Version 1.0 — effective from 10 September 2026
This Data Processing Agreement (“DPA”) forms part of the Public Offer Agreement or other services agreement (the “Agreement”) between the Client (“Controller”) and PT78 — Ivan Hrebinchenko, individual entrepreneur registered in Ukraine, correspondence address Poznańska 37, 00-689 Warsaw, Poland (“Processor”).
It applies where the Processor processes personal data on behalf of the Controller in the course of providing the Services, and reflects Article 28 of Regulation (EU) 2016/679 (“GDPR”) and equivalent provisions of the UK GDPR.
1. Roles
1.1 The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller’s documented instructions.
1.2 The Agreement, this DPA and the Order Form constitute the Controller’s complete documented instructions.
1.3 The Processor shall inform the Controller if, in its opinion, an instruction infringes applicable data protection law, and may suspend the relevant processing until the instruction is amended or confirmed.
1.4 The Controller is responsible for ensuring it has a lawful basis for the processing, that required notices and consents are in place, and that the data it makes available is accurate and lawfully obtained.
2. Scope of Processing — Annex I
Subject matter: provision of digital marketing services, including advertising campaign management, website and landing page development, analytics implementation, CRM configuration and lead generation.
Duration: the term of the Agreement, plus the deletion or return period in clause 9.
Nature and purpose: collection, recording, organisation, structuring, storage, retrieval, consultation, use, analysis, segmentation, transmission to advertising and marketing platforms, and erasure of personal data, for the purpose of delivering the Services.
Categories of data subjects: the Controller’s customers, prospective customers, website visitors, campaign recipients, newsletter subscribers, and the Controller’s own personnel involved in the engagement.
Categories of personal data:
- identity and contact data — name, job title, employer, business email address, telephone number, postal address;
- online identifiers — IP address, cookie and pixel identifiers, advertising IDs, device and browser data;
- behavioural and campaign data — pages viewed, form submissions, email opens and clicks, conversion events, lead source, campaign attribution;
- commercial data — enquiry content, deal stage, order and transaction history where provided by the Controller;
- any other personal data the Controller places in systems to which it grants the Processor access.
Special categories of data: none. The Controller shall not provide, and shall not instruct the Processor to process, special categories of personal data under Article 9 GDPR or criminal conviction data, without a prior written agreement setting out additional safeguards.
Frequency: continuous for the duration of the Agreement.
3. Processor Obligations
The Processor shall:
- process personal data only on documented instructions, including in respect of international transfers, unless required to do otherwise by law — in which case it shall inform the Controller in advance, unless that law prohibits it;
- ensure that all persons authorised to process the data are bound by an appropriate duty of confidentiality;
- implement and maintain the technical and organisational measures set out in Annex III;
- respect the conditions in clause 4 for engaging sub-processors;
- assist the Controller, taking into account the nature of the processing and by appropriate technical and organisational measures, in fulfilling its obligation to respond to data subject requests;
- assist the Controller in complying with its obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to it;
- at the Controller’s choice, delete or return the personal data in accordance with clause 9;
- make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits in accordance with clause 8;
- process personal data only for as long as necessary to provide the Services.
4. Sub-Processors — Annex II
4.1 The Controller grants the Processor general written authorisation to engage sub-processors, subject to this clause.
4.2 The Processor shall impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each sub-processor’s obligations.
4.3 The Processor currently uses sub-processors in the following categories:
| Category | Purpose | Typical location |
|---|---|---|
| Website hosting and infrastructure | Hosting of websites and landing pages built for the Controller | EEA / United States |
| Advertising platforms | Campaign delivery, audience management and conversion measurement | EEA / United States |
| Analytics and tag management | Measurement, attribution and reporting | EEA / United States |
| Email delivery and outreach platforms | Sending campaigns on behalf of the Controller | EEA / United States |
| CRM and marketing automation | Lead capture, storage and workflow | EEA / United States |
| Scheduling and communication tools | Meeting booking and project communication | EEA / United States |
| Cloud storage and project management | Storage of working files and task management | EEA / United States |
| Individual contractors and specialists | Delivery of parts of the Services under confidentiality obligations | Ukraine / EEA |
4.4 A current list naming each sub-processor is available on request from info@pt78.space.
4.5 The Processor shall notify the Controller in writing at least fourteen (14) days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If the parties cannot agree a solution, the Controller may terminate the affected part of the Services without penalty, and fees for the unperformed part will be refunded.
5. Security
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. The measures in force are described in Annex III and are reviewed at least annually.
6. International Transfers
6.1 The Processor operates from Ukraine and Poland and may transfer personal data to countries outside the EEA and the UK, including through the sub-processors listed in Annex II.
6.2 Where personal data originating in the EEA or the UK is transferred to a country without an adequacy decision, the transfer takes place under the European Commission’s Standard Contractual Clauses (Decision 2021/914), supplemented by the UK International Data Transfer Addendum where UK data is involved, together with any supplementary technical and organisational measures identified as necessary by a transfer impact assessment.
6.3 On request, the Processor shall provide the Controller with a copy of the relevant transfer mechanism and of any transfer impact assessment.
7. Personal Data Breach
7.1 The Processor shall notify the Controller without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting personal data processed on the Controller’s behalf.
7.2 The notification shall describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact for further information. Where information is not available at once, it shall be provided in phases without undue delay.
7.3 The Processor shall take reasonable steps to contain and remediate the breach and shall cooperate with the Controller in its own notification obligations to supervisory authorities and data subjects.
7.4 The Processor shall not notify a supervisory authority or data subjects on the Controller’s behalf unless instructed to do so, or unless required by law.
8. Audit and Information Rights
8.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.
8.2 The Controller may audit compliance, itself or through an independent auditor bound by confidentiality, no more than once per calendar year — and additionally following a personal data breach or at the documented request of a supervisory authority. Audits require at least thirty (30) days’ written notice, take place during business hours, and shall not unreasonably disrupt the Processor’s operations.
8.3 The Controller bears the cost of any audit it initiates, unless the audit reveals material non-compliance by the Processor.
9. Return and Deletion
9.1 On termination or expiry of the Agreement, the Processor shall, at the Controller’s written choice, return the personal data or delete it, together with existing copies, within sixty (60) days.
9.2 In the absence of a written instruction within thirty (30) days of termination, the Processor shall delete the data.
9.3 The Processor may retain personal data to the extent and for as long as required by applicable law, in which case it shall continue to protect it under this DPA and process it only for the purpose requiring retention.
9.4 Backups are deleted in accordance with the Processor’s ordinary backup rotation, which does not exceed ninety (90) days.
9.5 On request, the Processor shall confirm deletion in writing.
10. Data Subject Requests
10.1 If the Processor receives a request from a data subject relating to personal data processed on the Controller’s behalf, it shall not respond substantively but shall forward the request to the Controller without undue delay and in any event within five (5) Business Days.
10.2 The Processor shall provide reasonable assistance, at the Controller’s cost where the assistance goes beyond making available functionality of the systems used, in enabling the Controller to respond within statutory deadlines.
11. Liability
The liability provisions of the Agreement apply to this DPA, save that nothing in this DPA limits either party’s liability towards data subjects or supervisory authorities under applicable data protection law.
12. Term and Precedence
12.1 This DPA takes effect on the same date as the Agreement and remains in force for as long as the Processor processes personal data on the Controller’s behalf.
12.2 In the event of conflict, this DPA prevails over the Agreement in relation to data protection matters, and the Standard Contractual Clauses prevail over this DPA in relation to restricted transfers.
12.3 The Processor may update this DPA where required by a change in law, in the Standard Contractual Clauses, or in the sub-processors used, by publishing a new version and notifying the Controller.
Annex III — Technical and Organisational Measures
- Access control: access granted on a least-privilege, need-to-know basis; individual named accounts; access reviewed on role change and revoked on departure.
- Authentication: multi-factor authentication enforced on email, cloud storage, advertising platforms, CRM and hosting accounts; passwords managed in a dedicated password manager; credentials never shared over unencrypted channels.
- Encryption: TLS for all data in transit; full-disk encryption on work devices; encryption at rest provided by cloud service providers.
- Network and endpoint security: maintained operating systems and software, endpoint protection, firewalls, and VPN for remote access to protected resources.
- Availability and resilience: regular automated backups of websites and working data; documented restoration procedure; distributed team and infrastructure to mitigate localised disruption.
- Organisational measures: written confidentiality undertakings from all personnel and contractors; internal data protection guidance; onboarding and periodic security awareness briefing; documented offboarding procedure.
- Data minimisation: only data necessary for the Services is collected and retained; retention periods applied and reviewed.
- Vendor management: due diligence on sub-processors; written data protection terms with each; periodic review.
- Incident management: documented breach detection, escalation and notification procedure with defined responsibilities.
Contact
Data protection matters: info@pt78.space, subject line “Data Protection”.
Request a Consultation