DPA · wersja 2026-09-25 · translation
Personal Data Processing Agreement
Version 2026-09-25 · Convenience translation · Permanent address of this version:
https://opsway.com/legal/dpa/2026-09-25/en
This is a convenience translation. The Polish text governs. The authoritative text of this version is the Polish text published at
https://opsway.com/legal/dpa/2026-09-25. In the event of any discrepancy between this translation and the Polish text, the Polish text prevails (§ 12(3)).Polish statutory citations are given in their Polish form — k.c. is the Polish Civil Code (Kodeks cywilny) — with a short gloss on first use. RODO is the Polish name for the GDPR and is rendered here as GDPR.
This Personal Data Processing Agreement (the "DPA") governs the processing of personal data by Digital Delivery Center Spółka z ograniczoną odpowiedzialnością, with its registered office in Wrocław, ul. Kawalerzystów 17/12, 53-004 Wrocław, KRS 0000964819, NIP 8992922295, REGON 521700010, trading as OpsWay ("OpsWay"), on behalf of a client (the "Client").
The DPA forms an integral part of the Agreement concluded by signature of an Order Form incorporating the OpsWay General Terms of Service ("OWŚU") and takes precedence over the OWŚU in matters of personal data protection. The terms "personal data", "controller", "processor", "processing" and "personal data breach" have the meanings given to them in Regulation (EU) 2016/679 (the "GDPR").
"Services" means the services provided by OpsWay under an Order Form incorporating the OWŚU, in all Service Types A to E set out in § 4 of the OWŚU — including implementation, modification, build, consulting, configuration, training and support work.
§ 1. Roles
-
In respect of the Services OpsWay acts as processor and the Client as controller.
-
In respect of OpsWay's own data — business contact details of the persons designated by the Client, documentation of the conclusion and performance of the Agreement, the ticket record and billing documentation — OpsWay acts as a separate controller, and this DPA does not apply to it.
-
This DPA covers all work involving the processing of personal data on the Client's behalf within the Services.
-
Condition of processing. In accordance with § 15(3) of the OWŚU, conclusion of the DPA is a condition of OpsWay commencing the processing of personal data in the Client's production environment, and not a promise given for the future.
§ 2. Subject matter, duration, nature and purpose
-
Subject matter: the processing necessary to provide the Services.
-
Duration: for the term of the Parties' relationship, extended by the retention periods set out in § 8.
-
Nature: storage, access, organisation, adaptation, copying, transmission, erasure and other operations necessary to provide the Services, including transfer to the subprocessors identified on the Subprocessor List.
-
Purpose: provision of the Services on the Client's documented instructions. The OWŚU, the Order Form, reports, instructions and arrangements made by e-mail constitute the Client's documented instructions within the meaning of art. 28(3)(a) GDPR.
§ 3. Categories of data subjects and personal data
-
Data subjects: the Client's employees and associates, persons representing the Client's counterparties and suppliers, the Client's customers, and other natural persons whose data is present in the Client's environment.
-
Categories of personal data: identification data (name, e-mail address), business contact details, commercial transaction data, Odoo account data, and any other personal data present in the Client's environment.
-
Special category data. The data referred to in art. 9 GDPR, and payment card data, are not the subject of processing, unless the Parties expressly agree otherwise in writing and implement agreed additional safeguards. The Client shall not transfer such data to the Services.
§ 4. OpsWay's obligations
OpsWay undertakes to:
a) process personal data only on the Client's documented instructions, including as regards transfers to third countries, unless required to do so by Union or Member State law — in which case OpsWay informs the Client before processing, unless the law prohibits this; b) ensure that persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality; c) implement the technical and organisational measures set out in § 6 (art. 32 GDPR); d) comply with the conditions for engaging subprocessors set out in § 5; e) assist the Client — insofar as possible and at the Client's cost — in fulfilling its obligation to respond to data subject requests (Chapter III GDPR); f) assist the Client in fulfilling its obligations under arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to OpsWay; g) report a personal data breach to the Client without undue delay and no later than 72 hours after becoming aware of it, together with the information available to OpsWay at that time, supplementing it progressively; h) delete or return personal data after the provision of the Services ends, in accordance with § 8; i) make available to the Client the information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, by the Client or an auditor mandated by it, subject to reasonable notice, confidentiality and allocation of costs; j) inform the Client promptly if, in OpsWay's opinion, an instruction given infringes the GDPR or other data protection law.
A report by OpsWay does not release the Client from its own obligations under arts. 33 and 34 GDPR. OpsWay does not notify the supervisory authority or data subjects on the Client's behalf — that is the controller's obligation.
§ 5. Subprocessors
-
General authorisation. The Client grants OpsWay general authorisation to engage the subprocessors listed on the Subprocessor List in the version pinned by the Order Form, published at
https://opsway.com/legal/subprocessors/. -
The list is exhaustive. The Subprocessor List constitutes an exhaustive enumeration of subprocessors: a supplier not listed on it is not engaged.
-
Equivalent obligations. OpsWay imposes on every subprocessor the same data protection obligations as arise under this DPA (art. 28(4) GDPR) and remains fully liable to the Client for the performance of those obligations by the subprocessor.
-
Notice and objection — direct subprocessor. OpsWay notifies the Client of any intention to add or replace a direct subprocessor with at least thirty (30) days' prior notice, identifying the version of the new Subprocessor List and its permanent URL. Within that period the Client may object on reasonable data protection grounds, giving reasons. The Parties shall attempt to resolve the objection. Where an objection is raised that cannot reasonably be resolved, the Client may terminate the affected Order Form with effect as at the date the change takes effect; OpsWay is entitled to remuneration for services performed up to that date.
-
Notice — onward subprocessor. OpsWay passes on to the Client notice of a change of subprocessor made by a subprocessor without undue delay after receiving it; the objection period is set by the originating notice.
-
AI suppliers. The AI Systems used in providing the Services operate on OpsWay's account with the supplier (§ 13(3) of the OWŚU), and accordingly their suppliers are OpsWay's subprocessors and appear on the Subprocessor List.
-
No training. OpsWay does not train or fine-tune models on Client data and uses only those endpoints of AI suppliers whose terms exclude the use of data transferred for training the supplier's models or those of third parties. OpsWay minimises the personal data transmitted to AI endpoints to what is necessary for the task.
§ 6. Technical and organisational measures (art. 32 GDPR)
-
Principal place of processing. The principal place of processing is the Client's environment, which remains under the Client's exclusive control. OpsWay's systems hold derived copies and project artefacts as referred to in paragraph 2.
-
Basic measures: a) access to the Client's environments only from named accounts, with permissions limited to the scope of the task; permissions withdrawn on completion of the work or on a change of personnel; b) activities performed from named accounts, enabling the Client to attribute an action to a person in the logs of its own environment; c) encryption of personal data in transit (TLS 1.2 or higher); d) the Client's credentials and API keys held in secrets management tooling; they are not held in plain text in code repositories or in correspondence; e) devices of personnel with access to Client data subject to disk encryption; f) an incident response and breach notification procedure, in accordance with § 4(g); g) review of a subprocessor's level of data protection on every change to the Subprocessor List; h) confidentiality undertakings covering all personnel with access to Client data.
-
Copies of the Client's environments. OpsWay states expressly that, in providing the Services, it: a) makes and processes copies of the Client's databases and environments, including copies containing production and non-anonymised data — in particular neutralised copies, in which outbound mail, payments, scheduled jobs and integrations are disabled but personal data is not removed — for the purposes of diagnostics, testing and development work, including outside the Client's infrastructure; b) takes such copies only through authorised personnel, only for the purposes of a specific task, and stores them on devices subject to disk encryption; c) holds the Client's project code and configuration in private OpsWay repositories identified on the Subprocessor List, with branch protection and mandatory review of changes; d) deletes the copies referred to in (a) once the purpose has ceased, subject to § 8(3).
The Client acknowledges this. Provisions of any other document suggesting that OpsWay works exclusively on anonymised data or exclusively within the Client's infrastructure relate to the period before conclusion of the DPA (§ 15(3) of the OWŚU) and do not describe how OpsWay works after it has been concluded.
- What OpsWay does not state. OpsWay does not hold ISO 27001, SOC 2 or PCI DSS certification, does not operate 24/7 monitoring or periodic penetration testing, and gives no assurance in that respect. The measures described in this paragraph constitute the full extent of OpsWay's obligations under art. 32 GDPR.
§ 7. Transfers to third countries
-
Transfers of personal data outside the European Economic Area take place using an appropriate mechanism under Chapter V GDPR, including the standard contractual clauses (Commission Implementing Decision (EU) 2021/914) where applicable. The Parties regard those clauses as incorporated to the extent required, with OpsWay as data exporter or importer as the case may be.
-
The Subprocessor List identifies the region of processing for each entry.
§ 8. Retention, return and erasure
-
After the provision of the Services ends OpsWay — at the Client's election, expressed within thirty (30) days of the end — returns or deletes the personal data processed on the Client's behalf. Absent such an election, OpsWay deletes the data after that period expires.
-
Retention periods: a) copies of environments referred to in § 6(3) — deleted once the purpose has ceased, and no later than on completion of the work to which they related; b) project artefacts — code, configuration and documentation — for the term of the relationship and for the period during which they are necessary to discharge Guarantee obligations; c) the service ticket history and documentation of the conclusion and performance of the Agreement — for the term of the relationship and 3 years (art. 17(3)(e) GDPR, in connection with the limitation period under art. 118 k.c. — the general limitation period under the Polish Civil Code), and on an erasure request they are pseudonymised rather than deleted; d) backups of OpsWay's systems and version histories of the tools OpsWay uses — in accordance with the cycles of those tools; subject to paragraph 3.
OpsWay does not maintain backups of the Client's production environment; these are made by the Client or by the hosting provider under the Client's own contract (§ 5(1)(a) of the OWŚU).
-
Retention exception. The obligation to delete does not cover: a) copies necessary for audit, tax and the establishment or defence of legal claims; b) data fixed in automated backups, in the service ticket history, in the version history of code repositories and in the version history of OpsWay's tools, the selective deletion of which is not technically feasible. Such data remains subject to the confidentiality obligation and to the measures in § 6, is not processed for any other purpose, and is deleted upon expiry of the applicable retention period.
-
Honesty as to the extent of erasure. In responding to an erasure request OpsWay states the actual extent of the erasure performed, including the categories of data covered by paragraph 3; OpsWay does not confirm complete erasure where complete erasure is not feasible.
§ 9. Data subject requests
-
Where a data subject request is addressed directly to OpsWay, OpsWay notifies the Client without undue delay and does not respond to it itself, unless the Client instructs otherwise.
-
OpsWay assists the Client in handling the request in respect of data processed on the Client's behalf, on the terms of § 4(e).
§ 10. Controller's responsibilities
The Client is responsible for:
a) establishing and documenting the legal basis for processing all personal data processed through the Services, including data transferred to AI suppliers; b) providing the required information to data subjects; c) obtaining the required consents; d) the permissibility of transferring personal data to the Services and onward to the subprocessors identified on the Subprocessor List, in the light of the Client's own data protection arrangements; e) not introducing into the Services the data referred to in § 3(3); f) the lawfulness of the instructions given to OpsWay.
§ 11. Liability
-
Liability under this DPA is subject to the limitations set out in § 16 of the OWŚU, unless applicable data protection law provides otherwise.
-
Those limitations govern settlements between the Parties and do not affect the liability of either Party towards data subjects or towards the supervisory authority (art. 82 GDPR).
§ 12. Final provisions
-
Changes. A new version of the DPA is published at its own permanent URL. The version pinned by the Order Form applies in accordance with the amendment regime in § 18 of the OWŚU.
-
Superseded versions. Every published version remains available at its permanent URL after being superseded by a later version.
-
Governing law. Polish law. The authoritative text is the Polish text; versions in other languages are published solely for the convenience of the Parties, and in the event of any discrepancy the Polish text prevails.
Version 2026-09-25 · Digital Delivery Center sp. z o.o. · KRS 0000964819 ·
Convenience translation — the Polish text at https://opsway.com/legal/dpa/2026-09-25 governs