Legal information
DATA PROCESSING AGREEMENT
This English text is a translation provided for convenience. Only the Slovak wording of this document is legally binding.
entered into pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the ‘Regulation’)
1. INTRODUCTORY PROVISIONS
This Data Processing Agreement forms part of the Agreement on the Provision of Services and Bookkeeping (hereinafter also referred to as the ‘Main Agreement’) entered into between:
the Client, which determines the means and purposes of processing the personal data of data subjects in connection with the provision of services under the Main Agreement (hereinafter referred to as the ‘Controller’), and
BILVAO s. r. o., with its registered office at Janka Jesenského 564/9, Bánovce nad Bebravou 957 01, Company ID No.: 53 399 978, a company registered in the Commercial Register of the District Court Trenčín, Section: Sro, Insert No. 41118/R, which traded under the business name BJ accounting services s. r. o. until 28. 08. 2026, as the provider of services acting as processor within the meaning of the Regulation (hereinafter referred to as the ‘Processor’ or also as ‘BILVAO’ and, together with the Controller, hereinafter also referred to as the ‘Parties’).
Under the Main Agreement, services are provided in the following areas:
the Client's bookkeeping;
the administration of the Client's payroll and personnel matters;
professional advisory services in the fields of accounting, taxation, personnel matters, and the processing of clients' wages and remuneration;
and the performance of the Parties' rights and obligations under the Main Agreement involves the processing of personal data. The Parties have therefore agreed, pursuant to Article 28 of the Regulation, to entrust the processing of personal data under this Data Processing Agreement (hereinafter referred to as the ‘Agreement’).
2. SUBJECT MATTER OF THE AGREEMENT
The Controller hereby entrusts the Processor with processing personal data on behalf of the Controller in connection with performance of the Main Agreement, subject to the following conditions:
subject matter and purpose of the processing of personal data – the Processor shall process the personal data of data subjects when providing the services that are the subject of the Main Agreement solely for purposes necessary for the provision of services under the Main Agreement (i.e. purposes that are necessarily connected with the provision of bookkeeping, payroll and personnel administration services and related administrative services, including professional advisory services in the fields of accounting, taxation, personnel matters and the processing of wages and remuneration, and that are specified in the Controller’s record of processing activities, of which the Controller shall inform the Processor before processing on behalf of the Controller begins);
duration of processing – the Processor may process personal data on behalf of the Controller for the term of the Main Agreement. Upon termination of the Main Agreement, the authorisation granted to the Processor to process personal data pursuant to paragraph 1 of this Article of the Agreement and this Agreement as a whole shall also terminate, unless otherwise provided below. Termination of the authorisation shall not affect any obligations of the Processor or any sub-processor (if involved in the processing of personal data under this Article of the Agreement) that must be performed after termination of this Agreement;
type of personal data – ordinary personal data (processed in the performance of the Controller's obligations, in particular: first name, surname, contact details – residential address, billing address, e-mail address, telephone number, bank details and signature) and special categories of personal data whose processing, depending on the particular task performed under the Main Agreement, is necessary for the Processor to provide services on behalf of the Controller;
categories of data subjects – natural persons whose personal data are processed in connection with the processing of accounting documents, in particular (i) employees, persons close to the employees, former employees, persons close to former employees, job applicants and members of the Controller's governing bodies, (ii) representatives, contact persons, employees and other persons acting for customers and suppliers of goods and services, and (iii) other related natural persons identified in accounting, tax and payroll documents and records;
nature of the processing of personal data – the Processor shall process personal data by automated and non-automated means on the basis of the supporting materials provided by the Controller to the Processor electronically or in another agreed form pursuant to the relevant provisions of the Main Agreement and this Agreement.
If any of the facts specified in the preceding paragraph of this Article of the Agreement changes, the Parties shall notify each other of that change without undue delay and in any event within 10 days, and shall amend the wording of this Article on a case-by-case basis to reflect the identified changes.
The Controller shall:
provide the Processor only with personal data that have been obtained and are processed by the Controller in accordance with the Regulation and other legislation governing personal data protection;
issue the Processor with instructions for the processing of personal data that are at all times consistent with the Regulation and other legislation governing personal data protection.
When performing their obligations relating to the processing of personal data under this Agreement, the Parties shall comply with the Regulation and other legislation governing personal data protection (hereinafter collectively referred to as the ‘Data Protection Legislation’).
The Processor shall process personal data only on the basis of the Controller's documented instructions issued in writing or electronically, where such instructions are necessary for the processing of personal data on the basis of the purposes and means of processing determined by the Controller and are consistent with the Data Protection Legislation (hereinafter referred to as the ‘instructions’) and this Agreement. The Controller may amend or revoke any instructions issued. An amendment or revocation of instructions under the preceding sentence shall take effect in relation to the Processor 10 days after delivery of the Controller's notice of such amendment or revocation.
The relevant provisions of the Main Agreement governing the Processor's obligations in providing the services and the Controller's instructions, issued by electronic communication during the contractual relationship established by the Main Agreement concerning the manner in which the Processor is to provide the services, shall be deemed instructions issued by the Controller upon entering into this Agreement.
If the Processor has doubts regarding the Controller's instructions for processing personal data, the Processor shall inform the Controller of those doubts and request that the instructions be supplemented or clarified, or agree further steps with the Controller. Until further steps have been agreed, the Processor shall process personal data in accordance with the Main Agreement and applicable legislation.
The Controller shall supplement or clarify its instructions and/or agree further steps with the Processor within 5 days of being informed by the Processor of doubts concerning the processing of personal data or the Controller's instructions pursuant to the preceding paragraph of this Agreement. If the Controller fails, within the period specified in the preceding sentence, to supplement or clarify its instructions and/or agree further steps with the Processor, the Processor may interpret and/or replace the Controller's instructions so as to perform its contractual obligations and the obligations arising under applicable legislation. In the event of doubt, the Processor may suspend the provision of services under the Main Agreement and the processing of personal data under this Agreement and resume them only after the Controller has supplemented its instructions, without this constituting a breach of the Main Agreement or this Agreement.
The Processor shall maintain confidentiality regarding the processing of personal data and the personal data that it processes on behalf of the Controller; this obligation shall continue after the processing of personal data ends or this Agreement terminates. The Processor shall ensure that access to the personal data being processed is granted only to persons who necessarily require access to the personal data in order to perform the Processor's obligations for which they have been authorised (e.g. employees of the Processor acting as authorised persons within the meaning of Article 32(4) of the Regulation) or to perform this Agreement. The Processor shall bind persons authorised to process personal data to maintain confidentiality regarding the processing of personal data and the personal data that they process on behalf of the Controller, including after their authorisation ends.
Taking into account the nature of the processing and the information available to it, the Processor shall notify the Controller if a security incident occurs at the Processor and/or a sub-processor that results in the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data, or unauthorised access to personal data (hereinafter referred to as a ‘personal data breach’) without undue delay after becoming aware of the personal data breach.
The Processor may transfer personal data within the European Union. The Processor may transfer personal data to a state that is not a Member State of the European Union (hereinafter referred to as a ‘third country’) or to an international organisation only with the Controller's prior consent (which may be given electronically).
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement the following minimum technical and organisational measures pursuant to Article 32 of the Regulation in order to ensure a level of security of personal data processing appropriate to the risk:
specifying and minimising the group of persons who process personal data on behalf of the Processor and ensuring that such persons comply with the provisions of personal data protection legislation when processing personal data;
implementing measures to prevent unauthorised persons from accessing information systems in which personal data are processed on behalf of the Controller, through a system of passwords and access permissions;
implementing measures to ensure that personal data cannot be read or observed without authorisation during transmission or processing on display units or other technical devices, or in documents processed in hard-copy form;
implementing physical security measures (lockable doors, lockable cabinets and storage areas) to ensure an appropriate level of protection for paper media containing personal data, and software security measures (firewall, antivirus software, use of a secure network and regular updates to the software used) to ensure an appropriate level of protection for personal data processed electronically;
implementing vetting procedures for suppliers that will process the personal data of data subjects on behalf of the Processor as sub-processors;
adopting internal personal data protection documentation specifying additional security measures and the conditions for processing the personal data of data subjects.
The specific security measures are set out in Annex No. 1 and form a separable part of this Agreement.
If the Processor intends to change the adopted security measures specified in the preceding paragraph of this Agreement during the term of this Agreement, it shall notify the Controller of each such change in advance and adopt new security measures that provide at least the same level of protection for personal data as the security measures originally adopted.
The Processor may engage a sub-processor in the processing of personal data on behalf of the Controller only with the Controller's prior written consent (which may be given electronically). By entering into this Agreement, the Controller consents to the Processor's engagement of sub-processors that, on the basis of a contractual relationship with the Processor as at the date of this Agreement, provide their services to the Processor as subcontractors.
If the Processor intends to engage a new sub-processor in the processing of personal data under this Agreement or replace an existing sub-processor, it shall inform the Controller in advance. If the Controller does not respond within 3 working days of being notified of the Processor's intention to engage a sub-processor in the processing of personal data under this Agreement or replace an existing sub-processor, the Controller shall be deemed to have no objection to the engagement of the sub-processor and to have consented to its engagement in the processing under this Agreement.
Upon termination of this Agreement and completion of the processing of personal data on behalf of the Controller, the Processor shall, as decided by the Controller and notified to the Processor, delete (destroy) or return to the Controller all personal data processed on the Controller's behalf under this Agreement and delete (destroy) all existing copies, unless applicable legislation or the Data Protection Legislation requires those personal data to be retained. Without undue delay after termination of this Agreement and the deletion (destruction) or return of the personal data to the Controller, the Processor shall issue confirmation of the deletion (destruction) or return of the personal data to the Controller under the preceding sentence of this paragraph of the Agreement.
The Processor shall permit the Controller to audit the processing of personal data on behalf of the Controller under this Agreement in order to verify whether the Processor is complying with its obligations under this Agreement, subject to the following conditions:
the audit shall be conducted by the Controller or another person expressly authorised by the Controller, and the Controller shall inform the Processor of the audit of the processing of personal data at least 10 days in advance. In the notice of the audit, the Controller shall specify the date of the audit, identify the persons through whom the audit is to be conducted, and identify the information, records or documents that the Controller requires to be presented;
an audit pursuant to the preceding subparagraph of this paragraph of this Article of the Agreement may be conducted only during the term of this Agreement. The Controller may conduct one audit during each year of the term of this Agreement, and may conduct further audits if it has reasonable doubts as to whether the Processor, when processing personal data on behalf of the Controller, complies with the Data Protection Legislation and/or this Agreement.
An audit under the preceding paragraph of this Article of the Agreement shall be conducted in a manner that does not disrupt the ordinary activities of the Processor and sub-processors in relation to the Controller or the Processor's other business partners (clients). The Processor may determine the scope of the audit.
The Processor shall assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 of the Regulation, taking into account the nature of the processing of personal data and the information available to the Processor.
The Processor acknowledges that if the Controller suffers damage as a result of the Processor's breach of its obligations under this Agreement, the Processor shall compensate the Controller for that damage unless the breach was caused by the Controller issuing the Processor with instructions contrary to the Data Protection Legislation and/or by circumstances excluding liability.
3. FINAL PROVISIONS
The Parties agree that this Agreement shall not affect any agreement between the Parties governing the protection of confidential information (other than personal data) in connection with the Main Agreement, if any such agreement has been entered into.
This Agreement shall become valid and effective on the date of conclusion of the Main Agreement or when the Controller expresses its consent to its wording in any suitable form that clearly demonstrates the Controller's intention to enter into this Agreement (if the Main Agreement has already been entered into).
The Parties agree that amendments and supplements to this Agreement shall be made, at a minimum, in electronic form, by the Processor updating the wording of this Agreement and the Controller expressing its consent to the amendment in any form clearly demonstrating that the Controller agrees to the amendment, without the need to enter into amendments to the Main Agreement.
If any provision of this Agreement becomes invalid, ineffective and/or unenforceable, this shall not affect the validity, effectiveness and/or enforceability of the remaining provisions of this Agreement, unless this is precluded by legislation by reason of the nature of that provision. After the Parties discover that any provision of this Agreement or any part thereof is invalid, ineffective or unenforceable, the Parties shall replace the invalid, ineffective and/or unenforceable provision of the Agreement or part thereof without undue delay with a new provision that respects the purpose of this Agreement.
ANNEX NO. 1 TO THE DATA PROCESSING AGREEMENT
The Processor's internal technical and organisational measures to ensure an appropriate level of protection for the personal data processed
BILVAO s. r. o. uses the professional cloud services Render, Wasabi and iPodnik to host its web application and the POHODA accounting software and to back up data. All data are stored exclusively in certified data centres located within the European Union. This solution ensures the highest possible availability, reliability and maximum security of the data processed, in accordance with the GDPR and other relevant standards.
Application hosting – Render
Server location and infrastructure
The company's application is hosted in Render's modern, certified data centres in the EU.
The data centres hold SOC 2 Type II certification, ensuring rigorous compliance with security requirements.
Data security
All data are securely encrypted in transit using the TLS/SSL protocol and at rest using AES-256 encryption.
Render provides a multi-layered security architecture, including automatic protection against DDoS attacks, firewall protection and regular security updates.
Independent security audits are regularly conducted by external specialists to detect and eliminate potential risks at an early stage.
Availability and reliability
Render guarantees high availability (99.9% uptime), with computing resources automatically scaled to current requirements.
The service is protected by redundant systems and geographic redundancy to increase resilience to outages.
The IT department continuously monitors application performance and system resources and responds immediately when problems are identified.
Regular load testing ensures reliability even when user demand increases.
Data backup – Wasabi
Storage locations
Data are securely backed up to Wasabi cloud storage, with all data repositories located exclusively in certified data centres within the EU, in full compliance with the GDPR.
Backup security
All backed-up data are encrypted at rest using AES-256 and in transit using TLS/SSL, thereby ensuring maximum security and protection against unauthorised access.
Access to backups is strictly limited to authorised members of the company's IT department.
Access authentication is secured by two-factor authentication (2FA).
Regular backups
Data are backed up automatically every day under a defined retention policy that ensures backups are retained for at least 90 days.
All backup procedures are logged and regularly evaluated by the IT department.
Comprehensive data-recovery tests are conducted monthly to verify the availability, integrity and functionality of the backup systems.
Hosting of accounting software – iPodnik Pohoda
Server location and infrastructure
The POHODA accounting software is hosted through the iPodnik cloud solution, which uses certified data centres located within the European Union.
iPodnik ensures compliance with all GDPR requirements and applicable European standards.
Security and reliability
Data within the iPodnik service are protected by encryption in transit and at rest.
Access to the software and data is protected by multi-level authentication and rigorous access-rights management.
iPodnik provides high service availability (99.9% uptime), with regular security audits and updates.
Data backup
Backups of data within the POHODA accounting software are fully managed by iPodnik, which provides regular daily backups and data-recovery testing.
iPodnik is responsible for monitoring and overseeing the backup processes.
Backup monitoring and management (Render, Wasabi)
Monitoring
The IT department continuously monitors backup status and performs regular daily checks to verify the integrity and completeness of the backups made.
Automated notifications alert the IT department to any deviations or problems in the backup process.
Documentation and records
Each backup is documented in detail, including comprehensive records of the time of creation, size and all related parameters.
Backup records and history are retained for at least 12 months for audit and retrospective review purposes.
Access audits
All operations and access activities associated with backups are systematically logged, regularly reviewed and archived.
The IT department conducts quarterly internal audits of backup security and access rights.
The web application of BILVAO s. r. o. provides clients with efficient and secure access to accounting data and information. The company places the utmost emphasis on securing the web application and protecting data through the following measures:
In-house development: The application is developed by an in-house team of specialists at BILVAO s. r. o., which regularly tests and updates the software.
Two-factor authentication (2FA): Mandatory for all application users, with verification available through e-mail notifications or the Google Authenticator application.
Data encryption: All data are encrypted both in transit (TLS/SSL certificates) and at rest (AES-256), ensuring maximum protection for sensitive information.
Flexible access management (Role-Based Access Control – RBAC): Users are assigned access rights on the basis of their specific role in the company, thereby minimising the risk of unauthorised access to sensitive data.
Regular maintenance and updates: The application software and infrastructure are regularly updated in line with the latest security standards.
Hosting on the secure Render platform: The application is hosted in data centres within the European Union that meet all GDPR requirements and hold SOC 2 Type II certification.
Protection against cyberattacks: Automated protection against DDoS attacks and the firewall in place protect the application against cyber threats.
External security audits: The application regularly undergoes independent security audits, ensuring that security is continuously evaluated and strengthened.
Security incident monitoring: The IT department continuously monitors all access and activity within the application, and every incident is addressed immediately.
Management of access rights for the Controller's representatives in the web application
The Processor shall create user accounts in the web application for the Controller's representatives and grant them access after the Main Agreement has been signed.
The Controller is responsible for, and shall ensure, that access rights to the web application and the assigned passwords are secured and that security measures governing use of the application are implemented on the Controller's side.
The Controller shall be responsible for unauthorised access to the application and/or security incidents occurring on the Controller's side.
The administrator shall regularly review and update users' access rights and shall remove all access rights from a user no later than 24 hours after the end of their engagement or a change in their position.
Every change to access rights shall be recorded in writing, archived and regularly reviewed.
All users of the web application shall comply with these rules and security measures. Failure to comply with these rules may result in restricted access to the application and further disciplinary measures.
BILVAO s. r. o. uses Google Workspace as its principal platform for efficient internal and external communication, organisation of work activities, collaboration among employees, document management and secure hosting of client data. The following services are used as described below:
Gmail:
Provides secure e-mail communication with internal employees, clients and external partners.
All e-mail accounts are protected by encryption and anti-spam measures.
Employees receive regular training on identifying and handling suspicious e-mails, phishing threats and malicious content.
Google Drive:
A central cloud repository enabling secure storage, sharing and real-time collaboration on documents and data.
All data are stored in encrypted form, and access is controlled on the basis of roles and permissions.
Enables document versioning and provides a transparent history of changes and edits.
Google Meet:
Used for secure video conferences, online meetings, webinars and training for employees, clients and business partners.
Meetings are protected by access codes and secured through encrypted communications.
Google Calendar:
Used to schedule work meetings, coordinate appointments and reserve resources such as meeting rooms or other company resources.
Access to individual calendars is controlled according to work roles in order to ensure the privacy and confidentiality of scheduled meetings.
Google Forms:
Creation of forms to collect information from clients for the purpose of updating data or obtaining feedback.
Google Sheets:
Recording client data, financial analyses, reports and automated data collection.
Google Docs:
Creation of document templates, agreements and internal policies, and real-time collaboration among multiple employees.
Google Chat / Spaces:
Internal team communication, rapid exchange of information, coordination of work and handling client matters.
Google Keep:
Shared notes for recording deadlines, important updates and the rapid distribution of information within the team.
AppSheet:
Rapid no-code development of bespoke internal applications for asset records, client management or project management.
Google Tasks:
Planning, assigning and tracking completion of tasks within the team for effective workflow management.
BILVAO s. r. o. implements robust security measures to protect data managed through Google Workspace:
Access-rights management:
Access to data and documents is strictly managed according to work roles, thereby minimising the risk of unauthorised access.
Access permissions are reviewed quarterly by the IT department.
Access-management controls:
The IT department conducts quarterly audits of access rights and activities using automated tools and manual checks.
Revoking and changing access:
Upon termination of an employee's employment or a change in their position, the IT administrator shall change or revoke the relevant access rights within 24 hours.
All changes are recorded and archived in Google Sheets and are reviewed regularly each month.
Mandatory two-factor authentication (2FA):
All employees use 2FA when accessing Google Workspace.
Data encryption:
All data are encrypted in transit (TLS/SSL) and at rest on Google's servers in the EU.
Regular data backup and recovery:
Data are backed up automatically every day, with regular monthly recovery tests. Backups are available for at least 90 days.
Activity and incident monitoring:
The IT department continuously monitors access logs and archives them for 12 months.
Regular security updates:
Security policies and settings are updated quarterly in line with the latest standards.
BILVAO s. r. o. approaches data security with the utmost responsibility and care:
Data encryption: All data are protected by advanced encryption technologies (AES-256, TLS/SSL) both in transit and at rest.
Two-factor authentication (2FA): Mandatory in all systems in which sensitive data are handled.
Access-rights management: Strict and thorough configuration of access permissions according to employees' work roles, with regular reviews and updates.
Monitoring and security audits: Continuous monitoring of the IT environment, regular internal and external audits, and thorough documentation of all activities.
Automatic backups: Daily automated backups with monthly data-recovery testing minimise the risk of data loss.
IT administrator: Responsible for managing and overseeing all IT operations, securing data, monitoring systems and performing data recovery.
Employees: Required to comply fully with all internal policies, rules governing the use of IT services and security guidelines, thereby contributing to the company's overall security and integrity.
Through its comprehensive system of IT management and security measures, BILVAO s. r. o. provides maximum efficiency, security and trustworthiness in its services, thereby guaranteeing the satisfaction and trust of its clients.
BILVAO s. r. o. adopts, at personnel and organisational level, in particular, the following security measures:
it verifies the accuracy of the documents submitted and ensures the appropriate selection of employees, particularly employees responsible for processing personal data;
it ensures that authorised persons have been demonstrably instructed on the Data Protection Legislation, the company's internal policies and the company's personal data processing procedures;
it ensures that authorised persons, processors and other recipients of personal data return the personal data and comply with the confidentiality obligations arising from agreements entered into or authorisations granted;
it withdraws access to personal data from authorised persons, processors and other recipients when the reason for processing ends (e.g. termination of employment or business cooperation);
it ensures that personal data are retained solely for the period necessary to fulfil the purpose of processing;
it ensures that the company’s employees, processors, other recipients of personal data and data subjects are prepared in advance for security incidents;
it clearly and unambiguously identifies the employees/categories of employees (or other persons acting as authorised persons) who process personal data;
it ensures that the processing of and access to personal data is restricted to a group of authorised persons, an up-to-date record of whom is maintained by the company at all times;
it ensures that personal data are processed solely by authorised persons competent to do so;
it defines staff activity plans, objectives and duties, especially for authorised persons.