For Cloud-Based Appmixer Solution
Version 1.0 · 16 November 2026
This Data Processing Agreement (“DPA”) forms an integral, ancillary part of the Cloud-Based (SaaS) Agreement executed between the Parties based on Appmixer “Software as a Service” Terms and Conditions (“SaaS Terms”) (the applicable agreement hereinafter referred to as the “Master Agreement”) entered into by and between the Customer identified in the Order (“Customer” or “Data Controller”) and Appmixer s.r.o., with its registered office at Thámova 181/20, 186 00 Prague 8, Czech Republic, ID No.: 044 19 924 (“Provider” or “Data Processor”).
Whereas:
(A) The Customer acts as a Data Controller in respect of personal data processed through the Services (as defined in the Master Agreement).
(B) The Provider acts as a Data Processor providing the Services under the Master Agreement.
(C) The Parties seek to ensure compliance with Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and applicable Data Protection Laws.
The Parties have therefore agreed as follows:
1.1 Terms such as “Controller”, “Processor”, “Personal Data”, “Personal Data Breach”, “Processing”, and “Data Subject” shall have the meanings assigned to them in the GDPR.
1.2 “Customer Personal Data” means any Personal Data processed by the Provider solely on behalf of the Customer in performance of the Services under the Master Agreement.
1.3 “Sub-processor” means any third-party data processor engaged by the Provider to assist in fulfilling its obligations under the Master Agreement.
1.4 Defined Terms in Master Agreement. Capitalized terms used but not expressly defined in this DPA shall have the exact meanings ascribed to them in the Master Agreement, in particular in the SaaS Terms.
2.1 Scope and Purpose. The Provider shall Process Customer Personal Data solely for the purpose of executing and delivering the Services, ensuring system performance, maintaining workflow automations, and providing Support Services in accordance with the Master Agreement and this DPA.
2.2 Duration. The Processing shall continue for the entire term of the Master Agreement plus the mandatory data retention and/or deletion window specified in Section 8.
2.3 Documented Instructions. The Master Agreement, this DPA, and the Customer’s configuration of the Software constitute the Customer’s complete and documented instructions to the Provider. Processing outside these instructions shall require prior written agreement.
2.4 Unlawful Instructions. Provider shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
2.5 Processed Data. Given the nature of the Service, the content and use of which are determined by the Controller, it is not possible to define exhaustively in advance all categories of data subjects and types of personal data that will be processed in the course of providing the Service. The Processor shall process personal data to the extent that the Controller uploads, enters, transmits or otherwise makes available through the Service. The processing will typically include, in particular, the following categories, whereby this list is illustrative (non-exhaustive):
2.6 Controller’s Representation. The Controller represents and warrants, and shall be liable for ensuring, that it will not process through the Service, without prior written agreement with the Processor, any special categories of personal data within the meaning of Article 9 GDPR, nor any data relating to criminal convictions and offences within the meaning of Article 10 GDPR.
2.7 Provider as Controller. Notwithstanding the above, Provider acts as an independent Controller with respect to: (a) billing and account administration data; (b) contact details of Customer’s administrators and users necessary for service provision; and (c) data that has been anonymized or aggregated in a manner that no longer permits identification of Data Subjects.
3.1 Security Level. Taking into account the state of the art, implementation costs, and the nature of Processing, the Provider shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 of the GDPR. Details about Technical and Organizational Measures (TOM) are set forth in Annex 1 hereto.
3.2 Confidentiality. The Provider shall ensure that all personnel authorized to Process Customer Personal Data are bound by appropriate statutory or contractual confidentiality obligations. Provider shall ensure that access to Customer Personal Data is limited to personnel who need such access to perform the Services and are trained in data protection and information security.
4.1 Pre-Approved Sub-processors. The Customer grants general authorization to the Provider to engage the following infrastructure and service Sub-processors:
4.2 Notification of Changes. The Provider shall notify the Customer in writing (via email or administrative dashboard) at least thirty (30) days prior to engaging any new Sub-processor or replacing an existing one.
4.3 Right to Object. The Customer may object to a new Sub-processor on reasonable data protection grounds within fourteen (14) days of receiving notice. If the Customer objects and the Provider cannot reasonably adjust the Service to accommodate the objection, either Party may terminate the affected Service subscription upon written notice without any penalty, in such event no pre-paid fees (e.g., Subscription Fees) shall be refundable.
4.4 Sub-processor Obligations. The Provider shall impose data protection obligations upon any Sub-processor that are no less restrictive than those set forth in this DPA.
5.1 Data Subject Requests. The Provider shall promptly forward to the Customer any request received directly from a Data Subject exercising their rights under GDPR. The Provider shall not respond directly to Data Subject requests except on written instructions from the Customer or as required by applicable EU law.
5.2 Assistance. Taking into account the nature of the processing and the information available to the Provider, the Provider shall assist the Customer by technical measures fulfilling the Customer’s obligations to respond to Data Subject requests or perform Data Protection Impact Assessments (DPIA) under Articles 35 and 36 of the GDPR.
5.3 Cost Reimbursement. Unless the request or assessment is directly necessitated by a breach or defect attributable solely to the Provider, the Customer shall reimburse the Provider for reasonable engineering time and administrative costs incurred in providing assistance under Section 5.2, billed at the Provider’s standard professional service rates.
6.1 Notification. The Provider shall notify the Customer without undue delay and in any event within 48 hours, upon becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
6.2 Information Provided. The notification shall include available details regarding the nature of the breach, affected data categories, estimated number of affected Data Subjects, and initial remediation measures taken or proposed.
6.3 Mitigation. The Provider shall take prompt, commercially reasonable steps to contain, mitigate, and remediate the effects of any Personal Data Breach.
7.1 Documentation. Upon the Customer’s reasonable written request, the Provider shall make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 of the GDPR. The Provider may satisfy this obligation by providing recent third-party security certifications, SOC reports, executive summaries of internal audits, or standard security documentation.
7.2 On-Site Audits. If the documentation provided under Section 7.1 is insufficient to prove compliance, or if an audit is required by a competent supervisory authority, the Customer (or an independent certified auditor) may conduct an audit subject to the following rules:
8.1 Post-Termination Deletion. Upon termination of the Master Agreement (or expiration of any transition period specified in the SaaS Terms), the Provider shall at the choice of Customer, delete or return all Customer Personal Data to Customer and delete existing copies, unless Union or Member State law requires storage of such Personal Data. Customer shall communicate its choice within thirty (30) days of termination or expiry; failing such communication, Provider shall delete the Customer Personal Data.
8.2 Backups. Customer Personal Data residing in automated system backup archives shall be securely isolated and systematically overwritten in the ordinary course of the Provider’s backup lifecycle, not to exceed ninety (90) days from termination.
8.3 Data Retention. Provider may retain Customer Personal Data to the extent and for as long as required by applicable law, provided that Provider shall continue to protect such data in accordance with this DPA and shall Process it only for the purposes required by such law.
9.1 EU/EEA Processing. Customer Personal Data shall be stored and hosted primarily within servers located in the European Union / European Economic Area (EEA).
9.2 Third Country Transfers. The Provider shall not transfer Customer Personal Data to a country outside the EEA unless adequate safeguards are implemented in compliance with Chapter V of the GDPR (e.g., EU Standard Contractual Clauses or an EU Adequacy Decision).
10.1 Modifications. The Provider reserves the right to revise or modify this DPA from time to time. In such instances, the Provider shall provide written notice to the Customer regarding the availability of the updated DPA at least thirty (30) days prior to its effective date. It is the Customer’s responsibility to review the updated DPA upon receipt of such notification. Once timely notified, the new version of the DPA shall become binding and effective for the Customer on its designated effective date. If the Customer objects in writing to the updated DPA prior to its effective date, the Customer shall have the right to terminate the Services prior to the effective date of the change, under the same terms and procedures applicable to a material modification of the SaaS Terms under the Master Agreement.
10.2 Incorporation of Master Terms. This DPA is ancillary to the Master Agreement. In the event of any direct conflict between the provisions of this DPA and the Master Agreement (e.g. SaaS Terms), this DPA shall prevail strictly regarding the subject matter of Personal Data Processing under GDPR. On all commercial, operational, and general legal matters, the Master Agreement (e.g. the SaaS Terms) shall govern.
10.3 Governing Law and Jurisdiction. This DPA shall be governed by, construed, and enforced in accordance with the exact same governing law and choice-of-law principles set forth in the underlying Master Agreement, and any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the same courts designated in said Master Agreement.
10.4 Limitation of Liability. For the avoidance of doubt, any financial caps, exclusions, or limitations of liability established in the Master Agreement shall comprehensively apply to all claims, damages, or remedies arising under this DPA.