Paqso

Data processing agreement

1. Parties and subject

This agreement under Art. 28 GDPR is concluded between the customer organization (controller) and Yan Malinovskiy, Belchenstr. 2, 79276 Reute, Germany (processor) when the person founding the organization in Paqso accepts it together with the terms of service; that acceptance is recorded in the organization's audit trail. It governs the personal data the processor handles on the controller’s behalf while providing the service.

2. Nature, purpose, and duration

The processor stores, displays, transmits, and deletes data the controller enters or receives in its workspace, for the purpose of collecting packaging facts, requesting supplier evidence, and recording decisions. Processing lasts for the term of the service contract and the 30-day export period after it.

3. Data subjects and categories

Data subjects: the controller’s members, the contact persons of its suppliers, and persons named in evidence documents. Categories: names, business e-mail addresses, roles, the content of evidence requests and answers, and audit records of who acted when. No special categories under Art. 9 GDPR are intended to be processed.

4. Instructions

The processor processes data only on the controller’s documented instructions; the service’s functions as used by the controller’s members are those instructions. The processor informs the controller if an instruction appears to infringe data protection law.

5. Confidentiality and security

Persons authorized to process data are bound to confidentiality. The processor implements appropriate technical and organizational measures: encrypted transport, authentication with verified e-mail and account lockout, server-side tenant isolation with explicit capabilities, an audit trail of privileged actions, hosting in the EU for databases, backups, and least-privilege access for operations. Details are provided on request.

6. Sub-processors

The controller authorizes the following sub-processors: Cloudflare, Inc. (application hosting, e-mail delivery, network security); Neon, Inc., a Databricks company (database hosting, EU Frankfurt). Polar Software Inc. acts as merchant of record for the subscription and is not a sub-processor of workspace data. The processor announces changes to this list at least 30 days in advance; the controller may object for good cause.

7. Assistance and rights of data subjects

The processor assists the controller, with appropriate measures, in responding to data subject requests, in security of processing, in breach notification, and in impact assessments. A personal data breach is reported to the controller without undue delay.

8. Deletion and return

At the end of the service the controller may request a complete copy of its data for 30 days, which the processor provides within 30 days of the request; afterwards the processor deletes it and existing copies, unless Union or Member State law requires storage. Deletion from live systems is immediate; backups are purged within 30 days.

9. Audits

The processor makes available the information necessary to demonstrate compliance and allows for and contributes to audits, including inspections, conducted by the controller or an auditor mandated by it, with reasonable notice and during business hours.

10. Transfers

Databases are hosted in the EU. Where a sub-processor may access data from a third country, the transfer rests on an adequacy decision, including the EU–US Data Privacy Framework, or on the Standard Contractual Clauses.