Skip to content
Openbiznis
Platform Roles Integrations Security
Sign in Book a demo
Platform Roles Integrations Security Sign in
Legal

Data Processing Agreement

Last updated: 5 August 2026 · Effective: 5 August 2026

This Data Processing Agreement (DPA) forms part of the Terms of Service and applies whenever we process personal data on a customer's behalf. If your organisation needs a countersigned copy, email ceo@launchzy.eu and we will arrange it.

1. Parties and roles

This DPA is between the Customer (the "Controller") and Launchzy s. r. o., IČO 57605513, Jazernica 129, 038 44 Jazernica, Slovakia (the "Processor"), and supplements the Terms of Service.

It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR"). Where the Customer is itself a processor for a third party, the Customer acts as controller for the purposes of this DPA and warrants it has authority to instruct us.

2. Subject matter and duration

The subject matter is the provision of the Openbiznis platform. Processing lasts for the term of the subscription plus the retention window in section 9.

3. Nature and purpose of processing

We process personal data to host, operate, secure, support, and back up the platform, and to provide the integrations the Customer enables. We do not process it for our own purposes, do not sell it, and do not use it to train publicly available AI models.

4. Categories of data subject

  • The Customer's personnel and authorised users
  • The Customer's leads, prospects, clients, and their staff
  • Media and PR contacts stored in the marketing workspace
  • Any other individual whose data the Customer chooses to enter

5. Types of personal data

  • Identity and contact data: names, email addresses, phone numbers, employer, job title
  • Account data: role, permissions, authentication and MFA state, login and audit records
  • Commercial data: lead and deal records, pipeline stage, notes, tags, forecast values
  • Communications data: call logs, dispositions, call recordings where the Customer enables them, and messages synced from connected channels
  • Calendar data: appointments, attendees, and availability
  • Financial data: commissions, invoices, and expense records the Customer enters
  • Any further data contained in free-text fields or uploaded files

The Customer must not enter special category data under Article 9 GDPR, or criminal conviction data under Article 10, unless expressly agreed with us in writing beforehand.

6. Processor obligations

We will:

  • process personal data only on the Customer's documented instructions, including for transfers, unless required otherwise by EU or member state law — in which case we will inform the Customer first, unless the law prohibits it;
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement the technical and organisational measures required by Article 32, described in section 7;
  • respect the conditions in Article 28(2) and (4) for engaging sub-processors;
  • assist the Customer, by appropriate technical and organisational measures and insofar as possible, in responding to data subject rights requests;
  • assist the Customer with Articles 32 to 36, taking into account the nature of processing and the information available to us;
  • at the Customer's choice, delete or return the personal data at the end of the service, as set out in section 9; and
  • make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits under section 10.

We will immediately inform the Customer if, in our opinion, an instruction infringes the GDPR or other EU or member state data protection law.

7. Security measures

Taking account of the state of the art and the risks presented, we maintain measures including:

  • role-based access control, with every route and action gated by an explicit permission enforced server-side;
  • row-level security policies at the database layer, so a query cannot return data outside the requester's scope;
  • multi-factor authentication, with step-up verification required for sensitive roles and actions;
  • encryption of data in transit using current TLS, and encryption at rest by our hosting and database providers;
  • an audit trail of meaningful changes, recording actor and timestamp;
  • least-privilege administrative access, reviewed periodically;
  • segregated environments, with a demo mode so staff can be trained without live data; and
  • regular backups, with restoration procedures.

8. Sub-processors

The Customer grants general written authorisation for us to engage sub-processors. The current list is published at openbiznis.com/sub-processors.

We will give at least 30 days' notice before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Customer may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remain fully liable to the Customer for their performance.

9. Return and deletion

On termination, the Customer may export its data through the platform for 30 days, or request an export from us within that period. After 30 days we delete the personal data from live systems, and from backups in accordance with our backup rotation, unless EU or member state law requires continued storage.

10. Audits

We will make available information reasonably necessary to demonstrate compliance with Article 28 and will contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

Audits are limited to once per twelve months unless a data protection authority requires more, or a personal data breach has occurred. The Customer will give at least 30 days' notice, conduct the audit during business hours, minimise disruption, and ensure the auditor is bound by confidentiality and is not a competitor of ours. Each party bears its own costs, save that the Customer bears our reasonable costs for audits beyond the annual allowance.

11. Personal data breaches

We will notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Customer's personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information — to the extent that information is available at the time, supplemented in phases as it becomes available.

Notifying the Customer is not an admission of fault or liability.

12. International transfers

Personal data is hosted in the European Union or European Economic Area by default. Where a sub-processor processes data outside the EEA, the transfer is made under an adequacy decision where one applies, and otherwise under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor), together with any supplementary measures the transfer requires following a transfer impact assessment.

By entering into this DPA, the parties are deemed to have signed those Clauses where they apply, with the docking clause enabled, this DPA's sections 4 and 5 completing Annex I, section 7 completing Annex II, and the sub-processors page completing Annex III.

13. Data subject requests

If we receive a request from a data subject relating to the Customer's data, we will not respond directly other than to acknowledge and redirect, and will forward the request to the Customer without undue delay. We will assist the Customer in responding, taking into account the nature of processing.

14. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, those Clauses prevail.

15. Contact

Launchzy s. r. o., Jazernica 129, 038 44 Jazernica, Slovakia
ceo@launchzy.eu · +421 905 706 135

Related documents

Privacy Policy Terms of Service Cookie Policy Sub-processors Acceptable Use Policy Imprint
Openbiznis

The command center for modern agencies. One platform, every department, total control.

Platform
Overview Roles Integrations Security
Company
Launchzy Book a demo ceo@launchzy.eu Sign in
Legal
Privacy Policy Terms of Service Data Processing Cookie Policy Sub-processors Acceptable Use Imprint
© 2026 Launchzy s. r. o. All rights reserved. Jazernica 129, 038 44 Jazernica, Slovakia · IČO 57605513