Data Processing Agreement
Last updated: September 30, 2026
1.Subject and Purpose of the Agreement
1.1.The Client, as the Controller, and Ybug s.r.o., ID no.:06947182, with registred office at Nove sady 988/2, Stare Brno, 602 00 Brno, Czech Republic, as the Processor, cooperate on the basis of agreed Terms of Use, under which the Processor provides the Controller with the Ybug service (hereinafter as “Service”). Within such cooperation personal data are or may be transferred, when purpose of processing thereof and funds for such processing are determined and provided by the Controller and the Processor further processes the Personal Data for the Controller within this Data Processing Agreement.
1.2.This Agreement defines rights and duties of the Parties during such Personal Data processing under the terms of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation). When the data processing is not subject to the Regulation, this agreement shall not apply.
2.Personal Data Processing
2.1.The Processor shall be entitled to process for the Controller the following Personal Data of Controller’s website users (hereinafter as “User”):
- Name and surname
- E-mail address
- IP and location
- Browser and operation system information
- other information provided by the User
(hereinafter referred to as the “Personal Data”).
2.2.The Processor shall process the Personal Data only for the purpose of providing Service and only on documented instructions from the Controller. The Processor takes into account that in the case of breach of this provision the Processor shall be considered as a controller of Personal Data.
2.3.The Controller makes the Personal Data accessible to the Processor by the means of the Service, i.e. the Ybug software is run, stored and backed up on the Processor’s data servers and any interaction made by the Users within the Ybug software is being processed by the Processor.
2.4.The Controller instructs the Processor to retain Personal Data for the account’s lifetime unless the Controller sets a shorter retention period or instructs earlier deletion, and remains responsible for reviewing whether retention is necessary for its processing purposes. Cancelling a paid subscription does not delete the account or its data. Account deletion or termination of the Services triggers the return and deletion provisions below.
3.Rights and Duties of the Contracting Parties
3.1.The Processor undertakes to implement and maintain appropriate technical and organisational measures to protect the Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access. Having regard to the state of the art and cost of their implementation, as well as the nature, scope, context, and purposes for Processing the Personal Data the Processor agrees that such measures shall ensure a level of security appropriate to the risks to and the nature of the Personal Data. Annex 1 (Technical and Organisational Measures) forms part of this Agreement and shall be provided by the Processor to the Controller on request. The Processor may update the measures to reflect technical progress without reducing the overall level of protection of Personal Data.
3.2.The Processor also undertakes:
- (a)to process the Personal Data only in such form, in which they were transferred to it by the Controller;
- (b)to process the Personal Data only for the purpose defined hereby and solely to the extent necessary for fulfilment of such purpose;
- (c)not to merge Personal Data obtained for different purposes;
- (d)to keep the Personal Data only for the period set by the Controller;
- (e)to notify the Controller of any personal data breach without undue delay and within 72 hours of becoming aware of it, providing the information required by Article 33(3) of the Regulation as available and further information as it becomes available; to immediately mitigate risks to Personal Data upon discovery and provide full and prompt assistance and cooperation with the Controller’s investigation and compliance with Articles 33 and 34;
- (f)taking into account the nature of the processing, to assist the Controller through appropriate technical and organisational measures, insofar as possible, in responding to data subject requests under Chapter III of the Regulation, including requests for access, rectification, erasure, restriction, portability and objection; to forward any such request received directly to the Controller without undue delay and respond only on its instructions;
- (g)taking into account the nature of the processing and the information available to the Processor, to assist the Controller in complying with Articles 32 to 36 of the Regulation;
- (h)to immediately inform the Controller if, in the Processor’s opinion, a Controller instruction infringes the Regulation or other EU or Member State data protection law.
For assistance under points (f) and (g), the Controller shall primarily use the Service’s self-service features, including deletion, export and retention settings. The Processor may charge reasonable costs for additional assistance, except under point (e) for breaches caused by the Processor or its Sub-processors.
3.3.The Processor shall ensure that employees and other persons authorised to process Personal Data do so only within the scope and purpose of this Agreement and the Regulation, and are bound by a confidentiality commitment or an appropriate statutory duty of confidentiality. Confidentiality obligations continue after their engagement ends.
3.4.The Processor and the Controller undertake to observe, when processing the Personal Data on the basis hereof, duties set by the Regulation and other generally binding legal regulations relating to such activities.
3.5.The Processor undertakes upon the Controller´s call to repair, update, delete or transfer the Personal Data under the Controller´s instruction without undue delay after such call.
3.6.When fulfilling the duties herefrom the Processor shall be obliged to proceed with professional care, observe the Controller´s instructions and act in accordance with interests of the Controller.
3.7.The Controller agrees that the Processor shall be entitled to charge another processor with processing of the Personal Data without additional express particular permission of the Controller (hereinafter referred to as the “Sub-processor”). The Processor shall inform the Controller on all Sub-processors that it intends to charge with processing of the Personal Data and thus it provides the Controller with opportunity to express its objections to admission of such Sub-processors. If the Controller does not express its objections to the Sub-processors within three business days, the Processor shall be entitled to charge such Sub-processor with processing of the Personal Data. If the Processor involves the Sub-processor so that it carried out certain processing activities, the same duties for protection of the Personal Data must be imposed on the Sub-processor by an agreement, as are stated in this Agreement and in the Regulation. If the mentioned Sub-processor does not fulfil its duties regarding the data protection, the Processor shall be liable to the Controller for fulfilment of the duties of such Sub-processor.
The Processor currently charges with processing these following Sub-processors:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
- Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland
- BunnyWay d.o.o., Škofjeloška cesta 13, 1215 Medvode, Slovenia
- Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855, Luxembourg
3.8.The Processor undertakes to provide the Controller with any and all information necessary for proving that the duties stipulated by this Agreement or by the Regulation relating to the personal data were fulfilled and allow the Controller or third party bound towards the Controller by duty of confidentiality, to carry out an audit in the reasonable scope. Such audit must be notified well in advance, at least 30 days in advance and it must not intervene unreasonably in the Processor’s activities. Controller and Processor bear their costs related to such Audit.
3.9.The Processor shall not transfer Personal Data outside the EU except on the Controller's documented instructions, including when the Controller authorizes a connection to a third-party service. Any such transfer must comply with applicable data protection law. The Processor shall ensure that Sub-processor transfers outside the EU are covered by a European Commission adequacy decision (including the EU-U.S. Data Privacy Framework) or its standard contractual clauses.
4.Term of the Agreement
4.1.This Agreement applies throughout the Services contract and for as long as the Processor retains Personal Data on the Controller’s behalf, including backups, even after cancellation of a paid subscription.
4.2.On account deletion or termination of the Services, the Processor shall, at the Controller’s choice, return or delete Personal Data and delete existing copies without undue delay, unless EU or Member State law requires retention. Backup copies shall expire under Annex 1 within 90 days of deletion from operational systems, remaining protected by this Agreement and used only for disaster recovery until expiry.
5.Final Provisions
5.1.Any change or amendment hereto must be agreed on by both Contracting Parties.
5.2.Invalidity of any of provisions hereof shall not affect validity of other provisions hereof.
5.3.The Contracting Parties undertake to provide each other with all the necessary assistance and data to secure effective implementation hereof, in particular in the case of dealing with the Office for Personal Data Protection or other public authorities.
5.4.In the case that the contractual relation established hereby contains an international element, the Parties agree that this Agreement shall be governed by the Czech law.
5.5.In the case of disputes arisen herefrom, the Contracting Parties agree that all disputes shall be resolved by competent courts in the Czech Republic.
Need a signed copy? Click here to download the pre-signed DPA.