DATA PROCESSING AGREEMENT (DPA)

This Data Processing Agreement ("DPA") forms an integral part of the Terms and Conditions governing access to and use of the TRAVERF platform available through https://traverf.com and applies where the Provider processes Personal Data on behalf of the Client.

By accepting this DPA during first login, the Client agrees to its terms.

  1. PARTIES

    1. Controller / Client: the legal entity or business user using Traverf.

    2. Processor / Provider: Eryk Bębynek address: Augustyna Szamarzewskiego 21 lok. 2 60-514 Poznań, Poland email: eryk.bebynek@traverf.com

    3. The parties acknowledge that, depending on the nature of the data uploaded by the Client, the Client acts as the data controller (or processor acting on behalf of another controller), and the Provider acts as processor.


  1. PURPOSE AND SCOPE OF PROCESSING

    1. Provider shall process Personal Data solely for the purpose of performing the Agreement and providing the Services.

    2. Processing activities may include: hosting, storage, organization, structuring, retrieval, transmission, synchronization, deletion, technical support, troubleshooting, fraud prevention, abuse monitoring, infrastructure maintenance, security monitoring, backup creation, restoration activities, API processing, AI feature enablement, customer support activities.

    3. Provider shall not process Personal Data for purposes materially inconsistent with this DPA unless required by law.

    4. Client acknowledges that certain functionalities may involve automated processing, AI-assisted processing or third-party infrastructure processing.

  2. CATEGORIES OF DATA

    1. Depending on Client usage, Personal Data may include: names, surnames, email addresses, phone numbers, job titles, business contact details, uploaded documents, communications, platform-generated outputs, metadata, usage logs.

    2. The Client remains solely responsible for determining what data is uploaded.

  3. SPECIAL CATEGORY DATA

    1. The Client shall not upload special category data under Article 9 GDPR unless explicitly authorized in writing by Provider. This includes: health data, biometric data, political opinions, religious beliefs, sexual orientation data, criminal data.

    2. If uploaded without authorization, Client assumes full responsibility.

  4. CLIENT INSTRUCTIONS

    1. Provider shall process Personal Data only based on: this DPA, the Terms, Client instructions provided through normal use of the platform.

    2. Provider may refuse unlawful instructions.

  5. CONFIDENTIALITY

Provider shall ensure that personnel with access to Personal Data are subject to confidentiality obligations.

  1. SECURITY MEASURES

    1. Provider shall implement commercially reasonable technical and organizational measures appropriate to the nature of the Services.

    2. Such measures may include: encryption in transit where appropriate, access restrictions, authentication mechanisms, role-based permissions, infrastructure monitoring, logging systems, incident management procedures, backup procedures, vulnerability monitoring, employee access restrictions.

    3. Provider may update security measures from time to time based on technological developments.

    4. Client acknowledges that no system can guarantee absolute security.

    5. Client remains responsible for: proper user permission settings, secure credential management, lawful uploads, endpoint security, internal organizational controls.

  2. SUBPROCESSORS

    1. Client authorizes Provider to use subprocessors including: cloud providers, hosting providers, analytics providers, infrastructure providers, customer support tools, payment providers, AI providers.

    2. Provider may update subprocessors from time to time.

    3. Google LLC and its affiliates providing Google Gemini API and related artificial intelligence processing services.

    4. The Client acknowledges that prompts, uploaded content and generated outputs may be processed through Google Gemini API services in order to provide AI-powered functionalities.

  3. INTERNATIONAL TRANSFERS

Where Personal Data is transferred outside the EEA/UK, Provider shall use legally valid transfer mechanisms where required.

  1. DATA SUBJECT REQUESTS

Provider shall reasonably assist Client where feasible. Client remains primarily responsible for responding to data subject requests.

  1. SECURITY INCIDENTS

Provider shall notify Client without undue delay after becoming aware of a Personal Data breach where legally required.

  1. DATA RETENTION, RETURN AND DELETION

    1. During the term of the Agreement, Client may access Personal Data through platform functionality where available.

    2. Upon termination of the Services: Client may export data where functionality allows, Provider may delete Personal Data, backup retention periods may temporarily apply, certain technical logs may remain temporarily stored.

    3. Provider may retain Personal Data where required by: legal obligations, regulatory obligations, tax requirements, dispute resolution requirements, fraud prevention needs.

    4. Following applicable retention periods, Provider may permanently delete retained data.

    5. Client acknowledges that deleted data may not be recoverable.

  2. AUDITS

    1. Due to multi-tenant SaaS infrastructure, on-site audits are not permitted unless legally required.

    2. Provider may satisfy audit requests through: documentation, questionnaires, certifications, reasonable compliance materials.

  3. LIABILITY

    1. Liability arising under this DPA shall be subject to the liability limitations contained in the Traverf Terms and Conditions.

    2. Provider shall not be liable for unlawful processing instructions provided by Client.

    3. Provider shall not be liable for data uploaded without proper legal basis.

    4. Client remains solely responsible for determining whether use of the Services satisfies its regulatory obligations.

    5. Each party remains responsible for its own violations of applicable data protection law.

  4. ORDER OF PRECEDENCE

In case of conflict between this DPA and the Terms, this DPA governs solely with respect to Personal Data processing.