Data Processing Agreement

ANNEX 1 TO THE TERMS OF SERVICE OF THE FLABER SERVICE — Data Processing Agreement

Version: 2026-09-21 — identical with the version of the Terms. This Annex has no version marking of its own: it is an integral part of the Terms and shares their date.

English translation. This is a translation of the Polish original for information. The Polish version is the binding one; in the event of any discrepancy, the Polish version prevails.

§1. Who enters into this agreement with whom, and from when it binds

  • 1. This Annex constitutes an integral part of the Terms. You accept it together with the Terms when setting up an Account. There is no separate acceptance screen and it is not subject to negotiation.
  • 2. This Annex binds from the moment you enter the first data of a third party into the Book (§10(5) of the Terms). Until that moment it produces no effects — an Account without a Book does not give rise to an entrustment of processing.
  • 3. The processor is the Provider indicated in §1 of the Terms.
  • 4. The controller is the entity on whose behalf you act. If you conduct business on your own account and the data concern persons with whom you work within that business — you are the controller. If you act under authorisation from the entity for which you work — that entity is the controller, and you enter into this agreement on its behalf.
  • 5. We do not verify which of these cases applies, and we have no technical means of checking it. The effects of the declaration under §10(4) of the Terms are described in §13 of this Annex.
  • 6. Capitalised terms have the meaning given to them in §2 of the Terms.

§2. What you entrust, for what purpose and for how long

  • 1. Subject matter of the entrustment — the personal data of third parties which you enter into the Book, and the personal data contained in the documents of your work.
  • 2. Nature of the processing — storage, organisation, display to you, making backups and, in the Team Package, sending an invitation by electronic mail. We perform no other operations on these data.
  • 3. The purpose of the processing is determined by you as the controller. We provide solely the technical availability of the tool.
  • 4. Categories of data subjects:
    • persons whom you lead in the Book;
    • persons who have received an invitation from you and occupy a Seat in a Team.
  • 5. Categories of data:
    • the person's first name and position;
    • the person's electronic mail address;
    • the content of your notes, the course of conversations, arrangements, goals, summaries and reports about the person;
    • personal data contained in the documents of your work.
  • 6. Collaboration dimensions are not entrusted data. They are filled in by the person themselves in a sister service and they themselves copy the result into the form on their own Account. You have view access to them only, and the absence of a write right is enforced by the database. You never dispose of them, so you cannot entrust them to us. Within the boundaries of the Service we are their controller, on the basis of the agreement for the provision of the Service concluded with that person; the rules of their processing are described in the Privacy Policy, not in this Annex. The consequence upon removal of a person from the Book is set out in §12(4).
  • 7. A person's electronic mail address occurs in two roles and they must be kept apart. As long as it sits on the person card and in that person's invitation — it is entrusted data and you delete it by deleting the person from the Book. From the moment the person sets up their own Account, the same address becomes data of their Account, of which we are the controller. Deleting the person from your Book then deletes neither their Account nor their address in that second role — that Account belongs to them, not to your entrustment.
  • 8. The entrustment does not cover special categories of data within the meaning of Article 9 GDPR, nor the data referred to in Article 10 GDPR. The prohibition on entering them is set out in §9(5) of the Terms. The Service does not ask for such data, has no field for them and is not intended for storing them. Entering them nonetheless is an act contrary to instructions and burdens the controller.
  • 9. The duration of the entrustment is set out in §12.

§3. Instructions — what counts as one and what does not

  • 1. The documented instruction of the controller is the use of the Service in accordance with the Terms and within the scope of its functions. We do not require separate instructions in writing from you — every entry, every sharing and every deletion carried out in the Service is your instruction.
  • 2. An instruction going beyond the scope of the Service's functions is to be addressed to us by electronic mail at the address given in §1 of the Terms. We carry it out if it is technically feasible and lawful; otherwise we refuse, stating the reason.
  • 3. We do not process entrusted data for our own purposes. We do not sell them, do not disclose them to third parties other than the subprocessors under §6, do not build statistics on them and do not use them to develop the Service.
  • 4. We do not subject entrusted data to artificial intelligence analysis. They are not summarised, assessed or transmitted to any language model whatsoever. There is not a single such dependency in the Service.
  • 5. We will inform you if, in our assessment, your instruction infringes the provisions on personal data protection (Article 28(3), final sentence, GDPR). Pending clarification we may withhold its execution.
  • 6. We do not transfer entrusted data to public authorities unless such an obligation follows from a provision binding on us. In that case we inform you before the transfer, if the law does not prohibit it.

§4. Confidentiality and access on our side

  • 1. We admit to the processing of entrusted data only persons to whom we have granted authorisation and who have committed themselves to confidentiality.
  • 2. We do not review the content you enter. Persons on our side obtain access to it solely to the extent necessary to remove a fault or to carry out your request.
  • 3. We state it plainly: administrative access to the database exists, as in every system of this class, and today it is held by one person on our side. We do not declare encryption that would make it impossible for us to read content, because we do not apply such encryption.
  • 4. The operator console which we use when supporting the Service does not return the content of the Book or the first names of persons in a Team. It shows: billing data, the status of Teams and invitations, the Account's login address, the date of last login, the register of acts, the application error log and figures evidencing use — how many person cards, how many conversations. The function that feeds this screen is incapable of returning content, and extending it would require a change to the structure of the database.
  • 5. Neither an employer nor a Company administrator has any means of reading the Book kept by a User. This does not follow from a contractual prohibition, but from the absence of a path in the structure of the database: the tables of the relationship layer have no Company or Team column, so there exists no query that would return these data. This state is checked by a negative test upon every change to the structure of the database.

§5. Security of processing

  • 1. We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. The list of them constitutes Annex B to this Annex and is dated.
  • 2. The list describes the factual state as at the date indicated in it, together with the limitations that are named in it explicitly. We may change it, provided that the level of security is not lowered; a lowering requires the procedure under §14(1).
  • 3. We do not declare conformity with any certification standard, nor do we invoke the certificates of our subprocessors as our own.

§6. Subprocessors

  • 1. You give general consent to our use of subprocessors (Article 28(2) GDPR).
  • 2. The current list of subprocessors — together with an indication of the role, the place of processing and the basis for transfer outside the EEA — is published at profilon.pl/flaber/podprocesorzy and bears a date.
  • 3. We give notice of an intention to add or change a subprocessor by electronic mail at least 14 days in advance. If our own supplier gives us notice within a shorter period, we pass the notice on immediately after receiving it — we do not take on a commitment longer than the one we ourselves receive in the chain.
  • 4. You may object within 7 days of the notice. An objection does not suspend the change: it entitles you to terminate the agreement with immediate effect and to a refund of the fee for the unused period. We do not undertake to propose an alternative supplier, because at the present scale we do not have one.
  • 5. With every subprocessor we conclude an agreement imposing on it obligations no less protective than those arising from this Annex. We are liable for the acts and omissions of a subprocessor as for our own (Article 28(4) GDPR).

§7. Processing outside the European Economic Area

  • 1. The database, files, authentication and application execution operate within the European Economic Area — in Ireland.
  • 2. We name one exception plainly: the handling of outgoing mail. Our mail delivery provider delivers messages from Ireland, but stores its account data, message metadata and logs in the United States, irrespective of the sending region selected. This concerns the content of the invitations sent in the Team Package, which contain the electronic mail address of the person invited, the first name of the inviter and the name of the Team.
  • 3. The basis for this transfer is the standard contractual clauses adopted by European Commission Decision 2021/914 and the provider's certification under the EU–U.S. Data Privacy Framework.
  • 4. Suppliers operating within the EEA may obtain access to data from outside the EEA to the extent necessary to maintain the infrastructure. We indicate the basis for transfer separately for each subprocessor on the list under §6(2) — they do not all rely on the same one.
  • 5. We do not claim that no transfer outside the EEA takes place. Such a claim would be untrue.

§8. Assistance in exercising the rights of data subjects

  • 1. Requests from data subjects are addressed to the controller, not to us. The obligation to respond to a request for access, rectification, erasure, restriction, objection and portability rests on you.
  • 2. If a data subject addresses such a request directly to us, we will not answer it on the merits. We will inform them that the request is to be addressed to the controller. What we can do beyond that depends on whether we are able to establish who the controller is:
    • if the person has an Account with us and occupies a Seat in a Team — we will establish the controller and pass the request on to you immediately;
    • if the person does not have an Account with us — we will not find you ourselves. There exists no query that would return the content of the Book, and the operator console does not return the first names of persons in a Team (§4(4)). This is the same property thanks to which the Book cannot be read by an employer or a Company administrator (§4(5)). In such a case we ask the person to indicate the controller and only then pass the request on to you.

We do not undertake to pass on a request whose addressee we are unable to establish. Such an undertaking would be unperformable, and its non-performance would burden you as the controller. We state this plainly, instead of making a promise which the construction of the Service does not allow us to keep.

The above does not concern data of which we are the controller — that is, Account data.

  • 3. What you can do yourself, within the Service:
    • delete a person from the Book together with the entire history of conversations, goals and reports about them — always, as long as your Account and Team exist, irrespective of billing and the trial period. One exception: if the person runs a Team, first take the Team away from them;
    • generate a report in the form of a PDF document — as long as the Package is active; after the trial period expires you will not produce a new report, and existing ones remain readable;
    • produce a printout of the person card from the browser — this route always works.
  • 4. What the Service cannot do and what we do for you upon request: there is today no function for issuing the complete set of data of a single person from the Book in the form of a file. Upon your request we prepare such a compilation by our own action. We confirm receipt of the request within 72 hours on working days, and we carry it out no later than within one month (§13(3) of the Terms).
  • 5. The Service has no account, role or screen through which a person led in the Book would obtain access to it — such view access is not provided for in the construction of the Service. This does not mean that the right of access does not apply to them — it means that it is exercised by the controller outside the application, and our role is to assist in that.
  • 6. Rectification after expiry of the trial period. After the trial period elapses, the Book passes into a read state and you will not correct an existing entry in it (§6(8) of the Terms), although deleting a person remains possible. Because the right to rectification does not depend on your billing, in this state the rectification is carried out by us, upon your request, within the periods under paragraph 4. We carry it out free of charge and irrespective of your billing, because the reason for the impossibility of carrying it out yourself is a limitation of function introduced by us. Deleting a person from the Book remains feasible by yourself in this state and requires no request.
  • 7. When issuing data we redact information concerning third parties (Article 15(4) GDPR). The assessment of what is subject to redaction belongs to you as the controller; we carry out your indication.
  • 8. The information obligation towards the persons whose data you enter into the Book rests on you. It follows from Article 14 GDPR and concerns also persons to whom the Service sends no message at all — in the Leader Package it sends one to no one. We do not perform this obligation for you and we are not liable for its performance.
  • 9. We make available to you a template information clause under Article 14 GDPR — for you to complete yourself and pass on to the persons whose data you enter. The template is an auxiliary material: making it available does not transfer to us the obligation under paragraph 8, does not make us a co-performer of it and does not constitute legal advice. The template reflects the construction of the Service as at the date indicated in it; the choice of legal basis and retention period belongs to you.

§9. Assistance with the obligations under Articles 32–36 GDPR

  • 1. We provide you with assistance in discharging the obligations concerning the security of processing, the notification of breaches, the communication to data subjects and data protection impact assessment — to the extent of the information at our disposal, and taking into account the nature of the processing.
  • 2. Upon your request we make available a completed security questionnaire and the current Annex B. We respond within 30 days, free of charge, once every 12 months.
  • 3. We do not draw up a data protection impact assessment or a record of processing activities for you.

§10. Personal data breaches

  • 1. We will notify you of a breach of the protection of entrusted data within 24 hours of becoming aware of it. The period is deliberately shorter than the 72 hours available to you for notification to the supervisory authority — your period runs from the moment you learn of it from us.
  • 2. We address the notification by electronic mail to the Account's address and it contains: the nature of the breach, the categories and approximate number of persons and entries concerned, the likely consequences, the measures applied or proposed, and contact details for further arrangements.
  • 3. If at the moment of notification we do not have a full description at our disposal, we pass on the information successively, as it is established — the absence of a complete set does not withhold the notification.
  • 4. We do not notify a breach to the supervisory authority and we do not communicate it to data subjects on your behalf. These obligations rest on the controller.
  • 5. We cooperate with you in establishing the circumstances of the breach and in limiting its effects.

§11. Demonstrating compliance and audit

  • 1. We make available to you all information necessary to demonstrate that we discharge the obligations under Article 28 GDPR — under the procedure set out in §9(2).
  • 2. If the documents made available objectively do not suffice to demonstrate compliance, or if a breach concerning your data has occurred, you may carry out an inspection on the following conditions:
    • notice in writing at least 30 days in advance;
    • no more often than once every 12 months, save in the case of a breach;
    • at your cost, including reimbursement of the time we devote to supporting the inspection;
    • by an auditor bound by an obligation of confidentiality and not being a competitor of ours;
    • within a scope limited to the processing concerning you — without access to the data of other clients or to the infrastructure of subprocessors.
  • 3. We do not exclude inspection. The above conditions determine the manner of its exercise, they do not take away the right.
  • 4. The conditions under paragraph 2 may not render this right illusory. If in a particular case they would make its exercise impossible, we agree on another procedure. In the case of a breach concerning your data, the notice period is shortened to 7 days, the frequency limitation does not apply, and we do not charge you with the costs of supporting the inspection.

§12. Duration of the entrustment, return and erasure of data

  • 1. The entrustment lasts for as long as your Account exists. It does not depend on whether you use a paid Package or whether a trial period is running.
  • 2. The justification for this construction, because it is unusual: after the trial period expires the Book remains readable, and storing data is processing. All our obligations under this Annex — in particular security, breach notification and assistance with requests — continue to run in this state, even though we receive no fee.
  • 3. The entrustment ends at the moment your Account is deleted and, in relation to the data of a particular person — at the moment they are deleted from the Book.
    • You delete a person from the Book yourself and at any time. If the person runs a Team, first take the Team away from them.
    • Deletion of an Account is self-service only for an independent Account — without a Team or with its own Team outside the structure of a Company. An Account with an active Seat in a Team, the Account of a Company administrator and every Account belonging to a Company are deleted by us upon request, within the periods under §13(3) of the Terms. For these Accounts the ending of the entrustment depends on our action, not on a click.
  • 4. Deleting a person from the Book covers their entire history — the entry, all conversations, goals and reports about them, including approved ones, together with the electronic mail address recorded in their invitation. It does not cover collaboration dimensions, which are not entrusted data (§2(6)), nor renditions of PDF documents issued earlier to third parties — those documents have already left the Service. Nor does it cover that person's Account, if they have set one up (§2(7)).
  • 5. The return and issuance of the content of the Book takes place upon your request, by our action, within the periods under §13(3) of the Terms. We state the reason why we do not accept the standard "return or erase all data" clause in an automatic shape: the Account export file never contains the Book, and the only documents arising on a self-service basis are the reports and printouts produced by you. We make a commitment as to the data and the deadline, not as to the file format.
  • 6. Erased data remain in the database backups for 7 days and are overwritten along with their rotation. We have no means of erasing them from the backups earlier. We do not issue a confirmation of erasure of data from the backups before that period elapses, because it would be untrue.
  • 7. After the entrustment ends we do not retain the entrusted data, with the exception of entries in the register of administrative acts on the terms set out in §13(4) of the Terms.

§13. Liability and absence of authorisation

  • 1. You are liable for the lawfulness of the data you enter, for the basis of their processing and for the performance of the information obligation towards the persons they concern (§10(4) and (6) of the Terms). We have no technical means of checking any of these things.
  • 2. If you concluded this agreement without authorisation from the entity for which you act, it binds you personally — and you are then the controller of the entrusted data with all the consequences thereof.
  • 3. If the controller turns out to be an entity that did not know about the Service, and that entity demonstrates that the data concern its activity — we perform towards it the obligations under this Annex from the moment of notification and we inform it of the scope and categories of the data processed. We do not issue to it the content of the Book without a legal basis and without a determination as to whom that content belongs.
  • 4. Our liability towards a User who is not a Consumer is subject to the limitations under §15 of the Terms. Towards a Consumer we do not limit it in any way. These limitations do not concern liability towards data subjects, nor towards the supervisory authority (Article 82 GDPR).

§14. Final provisions

  • 1. An amendment to this Annex takes place under the procedure set out in §17 of the Terms, together with a change of the version of the Terms.
  • 2. In matters not regulated herein, the Terms, the GDPR and Polish law apply.
  • 3. In the event of a conflict between this Annex and the Terms as regards the processing of entrusted data, this Annex prevails.
  • 4. The invalidity of any provision does not affect the validity of the remaining ones.

ANNEX B — technical and organisational measures

As at 8 September 2026. It describes what exists. The limitations are named plainly and are part of this list, not a gap in it.

Data isolation

  • Access rules enforced by the database engine on all tables, independently of the correctness of the application. Every query is narrowed to the identity of the owner. The enforcement covers the table owner as well, who in the default configuration would be excluded from it.
  • The tables of the relationship layer have no Company or Team column — there exists no query by which a Company administrator would read a User's Book.
  • Coverage by over a thousand automated assertions, including negative tests ("does the other person really not see this"), run manually before every change to the structure of the database. We do not operate an automated continuous integration process and we do not present its records.

Encryption and transmission

  • Disk encryption on the side of the infrastructure provider.
  • Encrypted transmission on all connections.
  • We do not apply end-to-end encryption or server-side encryption. Content sits in the database in plain text, so the infrastructure provider and we are technically able to read it. That is how the entire mainstream of tools of this class works. An employer has no such possibility — not by prohibition, but through the absence of a path in the structure of the database.

Access control

  • Passwords stored in the form of an irreversible hash; protection against passwords originating from leaks.
  • Two-factor login on the infrastructure owner's accounts.
  • There is no two-factor login for Users.
  • There is no account lockout after multiple failed password attempts — there is a general rate limit on attempts on the side of the authentication provider.
  • Administrative access to the infrastructure is held today by one person. The declared response time says how long you wait — it does not make someone else answer.

Location

  • Database, files and authentication: Ireland. Application execution: Dublin.
  • Application error log: Germany (EEA region selected permanently when the organisation was set up, verified on 8 September 2026).
  • Outgoing mail: sending from Ireland, storage on the provider's side in the USA — see §7.

Minimisation in technical logs

  • Page addresses masked before recording — we record the pattern, not the specific address, so neither the identifier of a person card nor the one-time key from an invitation reaches the application error log.
  • Session recording and performance measurement are switched off and treated as prohibited — the first would record work in the Book, the second would carry working times on the cards of specific persons.
  • Use of error messages and stack traces by the application error log provider is switched off (verified on 8 September 2026). The use of non-identifying elements follows from that provider's terms and is not subject to being switched off.
  • An error message may carry a crumb of data — a database message about a duplicate is capable of quoting the value that triggered it. This cannot be ruled out and we do not pass over it in silence.

Backups and work on the structure of the database

  • Database backups: 7 days, rotation, no possibility of earlier erasure.
  • Before every change to the structure of the database a manual dump of production is made. This is a file with the full content, outside the provider's access mechanisms. It is created solely for the purposes of the migration, is stored on the Provider's device and is deleted after verification that the change is correct. This is the least protected copy of the data in the whole process and we point to it deliberately.

Content processing

  • No artificial intelligence analysis over User content — there is not a single such dependency in the Service.
  • No dashboard for a superior or HR, no indicators, assessments or rankings.
  • We do not record what a User read and for how long.

What we do not declare

We do not declare conformity with ISO 27001, SOC 2 or any other certification standard — including in the form of "in accordance with standards" or "on certified infrastructure". The certificates of subprocessors are their certificates and we indicate them solely alongside them, on the list under §6(2).

*The list of subprocessors, together with the role, the place of processing and the basis for transfer, constitutes a separate, dated page at profilon.pl/flaber/podprocesorzy and is not part of this Annex.*