Contents (12)
Data Processing Addendum (DPA)
Reference template — not an executed contract
This document is a reference template of the Data Processing Addendum. To become binding for your organisation it must be signed by an authorised representative of both parties. Use the button below to request signing.
Request DPA SigningThis addendum is required for organisations using Actio to process personal data of third parties as a data controller under GDPR.
1. Introduction and Definitions
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", "Data Controller") and Прайс Екс ЕООД, which operates the Actio platform ("Data Processor", "Actio", "we"), regarding the use of the Actio platform services.
1.1 Definitions
- "Personal Data" — any information relating to an identified or identifiable natural person
- "Data Controller" — the customer organisation which determines the purposes and means of processing
- "Data Processor" — Actio, which processes personal data on behalf of the controller
- "Processing" — any operation performed on personal data, including collection, recording, organisation, storage
- "GDPR" — General Data Protection Regulation (EU) 2016/679
- "Data Subject" — the natural person to whom the personal data relates
2. Subject Matter and Scope of Processing
2.1 Subject Matter
Actio processes personal data on behalf of and according to the instructions of the Customer solely for providing the platform services.
2.2 Categories of Personal Data
- Identification data (name, email, phone)
- Professional data (position, organisation)
- Activity participation data
- Communication data (messages, comments)
- Technical data (IP address, browser data)
- Photos and media files
2.3 Categories of Data Subjects
- Employees and representatives of customer organisations
- Volunteers and activity participants
- Service beneficiaries
- Contacts and partners
2.4 Processing Purposes
- Organisation and member management
- Project and activity coordination
- Communication and messaging
- Reporting and analytics
- Technical support and security
3. Processor Obligations (Actio)
3.1 Processing on Instructions
Actio undertakes to process personal data solely:
- On documented instructions from the data controller
- Within the scope of services provided through the platform
- In accordance with applicable law
3.2 Confidentiality
- Ensures processing confidentiality
- Guarantees that all authorised persons have committed to confidentiality
- Implements appropriate technical and organisational measures (GDPR Art. 32)
- Notifies of security breaches without undue delay (section 10)
3.3 Technical and Organisational Measures
Actio applies the following protective measures. Their exact scope is subject to review as part of the annual compliance documentation (section 8):
- Encryption in transit: TLS 1.2+ for all traffic; HSTS is enabled.
- Password hashing: bcrypt with a minimum of 10 rounds.
- Access control: Multi-factor authentication (2FA / Passkeys), role-based management within organisations, tenant data isolation.
- Monitoring: Automated error monitoring via Sentry; centralised security logs; CSP violation reporting.
- Backups: Automated database backups via
spatie/laravel-backup, stored in an off-site EU destination; the restore process is periodically tested. - Maintenance: Regular dependency updates and static analysis (PHPStan).
Note: Actio does not claim that data at rest is encrypted at the filesystem or database layer by default. If your organisation requires additional measures (e.g. application-level field encryption, specific SCC modules, SOC 2 / ISO 27001 attestation), please state these requirements during the DPA signing request.
4. Sub-processors
4.1 Approved Sub-processors
The Customer gives general authorisation for the use of the following sub-processors. The list mirrors the sub-processor table in the Privacy Policy §6.
| Service | Provider | Jurisdiction | Purpose |
|---|---|---|---|
| Hosting | EU hosting partner | Bulgaria / EU | Server infrastructure and storage |
| Payments | Stripe Payments Europe, Ltd. | Ireland / EU | Payment and subscription processing |
| Error monitoring | Functional Software, Inc. (Sentry) | United States (SCCs) | Aggregated stack traces and diagnostic metadata |
| Analytics (if enabled) | Plausible Insights OÜ | Estonia / EU | Anonymous web analytics (cookieless) |
| Email delivery | EU SMTP / email provider | EU | Transactional emails and notifications |
4.2 Flow-down of Obligations
Actio ensures that each sub-processor is bound by a written contract imposing the same data protection obligations as those applicable under GDPR Art. 28(4).
4.3 Changes to Sub-processors
For changes to the list, Actio will notify customers at least 30 days in advance. Customers have the right to object within 14 days.
5. Data Subject Rights
Actio assists the data controller in fulfilling obligations regarding data subject rights (GDPR Art. 28(3)(e)):
- Right of Access: providing copies of personal data
- Right of Rectification: correcting inaccurate or incomplete data
- Right of Erasure: deletion while respecting legal obligations
- Right of Restriction: temporary restriction of processing
- Right of Portability: export in a structured, machine-readable format
- Right to Object: ceasing processing under certain grounds
6. Data Transfer Outside the EU
Main data processing takes place within the European Union. The only sub-processor outside the EU is Sentry (United States) — the transfer is protected by Standard Contractual Clauses (SCCs) of the European Commission (Implementing Decision 2021/914, Module 3) pursuant to GDPR Art. 46. Data shared with Sentry is limited to technical stack traces and diagnostic metadata.
7. Retention Period and Deletion
7.1 Periods
- Active accounts: while the contract is in force
- Terminated accounts: fully deleted within 30 days
- Inactive accounts: anonymised after 365 days
- Security logs: up to 365 days
- Legal obligations: according to applicable law
7.2 Deletion Procedures
Upon contract termination, Actio deletes or returns all personal data within 30 days, unless longer retention is required by law. Existing backups rotate and are deleted according to the log retention period.
8. Audits and Cooperation
8.1 Audits
Pursuant to GDPR Art. 28(3)(h), the data controller has the right to:
- Obtain all information necessary to demonstrate compliance with Art. 28
- Conduct audits or inspections, in person or through a mandated auditor, upon reasonable written notice (typically 30 days) and during business hours
- Obtain copies of the applicable technical and organisational documentation
- Request assistance in preparing a Data Protection Impact Assessment (DPIA) under Art. 35 and prior consultations under Art. 36
8.2 Cooperation with Supervisory Authorities
Actio undertakes to assist the data controller in communication with supervisory authorities (e.g. the Bulgarian CPDP) and to provide information necessary to demonstrate compliance.
9. Liability
9.1 Mutual Liability
Each party bears responsibility for damages caused by GDPR violations within its obligations:
- Controller: GDPR compliance of instructions
- Processor: following instructions and maintaining security measures
9.2 Limitation of Liability
Specific financial liability caps, insurance coverage and indemnification clauses are negotiated individually as part of the DPA signing process (section 12). Actio does not maintain an automatically published insurance coverage amount in this reference template.
10. Breach Notifications
10.1 Notification Procedure
Upon identifying a personal data security breach, Actio:
- Notifies the controller without undue delay upon becoming aware (GDPR Art. 33(2))
- Provides the following information:
- Nature of the breach
- Categories and approximate number of affected subjects
- Likely consequences
- Measures taken to address the breach
- Recommendations for the controller
- Documents the incident for audit purposes
11. Entry into Force and Amendments
11.1 Entry into Force
This DPA enters into force once countersigned by an authorised representative of both parties, or upon explicit electronic acceptance by the owner of the organisation account within the platform settings. Until signed, this document is a reference template only.
11.2 Amendments
Changes to the DPA require written consent from both parties or, in cases of mandatory legislative changes, with 30 days advance notice.
12. Data Protection Contacts
Actio (Data Processor)
Legal entity:
Прайс Екс ЕООД
DPA questions:
[email protected]
Address: България, Пловдив, ул. "Петьофи" 1
Signing Request Procedure
- Submit a request via the DPA signing form.
- Include organisation details.
- Receive a signed DPA within 5 business days.
- DPA may be signed electronically or physically.
Version: 1.1 | Effective from:
This DPA is prepared in accordance with the requirements of Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.