MONODAT

Version: 1.3.1 · Effective date: 2026-10-15

The binding version of this document is the Polish version. Other language versions are provided for information only.

Data Processing Agreement (DPA)

Pursuant to Art. 28 GDPR

Template for B2B clients requesting a DPA to meet their own GDPR obligations. Fill in client data in the [CLIENT_*] fields. To conclude a DPA, contact us at help@monodat.com.

This Data Processing Agreement ("DPA") is entered into between:

Data Controller: [CLIENT_COMPANY_NAME] [CLIENT_ADDRESS] Tax ID: [CLIENT_TAX_ID] hereinafter "Controller"

and

Data Processor: Moises Lopez Otero Studio Programistyczne ul. Osiedle Willowe 5, 31-901 Kraków, Poland NIP: 6793218612 | REGON: 389287603 Email (operational contact for matters under this DPA): help@monodat.com hereinafter "Processor"

in connection with the Controller's use of the MONODAT platform under the Terms of Service.


§1. Subject and Purpose

  1. The Controller engages the Processor to process personal data to the extent necessary to provide MONODAT services as described in the Terms of Service.

  2. The Processor processes personal data solely on documented instructions from the Controller and exclusively for the purpose of providing the Services.

  3. Scope limited to processing on the Controller's behalf. The Processor also processes certain personal data of the Controller's individual Account users (e.g. login credentials, individual usage history, security logs) as an independent Controller for its own purposes — account security, billing to the Controller, and compliance with the Processor's own legal obligations — as described in the Processor's Privacy Policy. This DPA governs only the processing described in paragraphs 1-2, i.e. personal data the Processor handles on the Controller's documented instructions (in particular the third-party register data described in §2); it does not re-characterise processing the Processor carries out for its own purposes as Controller.

  4. Data retrieved outside the Platform. Personal data — in particular CEIDG entrepreneurs' data — that the Controller retrieves outside the Platform through the API, exports or copies is processed by the Controller solely as an independent controller, on its own legal basis and at its own responsibility, subject to the prohibitions in §12 and §15d of the Terms of Service (including the prohibition of direct marketing and re-identification). This DPA covers only the processing of such data within the Platform (watchlists, viewing history, alerts, reports generated on the Platform).

§2. Categories of Data and Data Subjects

Categories of data subjectsCategories of personal data
Controller's Account users in MONODATName, surname, email, login credentials, activity history
Natural persons carrying out business activity (CEIDG) viewed, watched or exported by the ControllerBusiness name (containing first name and surname), NIP, REGON, activity status and dates, PKD codes, the address of the fixed place of business as published by CEIDG (street, number, postal code, town, commune, county, voivodeship), age in whole years, participation in civil partnerships, type and validity of licences and permits, signals from public registers matched by NIP/REGON, change history and debt sale offers from dlugi.info labelled as a probable match — without contact details, home address, date of birth or PESEL number (Privacy Policy, section 3.3)
Natural persons in public registries (KRS, CRBR, SUDOP, BZP) accessed by the ControllerName, surname, company role, address (as disclosed by registries), national identification number (as disclosed by registries), and — where the Controller's plan includes them — Person Risk Indicators (director-count and sanctions/PEP-match flags) computed by the Processor as described in the Processor's Privacy Policy §4.2

Nature of processing: collection, storage, analysis, provision of analysis results to the Controller as part of the Services.

Duration: the term of the MONODAT services Agreement.

§3. Processor Obligations

The Processor undertakes to:

a) process personal data solely on documented Controller instructions, including with regard to transfers to third countries, unless required to do so by Polish or EU law,

b) ensure that persons authorised to process data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality,

c) implement appropriate technical and organisational measures in accordance with Art. 32 GDPR,

d) not engage further processors without Controller authorisation, subject to §4,

e) assist the Controller in fulfilling data subject rights (Arts. 12-22 GDPR) to the extent appropriate given the nature of processing,

f) assist the Controller in complying with Arts. 32-36 GDPR (security, breach notifications, impact assessments, consultations),

g) delete or return all personal data after the end of service provision according to the Controller's choice,

h) make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits.

§4. Sub-Processors

  1. The Controller grants general authorisation for use of the following sub-processors. The list below is complete and reflects the factual state as at the last update date:
Sub-processorRoleData receivedLocation and transfer basis
Google Ireland Ltd. / Google LLC (Firebase Authentication)Authentication and sign-in managementE-mail, name, profile picture of the Controller's usersEEA / USA — EU-US Data Privacy Framework + SCCs
Google Ireland Ltd. / Google LLC (Gemini API)AI model for the analytical chatQuery content, conversation history, SQL result rows (max. 20 rows). Without user identity and without PESEL numbers — technically stripped before sendingEEA / USA — EU-US Data Privacy Framework + SCCs
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment and subscription handlingE-mail, billing address, tax ID, amounts. Card data never reaches the ProcessorEEA / USA — EU-US Data Privacy Framework + SCCs
Brevo (Sendinblue SAS)Sending e-mail notifications and digestsRecipient's e-mail address, notification contentFrance (EEA) — no transfer outside the EEA
Cloudflare, Inc. / Cloudflare Ireland Ltd. (Turnstile)Anti-bot / anti-abuse verification of the Controller's Account users, triggered only when a session is flagged as potentially automatedIP address, browser/device signalsEEA / USA — appropriate safeguards under Art. 46 GDPR
Server infrastructure provider (VPS)Hosting of the Platform and databaseAll data stored on the PlatformDetails, including server location, available on the Controller's request
  1. An up-to-date list of sub-processors is available upon Controller request at help@monodat.com.

2a. The Processor declares that it uses no analytics, tracking or advertising tools and does not share entrusted data with advertising networks or data brokers. It also does not use entrusted data to train its own artificial intelligence models.

  1. The Processor notifies the Controller at least 14 days in advance of planned additions or replacements of sub-processors. The Controller may raise a reasoned objection. If no agreement is reached, either party may terminate this DPA.

  2. The Processor concludes contracts with sub-processors providing data protection levels at least equivalent to this DPA.

§5. Security Measures (Art. 32 GDPR)

The Processor applies, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, at minimum the following measures:

Confidentiality: data transmission encryption (HTTPS/TLS); authentication delegated to a specialist provider (Google Firebase Authentication) — the Processor stores no user passwords; role-based access control and permission management; environment separation and restricted access to the production database.

Integrity: pseudonymisation and masking of data where possible — in particular unconditional masking of PESEL numbers in the interface and their technical removal before transmission to AI models; data minimisation principle applied to third-party integrations; automated anti-bot/anti-abuse verification (§4) to reduce the risk of bulk unauthorised extraction.

Availability and resilience: regular backups; infrastructure security monitoring.

Testing and evaluation: regular security testing and review; incident response procedures; a responsible disclosure programme as described in the Privacy Policy.

§6. Data Breaches

  1. Upon discovering a breach of personal data entrusted by the Controller, the Processor informs the Controller without undue delay, no later than 48 hours from discovery.

  2. The information includes: a) description of the nature of the breach, b) categories and approximate number of data subjects, c) categories and approximate number of data records, d) likely consequences of the breach, e) measures taken or proposed.

  3. The Processor cooperates with the Controller in fulfilling supervisory authority notification obligations and notifying affected individuals.

§7. International Data Transfers

  1. Data transfers outside the EEA take place only under appropriate safeguards (Art. 46 GDPR):

    • Standard contractual clauses (SCCs) approved by the European Commission,
    • Adequacy decisions,
    • Other GDPR-compliant mechanisms.
  2. The Processor informs the Controller about locations of data processing outside the EEA and applied safeguards on request.

§7a. UK GDPR and Swiss FADP

Where the Controller is subject to the UK GDPR (Data Protection Act 2018) or the Swiss Federal Act on Data Protection (FADP), references in this DPA to "GDPR" and to specific GDPR articles are read as references to the corresponding provisions of the UK GDPR or FADP, and international transfers from the United Kingdom or Switzerland are additionally covered, as applicable, by the UK International Data Transfer Addendum or Swiss-law-conforming standard contractual clauses. The Processor provides the Controller with the relevant transfer documentation on request.

§8. Audits

  1. The Controller has the right to audit or inspect the Processor's compliance with this DPA, no more than once a year, with 30 days' notice, during business hours and without unreasonably disrupting Processor operations.

  2. Audit costs are borne by the Controller, unless the audit reveals material non-compliance by the Processor.

  3. Instead of an audit, the Controller may accept reports from audits conducted by independent auditors or compliance certifications (e.g., ISO 27001, SOC 2).

§9. Duration and Termination

  1. This DPA is effective for the duration of the MONODAT services Agreement.

  2. Upon termination, the Processor, in accordance with the Controller's written instruction: a) deletes all personal data entrusted for processing, or b) returns all personal data entrusted for processing,

    unless Polish or EU law requires data retention. In such case, the Processor informs the Controller of the obligation and retains data only to the extent required. This is without prejudice to the Controller's right to export its own Account data during the window described in §26a of the Terms of Service.

§10. Liability

  1. Each party is liable for violations of this DPA in accordance with applicable law, including Art. 82 GDPR.

  2. The Processor's total liability under this DPA is limited as per the MONODAT Terms of Service (3 months of subscription fees; see §17 and §17b of the Terms), except in cases where limitation is not permitted under mandatory law. This limitation applies to the Processor's liability to the Controller and does not affect the Controller's own indemnification obligations to the Processor under §12(4) and §12b of the Terms of Service, which are separate and uncapped save as mandatory law requires otherwise.

§11. Governing Law and Jurisdiction

  1. This DPA is governed by Polish law.

  2. The competent court is the court with jurisdiction over the Processor's seat (Kraków, Poland).

§12. Final Provisions

  1. In case of conflict between this DPA and the MONODAT Terms of Service, this DPA prevails in matters of personal data protection.

  2. Amendments to this DPA require written form (including electronic) under penalty of invalidity.

  3. Invalidity of any provision does not affect the validity of others.


Signed in Kraków, on: _______________

ControllerProcessor
[CLIENT_COMPANY_NAME]Moises Lopez Otero Studio Programistyczne
______________________________________________
(signature and stamp)(signature)