Data Processing Agreement
Required under GDPR when we hold personal data on your behalf. Names every company involved.
Last updated 23 July 2026
Between the Client ("Controller") and Bleep Digital, poslovno svetovanje, Tomi Toth s.p. ("Processor"). Forms part of the AGB.
1. Subject matter and duration#
1.1 The Processor processes personal data on the Controller's behalf to provide website hosting, email services, backups and support.
1.2 Duration matches the main contract, plus the retention period in AGB §5.9.
2. Nature and purpose#
Hosting and operating the Controller's website and mailboxes; storing and transmitting data the Controller or its own users place there; backups; technical support.
3. Categories of data subject#
- The Controller's customers, clients and patients
- Visitors to the Controller's website
- People who contact the Controller through the website or by email
- The Controller's own staff with dashboard or mailbox access
4. Categories of personal data#
| Contact data | name, email, telephone, address |
| Content of communications | contact form submissions, email content and attachments |
| Technical data | IP addresses, user agents, access logs |
| Account data | dashboard usernames, hashed passwords |
| Whatever the Controller chooses to store | we do not control what is placed on the site or sent to mailboxes |
Special category data (GDPR Art. 9) — health, biometric, religious, and similar. Our service is not designed for it and we apply no additional safeguards for it.
Directly relevant to your market. A physiotherapist, dentist or clinic receiving appointment requests through a contact form is processing health data. If you sell to healthcare clients, this section needs specific legal attention and may require additional technical measures. Decide deliberately whether to accept those clients.
5. Processor obligations#
The Processor shall:
5.1 Process personal data only on documented instructions from the Controller, including for transfers outside the EU. The main contract and this DPA are the initial instructions.
5.2 Ensure persons authorised to process are bound by confidentiality.
5.3 Implement the technical and organisational measures in §9.
5.4 Respect the conditions on sub-processors in §6.
5.5 Assist the Controller in responding to data subject requests, insofar as possible, by providing access, export and deletion tools.
5.6 Assist with GDPR Arts. 32–36 — security, breach notification, impact assessments — taking into account the information available.
5.7 On termination, delete or return personal data per AGB §5.6–5.9.
5.8 Make available information necessary to demonstrate compliance and allow audits per §10.
5.9 Immediately inform the Controller if an instruction appears to infringe data protection law.
6. Sub-processors#
6.1 The Controller grants general authorisation for the sub-processors listed below.
6.2 Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| OVH SAS | Server infrastructure | European Union |
| Cloudflare, Inc. | Authoritative DNS | EU / global anycast |
| Stripe Payments Europe Ltd | Payment processing | Ireland / EU |
Email is sent and received on infrastructure we operate ourselves; no third-party email provider processes client mail.
Backups are held on infrastructure operated by OVH SAS within the European Union, in a different datacentre from the servers they protect. No additional sub-processor is involved. If that changes, this table is updated and clients notified under §6.4 before the new provider is used.
Keep this table accurate. An out-of-date sub-processor list is one of the most commonly cited failures in GDPR enforcement. Update it whenever the stack changes — the mail node, a monitoring service, an AI provider.
6.3 The Processor imposes the same data protection obligations on each sub-processor by contract, and remains fully liable for their performance.
6.4 The Processor gives 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate without penalty.
7. International transfers#
7.1 Personal data is processed within the European Union in the ordinary course.
7.2 Any transfer outside the EU/EEA occurs only with an adequacy decision, Standard Contractual Clauses, or another lawful mechanism.
Check Cloudflare specifically. As a US company operating global anycast DNS, its position needs confirming — DNS query data may be processed outside the EU. Cloudflare offers an EU DPA and SCCs; make sure they are executed.
8. Data subject rights#
8.1 The Controller is responsible for responding to data subjects.
8.2 The Processor provides tools for access, export and deletion, and assists with anything not achievable through them.
8.3 If a data subject contacts the Processor directly, the Processor does not respond substantively but forwards the request to the Controller without undue delay.
9. Technical and organisational measures#
Per GDPR Art. 32. These describe the platform as built:
9.1 Access control#
- Per-client isolation: separate network, database user, cache credentials and mail credentials, each scoped to that client alone
- No client can reach another client's data — verified by testing, not assumed
- Administrative access restricted to authorised personnel
- Key-based server authentication
9.2 Encryption#
- In transit: TLS for all website traffic, HSTS enforced; TLS for email submission and retrieval; opportunistic TLS for message delivery
- At rest: backups encrypted; passwords hashed with a modern algorithm
9.3 Isolation and containment#
- Each site in its own container with all Linux capabilities dropped, no privilege escalation, and a non-root user
- Databases and caches are not reachable from the internet
- Firewall permits only the ports required for service
9.4 Availability and resilience#
- Nightly backups held separately from the systems they protect
- Quarterly restore testing
- Monitoring of availability, capacity and certificate expiry
- Automated intrusion prevention against repeated authentication failures
9.5 Integrity#
- Configuration under version control with an audit trail
- Changes reviewed before deployment
9.6 Review#
Measures are reviewed at least annually and after any significant change or incident.
Only claim what is actually true at signature. Several items above are implemented; offsite backup and external monitoring are not yet. Do not execute this DPA until every measure listed is real — describing controls you do not have is a misrepresentation in a contract.
10. Audit#
10.1 The Controller may verify compliance once per year, at reasonable notice, during business hours, at its own cost.
10.2 The Processor may first offer documentation, a completed questionnaire, or a third-party certification, where these reasonably satisfy the request.
10.3 Audits must not disproportionately disrupt operations or compromise the confidentiality of other clients.
11. Breach notification#
11.1 The Processor notifies the Controller of a personal data breach without undue delay and in any case within 72 hours of becoming aware.
11.2 Notification describes the nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken.
11.3 The Processor assists the Controller with its own notification obligations.
12. Liability#
Liability under this DPA follows AGB §8, save where GDPR imposes liability that cannot be limited by contract.