Legal Documentation
Data Processing Agreement (DPA)
Annex No. 1 to the Terms of Service of the aprovo.eu platform
Version: 2.0 | Effective date: September 5, 2026
Section 1. Parties to the Agreement
- This Data Processing Agreement (hereinafter: „Agreement" or „DPA"), executed pursuant to Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: „GDPR"), constitutes an integral annex to the Terms of Service of the aprovo.eu platform (hereinafter: „Terms of Service") and is entered into between:
- the Controller — an entity (a natural person conducting business activity or a legal person) that has concluded an agreement for the provision of services with the Service Provider under the terms of the Terms of Service, and which independently or jointly with others determines the purposes and means of processing the personal data of its clients (patients, consumers) within the meaning of Article 4(7) of the GDPR;
- the Processor — AMS SOFTWARE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office in Zabrze (41-808), ul. Józefa Wajzera 19/22, entered into the Register of Entrepreneurs of the National Court Register maintained by the District Court in Gliwice, X Commercial Division, under KRS number: 0001242326, NIP: 6482836354, REGON: 544821193 (hereinafter: „Processor").
- The Controller and the Processor are hereinafter collectively referred to as the „Parties", and each individually as a „Party".
Section 2. Subject Matter, Nature, Purpose, and Scope of Processing
- Under this Agreement, the Controller entrusts the Processor with the processing of personal data for the purpose and to the extent necessary to provide the digital service of the aprovo.eu platform, in accordance with the terms of the Terms of Service.
- Nature of processing: automated processing in an IT system (SaaS web application) with elements of non-automated processing (customer support).
- Purpose of processing: enabling the Controller to digitally manage consent documentation of clients (patients), including in particular:
- collecting and recording personal data of clients in digital consent forms,
- generating signed PDF documents with biometric signatures,
- storing treatment photo documentation (before/after photos),
- managing the Controller's client database,
- sending email communications to the Controller's clients upon its documented instruction.
- Categories of processing operations: collection, recording, organization, structuring, storage, adaptation (conversion to PDF), retrieval, consultation, use, disclosure by transmission (data export, email), restriction, erasure, destruction.
- The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Article 28(3)(a) GDPR).
Section 3. Categories of Data Subjects and Types of Personal Data
- Categories of data subjects:
- clients (patients, consumers) of salons and clinics using the Platform,
- employees/collaborators of the Controller (strictly within the scope of profile data in the Platform: first name, last name, business email address).
- Types of processed personal data — standard data:
- identification data: first name, last name, national identification number where the Controller collects one (e.g. PESEL in Poland), identity document type and number, date of birth,
- contact data: phone number, email address,
- address data (if entered by the Controller into the form),
- image: treatment photo documentation (before and after treatment photos).
- Types of processed personal data — special categories of data (Article 9(1) GDPR):
- Health data: health declarations contained in consent forms (medical interviews, information on allergies, contraindications, chronic diseases, medications taken, pregnancy, and other health information entered by the Controller into the form template).
- Biometric data: data resulting from specific technical processing relating to the electronic signature on a touch screen device (tablet), including: signature stroke vectors, stylus pressure dynamics, stylus tilt angle, stroke speed, signature duration — to the extent that they serve the unique identification of a natural person or confirmation of their identity within the meaning of Article 4(14) GDPR.
- The Processor declares that it is fully aware that the entrusted data includes special categories of data within the meaning of Article 9(1) GDPR and undertakes to apply heightened technical and organizational protection measures to them, the categories of which are described in Annex No. 1 to this Agreement.
Section 4. Duration of Processing
- The processing of personal data under this Agreement commences upon the first entry of personal data into the Platform by the Controller and continues for the entire duration of the agreement for the provision of services (Terms of Service) between the Parties.
- Upon expiration or termination of the agreement for the provision of services (for any reason):
- the Processor shall, within 30 (thirty) calendar days from the date of termination of the agreement, enable the Controller to export personal data in a format allowing its further use (JSON, CSV, or compiled PDF files), in accordance with the Controller's request submitted electronically to contact@aprovo.eu;
- the Processor shall, within 90 (ninety) calendar days from the date of termination of the agreement, permanently and irrevocably erase all personal data from its IT systems, including the production database, backups, and file storage service (Amazon S3), except for data whose further storage is required under mandatory provisions of Union or Member State law (in particular tax and accounting regulations);
- the Processor shall confirm to the Controller the permanent erasure of data in writing or electronically within 7 (seven) days of performing the erasure.
Section 5. Obligations of the Processor
- The Processor undertakes to:
- process personal data strictly within the scope, manner, and purpose specified in Section 2 of this Agreement and in the Terms of Service, on documented instructions from the Controller;
- ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b) GDPR);
- implement appropriate technical and organisational measures required under Article 32 GDPR, the categories of which are described in Annex No. 1 to this Agreement, to ensure a level of security appropriate to the risk of infringing the rights and freedoms of natural persons, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity;
- respect the conditions for engaging another processor (subprocessor) specified in Section 7 of this Agreement;
- taking into account the nature of the processing, assist the Controller — insofar as possible and through appropriate technical and organisational measures — in fulfilling the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR (Articles 15-22 GDPR), within no more than 10 (ten) business days from the date of receiving the Controller's request;
- taking into account the nature of processing and the information available to the Processor, assist the Controller in ensuring compliance with the obligations pursuant to: Article 32 GDPR (security of processing), Article 33 GDPR (notification of a personal data breach to the supervisory authority), Article 34 GDPR (communication of a personal data breach to the data subject), Article 35 GDPR (data protection impact assessment — DPIA), Article 36 GDPR (prior consultation with the supervisory authority);
- at the choice of the Controller, delete or return all personal data after the end of the provision of services relating to processing, and delete existing copies in accordance with Section 4(2) of this Agreement;
- make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, under the conditions specified in Section 9 of this Agreement;
- immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions (Article 28(3) second subparagraph GDPR).
- The Processor declares that as of the date of conclusion of this Agreement:
- it has not appointed a Data Protection Officer (DPO) within the meaning of Article 37 GDPR, provided that this declaration will be promptly updated upon any appointment of a DPO;
- the contact point for personal data protection matters is: contact@aprovo.eu.
Section 6. Confidentiality
- The Processor undertakes to keep strictly confidential all personal data entrusted to it under this Agreement, as well as all information regarding the technical and organizational measures used for their security.
- The confidentiality obligation referred to in paragraph 1 shall apply indefinitely, including after the expiration or termination of this Agreement and the agreement for the provision of services.
- The Processor ensures that only persons holding a written, named authorization issued by the Processor, who have been previously trained in personal data protection and committed themselves to confidentiality — including through signing separate non-disclosure agreements (NDAs) or relevant clauses in employment or cooperation contracts — will be permitted to process personal data.
Section 7. Subprocessing (Subprocessors)
- The Controller hereby grants the Processor general written authorization (within the meaning of Article 28(2) first sentence GDPR) to engage subprocessors listed in Annex No. 2 to this Agreement.
- The Processor shall inform the Controller of any intended changes concerning the addition or replacement of subprocessors at least 14 (fourteen) days in advance electronically (email to the address specified in the Controller's account or notification in the Platform), thereby giving the Controller the opportunity to object to such changes (Article 28(2) second sentence GDPR).
- The Controller's objection should be reasoned and submitted in writing (email) within 14 (fourteen) calendar days from the date of receiving the notification referred to in paragraph 2. In the event of a reasoned objection:
- the Processor shall make reasonable efforts in good faith to propose an alternative solution to the Controller enabling the continuation of service provision without using the objected subprocessor;
- if an alternative solution is not objectively available, either Party has the right to terminate the agreement for the provision of services (Terms of Service) subject to a 30-day notice period, without incurring contractual penalties or other sanctions for early termination.
- The Processor undertakes to impose on each subprocessor — by way of a contract or other legal act — the same data protection obligations as those set out in this Agreement, in particular the requirement to implement appropriate technical and organizational measures (Article 28(4) GDPR).
- The Processor shall remain fully liable to the Controller for the performance of the subprocessor's data protection obligations as if it performed those processing operations itself.
Section 8. Personal Data Breaches
- The Processor undertakes to notify the Controller of any personal data breach (within the meaning of Article 4(12) GDPR) of which it becomes aware, without undue delay — and no later than within 24 (twenty-four) hours from confirming the breach.
- The breach notification shall be sent electronically to the Controller's email address specified in the Platform account and shall contain at least:
- the date and time when the breach was confirmed and — if possible to determine — the date and time when the breach occurred;
- a description of the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- the name and contact details of the contact point designated by the Processor where more information can be obtained;
- a description of the likely consequences of the personal data breach;
- a description of the measures taken or proposed to be taken by the Processor to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
- Where, and in so far as, it is not possible to provide the information at the same time, the Processor shall provide the information in phases without undue further delay as an update to the initial notification.
- The Processor shall document any personal data breaches, including the facts relating to the personal data breach, its effects and the remedial action taken, and make this documentation available to the Controller upon request (Article 33(5) GDPR).
- The Processor is not entitled to independently notify data subjects of a breach of their personal data protection (Article 34 GDPR). The decision to notify data subjects rests exclusively with the Controller. The Processor undertakes to cooperate with the Controller in fulfilling this obligation, including by providing necessary information and technical support.
- The Processor actively cooperates with the Controller to determine whether the breach requires notification to the supervisory authority competent for the Controller under Article 33 GDPR, providing all necessary information enabling the Controller to conduct a risk assessment regarding the rights and freedoms of natural persons.
Section 9. Right to Audit and Inspection
- The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
- Audits and inspections shall be conducted:
- upon prior agreement of the date — with at least 14 (fourteen) days' prior written notice (email);
- during the Processor's business hours;
- in a manner that does not unreasonably disrupt the Processor's operational activities;
- subject to the auditor signing an appropriate confidentiality agreement.
- The Controller is entitled to conduct one planned audit in each calendar year. The right to an additional audit applies in the event of:
- reasonable suspicion of a breach of this Agreement or the GDPR,
- a personal data breach referred to in Section 8,
- a request from a supervisory authority competent for the Controller.
- The Processor may propose, as an alternative or supplement to an individual audit, providing current results of external audits conducted by an independent auditor (e.g., SOC 2 Type II report, ISO/IEC 27001 certificate, penetration test report), provided that they cover the scope of processing subject to this Agreement. Providing an external report does not exclude the Controller's right to audit referred to in paragraph 3.
- Audit costs shall be borne by the Controller, unless the audit reveals a material breach of this Agreement or the GDPR by the Processor — in which case the costs shall be borne by the Processor.
Section 10. Data Transfers to Third Countries
- As of the date of conclusion of this Agreement, personal data entrusted to the Processor is processed exclusively within the European Economic Area (EEA), in the Frankfurt, Germany region — both by the Processor and by the subprocessors listed in Annex No. 2.
- The Processor shall not transfer personal data to a third country (outside the EEA) or an international organization without the Controller's prior written consent and the application of one of the transfer mechanisms provided for in Chapter V of the GDPR (Articles 44-49), in particular:
- an adequacy decision by the European Commission (Article 45 GDPR), or
- standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 (Article 46(2)(c) GDPR), supplemented — if necessary — by additional safeguard measures resulting from a Transfer Impact Assessment (TIA).
- In the case of Google LLC (Gemini API) — the Processor declares that in the service configuration, data processing has been forced within the EU/EEA region. In the event of a change in service terms by Google LLC resulting in data processing outside the EEA, the Processor shall promptly inform the Controller and apply appropriate transfer mechanisms referred to in paragraph 2.
Section 11. Data Protection Impact Assessment (DPIA)
- In view of the processing of special categories of data (health data and biometric data), the Processor undertakes — at the Controller's request — to provide all necessary assistance in conducting a Data Protection Impact Assessment (DPIA) pursuant to Article 35 GDPR, including:
- providing information on the technical and organizational measures applied,
- providing results of risk assessments conducted by the Processor,
- participating in prior consultations with the supervisory authority (Article 36 GDPR), should they prove necessary.
Section 12. Liability
- The Processor shall be liable for damage caused by processing personal data only where it has not complied with obligations of GDPR specifically directed to processors or where it has acted outside or contrary to lawful instructions of the Controller (Article 82(2) GDPR).
- Where one Party has paid full compensation for the damage suffered, that Party shall be entitled to claim back from the other Party that part of the compensation corresponding to their part of responsibility for the damage (Article 82(5) GDPR — recourse).
- The total liability of the Processor arising out of or in connection with this Agreement is limited to an amount equal to 12 times the monthly subscription fees paid by the Controller during the 12-month period preceding the event giving rise to liability, but not less than EUR 2,500. The above limitation does not apply to liability resulting from:
- intentional breach of this Agreement,
- unlawful processing of personal data,
- breach of the confidentiality obligation referred to in Section 6.
- The Processor shall not be liable for damages resulting from:
- acts or omissions of the Controller contrary to this Agreement, the Terms of Service, or the GDPR,
- instructions of the Controller, the execution of which leads to a breach of the GDPR, provided that the Processor informed the Controller of such risk pursuant to Section 5(1)(i),
- force majeure (i.e., an external event, impossible to foresee and impossible to prevent) lasting longer than 30 (thirty) calendar days.
Section 13. Final Provisions
- This Agreement enters into force upon acceptance of the Terms of Service by the Controller (in particular: upon ticking the appropriate acceptance box during account registration on the Platform) and remains valid for the entire duration of the legal relationship between the Parties under the Terms of Service.
- In matters not covered by this Agreement, the provisions of the GDPR and other applicable Union and Member State data protection law shall apply.
- Any amendments to this Agreement require notification to the Controller electronically with at least 14 (fourteen) days' advance notice. A Controller that does not consent to the amendment has the right to terminate the agreement for the provision of services (Terms of Service) subject to a 30-day notice period, without incurring sanctions.
- This Agreement is governed by Polish law and follows the governing law of the Terms of Service. The Parties, both acting in a professional capacity, submit to the exclusive jurisdiction of the court having jurisdiction over the Processor's registered office, in accordance with Article 25 of Regulation (EU) No 1215/2012. This does not limit the right of a supervisory authority to act, nor the right of a data subject under Article 79 GDPR to bring proceedings in another forum.
- If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. The Parties undertake to replace the invalid provision with a valid provision whose economic and legal effect is as close as possible to that of the provision replaced.
Annex No. 1 — Technical and Organizational Measures (Article 32 GDPR)
The Processor implements and maintains appropriate technical and organizational measures, including in particular the following categories of safeguards:
A. Encryption and pseudonymisation (Article 32(1)(a) GDPR)
- Encryption of sensitive data at rest using AES-256 class block cipher algorithm.
- Encryption of all network connections using TLS 1.2+ (HTTPS) protocol.
- Pseudonymisation of searchable data using blind index technique (salted hash), enabling search without decryption.
- Cryptographic integrity verification of signed documents (integrity hash).
B. Ensuring ongoing confidentiality, integrity, availability and resilience of processing systems (Article 32(1)(b) GDPR)
- Multi-tenancy data isolation at the database level — every query is automatically scoped to the given salon's data.
- Authentication with XSS protection (session tokens in secure cookies).
- Optional two-factor authentication (2FA).
- Role-based system with the principle of least privilege, with additional PIN protection on shared devices.
- Protection against CSRF, XSS, and HTML injection attacks.
- HTTP security headers (CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy).
- Rate limiting on key endpoints.
- Strong password policy (minimum 10 characters, salted hashing).
C. Ability to restore availability of personal data in a timely manner (Article 32(1)(c) GDPR)
- Automated database backups with Point-in-Time Recovery (PITR) mechanism.
- Redundant file storage with 99.999999999% (11×9) durability.
- Continuous monitoring of system availability and performance, with error tracking that does not disclose PII.
D. Regular testing, assessing and evaluating (Article 32(1)(d) GDPR)
- Automated security and functional tests executed in the CI/CD pipeline with every deployment.
- Audit Trail logging all relevant personal data operations.
- Automated dependency auditing for known vulnerabilities.
E. Organizational measures
- Written non-disclosure agreements (NDAs) with all personnel having access to data.
- Named, written authorizations to process personal data.
- Record of Categories of Processing Activities (Article 30(2) GDPR).
- Personal data protection training.
Note: The above description presents the categories of implemented safeguards in a general form. A detailed description of technical and organizational measures, including the specification of technologies used and security architecture, is made available to the Controller upon request submitted electronically to contact@aprovo.eu.
Annex No. 2 — List of Approved Subprocessors
As of: June 6, 2026
| No. | Entity | Registered Office | Processing Region | Scope of Entrusted Processing | Legal Basis for Transfer (if outside EEA) |
|---|---|---|---|---|---|
| 1 | Render Services, Inc. | San Francisco, CA, USA | Frankfurt, Germany (EEA) | Backend application hosting (Node.js), static frontend hosting (React, Next.js), managed PostgreSQL 16 database (including PITR backups) | No transfer outside the EEA — data processed exclusively in the Frankfurt region |
| 2 | Amazon Web Services, Inc. (AWS) | Seattle, WA, USA | eu-central-1, Frankfurt, Germany (EEA) | File storage in Amazon S3 service: signed PDF documents, treatment photo documentation (before/after photos), other files uploaded by the Controller | No transfer outside the EEA — S3 bucket configured exclusively in the eu-central-1 region |
| 3 | Stripe, Inc. | San Francisco, CA, USA | EEA | Processing Controller's subscription payments (payment card processing, invoice generation). Note: regarding payment data, Stripe acts as a separate data controller (pursuant to Stripe DPA). Data of the Controller's clients/patients is not transferred to Stripe. | Not applicable (separate controller) |
| 4 | Google LLC | Mountain View, CA, USA | EEA (forced EU processing location in service configuration) | Gemini API service — one-time processing of document content (PDF/DOCX) uploaded by the Controller to extract form structure. Data is not used to train Google models. Processing is transient (data is not permanently stored after processing is completed). | SCC (Standard Contractual Clauses, Article 46(2)(c) GDPR) included in the Google Cloud Data Processing Addendum — used as a fallback safeguard in case of processing outside the EEA |
Change History
| Version | Date | Description of change |
|---|---|---|
| 2.0 | September 5, 2026 | European edition. References to Polish law replaced with „Union or Member State law” where the GDPR uses that formula; the supervisory authority is no longer fixed to the Polish authority but follows the Controller; the Polish implementing act removed from the final provisions; liability floor restated in EUR and aligned with the Terms of Service; national identification number generalised beyond PESEL; SMS dispatch and the SMSAPI subprocessor removed, as the feature is not offered; sections renumbered from „§” to „Section”. |
| 1.0 | June 6, 2026 | First version of the Data Processing Agreement. |
Processor's Contact Point for Data Protection:
AMS SOFTWARE SP. Z O.O.
ul. Józefa Wajzera 19/22, 41-808 Zabrze
Email: contact@aprovo.eu