Legal information

Data Processing Agreement (DPA)

This data processing agreement (the "DPA") forms part of the Terms of Service and governs the processing of personal data carried out by the operator of the dashiox service on behalf of the user under Art. 28 of Regulation (EU) 2016/679 (GDPR). By accepting the Terms of Service the user also enters into this DPA.

Parties

  • Controller: the user of the service who connects platform accounts containing their own data or the data of their clients (agencies act as controller or as processor of their client; in that case the operator is a sub-processor).
  • Processor: the operator of the service Pavel Hladný
  • Processor legal form: sole trader registered under the Czech Trade Licensing Act
  • Processor Company ID (IČO): 02645351
  • Processor registered office: Nové sady 988/2, 602 00 Brno – Staré Brno, Česká republika
  • Processor privacy contact:

Personal data the operator processes about the users themselves (account, sign-in, billing) is processed by the operator as controller under the Privacy Policy; this DPA does not apply to it.

Subject matter

The subject matter of this DPA is the processing of personal data contained in the data of connected platforms (e.g. Google Ads, Google Analytics, Search Console, Merchant Center, Tag Manager; Meta and Sklik once their integrations are available) and in the data the user enters into the service (notes, client context), to the extent necessary to provide the service.

Duration

Processing lasts for as long as the user uses the service. After the account or workspace is deleted, the data is deleted as described in Return and deletion.

Nature and purpose of processing

  • Nature: retrieving data from the APIs of connected platforms on the user's instruction, storing it for a short time, processing it into reports and analyses, passing the results to the user's AI client (making changes in platform accounts is in preparation and will happen only after the user's explicit approval).
  • Purpose: providing the features of the service to the user (reports, analyses, checks). The processor does not use the data for any other purpose, in particular not for advertising or sale.

Categories of data and data subjects

  • Categories of data subjects: employees and collaborators of the user and of the user's clients (users of platform accounts), client contact persons and, where the platforms make it available, website visitors and customers of the clients.
  • Categories of data: identification and contact data of platform account users (name, e-mail), account identifiers, data on advertising campaigns and their performance, aggregated traffic and conversion data, product data. The service does not process special categories of personal data under Art. 9 GDPR; the user does not enter them into the service.

Obligations of the controller

The controller is responsible for having a legal basis for the processing, for being authorised to connect the platform accounts and to engage the processor, and for having informed the data subjects. The controller's instructions are given by these terms, the settings of the service and the actions the user runs and approves in the service.

Obligations of the processor

The processor:

  • processes personal data only on documented instructions from the controller, including with regard to transfers outside the EU/EEA, unless required to do so by EU or member state law (in which case it informs the controller in advance, unless that law prohibits it);
  • ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality;
  • takes the technical and organisational measures required by Art. 32 GDPR (see Security measures);
  • respects the conditions for engaging another processor (see Sub-processors);
  • informs the controller without delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

Sub-processors

The controller gives general authorisation to engage sub-processors. The current list is on the subprocessors page. The processor informs the controller of any intended change (adding or replacing a sub-processor) by e-mail or in the portal at least 30 days in advance; the controller may object to the change and, if the objection cannot be resolved, delete the account. The processor imposes the same data protection obligations as set out in this DPA on each sub-processor and remains liable for their performance. Platform providers (Google, Meta and others) and the AI client the user connects are not sub-processors of the operator – they are recipients on the controller's instruction, governed by the agreements between them and the controller.

Technical and organisational measures

  • encryption in transit (TLS) and encryption of platform access tokens at rest (AES-256-GCM);
  • logical separation of the data of individual workspaces and authorisation checks on every request, including database-level protection (row-level security);
  • sign-in with a password and mandatory two-factor authentication (TOTP), or sign-in with a verified Google account (sign-in security governed by the Google account), limited sign-in attempts, separate and audited administrator access;
  • masking of tokens and passwords in logs, an audit record of important actions;
  • regular, rotated backups, system updates and restricted network access to the servers;
  • no writes to platform accounts during the beta; once available, writes only after the user's explicit approval;
  • an overview of the measures is also on the Security page.

Assistance

The processor provides the controller with reasonable assistance in fulfilling its obligations, in particular in responding to data subject requests (access, rectification, erasure, portability), ensuring security, notifying personal data breaches, data protection impact assessments and prior consultation with the supervisory authority, taking into account the nature of processing and the information available to it. The controller can ask the processor to disconnect platforms or delete the account at any time by e-mail (and, once available, do so itself in the portal); the processor provides a data export on request.

Audit

On request, the processor makes available to the controller the information necessary to demonstrate compliance with Art. 28 GDPR and allows for audits or inspections conducted by the controller or an auditor mandated by the controller and bound by confidentiality. Audits must be announced at least 30 days in advance, take place during normal business hours, without disrupting operations and without access to other users' data; the controller bears the costs unless the audit reveals a material breach of this DPA.

Personal data breach

The processor notifies the controller of a personal data breach without undue delay after becoming aware of it, and no later than within 48 hours. The notification contains the information available to the processor: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The processor takes measures to mitigate the consequences without delay.

Return and deletion of data

When the provision of the service ends (deletion of the account or workspace), the processor makes the personal data inaccessible without undue delay and physically deletes it within 30 days at the latest, unless EU or member state law requires further storage. The data disappears from backups no later than 30 days after deletion from the production system. Before deleting the account, the controller can request a data export at .

Transfers outside the EU/EEA

The processor transfers personal data to third countries only on the controller's instruction (e.g. by connecting an AI client or platform based outside the EEA) or with appropriate safeguards under Chapter V GDPR, in particular an adequacy decision of the European Commission or standard contractual clauses. The processing location of each sub-processor is stated on the subprocessors page.

Final provisions

This DPA is governed by the law of the Czech Republic and remains in force for as long as the processor processes personal data on behalf of the controller. In case of conflict between this DPA and the Terms of Service, this DPA prevails in matters of data protection. Changes to this DPA are announced in the same way as changes to the Terms of Service.