01Parties and roles
Controller: the client identified in the client account, in the quote, or in the signed paper version (the “controller”). Processor: LISTIFY s.r.o., Company ID: 04198042, with its registered office at Rybná 716/24, Staré Město, 110 00 Prague 1, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 243995 (“Listify”).
This agreement is entered into under Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”) and Act No. 110/2019 Coll., on Personal Data Processing. Terms have the meanings given to them in the GDPR (in particular personal data, processing, controller, processor, and personal data breach).
02Subject matter, nature, and purpose of processing
Listify processes personal data on behalf of the controller only to the extent necessary to perform projects and ongoing services under accepted quotes. The nature of the processing includes, in particular:
- development, testing, and deployment of websites, online stores, applications, and systems,
- management and operation on the client's infrastructure or with a provider chosen by the client, backups, monitoring, and security updates,
- support and handling of requests, including access to data when fixing bugs,
- data import and migration, and integration with the controller's other systems,
- setting up analytics and marketing tools within the scope of the project.
03Duration of processing
Processing lasts for as long as services are provided under accepted quotes and, after that, only for the time needed to return or delete the data under the article on termination.
04Categories of data subjects and personal data
The specific scope follows from the project, and the controller may specify it further in the quote or in the client account. It typically covers:
- data subjects: the controller's customers, users, website visitors, prospects, subscribers to marketing communications, business partners, and employees,
- identification and contact data, delivery and billing data,
- data on orders, payments (excluding full payment card numbers), contracts, and communications,
- login credentials in encrypted form and user account data,
- technical and operational data: IP addresses, device identifiers, cookies, logs, and data on website behavior.
Listify processes special categories of data (for example, health data) and children's data only if the controller expressly specifies this in advance and the parties agree on additional safeguards.
05Controller's instructions
Listify processes data only on documented instructions from the controller, including with regard to transfers to third countries. Documented instructions consist of this agreement, accepted quotes and their specifications, service configurations, and requests submitted in the client account or by email by a person authorized to act on behalf of the controller.
If, in Listify's opinion, an instruction infringes the GDPR or other legislation, Listify will inform the controller without delay and need not carry it out until the matter is clarified. If Listify is required by law to process data, it will inform the controller in advance, unless the law prohibits this.
06Controller's obligations
The controller is responsible for ensuring that:
- it has a valid legal basis for the processing and the processing complies with the GDPR,
- it has properly informed data subjects and, where applicable, obtained their consent (including consent to cookies),
- its instructions comply with the law, and the data it provides to Listify is accurate and was lawfully obtained,
- it notifies Listify in good time of changes that affect the processing (new categories of data, new purposes, requirements of the supervisory authority).
07Confidentiality and authorized persons
Only Listify staff and subcontractors who need access to personal data for performance, have been trained in data protection, and are bound by confidentiality have access to it. The confidentiality obligation continues after this agreement ends and after the employment or other relationship ends.
08Security
Listify implements technical and organizational measures under Article 32 of the GDPR that are appropriate to the nature of the data and the risk. It regularly evaluates and improves these measures. They include, in particular:
- encrypted transmission (HTTPS/TLS) and encryption of backups and sensitive data at rest,
- role-based access control following the principle of least privilege, two-factor authentication, regular access reviews, and removal of access when a staff member leaves,
- storage of production data and databases with Vercel Inc. (application hosting) and Neon Inc. (PostgreSQL databases), for clients from the Czech Republic and Slovakia primarily in the Frankfurt region (Germany, EU), and for projects aimed at other countries in the region closest to their users, usually under the controller's account; storage outside the EU only with the controller's consent under the article on transfers outside the EU; access by Listify only within the scope of the project,
- automatic database backups by Neon, with restore to any point in time within the configured retention period,
- regular backups stored separately, restore testing, and a disaster recovery plan,
- security updates, availability and vulnerability monitoring, and access logging within the scope of the agreed maintenance service,
- separation of test and production environments; in test environments, we use anonymized or fictitious data where possible,
- secured work devices (encrypted drives, screen lock, password manager).
09Artificial intelligence tools
Listify does not enter the controller's personal data into artificial intelligence tools that could use it to train models or make it available to others. It uses AI tools with personal data only under settings that exclude this, and only where needed for the project; such a tool is then a sub-processor under this agreement.
10Sub-processors
The controller gives general authorization to engage sub-processors. As of the effective date of this agreement, they are:
- Vercel Inc.: hosting of websites, applications, and the client account, and file storage (Vercel Blob); data in the EU (Frankfurt); EU-U.S. Data Privacy Framework.
- Neon Inc.: PostgreSQL databases and their backups; data in the EU (Frankfurt); EU-U.S. Data Privacy Framework.
- Functional Software, Inc. (Sentry service): application error reporting; data in the EU.
- Plus Five Five, Inc. (Resend service): email delivery; processing in the USA based on the EU-U.S. Data Privacy Framework and standard contractual clauses.
- OpenAI (ChatGPT), Anthropic (Claude), and GitHub (Copilot): artificial intelligence tools in business editions that do not use data to train models; processing in the USA based on the EU-U.S. Data Privacy Framework and standard contractual clauses.
Vercel and Neon act as sub-processors only where Listify holds the account with them (the client account and smaller projects as agreed in the quote). If the account is held in the controller's name, the controller has a direct contract with the provider. The current list is also always available in the client account.
Listify will announce the engagement or replacement of a sub-processor in the client account at least 30 days in advance. The controller may raise a reasoned objection within 14 days; the parties will then seek a solution, and if they cannot agree, the controller may terminate the affected service without penalty.
Listify binds its sub-processors by contract to the same data protection obligations as those set out in this agreement and is liable for them as if it were processing the data itself.
11Transfers outside the EU
We store personal data primarily in the EU. We use services that also process data in the USA (email delivery and artificial intelligence tools) only on the basis of a European Commission adequacy decision (EU-U.S. Data Privacy Framework) or the European Commission's standard contractual clauses, with supplementary measures where appropriate. We store the controller's databases and files outside the EU only with its prior consent.
12Data subject rights
Listify assists the controller, through appropriate technical and organizational measures, in handling data subject requests (access, rectification, erasure, restriction of processing, portability, objection), usually within 5 business days of the controller's request. Listify forwards any request it receives directly to the controller without delay and does not respond to its substance unless the controller authorizes it to do so.
13Assistance with the controller's obligations
Taking into account the nature of the processing and the information available to it, Listify assists the controller in ensuring security, notifying personal data breaches, carrying out data protection impact assessments, and conducting prior consultations with the competent supervisory authority (Articles 32 to 36 of the GDPR).
Listify charges for assistance beyond normal operations (for example, large-scale exports, impact assessments, or extraordinary audits) at the hourly rate stated in the quote, after the controller has approved an estimate in advance. Listify does not charge for assistance required as a result of its own breach of obligations.
14Personal data breach
Listify will notify the controller of a personal data breach without undue delay, and no later than 24 hours after discovering it, by phone or email to the contact person and by a message in the client account. The notification will include, to the extent the information is available:
- a description of the nature of the breach, the categories concerned, and the approximate number of data subjects and records,
- the likely consequences,
- the measures taken or proposed to address the breach and mitigate its effects,
- contact details of the person at Listify handling the breach.
Where information is not immediately available, Listify provides it in phases as it becomes available. This enables the controller to meet its obligation to notify the supervisory authority of the breach within 72 hours and, where applicable, to inform data subjects (Articles 33 and 34 of the GDPR). Listify does not itself notify the authority or data subjects of the breach unless the controller instructs it to do so or the law requires it.
15Records and demonstrating compliance
Listify maintains records of processing activities carried out on behalf of the controller under Article 30(2) of the GDPR and, on request, provides the controller with the information needed to demonstrate that it complies with its obligations under this agreement and Article 28 of the GDPR.
16Audits and inspections
The controller, or an independent auditor it appoints who is bound by confidentiality, may conduct an audit no more than once every 12 months, with at least 30 days' prior notice, during business hours, and without disrupting the operations or security of other clients. Audits are preferably conducted by questionnaire and by reviewing documentation and certifications.
The controller bears the costs of the audit; Listify charges for its time at the hourly rate stated in the quote. If the audit reveals a material breach of this agreement, Listify bears the costs and remedies the breach free of charge. An extraordinary audit is possible after a personal data breach or at the request of the supervisory authority. This does not limit inspections by the supervisory authority.
17Termination, return, and deletion
When the provision of services ends, Listify will, at the controller's choice, return the data in a machine-readable format or delete it, within 60 days at the latest. If the controller does not respond within 30 days of the end of the services, Listify will delete the data. Copies in backups are deleted through backup rotation within 90 days at the latest; until then, they remain protected by this agreement and are not used.
Listify retains data it is required to keep by law only for as long as necessary and only for that purpose. Listify will confirm deletion in writing on request.
18Liability
Each party is liable for damage it causes by breaching the GDPR or this agreement, in accordance with Article 82 of the GDPR. Listify is liable only if it has failed to comply with obligations that the GDPR imposes specifically on processors or has acted outside or contrary to the controller's instructions.
The limitation of liability under Listify's Terms and Conditions applies to the extent permitted by law; it does not apply to claims by data subjects. Fines imposed by the supervisory authority are borne by the party whose breach led to them.
19Term and termination of the agreement
This agreement is effective upon signature and remains in force for as long as Listify processes personal data for the controller. It cannot be terminated separately while the services involving the processing continue. Obligations relating to confidentiality, return, and deletion survive its termination.
20Conclusion of the agreement
This agreement may be concluded in the client account, by accepting a quote to which it is attached, or by signing a paper or electronically signed version. A confirmation in the client account after logging in with personal login credentials constitutes a signature within the meaning of Section 561(1) of Act No. 89/2012 Coll., the Czech Civil Code, and an electronic signature under the eIDAS Regulation. We record the person's name and role, the date and time, the IP address, the device, and the version of the agreement; the agreement remains permanently available in the client account.
The person signing this agreement represents that they are authorized to act on behalf of the controller.
21Relationship to other documents and changes
This agreement supplements Listify's Terms and Conditions and accepted quotes and supersedes any previous arrangements between the parties on personal data processing. In matters of personal data protection, it takes precedence over the Terms and Conditions, quotes, and the Non-Disclosure Agreement.
We announce changes in the client account and by email at least 30 days in advance; until a change takes effect, the controller may terminate the affected services without penalty. A change required by law or by a decision of an authority may take effect sooner.
22Governing law and final provisions
This agreement is governed by the laws of the Czech Republic and the GDPR. Disputes will be resolved by the court determined under Listify's Terms and Conditions. If any provision is invalid or ineffective, the remaining provisions remain in force, and the parties will replace it with a provision that best reflects the GDPR and the purpose of this agreement.