DATA PROCESSING AGREEMENT (DPA)
1. Parties
The data controller is the Creator. The processor is Cashly Finance sp. z o.o.
2. Scope of data
The DPA covers the data of:
- webinar participants,
- sign-ups,
- webinar activity,
- technical data,
- marketing and analytical data.
3. Purpose of processing
Processing takes place solely for the purpose of providing the services of the Webivio Platform.
4. Obligations of the processor
The processor undertakes to:
- act solely on the instructions of the controller,
- apply appropriate security measures,
- report security incidents,
- ensure confidentiality,
- maintain records of processing.
5. Sub-processing
The controller consents to the use of the sub-processors indicated in the Privacy Policy.
6. Retention
After an account is deleted, data is removed from operating systems and backups in accordance with the retention policy.
8. Rights of data subjects
The processor undertakes to promptly forward to the Controller all applications and requests from data subjects (in particular those concerning access, rectification, erasure, restriction of processing, data portability, or objection), and to provide the Controller with the technical and organizational assistance necessary to fulfill the obligation to respond to these requests within the time limit specified by the GDPR.
9. Personal data breaches
The processor undertakes to promptly — no later than within 24 hours of detection — inform the Controller of any identified personal data breach and to provide all necessary assistance in fulfilling the Controller's obligations under Articles 33 and 34 of the GDPR (notification to the supervisory authority and communication to data subjects).
10. Data protection impact assessment (DPIA)
The processor undertakes to provide the Controller with all necessary assistance in carrying out a data protection impact assessment (Article 35 of the GDPR) and prior consultations with the supervisory authority (Article 36 of the GDPR), with respect to the areas managed by the Processor.
11. Audit and inspection
The Controller has the right to verify the compliance of the Processor's activities with this Agreement, including through audits and inspections carried out by the Controller or an auditor authorized by it. The processor undertakes to make available all information necessary to demonstrate compliance with the obligations arising from Article 28 of the GDPR and to cooperate in the conduct of audits.
12. AI and future features
The Platform may in the future use AI features supporting webinar analysis, content generation, and communication automation in accordance with the GDPR.