EURO.REVIEWS / LEGAL DOCUMENTS
Data Processing Addendum
Controller-to-processor terms for order, invitation and customer data.
Parties, scope and hierarchy
This DPA forms part of the agreement between the Client as controller and the Operator as processor where Euro.Reviews processes Client Personal Data solely on documented instructions. GDPR terms have the meanings given in Regulation (EU) 2016/679.
If this DPA conflicts with the Terms on processing Client Personal Data, this DPA prevails. It does not govern processing for which the Operator is an independent controller, including account security, billing, public review integrity and independent moderation as described in the privacy notices.
Documented instructions
The processor will process Client Personal Data only to provide the configured Service, comply with documented instructions in the agreement, account settings, API calls or support requests, and meet applicable legal obligations. If an instruction appears unlawful, the processor will inform the controller unless prohibited by law.
Confidentiality and security
Persons authorised to process Client Personal Data are bound by confidentiality. The processor maintains measures appropriate to the risk, including access control, authentication, encryption in transit, logging, backups, vulnerability and patch management, data separation and incident response.
Subprocessors and transfers
The Client grants general written authorisation for the subprocessors published in the Subprocessors document. The processor will impose materially equivalent data protection obligations and remains responsible for their performance as required by law.
The processor will provide reasonable advance notice of a new subprocessor where required, allowing the Client to object on documented data protection grounds. Restricted transfers use an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism.
Assistance and incidents
- Assist the Client with data-subject requests, considering the nature of processing.
- Assist with security, breach notification, data protection impact assessments and regulatory consultations where applicable.
- Notify the Client without undue delay after becoming aware of a personal data breach affecting Client Personal Data.
- Provide information reasonably necessary to demonstrate compliance with Article 28 GDPR.
Deletion, return and audit
At the end of the Service, the processor will delete or return Client Personal Data at the Client’s choice where technically reasonable, unless retention is required by law. Backup copies are deleted according to the normal protected backup cycle.
The Client may request a reasonable remote audit no more than once per year unless a breach or authority requires more. Audits must protect other customers, security and confidential information. On-site audits require reasonable notice and may be subject to justified costs.
Processing details
Item | Description |
|---|---|
Subject and duration | Review invitation, verification and related service processing for the agreement term plus deletion and backup periods. |
Nature and purpose | Receive orders, create invitations, send email, connect reviews to purchases, support products, prevent abuse and provide configured analytics. |
Data subjects | Customers and prospective reviewers of the Client; authorised Client users where processed on instruction. |
Personal data | Name, email, order reference, dates, language, shop, products, delivery events, IP/security events and support data. |
Sensitive data | Not intentionally required. The Client must not provide special-category data unless expressly agreed and lawful. |
Controller obligations | Lawful basis, transparency, data minimisation, accurate instructions and handling of customer rights. |
Contact and governing terms
Data protection notices under this DPA may be sent to tichy@eurion.sk. The governing law and dispute terms in the main agreement apply unless mandatory data protection law requires otherwise.
Version | 0.9 |
Status | Draft for legal review |
Updated | 29 July 2026 |
Operator | European Business Solutions s. r. o. |