Към основното съдържание
Contents (12)

Data Processing Addendum (DPA)

Последна актуализация:
Версия: 1.1

Reference template — not an executed contract

This document is a reference template of the Data Processing Addendum. To become binding for your organisation it must be signed by an authorised representative of both parties. Use the button below to request signing.

Request DPA Signing

This addendum is required for organisations using Actio to process personal data of third parties as a data controller under GDPR.

1. Introduction and Definitions

This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", "Data Controller") and Прайс Екс ЕООД, which operates the Actio platform ("Data Processor", "Actio", "we"), regarding the use of the Actio platform services.

1.1 Definitions

  • "Personal Data" — any information relating to an identified or identifiable natural person
  • "Data Controller" — the customer organisation which determines the purposes and means of processing
  • "Data Processor" — Actio, which processes personal data on behalf of the controller
  • "Processing" — any operation performed on personal data, including collection, recording, organisation, storage
  • "GDPR" — General Data Protection Regulation (EU) 2016/679
  • "Data Subject" — the natural person to whom the personal data relates

2. Subject Matter and Scope of Processing

2.1 Subject Matter

Actio processes personal data on behalf of and according to the instructions of the Customer solely for providing the platform services.

2.2 Categories of Personal Data

  • Identification data (name, email, phone)
  • Professional data (position, organisation)
  • Activity participation data
  • Communication data (messages, comments)
  • Technical data (IP address, browser data)
  • Photos and media files

2.3 Categories of Data Subjects

  • Employees and representatives of customer organisations
  • Volunteers and activity participants
  • Service beneficiaries
  • Contacts and partners

2.4 Processing Purposes

  • Organisation and member management
  • Project and activity coordination
  • Communication and messaging
  • Reporting and analytics
  • Technical support and security

3. Processor Obligations (Actio)

3.1 Processing on Instructions

Actio undertakes to process personal data solely:

  • On documented instructions from the data controller
  • Within the scope of services provided through the platform
  • In accordance with applicable law

3.2 Confidentiality

  • Ensures processing confidentiality
  • Guarantees that all authorised persons have committed to confidentiality
  • Implements appropriate technical and organisational measures (GDPR Art. 32)
  • Notifies of security breaches without undue delay (section 10)

3.3 Technical and Organisational Measures

Actio applies the following protective measures. Their exact scope is subject to review as part of the annual compliance documentation (section 8):

  • Encryption in transit: TLS 1.2+ for all traffic; HSTS is enabled.
  • Password hashing: bcrypt with a minimum of 10 rounds.
  • Access control: Multi-factor authentication (2FA / Passkeys), role-based management within organisations, tenant data isolation.
  • Monitoring: Automated error monitoring via Sentry; centralised security logs; CSP violation reporting.
  • Backups: Automated database backups via spatie/laravel-backup, stored in an off-site EU destination; the restore process is periodically tested.
  • Maintenance: Regular dependency updates and static analysis (PHPStan).

Note: Actio does not claim that data at rest is encrypted at the filesystem or database layer by default. If your organisation requires additional measures (e.g. application-level field encryption, specific SCC modules, SOC 2 / ISO 27001 attestation), please state these requirements during the DPA signing request.

4. Sub-processors

4.1 Approved Sub-processors

The Customer gives general authorisation for the use of the following sub-processors. The list mirrors the sub-processor table in the Privacy Policy §6.

Service Provider Jurisdiction Purpose
Hosting EU hosting partner Bulgaria / EU Server infrastructure and storage
Payments Stripe Payments Europe, Ltd. Ireland / EU Payment and subscription processing
Error monitoring Functional Software, Inc. (Sentry) United States (SCCs) Aggregated stack traces and diagnostic metadata
Analytics (if enabled) Plausible Insights OÜ Estonia / EU Anonymous web analytics (cookieless)
Email delivery EU SMTP / email provider EU Transactional emails and notifications

4.2 Flow-down of Obligations

Actio ensures that each sub-processor is bound by a written contract imposing the same data protection obligations as those applicable under GDPR Art. 28(4).

4.3 Changes to Sub-processors

For changes to the list, Actio will notify customers at least 30 days in advance. Customers have the right to object within 14 days.

5. Data Subject Rights

Actio assists the data controller in fulfilling obligations regarding data subject rights (GDPR Art. 28(3)(e)):

  • Right of Access: providing copies of personal data
  • Right of Rectification: correcting inaccurate or incomplete data
  • Right of Erasure: deletion while respecting legal obligations
  • Right of Restriction: temporary restriction of processing
  • Right of Portability: export in a structured, machine-readable format
  • Right to Object: ceasing processing under certain grounds

6. Data Transfer Outside the EU

Main data processing takes place within the European Union. The only sub-processor outside the EU is Sentry (United States) — the transfer is protected by Standard Contractual Clauses (SCCs) of the European Commission (Implementing Decision 2021/914, Module 3) pursuant to GDPR Art. 46. Data shared with Sentry is limited to technical stack traces and diagnostic metadata.

7. Retention Period and Deletion

7.1 Periods

  • Active accounts: while the contract is in force
  • Terminated accounts: fully deleted within 30 days
  • Inactive accounts: anonymised after 365 days
  • Security logs: up to 365 days
  • Legal obligations: according to applicable law

7.2 Deletion Procedures

Upon contract termination, Actio deletes or returns all personal data within 30 days, unless longer retention is required by law. Existing backups rotate and are deleted according to the log retention period.

8. Audits and Cooperation

8.1 Audits

Pursuant to GDPR Art. 28(3)(h), the data controller has the right to:

  • Obtain all information necessary to demonstrate compliance with Art. 28
  • Conduct audits or inspections, in person or through a mandated auditor, upon reasonable written notice (typically 30 days) and during business hours
  • Obtain copies of the applicable technical and organisational documentation
  • Request assistance in preparing a Data Protection Impact Assessment (DPIA) under Art. 35 and prior consultations under Art. 36

8.2 Cooperation with Supervisory Authorities

Actio undertakes to assist the data controller in communication with supervisory authorities (e.g. the Bulgarian CPDP) and to provide information necessary to demonstrate compliance.

9. Liability

9.1 Mutual Liability

Each party bears responsibility for damages caused by GDPR violations within its obligations:

  • Controller: GDPR compliance of instructions
  • Processor: following instructions and maintaining security measures

9.2 Limitation of Liability

Specific financial liability caps, insurance coverage and indemnification clauses are negotiated individually as part of the DPA signing process (section 12). Actio does not maintain an automatically published insurance coverage amount in this reference template.

10. Breach Notifications

10.1 Notification Procedure

Upon identifying a personal data security breach, Actio:

  1. Notifies the controller without undue delay upon becoming aware (GDPR Art. 33(2))
  2. Provides the following information:
    • Nature of the breach
    • Categories and approximate number of affected subjects
    • Likely consequences
    • Measures taken to address the breach
    • Recommendations for the controller
  3. Documents the incident for audit purposes

11. Entry into Force and Amendments

11.1 Entry into Force

This DPA enters into force once countersigned by an authorised representative of both parties, or upon explicit electronic acceptance by the owner of the organisation account within the platform settings. Until signed, this document is a reference template only.

11.2 Amendments

Changes to the DPA require written consent from both parties or, in cases of mandatory legislative changes, with 30 days advance notice.

12. Data Protection Contacts

Actio (Data Processor)

Legal entity:
Прайс Екс ЕООД

DPA questions:
[email protected]

Address: България, Пловдив, ул. "Петьофи" 1

Signing Request Procedure

  1. Submit a request via the DPA signing form.
  2. Include organisation details.
  3. Receive a signed DPA within 5 business days.
  4. DPA may be signed electronically or physically.

Version: 1.1 | Effective from:

This DPA is prepared in accordance with the requirements of Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.

Бисквитки

Използваме бисквитки, за да осигурим основната функционалност на сайта и да подобряваме услугите. Можете да приемете всички бисквитки или да управлявате предпочитанията си. Повече в Политика за бисквитки и Политика за поверителност.