Data Processing Agreement
Last updated: June 26, 2026
This Data Processing Agreement (DPA) forms part of the agreement between the organization using the ACTE123 organizations feature (the Controller) and ACTE123 (the Processor). It governs the processing of personal data carried out by ACTE123 on the organization's behalf, in accordance with Article 28 GDPR.
In Brief
- ACTE123 acts as your processor; your organization remains the controller of your clients' data.
- We process data only on your documented instructions, never for our own purposes.
- Sub-processors (Supabase, Vercel, Resend) are listed and bound by equivalent obligations.
- We help you meet data-subject requests, breach notifications, and impact assessments.
- On termination, we return or delete the data at your choice.
1. Parties and Roles
For personal data processed through the ACTE123 organizations feature, the organization is the data controller and ACTE123 is the data processor (GDPR Art. 4(7)-(8)). For ACTE123's own platform operations, and for individual (non-organization) users, ACTE123 acts as controller under its Privacy Policy.
2. Subject Matter and Duration
The subject matter is the processing of personal data necessary to provide the organizations feature β preparing and managing administrative-procedure plans and documents for the organization's clients. Processing lasts for the duration of the organization's use of the feature and until data is returned or deleted under Section 11.
3. Nature and Purpose of Processing
ACTE123 processes personal data to host, store, organize, and make available the plans, requirements, and documents that the organization and its clients create or upload, and to provide related features such as document matching and package preparation. Processing is limited to these purposes.
4. Categories of Data and Data Subjects
Depending on how the organization uses the platform, processing may involve:
- Data subjects: the organization's clients and its members (employees).
- Identification data: names, contact details, and national identification numbers (CNP) where provided.
- Documents: identity and administrative documents uploaded to the Vault (end-to-end encrypted).
- Plan data: selected procedures, requirement progress, notes, and statuses.
5. Processor Obligations
ACTE123 undertakes to:
- process personal data only on the controller's documented instructions, including for transfers, unless required by law (Art. 28(3)(a));
- ensure persons authorized to process the data are bound by confidentiality (Art. 28(3)(b));
- implement the security measures required by Art. 32 (Section 6);
- respect the conditions for engaging sub-processors (Section 7);
- assist the controller with data-subject requests, security, breach notification, and impact assessments (Sections 8-10);
- at the controller's choice, return or delete the data at the end of the service (Section 11);
- make available the information necessary to demonstrate compliance and allow for audits (Section 12).
6. Security Measures (Art. 32)
ACTE123 maintains appropriate technical and organizational measures, including:
- end-to-end (zero-knowledge) encryption of Vault documents β the server cannot read document contents;
- encryption in transit (TLS) and encryption at rest for sensitive tokens;
- row-level security and application-level access controls;
- restriction of access to authorized maintainers, with audit logging of administrative actions.
7. Sub-processors
The controller provides a general authorization for ACTE123 to engage the following sub-processors, each bound by data-protection terms equivalent to this DPA. ACTE123 will inform the controller of intended changes and give the opportunity to object:
- Supabase β authentication, database, and file storage (EU-hosted);
- Vercel β hosting and deployment (US, under Standard Contractual Clauses);
- Resend β transactional email delivery (US, under Standard Contractual Clauses).
8. Assisting with Data-Subject Rights
Taking into account the nature of the processing, ACTE123 assists the controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the controller's obligation to respond to requests to exercise data-subject rights (Art. 15-22). Self-service export and deletion tools are available to the controller and to individual users.
9. Personal Data Breach
ACTE123 notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, and assists the controller in meeting its Art. 33-34 obligations. ACTE123's internal procedure is described in BREACH_RESPONSE.md.
10. Impact Assessments and Prior Consultation
ACTE123 provides reasonable assistance to the controller with data protection impact assessments and prior consultations with the supervisory authority (Art. 35-36), taking into account the nature of the processing and the information available to ACTE123.
11. Return and Deletion of Data
At the controller's choice, ACTE123 deletes or returns the personal data after the end of the provision of services and deletes existing copies, unless storage is required by law. Individual deletion and export tools remain available throughout the service.
12. Audits and Information
ACTE123 makes available to the controller the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates, subject to reasonable notice and confidentiality.
13. International Transfers
Where a sub-processor processes data outside the EU/EEA (for example Vercel and Resend in the US), transfers are protected by EU Commission-approved Standard Contractual Clauses and additional safeguards, in line with GDPR Chapter V.
14. Final Provisions
This DPA supplements the Terms and Conditions and the Privacy Policy. In case of conflict regarding the processing of the controller's personal data, this DPA prevails. It is governed by Romanian law and applicable EU legislation.
15. Contact
For questions about this DPA or to exercise controller rights, contact us at [email protected].