EN — Data Processing Agreement (DPA)

1. Parties, roles and application

This DPA supplements the Mandoberdani Service Terms and applies when Variosity, MB, company code 306006123, Žalumos 18-oji g. 6, Brinkiškės, Vilnius district, Lithuania, contact info@mandoberdani.it (Processor), processes personal data on behalf of the Customer. The Customer is the Controller or, where it processes for another controller, a Processor and Variosity, MB is the Sub-processor. This DPA prevails over the general Terms for data-processing matters.

It becomes contractual only when an order, quote or separate written agreement expressly identifies this version. Publication alone does not start Customer-data processing.

2. Subject matter, duration, nature and purpose

The subject matter is the Customer-selected Mandoberdani agent, automation, hosting, portal, communication, integration and managed-support functions. Processing lasts for the agreement and thereafter only as needed to return/delete data, recover from an incident or comply with mandatory law. Operations may include collection, recording, structuring, storage, use, disclosure to Customer-authorised recipients, restriction, export, return and deletion. The purpose is to provide and secure the functions ordered in writing.

3. Data subjects and categories

Data subjects may include the Customer’s staff, candidates, contractors, contacts, customers, prospects, suppliers, drivers, portal users and other persons whose data the Customer lawfully submits for the ordered purpose.

Data may include identity/contact details, professional roles, account/access data, business correspondence, order/invoice information, portal events, prompts, files, messages, context, outputs, technical identifiers, IP addresses and device/security/audit logs. Special-category, biometric, health, children’s, credential-secret or highly sensitive financial data is excluded unless separately assessed in writing with additional safeguards.

4. Documented instructions and lawfulness

The Processor processes data only on documented instructions contained in the order, this DPA, approved configuration and lawful Customer actions in the service, including for international transfers. If law requires other processing, the Processor informs the Customer beforehand unless prohibited. It informs the Customer without undue delay if an instruction, in its reasonable view, infringes the GDPR or other applicable data-protection law.

The Customer is responsible for lawful basis, transparency, minimisation, accuracy, retention and authority to submit data and instructions.

5. Confidentiality and security

Access is limited to personnel who need it and are bound by confidentiality. Risk-proportionate measures include access control/least privilege, strong authentication, TLS in transit, encryption or equivalent protection at rest, secret separation, backups, log/incident monitoring, vulnerability/change management, tenant separation and timely access revocation. An order may detail the measures; they will not be materially weakened without risk assessment.

6. Sub-processors

The Customer gives general authorisation for the direct Sub-processors in the public Mandoberdani Sub-processor Register, incorporated into this DPA by reference and updated from time to time, only for the corresponding activated functions. The Processor imposes written, materially equivalent data-protection duties and remains responsible as required by the GDPR.

Active Customers receive at least 30 days’ notice of a new/replacement direct Sub-processor, except urgent security/operational need where notice is given as soon as practicable. The Customer may object on reasonable data-protection grounds within 30 days; absent an objection within that period, the change is deemed accepted. The parties seek an alternative in good faith; failing that, only the affected function/order may be terminated.

7. Assistance

Taking account of the nature of processing, the Processor assists the Customer by appropriate measures with data-subject requests. Taking account of available information, it also assists with GDPR Articles 32–36, including security, DPIAs and prior consultation. It does not answer a data subject for the Customer without instruction unless legally required.

8. Personal Data Breaches

After becoming aware of a breach affecting Customer data, the Processor notifies the Customer without undue delay and provides available information on its nature, likely consequences, affected categories and measures taken/proposed. Notice is not an admission of liability. The Customer decides regulatory/data-subject notifications; the Processor reasonably assists.

9. International transfers

Transfers outside the EEA use an applicable adequacy decision, the EU Standard Contractual Clauses (Decision (EU) 2021/914) or another lawful GDPR Chapter V mechanism, with transfer assessment and supplementary measures where required. Controller-to-Processor applies when the Customer is Controller; Processor-to-Sub-processor applies when it is Processor. A provider’s available/configurable region is described as actually used only after account-specific configuration is verified.

10. Return, deletion and backups

When the affected service ends, data is returned in a commonly available format or deleted at the Customer’s choice unless law requires retention. Active data is normally deleted within 90 days and rotating backups within a further 30 days unless the order requires less. Legal-hold/security-investigation data is restricted and deleted when the ground ends. After incident recovery, prior deletion instructions are re-applied.

11. Compliance information and audit

The Processor supplies information reasonably necessary to demonstrate Article 28 compliance. Existing audit/security/control material is used first. If reasonably insufficient, the Customer may audit once yearly with 30 days’ notice, confidentiality and safeguards against disruption or other-customer exposure. Further audits are allowed after a material breach or regulator requirement. The Customer bears its costs unless the parties agree in writing, or a final decision of a competent court or supervisory authority determines, that a material Processor breach occurred; in that case the Processor reimburses reasonable direct audit costs.

12. Liability, law and language

The Terms’ liability limits apply insofar as the GDPR or mandatory law permits. Nothing removes data-subject or authority rights. Lithuanian law applies; B2B disputes go to competent Vilnius courts to the extent permitted. The Lithuanian text prevails if translations conflict.

Data Processing Agreement — Mandoberdani