Data Processing Agreement
How this agreement is concluded. You enter into it by accepting the Terms when you create your account — it is an integral part of them and needs no separate signature. If your organisation needs a signed copy (for example for its own contract register), email hej@flaminjoe.studio and we will send the same text as a PDF for electronic signature.
1. Parties and roles
- Controller — you, the Zapyo user acting in the course of your business or profession. You decide which data about your clients you store and why.
- Processor — Flamin Joe Studio Dominika Kasprzyk, Polish tax ID (NIP) 5792303226, contact hej@flaminjoe.studio (the “Provider”), operating the Zapyo application.
- This agreement covers only Customer Data: personal data you enter into the service. Your own data (account email, billing data) is processed by us as a controller — see the Privacy Notice.
2. Subject matter, duration, nature and purpose
- Subject matter: storing, displaying, searching, organising, editing and deleting data on your instructions given through the application interface; making backups; sending reminders you set yourself.
- Purpose: providing the service — running your client base, quotes and schedule. We do not process Customer Data for any purpose of our own, do not analyse or profile it, and do not disclose it to anyone other than the sub-processors in section 6.
- Duration: for as long as you hold an account, plus the deletion period in section 8.
- Nature: automated processing in an IT system; the Provider does not look into the content of your data unless you request technical help that requires it or the law requires it.
3. Types of data and categories of data subjects
- Types of data: identification and contact data (name, company name, phone, email, address), the content of quotes, notes, cases and appointments, values of custom fields you define, and data uploaded when importing from files or other systems.
- Data subjects: your clients and prospective clients, and contact persons at those clients.
- The service is not intended for special categories of data (GDPR Art. 9, e.g. health data) or criminal-conviction data. Do not enter them into Zapyo.
4. Provider’s obligations as processor
In line with GDPR Art. 28(3), the Provider:
- processes Customer Data only on your documented instructions — the Terms, this agreement and the actions you take in the app (adding, editing, importing, deleting data, setting a reminder) count as instructions; if we believe an instruction infringes the law, we will tell you;
- ensures that persons with access to the data are bound by confidentiality — only the Provider has access to the production environment, on a need-to-know basis;
- applies the security measures in section 5 (Art. 32);
- engages sub-processors only under section 6;
- assists you with data-subject requests (access, rectification, erasure, portability): basic actions you can do yourself in the app; where that is not possible, we carry them out at your request by email within 7 days;
- assists you with your obligations under Arts. 32–36, in particular by notifying breaches under section 7;
- deletes data at the end of the service under section 8;
- makes available the information needed to demonstrate compliance and allows audits under section 9.
5. Technical and organisational measures
- Database hosted in the European Union: Supabase, Frankfurt region (AWS eu-central-1); storage encryption on the hosting provider’s side.
- Encrypted connections (TLS) and application security headers (including CSP, HSTS).
- Row Level Security in the database: every query is filtered by the identity of the signed-in user, including in read-only mode after the trial.
- Authentication via Supabase Auth: passwords stored only as cryptographic hashes; alternatively Google sign-in (OAuth) or a one-time email code.
- Push-notification content encrypted between the app and your browser; the push vendor cannot read it.
- Automatic database backups, overwritten on a rolling cycle of up to 30 days.
- Automated secret scanning of the code repository; access keys rotated after any incident.
6. Sub-processors
By accepting the Terms you give general authorisation (Art. 28(2)) for the following sub-processors:
| Entity | Purpose | Data location |
|---|---|---|
| Supabase, Inc. | database, authentication, sending sign-in emails | EU — AWS Frankfurt (eu-central-1) |
| Vercel, Inc. | hosting the application code; handles connections, so it sees technical request data (IP address, headers). Your database content is not stored at Vercel | USA; transfer under the EU–US Data Privacy Framework / standard contractual clauses |
| Browser push vendors (Apple, Google, Mozilla) | delivering notifications; content encrypted, the vendor sees only a device identifier | depends on the browser; content unreadable to the vendor |
Stripe Payments Europe, Ltd. (Ireland) processes payments for the service and receives only your data as a Zapyo customer — it has no access to Customer Data. Google (Google sign-in) acts as an independent controller of sign-in data, not as a sub-processor.
- We will inform you of any intended addition or replacement of a sub-processor by email or in the app at least 14 days in advance.
- You may object by email within that period. If we cannot offer a solution, you may stop using the service and delete your account before the change takes effect — at no extra cost, with a refund for the unused period.
- Each sub-processor is bound by a data-processing agreement imposing data-protection obligations at least equivalent to this one; we remain liable for sub-processors as for ourselves.
7. Personal-data breaches
- We will notify you by email of any breach affecting Customer Data without undue delay and no later than 72 hours after becoming aware of it, so that you can assess your duty to notify the supervisory authority (Art. 33) and data subjects (Art. 34).
- The notification includes, as far as information is available: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken and proposed, and contact details. We supplement the information as it becomes available.
8. End of processing: export and deletion
- Before deleting your account you may export your data: in the app where an export function is available, and otherwise on request by email — we prepare a full export within 14 days in a commonly used format (CSV or JSON).
- On your request to delete the account we delete it together with all Customer Data within 14 days at the latest. Backups containing that data are overwritten automatically within up to 30 days; until then they are used for nothing but disaster recovery.
- After the trial ends without choosing a plan, your data stays available in read-only mode so that you can export and delete it. We do not delete it without your request unless we notify you by email at least 30 days in advance.
- We keep no copies of Customer Data after deletion, except where the law requires it.
9. Information and audits
- On request we provide documents demonstrating compliance: this agreement, a description of the measures in section 5, the current sub-processor list, and confirmation that data-processing agreements are in place with them.
- If documents are not sufficient, you may carry out a remote audit once every 12 months (a call and a review of configuration to the extent it concerns your data) — with 14 days’ notice, on working days, keeping other users’ data and the Provider’s trade secrets confidential. Each party bears its own costs.
- We will tell you if, in our view, your instruction or audit request infringes the GDPR or other law.
10. Liability
- Each party is liable for damage caused by processing under GDPR Art. 82. The Provider is liable where it has not complied with obligations specifically directed to processors or has acted contrary to your lawful instructions.
- You are responsible for the lawfulness of the data you enter, in particular for the legal basis of processing and for data imported from other systems having been collected there lawfully. The Provider does not verify the lawfulness of an uploaded database. Indemnity rules are set out in section 4 of the Terms.
11. Final provisions
- This agreement applies for as long as you hold an account and ends when the data is deleted under section 8. We amend it in the manner provided for the Terms (section 8 of the Terms); amendments unfavourable to the Controller do not apply retroactively.
- Matters not covered here are governed by the Terms and the GDPR. Polish law applies.
- If any provision proves invalid, the others remain in force and the GDPR provision closest to its purpose applies in its place.