer is the Controller, it will not decide the request independently except where required by law; it will forward the request to the Controller or inform the person about the appropriate controller.

§ 8. Incidents, DPIA and consultations

• The Processor will inform the Controller without undue delay after becoming aware of a personal data breach affecting entrusted data, providing the available information necessary for the Controller to assess its obligations under Articles 33 and 34 GDPR.

• Where possible, the Processor will provide initial information within 48 hours of confirming that an incident concerns the data of that Controller; lack of complete information does not delay the first notification.

• The Processor provides reasonable assistance with data-protection impact assessments and consultations with the supervisory authority where connected with the Processor’s service and proportionate to the nature of processing.

§ 9. International transfers

• The Processor ensures that any transfer of data outside the EEA takes place only on a basis permitted by the GDPR.

• For sub-processors outside the EEA, mechanisms may include in particular the European Commission’s Standard Contractual Clauses or an adequacy decision, where applicable.

• Selecting a European hosting region limits the location of the project’s primary data, but does not exclude all cross-border ancillary processing by providers.

§ 10. Return and deletion of data

• After termination of the service, at the Controller’s choice and to the extent technically available, the Processor enables data download/export or deletes data from active systems.

• Unless the Controller gives a different lawful instruction, Customer Data should generally be removed from active systems within up to 30 days after termination of the agreement. Backups may be deleted according to the rotation cycle, provided they are not used for further active processing.

• The Processor may retain data whose further storage is required by law only for the required period and to the required extent.

§ 11. Audit and compliance information

• The Processor makes available to the Controller information necessary to demonstrate compliance with Article 28 GDPR obligations, within a reasonable scope and taking into account trade secrets and the security of other customers.

• An on-site audit is possible by prior arrangement where documentation and remote audit are insufficient, or where required by an authority or a material incident. As a rule, no more than once per year unless there is a justified reason.

• The Controller bears reasonable costs of an additional audit going beyond standard documentation where the audit does not reveal a material breach by the Processor.

§ 12. Priority and form

• In the event of a conflict with the Terms of Service, this Agreement takes precedence in matters concerning protection of entrusted personal data.

• This Agreement may be accepted electronically and forms part of the agreement for use of the Application.

• Changes to this Agreement resulting from legal requirements or changes of sub-processors will be communicated in accordance with the Terms and the principles of Article 28 GDPR.

Appendix A – Minimum technical and organisational measures

• HTTPS/TLS encryption in transit

• user and session authentication

• role-based access control (e.g. owner, employee, shared workstation, technical administrator)

• logical separation of individual salons’ data and authorisation of backend operations

• minimisation of publicly exposed keys/secrets; use on the client side only of keys intended for publication

• local encryption of remembered credentials using Web Crypto/AES-GCM where the remember-me function is active and technically supported

• PWA and Service Worker update mechanisms

• restriction and reasonable logging of administrative access

• data backups/exports and recovery procedures appropriate to available functions and providers

• vulnerability, update and incident management

• procedure for deleting data after termination of the agreement

Appendix B – Main sub-processors (as at the document date)

EntityRoleLocation / notesContractual basis
Supabase, Inc.backend, database, authentication, APIproject in the Central EU (Frankfurt) region; ancillary processing in accordance with provider documentationSupabase DPA; GDPR-compliant transfer mechanisms
Netlify, Inc.hosting/front-end/CDN and handling requests to the Applicationpossible processing of technical data and transfers outside the EEA in accordance with the provider’s DPANetlify DPA; GDPR-compliant transfer mechanisms
Payment providerpayments/subscriptionsnot implemented as at the document version date; the provider will be identified before online payments are launchedprovider DPA/terms after implementation
Plus Five Five, Inc. (Resend)transactional messages / e-mail notifications / supportcustomer data stored in the United States; the e-mail sending region does not change the data-storage locationResend DPA; Standard Contractual Clauses (SCCs) and EU-US Data Privacy Framework where applicable
Service provider: H&S Agnieszka Adamska, ul. Bażantów 24/9, 40-668 Katowice, Poland, Tax ID (NIP) 2220930216 • kontakt@salonivo.pl