Data Processing Agreement

This Data Processing Agreement (the Agreement) is entered into under Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (the GDPR) between Forgmatic, with registered office at Orechov 88 59452 Orechov, company ID No. (IČO) 07924925, the operator of the Forgmatic software service (the Operator or Processor), and the business that has set up the service (the Customer or Controller).

This Agreement forms an integral part of the service terms of use and is concluded electronically by accepting it during registration. The Operator records the moment of acceptance, the exact wording and its fingerprint (hash).

1. Roles of the parties and scope

1.1 The Customer is the controller of the personal data of the persons whose data it enters into the service or whose data arise from the operation of its shop — in particular the data of its customers, enquirers and newsletter subscribers.

1.2 The Operator processes those data as a processor for the Customer, solely for the purpose of providing the service.

1.3 This Agreement does not apply to data for which the Operator itself is the controller — in particular the Customer's registration and billing data and the data of its users, operational records of service usage, and data processed to secure the platform. Their processing is described in the Operator's privacy policy.

2. Subject matter, nature and purpose of processing

2.1 The subject matter of the processing is the operation of an online shop and a custom-manufacturing configurator on the Operator's infrastructure: storing, displaying, transmitting in the course of order fulfilment, backing up and deleting personal data.

2.2 The purpose of the processing is the provision of the service to the Customer within the scope of the features the Customer has chosen. The Operator does not process the data for its own purposes, does not build profiles from them and does not disclose them to third parties beyond this Agreement.

2.3 A detailed description of the processing (categories of data subjects and categories of data) is set out in Annex 1.

3. Duration

3.1 The processing lasts for the duration of the service terms of use. Upon their termination, Section 9 applies.

4. Controller's instructions

4.1 The Operator processes personal data only on the Customer's documented instructions. Documented instructions means this Agreement, the service configuration made by the Customer in the administration, and the use of the service's features by the Customer or its users (including the API).

4.2 Where processing beyond those instructions is required by European Union or Member State law to which the Operator is subject, the Operator shall inform the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.

4.3 If the Operator considers an instruction to infringe the GDPR or other data protection provisions, it shall inform the Customer without undue delay.

5. Confidentiality

5.1 Access to personal data is limited to persons who strictly need it to perform this Agreement. Those persons are bound to confidentiality by contract or are under an appropriate statutory obligation of confidentiality; the obligation survives the end of their relationship with the Operator.

6. Security of processing

6.1 The Operator has adopted and maintains technical and organisational measures appropriate to the risk within the meaning of Article 32 GDPR. Their current description is set out in Annex 2.

6.2 The Operator continuously evaluates and develops the measures. No change of measures may reduce the overall level of security agreed in this Agreement.

7. Sub-processors

7.1 The Customer grants the Operator a general authorisation to engage further processors (sub-processors) for partial processing activities — in particular hosting, file storage, e-mail delivery, payment processing and error monitoring.

7.2 The Operator maintains and publishes the current list of sub-processors, including the country of processing and the transfer tool for third-country transfers, on the sub-processor list page available from the service footer (path /subprocessors). The list states the date of its last change; removed sub-processors remain on it marked as inactive.

7.3 The Operator shall give notice of any intended addition or replacement of a sub-processor by publishing it on that list at least 14 days before the engagement. The Customer may object to the change on data protection grounds; if no agreement is reached, the Customer may terminate the service terms of use as of the day the new sub-processor is engaged. Continued use of the service after the notice period is deemed approval of the change.

7.4 The Operator imposes on every sub-processor, by contract, data protection obligations at least equivalent to those of this Agreement, and remains fully liable to the Customer for the sub-processor's performance as if it performed itself.

8. Assistance

8.1 Data subject rights. The Operator assists the Customer in fulfilling its obligation to respond to data subjects' requests (Articles 12–22 GDPR), primarily through the service's features: data export in a machine-readable format, rectification in the administration, and erasure or anonymisation on request. If the Operator receives a data subject request concerning processing for which the Customer is the controller, it shall forward it to the Customer without undue delay and shall not respond on the merits itself.

8.2 Personal data breach. If the Operator becomes aware of a breach of security of personal data processed for the Customer, it shall notify the Customer without undue delay, together with the information available to it that the Customer needs to comply with Articles 33 and 34 GDPR (nature of the breach, categories and approximate scale affected, likely consequences, measures taken). The information may be provided in phases.

8.3 Impact assessment and consultation. Upon request, the Operator shall assist the Customer with data protection impact assessments (Article 35 GDPR) and with prior consultation of the supervisory authority (Article 36 GDPR), taking into account the nature of the processing and the information available to it.

9. End of processing

9.1 Upon termination of the service terms of use, the Operator shall allow the Customer to download its organisation's data through a machine-readable export for a period of 30 days.

9.2 After that period, or earlier at the Customer's express request, the Operator shall delete the personal data, including copies in backups after their retention cycle expires. This does not apply to data whose storage is required by European Union or Member State law (in particular accounting and tax documents); the Operator shall retain those only for the statutory period and to the necessary extent, anonymising data beyond that extent.

10. Demonstrating compliance and audits

10.1 The Operator shall make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR — in particular the description of technical and organisational measures, the sub-processor list, and the records of export operations over the Customer's organisation data kept in the service's audit log.

10.2 The Customer may audit compliance with this Agreement at most once every 12 months (except in the case of a documented security breach, where this limit does not apply), upon written notice of at least 30 days, during normal business hours and in a manner that does not disrupt the operation of the service or the security of other customers' data. The auditor must not be a competitor of the Operator and is bound by confidentiality. The Customer bears the costs of the audit.

10.3 The Operator may satisfy an audit primarily by providing reports of independent reviews or certifications covering the subject of the audit, where available.

11. Transfers to third countries

11.1 Personal data are processed primarily within the European Economic Area. Where a sub-processor processes data outside the EEA, it does so solely on the basis of an adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR (in particular Standard Contractual Clauses), as stated for each of them on the list referred to in Section 7.2.

12. Liability

12.1 The parties' liability is governed by Article 82 GDPR and the liability provisions of the service terms of use; any agreed limitation of damages does not apply to liability towards data subjects or to fines imposed by a supervisory authority as a result of the other party's breach of this Agreement.

13. Final provisions

13.1 This Agreement is governed by the laws of the Czech Republic and by the GDPR.

13.2 The Operator may amend this Agreement by issuing a new version. It shall notify the Customer of the new version through the service or by e-mail at least 14 days before it takes effect; if the Customer does not agree, it may terminate the service terms of use as of the effective date of the new version. The version and the fingerprint of the accepted wording are recorded.

13.3 If any provision of this Agreement is or becomes invalid, the validity of the remaining provisions is not affected. In case of conflict between this Agreement and the service terms of use, this Agreement prevails in data protection matters.

Annex 1 — Description of processing

Categories of data subjects

  • customers and enquirers of the shop operated by the Customer, including guests with an in-progress cart,
  • contact persons of the Customer's business buyers,
  • subscribers to the Customer's newsletter,
  • senders of messages via the contact forms of the Customer's shop,
  • users invited into the service by the Customer (to the extent the Customer is their controller).

Categories of personal data

  • identification and contact data (name, e-mail, phone),
  • delivery and billing addresses,
  • data on orders, enquiries and quotations, including their history and related communication,
  • tax documents and the data they contain,
  • files uploaded to the configurator (drawings and manufacturing inputs) and any data they may contain,
  • records of consents given,
  • technical data necessary to provide the service (truncated IP address, session identifier).

Special categories of data (Article 9 GDPR) are not required by the service, and the Customer undertakes not to enter them into the service or allow them to be entered.

Annex 2 — Technical and organisational measures

  • encryption of data in transit (TLS, enforced HTTPS),
  • passwords stored exclusively as a strong cryptographic hash, never in readable form,
  • role-based access control; privileged roles with mandatory two-factor authentication,
  • application-level separation of individual customers' data, with tenant isolation verified by automated tests,
  • an audit log of sign-in events, administrative actions and export operations,
  • redaction of tokens and personal data in operational logs and error reports,
  • regular automated database backups and versioned file storage; a documented recovery procedure with a recovery time objective of 4 hours and a maximum data loss of 24 hours,
  • separation of development, test and production environments; testing without production personal data,
  • continuous security checks of dependencies and code within the development process, and a regularly refreshed internal security audit,
  • documented key and secret rotation procedures,
  • automated retention jobs deleting data after the defined periods expire.

Annex 3 — Sub-processors

The current list of sub-processors under Section 7 of this Agreement is maintained on the service's sub-processor list page (path /subprocessors) and forms an integral part of this Agreement.

Effective from: 2026-09-01