This Data Processing Agreement ("DPA") is part of the Terms of Service between the company that uses Digital Specialist ("Customer") and Vladimir Kozlov, an individual, Srebrna St. 27B, entrance V, apt. 10, 1407 Sofia, Bulgaria ("Provider"). It applies whenever the Provider processes personal data on the Customer's behalf in providing the Service ("Customer Personal Data"), and meets Article 28 of the EU General Data Protection Regulation ("GDPR"). Accepting the Terms accepts this DPA; no separate signature is needed. It lasts as long as the Provider processes Customer Personal Data.
The Customer is the controller of Customer Personal Data and the Provider its processor. For the data it needs to run its own business — the account of the person who signs up, billing contacts, security logs and its website — the Provider is a controller, as described in the Privacy Policy.
The Provider processes Customer Personal Data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's use and settings of the Service (for example turning location sharing on, setting working hours, inviting or removing members). If EU or member-state law requires other processing, the Provider tells the Customer first unless that law forbids it. The Provider tells the Customer if it believes an instruction infringes data protection law.
Everyone the Provider authorises to process Customer Personal Data is bound by confidentiality.
The Provider applies the technical and organisational measures in Annex II, appropriate to the risk (GDPR Art. 32), and may improve them over time without lowering the overall level of protection.
The Service lets the Customer access, correct, export and delete the data of its members. The Provider helps the Customer, as far as reasonably possible, to answer requests from data subjects, and passes on to the Customer any request it receives directly about Customer Personal Data.
The Provider notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay, and where feasible within 48 hours of becoming aware of it, with the information GDPR Article 33(3) requires as it becomes available, and takes reasonable steps to contain it.
Taking into account the nature of the processing, the Provider assists the Customer with data protection impact assessments and prior consultations with a supervisory authority.
The Customer can export its data while it uses the Service. When the company is closed or the Customer stops using the Service, the Provider deletes Customer Personal Data within 30 days, except where law requires keeping it (for example accounting records) or as described in the Privacy Policy. Backups are not rewritten; if one is restored, the deletion is applied again.
The Provider makes available the information needed to demonstrate compliance with this DPA — this page, its annexes and answers to reasonable written questions. The Customer, or an auditor bound by confidentiality, may audit compliance once a year, with 30 days' notice, at its own cost, in a way that does not disrupt the Service or expose other customers' data.
Where a sub-processor processes Customer Personal Data outside the EEA, the transfer relies on an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or on the European Commission's Standard Contractual Clauses (Decision 2021/914, Module 3, processor to processor) with a transfer impact assessment.
Liability under this DPA is subject to the limits in the Terms. On data protection matters this DPA prevails over the Terms. It is governed by the law that governs the Terms. Questions: vvkozlov.work@gmail.com.
Not sub-processors: Paddle.com sells the subscription as Merchant of Record and is an independent controller of the billing data it collects; Telegram processes data only when a member chooses to link the Telegram bot, under its own terms; Google Analytics and Microsoft Clarity measure our public website only.