Legal

Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") forms part of the agreement between Infotech Solutions, s. r. o., Konopná 194/23, 027 44 Tvrdošín, Slovak Republic, IČO 56 660 308 ("Processor", "we") and the Customer ("Controller", "you") for the use of the Tamanor service (the "Agreement"). It governs processing of personal data carried out by us on your behalf and is concluded pursuant to Article 28 GDPR. Where a conflict arises, this DPA prevails over the Terms of Service in respect of data processing.

Last updated: 17 July 2026

This is early-product wording provided for transparency. It is not legal advice and will be finalized before general availability.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings in the GDPR (Regulation (EU) 2016/679).

2. Roles and scope

You are the Controller and we are the Processor for the personal data contained in content and author metadata ingested by Tamanor from your connected platform accounts and processed to provide the Service ("Customer Personal Data"). We process Customer Personal Data only on your documented instructions, including those given through configuration of the Service, unless required to act by EU or Member State law (in which case we inform you unless legally prohibited).

3. Subject-matter, duration, nature and purpose

Subject-matter: provision of the Tamanor reputation-moderation service. Duration: for the term of the Agreement plus the retention/return-and-deletion period. Nature and purpose: reading publicly available content via official platform APIs, AI-assisted risk classification, human-approval workflow, moderation actions you enable, reporting, and audit logging. Types of personal data: identifiers and display names of content authors, the content text/media metadata, ratings, permalinks, timestamps, and derived risk/sentiment labels. Categories of data subjects: authors of public comments/reviews/mentions on your accounts, and your own personnel who operate the Service. Special-category data is not intentionally requested; you must not configure the Service to process it as its primary purpose.

4. Processor obligations

We shall: (a) process Customer Personal Data only on your documented instructions; (b) ensure persons authorised to process are bound by confidentiality; (c) implement appropriate technical and organisational measures under Article 32 (see Annex 2 and our Security Policy); (d) respect the conditions for engaging sub-processors (Section 5); (e) assist you, taking into account the nature of processing, in responding to data-subject requests (Chapter III) and in meeting your obligations under Articles 32–36 (security, breach notification, DPIA, prior consultation); (f) at your choice, delete or return all Customer Personal Data after the end of provision and delete existing copies, unless storage is required by law; and (g) make available information necessary to demonstrate compliance and allow for and contribute to audits (Section 7).

5. Sub-processors

You provide general written authorisation for us to engage sub-processors listed in our Subprocessor List. We impose data-protection obligations on each sub-processor equivalent to those in this DPA by written contract and remain fully liable for their performance. We will give at least 30 days' prior notice of any intended addition or replacement of a sub-processor (via the Subprocessor List and/or e-mail), during which you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected part of the Service.

6. Data-subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise data-subject rights. If a data subject contacts us directly regarding Customer Personal Data, we will (unless legally required to act) refer them to you and forward the request without undue delay.

7. Audits

We will make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, no more than once per year (or more often following a substantiated incident), on reasonable prior notice, during business hours, subject to confidentiality and without compromising other customers' security. We may satisfy audit requests by providing current third-party certifications or reports where available.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to help you meet your notification obligations under Articles 33–34. Our internal handling follows our Incident & Breach Policy. We do not determine on your behalf whether you must notify the supervisory authority or data subjects.

9. International transfers

We will not transfer Customer Personal Data outside the EEA except in accordance with Chapter V GDPR. Where a sub-processor processes data outside the EEA, the transfer is covered by an adequacy decision and/or the Standard Contractual Clauses (2021/914) with a Transfer Impact Assessment, as set out in our International Transfers Notice, which forms part of the safeguards under this DPA.

10. Deletion and return

Upon termination or expiry, and at your choice, we will return and/or delete Customer Personal Data within a reasonable period (default: deletion within 30 days), except where EU or Member State law requires retention. Backups are overwritten in the ordinary backup cycle. Audit-log entries required for accountability may be retained in accordance with the Data Retention Policy.

11. Liability and precedence

Each party's liability under this DPA is subject to the limitations agreed in the Agreement, to the extent permitted by law. This DPA does not limit any rights of data subjects or supervisory authorities under the GDPR.

Annex 1 — Details of processing

Categories of data subjects, types of personal data, nature and purpose, and duration as described in Sections 2–3 above.

Annex 2 — Technical and organisational measures (Art. 32)

Encryption of OAuth tokens at rest and data in transit (TLS); pseudonymisation where feasible; strict multi-tenant isolation with database row-level security; role-based access control and least privilege; append-only, immutable audit logging; fail-safe/fail-closed defaults (no destructive default action; unsupported actions never simulated); signed and verified inbound webhooks; secrets held only server-side; regular backups; access logging and monitoring; vulnerability management; and staff confidentiality. Full description in the Security Policy and Information Security Statement.

Annex 3 — Approved sub-processors

As set out in the Subprocessor List in force from time to time.

Signatures. Acceptance of the Agreement and/or use of the Service constitutes acceptance of this DPA by both parties. A countersigned copy is available on request via info@tamanor.com.

Data Processing Agreement (DPA) — Tamanor