Data Processing Agreement
Version: DPA-2026-09-12
Effective date: September 12, 2026
This Data Processing Agreement (“DPA”) forms an integral part of the Ofinly Terms of Service between a Business User using Ofinly for salon or team management (“Controller”) and Damian Masior, ul. Oswiecimska 51, Gorzow, Poland, NIP 5492377002 (“Processor” or “Ofinly”). Where an account is used for an entity, that entity is the Controller and the person accepting this DPA confirms that they are authorized to act for it. This DPA applies where Ofinly processes personal data on the Controller's behalf.
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in Regulation (EU) 2016/679 (“GDPR”).
1. Roles and scope
The Controller determines the purposes and essential means of processing personal data concerning its clients, prospective clients, staff and other persons whose data it enters into or manages through Ofinly. Ofinly processes that data on the Controller's documented instructions to provide the Service.
This DPA does not apply to processing for which Ofinly determines its own purposes and means, including account administration, authentication, subscription administration, platform security, fraud prevention, legal compliance and management of Ofinly's own support relationship. Ofinly acts as a controller for that processing as described in the Privacy Policy. A service provider acting as an independent controller, including a payment provider acting in that capacity, is not a sub-processor under this DPA.
2. Details of processing
- Subject matter: processing personal data entered, generated or managed by the Controller through the salon management, client relationship, team, appointment and communication features of Ofinly.
- Duration: from the first processing on the Controller's behalf until deletion or return in accordance with Section 11, including any trial, paid service, restricted-access period, deletion grace period and agreed retention period.
- Nature: collection, recording, organization, storage, retrieval, consultation, display, updating, matching, transmission to authorized recipients, notification delivery, restriction, anonymization and deletion.
- Purpose: providing and securing the features selected and configured by the Controller, including salon and team management, client records, appointments, service delivery, reminders, support and reporting available within the Service.
3. Data subjects and personal data
Data subjects may include the Controller's clients and prospective clients, salon owners, managers, workers, invited staff, contractors and persons identified in appointment, support or communication records.
Personal data may include names, contact details, identifiers, salon or team role, worker profile and schedule information, appointment history and status, service and price information, client addresses for mobile services, notes, tags, preferences, ratings and reviews, communications, notification delivery data, and technical records necessary to provide or secure the Service.
The Service is not intended for the Controller to enter special categories of personal data under Article 9 GDPR or criminal conviction data under Article 10 GDPR. The Controller must not enter such data unless it has first established a lawful basis, satisfied applicable requirements and obtained Ofinly's written agreement where additional safeguards are necessary.
4. Controller instructions and responsibilities
The Terms, this DPA, the Controller's documented use and configuration of the Service, and additional written instructions accepted by Ofinly constitute documented instructions. Ofinly will process personal data only on those instructions, including for transfers outside the European Economic Area (“EEA”), unless Union or Member State law requires otherwise. Where legally permitted, Ofinly will inform the Controller before processing required by law.
The Controller is responsible for the lawfulness, fairness and transparency of its processing, the accuracy of its instructions, required notices and lawful bases, and ensuring that its use of the Service complies with applicable law. The Controller must not instruct Ofinly to process data in a manner that violates applicable data protection law.
Controller Representations and Warranties: The Controller represents, warrants, and covenants that:
- it maintains a valid, effective, demonstrable, and lawful legal basis under Article 6 GDPR (and Article 9 GDPR for any special category data) for all client, prospective client, and staff personal data entered into, imported to, or managed within the CRM database through the Service;
- it has fully complied with all transparency and information obligations owed to data subjects under Articles 13 and 14 GDPR, including informing individuals of the engagement of salon management service providers;
- it has obtained and maintains all legally required, prior, verifiable consents for sending electronic commercial communications (under Article 10 of the Polish Act on Providing Services by Electronic Means – UŚUDE) and for using telecommunications terminal equipment and automated calling systems for direct marketing purposes (under the Polish Electronic Communications Act – Prawo komunikacji elektronicznej / PKE) with respect to all marketing, promotional, SMS, or email communications initiated by the Controller via the Service;
- it will promptly record withdrawals of consent and objections from clients and immediately cease sending marketing communications to those individuals via the Service.
If Ofinly considers that an instruction infringes the GDPR or other applicable Union or Member State data protection law, it will inform the Controller without undue delay and may suspend the affected processing until the instruction is clarified or changed.
5. Confidentiality
Ofinly will ensure that persons authorized to process personal data are subject to an appropriate statutory or contractual duty of confidentiality and receive access only where necessary for their duties.
6. Security and technical and organizational measures
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals, Ofinly will implement and maintain measures appropriate to the risk under Article 32 GDPR. Measures applicable to the Service include, as appropriate:
- encrypted transport using HTTPS/TLS;
- authentication, session controls and role-based authorization;
- restricted administrative and production access based on operational need;
- separation and controlled handling of application secrets and credentials;
- logging, monitoring and redaction controls designed to reduce exposure of credentials and selected personal data;
- data deletion, anonymization and session revocation procedures;
- availability, recovery and incident-response procedures proportionate to the Service;
- periodic review and adjustment of measures where warranted by risk or material system changes.
These measures describe controls, not a guarantee that every security incident can be prevented.
7. Assistance with data subject rights
Taking into account the nature of processing, Ofinly will assist the Controller through available product functions and reasonable additional measures to respond to requests under Articles 12–23 GDPR. If Ofinly receives a request concerning data processed solely on the Controller's behalf, it will direct the person to the Controller where reasonably identifiable and will not respond on the Controller's behalf unless instructed or legally required.
8. Assistance under Articles 32–36 GDPR
Taking into account the nature of processing and information available to it, Ofinly will reasonably assist the Controller with security obligations, personal data breach assessments and notifications, data protection impact assessments, and prior consultation with a supervisory authority. Additional work outside standard Service functions may be subject to reasonable agreed charges unless required because Ofinly breached this DPA.
9. Personal data breaches
Ofinly will notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed on the Controller's behalf. Where available, the notice will describe the nature of the breach, affected data and persons, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases where it is not available at the same time.
Notification does not constitute an admission of fault or liability. The Controller remains responsible for determining whether notification to a supervisory authority or affected individuals is required.
10. Sub-processors
The Controller grants Ofinly general written authorization to engage sub-processors necessary to provide and secure the Service. Depending on enabled features and the data concerned, current providers or provider groups used in processing may include:
| Provider or service | Processing function |
|---|---|
| Amazon Web Services (AWS) | Email delivery through SES and object storage through S3. |
| Google Firebase | Push notification delivery and mobile crash diagnostics. |
| Cloudflare | Website delivery, network security, CDN and request proxying. |
| SMSAPI | SMS verification and service-related SMS delivery. |
| Slack | Support requests, operational communications and salon-related event handling. |
| Hetzner Cloud | Production and geocoding infrastructure hosting. |
A provider is a sub-processor only to the extent it processes personal data on Ofinly's behalf for the Controller. Ofinly will maintain information about applicable sub-processors and make current identifying and location details available to the Controller on request.
Ofinly will impose data protection obligations on each sub-processor that provide substantially the same protection required by this DPA for the processing entrusted to it. Ofinly remains responsible to the Controller for the sub-processor's performance of those obligations as required by Article 28(4) GDPR.
Ofinly will provide reasonable advance notice of an intended addition or replacement that materially affects processing, normally at least 14 days before the change takes effect unless an urgent security, availability or legal need requires a shorter period. The Controller may object during the notice period on reasonable data protection grounds. The parties will seek a practical resolution. If no reasonable resolution is available, the Controller may stop using the affected feature or terminate the affected Service in accordance with the Terms.
11. Return and deletion
On termination of processing, Ofinly will, at the Controller's choice communicated before deletion becomes final, delete or return personal data processed on its behalf and delete remaining copies, unless applicable law requires retention. Return is limited to export formats reasonably supported by the Service or otherwise agreed by the parties. The Controller is responsible for requesting and retrieving an available export before the applicable deletion deadline.
Data may remain in protected backups until overwritten or deleted under the applicable backup cycle and will not be restored for ordinary use. If law requires retention, Ofinly will isolate the retained data from further processing except for that legal purpose.
12. Information and audits
Ofinly will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. The Controller may conduct an audit itself or through an independent auditor bound by confidentiality, no more than once per year unless a breach, supervisory authority request or credible evidence of material non-compliance justifies an additional audit.
Audits must use reasonable advance notice, avoid unnecessary access to other customers' data, protect security and confidentiality, and minimize disruption. The parties will first use available documentation and remote review where sufficient. The Controller bears its audit costs unless the audit identifies a material breach by Ofinly.
13. International transfers
Ofinly will not transfer personal data processed under this DPA outside the EEA unless the transfer complies with Chapter V GDPR. Depending on the recipient and circumstances, the transfer mechanism may include an adequacy decision, the EU–US Data Privacy Framework where valid and applicable, the European Commission's Standard Contractual Clauses, or another lawful safeguard.
Where Standard Contractual Clauses are required, Ofinly will implement the applicable module and reasonable supplementary measures identified by the transfer assessment. Ofinly will provide information reasonably required for the Controller to assess the transfer. Provider infrastructure may involve remote support or resilient processing from more than one country; the applicable contractual terms and current processing configuration determine the transfer mechanism.
14. Liability, recourse, precedence and changes
Liability under this DPA is subject to the Terms to the extent permitted by applicable law. If this DPA conflicts with the Terms on processing personal data on the Controller's behalf, this DPA prevails. Mandatory provisions of applicable data protection law prevail over both.
Provider's Right of Recourse: In the event that an administrative fine is imposed on Ofinly (the Processor) by the President of the Personal Data Protection Office (Prezes UODO) or any other competent supervisory authority, or if Ofinly is held liable to pay compensation or damages to data subjects (including under Article 82 GDPR) or third parties, and such fine, liability, or damage arises directly or indirectly from the Controller's fault, unlawful acts, lack of a valid legal basis under Article 6 GDPR for data held in the CRM database, absence of required marketing consents under the Polish Electronic Communications Act (PKE) or Act on Providing Services by Electronic Means (UŚUDE), or breach by the Controller of its representations and warranties in this DPA or the Terms, the Controller agrees to indemnify and hold Ofinly harmless and reimburse Ofinly in full for all losses incurred (claim for recourse). This includes the obligation to promptly reimburse the full amount of any paid administrative fine, any awarded or settled damages or compensation, and all reasonable legal defense costs, attorney fees, and litigation expenses incurred by Ofinly. The Controller's recourse liability under this provision is not subject to the limitation of liability caps or damage exclusions set out in the Terms or this DPA, to the fullest extent permitted by mandatory applicable law.
Ofinly may update this DPA where necessary to reflect legal requirements, security measures, or Service changes. Material changes will be notified in accordance with the Terms. A change will not materially reduce the protection of personal data without a lawful basis and appropriate notice.
15. Contact and governing law
Questions, instructions and audit requests under this DPA may be sent to [email protected]. The governing law and dispute provisions in the Terms apply, without limiting rights or powers granted to data subjects and supervisory authorities by the GDPR.