DEVFORCES DATA PROCESSING AGREEMENT TEMPLATE ============================================== This Data Processing Agreement ("DPA") is entered into between: Controller: [CLIENT NAME], with its principal place of business at [ADDRESS] Processor: DevForces Sp. z o.o. (or applicable DevForces entity), with its principal place of business at ul. Zjednoczenia 8, 65-120 Zielona Góra, Poland. This DPA supplements and forms part of the Master Services Agreement or Statement of Work between the parties (the "Agreement") and reflects the parties' agreement with respect to the processing of personal data under Regulation (EU) 2016/679 ("GDPR"). 1. DEFINITIONS 1.1 "Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Supervisory Authority" and related terms have the meanings given in the GDPR. 1.2 "Services" means the software engineering, consulting, integration and related services described in the Agreement. 2. ROLE OF THE PARTIES 2.1 The Client acts as Controller and DevForces acts as Processor for any Personal Data processed in the course of the Services. 2.2 DevForces shall process Personal Data only on documented instructions from the Client, including for the purposes of providing the Services, ensuring the security of the Services, and complying with applicable law. 3. PURPOSE AND SCOPE OF PROCESSING 3.1 Purpose: provision of the Services and related support. 3.2 Categories of Data Subjects: employees, contractors, end users, and other individuals whose Personal Data is provided by or on behalf of the Client for the purposes of the Services. 3.3 Categories of Personal Data: contact details, account identifiers, system usage data, and any other Personal Data supplied by the Client. 4. DATA LOCATION AND TRANSFERS 4.1 DevForces shall process and store Personal Data within the European Economic Area (EEA) unless otherwise agreed in writing. 4.2 No transfer to a third country shall occur without the Client's prior written consent and, where required, the implementation of appropriate safeguards (e.g., EU Commission standard contractual clauses). 5. SUB-PROCESSORS 5.1 DevForces may engage sub-processors to assist in providing the Services, provided they are bound by data protection obligations no less protective than those in this DPA. 5.2 A current list of sub-processors is available on request. 6. SECURITY MEASURES 6.1 DevForces shall implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing, accidental loss, destruction, damage, theft, alteration, or disclosure. 6.2 Measures include role-based access control, encryption in transit and at rest where appropriate, audit logging, and regular security reviews. 7. CONFIDENTIALITY AND PERSONNEL 7.1 DevForces shall ensure that personnel authorised to process Personal Data are bound by confidentiality obligations. 7.2 Each engineer engaged on the Client's account is bound by individual confidentiality obligations referenced in their employment contract. 8. DATA SUBJECT RIGHTS AND COOPERATION 8.1 DevForces shall promptly notify the Client of any request received from a Data Subject or Supervisory Authority relating to the Client's Personal Data. 8.2 DevForces shall cooperate with the Client in responding to such requests and in conducting data protection impact assessments where required. 9. PERSONAL DATA BREACHES 9.1 DevForces shall notify the Client without undue delay and in any case within 48 hours of becoming aware of any Personal Data Breach. 9.2 Notification shall include the nature of the breach, categories and approximate number of affected Data Subjects and records, likely consequences, and measures taken or proposed. 10. AUDITS AND RECORDS 10.1 DevForces shall maintain records of Processing activities and make them available to the Client on reasonable request. 10.2 The Client may audit DevForces' compliance with this DPA annually or in connection with a regulatory requirement, subject to reasonable notice and confidentiality protections. 11. RETURN AND DELETION OF DATA 11.1 On termination or expiry of the Agreement, DevForces shall, at the Client's choice, return or delete all Personal Data and existing copies, except where retention is required by applicable law. 12. LIMITATIONS AND LIABILITY 12.1 DevForces' liability for breaches of this DPA shall be subject to the limitation of liability provisions of the Agreement. 12.2 Nothing in this DPA limits the rights of Data Subjects under applicable data protection law. 13. TERM AND TERMINATION 13.1 This DPA enters into force on the date of the Agreement and continues for the duration of the Services. 14. GOVERNING LAW 14.1 This DPA shall be governed by the laws of Poland, without prejudice to the mandatory application of the GDPR. IN WITNESS WHEREOF, the parties have executed this DPA as of the date of the Agreement. _________________________ _________________________ [CLIENT NAME] DevForces Sp. z o.o. Contact for data protection: security@devforces.io This template is provided for discussion and review. Final terms must be agreed in writing and signed by both parties before they take effect.