This Personal Data Processing Entrustment Agreement, hereinafter referred to as the "Entrustment Agreement" or the "DPA", constitutes an appendix to the Terms and Conditions for the provision of the Bezpieczna Kancelaria service and part of the Agreement concluded between the Customer and the Service Provider.
1. Parties to the Entrustment Agreement
1.1. Controller
The controller of the personal data entrusted for processing is the Customer using the Bezpieczna Kancelaria service, i.e. the entity that has concluded an agreement with the Service Provider for the provision of the service, hereinafter referred to as the "Controller" or the "Customer".
The Controller's details are specified in the organisation account, order, offer, registration form, Main Agreement or another document confirming the conclusion of the Agreement.
1.2. Data Processor
The entity processing personal data on behalf of the Controller is:
Aurea Enterprises sp. z o.o., with its registered office at ul. Plac Bankowy 2, 00-095 Warszawa, NIP: 9591956107, KRS: 0000510950, REGON: 260773108, hereinafter referred to as the "Data Processor", "Processor" or "Service Provider".
1.3. Collective designation of the Parties
The Controller and the Data Processor are hereinafter collectively referred to as the "Parties", and each individually as a "Party".
2. Manner of concluding the Entrustment Agreement
The Entrustment Agreement may be concluded electronically, in particular by accepting its content in the Application, selecting the appropriate checkbox, accepting the Terms and Conditions containing a reference to this Entrustment Agreement, applying an electronic signature, applying a qualified electronic signature, signing a PDF document or signing a paper document.
The person accepting the Entrustment Agreement on behalf of the Customer represents that they are authorised to represent the Customer or to perform this act on its behalf.
The Service Provider may record evidence of acceptance of the Entrustment Agreement, in particular: the organisation identifier, user identifier, first name and surname, e-mail address, date and time of acceptance, IP address, user-agent, document version, document hash and the content of the accepted version.
3. Definitions
For the purposes of the Entrustment Agreement, the following terms shall have the following meanings:
Application - the Bezpieczna Kancelaria IT system made available by the Service Provider.
Bezpieczna Kancelaria or BK - the SaaS service provided by the Service Provider to the Customer.
Personal Data - personal data within the meaning of RODO, entrusted to the Data Processor by the Controller or processed on behalf of the Controller in connection with the use of BK.
Customer Data - data, documents, files, recordings, transcriptions, notes, case information, law firm client data, calendar data, invoice data, integration data and other content entered, transmitted, stored or generated by the Controller or its users in BK.
RODO - Rozporządzenie Parlamentu Europejskiego i Rady (UE) 2016/679 z dnia 27 kwietnia 2016 r.
Subprocessor - a further processor engaged by the Data Processor in the provision of BK.
Terms and Conditions - the terms and conditions for the provision of the Bezpieczna Kancelaria service.
Main Agreement - the agreement, terms and conditions, order, offer, price list or another document specifying the rules for the provision of BK to the Customer.
User - a person using BK on behalf of or at the invitation of the Controller.
4. Subject matter of the Entrustment Agreement
The Controller entrusts the Data Processor with the processing of Personal Data to the extent necessary to provide, maintain, secure, develop and support the Bezpieczna Kancelaria service.
The Data Processor undertakes to process Personal Data exclusively in accordance with the rules set out in this Entrustment Agreement, the Main Agreement, the Terms and Conditions, the BK documentation and the documented instructions of the Controller.
The Entrustment Agreement does not transfer to the Data Processor the role of data controller with respect to Customer Data. The Customer remains the controller of Customer Data.
5. Nature and purpose of processing
Personal Data is processed for the purpose of providing the Bezpieczna Kancelaria service, in particular for the purpose of:
- maintaining the Customer's organisation account,
- handling User accounts,
- managing cases, documents, files and permissions,
- storing and synchronising Customer Data,
- handling audio recordings,
- handling transcriptions,
- handling AI functions,
- creating notes, abstracts, summaries and other content generated at the User's instruction,
- handling calendars and deadlines,
- handling external integrations, including calendars, KSeF, court systems, electronic mail or other services configured by the Customer,
- handling invoicing, if the module is active,
- making backups,
- ensuring security,
- maintaining technical and audit logs,
- diagnosing errors,
- handling technical support requests,
- performing other functions activated by the Controller or User.
The processing is automated and partially manual, to the extent necessary to provide BK, maintain the system, provide technical support and ensure security.
6. Duration of processing
The processing entrustment shall continue for the term of the Main Agreement.
Following termination of the Main Agreement, Personal Data shall be processed exclusively to the extent and for the period necessary to:
- enable the Controller to export the data,
- carry out the service termination procedure,
- delete, return or anonymise the data,
- retain backups for the technical retention period,
- perform obligations arising from the law,
- pursue or defend against claims, where this concerns data in respect of which the Data Processor is a separate controller.
Detailed retention periods may be specified in the Main Agreement, the Terms and Conditions, the Privacy Policy, the BK documentation or the configuration of the Customer's account.
7. Types of personal data
Depending on how the Controller uses BK, the entrusted Personal Data may include in particular: first name and surname, e-mail address, telephone number, residential or correspondence address, position, function or role, company or organisation name, identification data of the law firm's clients, data of parties to proceedings, data of legal representatives, data of witnesses, data of business partners, data of the Controller's employees and associates, data contained in documents and case files, data contained in agreements, pleadings, opinions, statements of claim, responses, notes and other documents, data contained in audio recordings, the voices of persons participating in recordings, data contained in transcriptions, data contained in summaries and outputs of AI functions, calendar data, data concerning deadlines, meetings and activities, data from invoices and accounting documents, data from KSeF and court systems (if the integration is active), technical data related to the use of BK, IP addresses, session identifiers, activity logs, security logs and other data entered into BK by the Controller or Users.
8. Special categories of data and data concerning proceedings
The Controller acknowledges that, in connection with the use of BK, special categories of personal data may be processed, in particular data concerning health, family life, financial circumstances, personal relationships, employment, views, affiliations, court disputes, administrative, criminal, civil, family, commercial or other proceedings conducted by the Controller.
BK may also process data concerning criminal convictions, prohibited acts or infringements of law, if such data are contained in documents, case files, recordings or other materials processed by the Controller.
The Controller shall be responsible for ensuring the existence of an appropriate legal basis for the processing of such data and for fulfilling the information obligations towards data subjects.
The Processor shall process such data solely to the extent resulting from the Data Processing Agreement, the Main Agreement and the Controller's instructions.
9. Categories of data subjects
The Entrusted Personal Data may concern in particular: the Controller's clients, the Controller's prospective clients, parties to proceedings, participants in proceedings, witnesses, attorneys-in-fact, opposing parties in litigation, contractors, contact persons, employees and associates of the Controller, lawyers, trainee lawyers, assistants and law firm personnel, persons participating in meetings, conversations and recordings, persons identified in documents, case files, calendars, invoices or correspondence, as well as other persons whose data the Controller or Users enter into BK.
10. Documented instructions of the Controller
The Processor shall process Personal Data solely on the documented instructions of the Controller.
The following shall in particular be deemed documented instructions of the Controller:
- conclusion of the Main Agreement,
- acceptance of the Terms and Conditions,
- acceptance of the Data Processing Agreement,
- configuration of the organisation account,
- actions of the Controller or Users in the Application,
- entering, transmitting, modifying, deleting or exporting data in BK,
- activating or deactivating features,
- activating or deactivating integrations,
- assigning roles and permissions,
- support requests,
- written or electronic instructions of the Controller.
If the Processor considers that an instruction of the Controller infringes RODO or other data protection provisions, it shall inform the Controller thereof, unless the law prohibits such notification.
11. Obligations of the Processor
The Processor undertakes to:
- process Personal Data solely on the documented instructions of the Controller,
- ensure that persons authorised to process the data have undertaken to maintain confidentiality or are subject to a statutory obligation of secrecy,
- implement appropriate technical and organisational measures for data protection,
- assist the Controller in fulfilling the obligations arising from RODO to the extent specified in the Data Processing Agreement,
- engage Subprocessors solely in accordance with the rules specified in the Data Processing Agreement,
- make available to the Controller the information necessary to demonstrate compliance with the obligations arising from Article 28 of RODO,
- allow audits in accordance with the rules specified in the Data Processing Agreement,
- after the completion of the provision of services, delete or return Personal Data in accordance with the Controller's decision, subject to backup copies, technical retention and legal obligations,
- not use Client Data for its own purposes unrelated to the provision of BK,
- not sell Client Data,
- not use Client Data to train AI models for general purposes or for other clients without a separate, explicit legal basis or the Controller's consent.
12. Obligations of the Controller
The Controller undertakes to:
- process Personal Data in accordance with the law,
- have an appropriate legal basis for the processing of Personal Data in BK,
- fulfil the information obligations towards data subjects,
- ensure that persons entering data into BK are authorised to do so,
- manage the roles and permissions of Users,
- not enter into BK data whose processing in BK would infringe the law or the rights of third parties,
- inform persons participating in recordings about the recording, transcription or other processing, if required by law, rules of professional conduct or the Controller's internal procedures,
- ensure that the use of BK complies with professional secrecy and other confidentiality obligations,
- use AI and transcription features in accordance with the law,
- not issue unlawful instructions to the Processor,
- cooperate with the Processor to the extent necessary for the performance of the Data Processing Agreement.
13. Confidentiality
The Processor shall ensure that persons authorised to process Personal Data are bound by confidentiality or are subject to an appropriate statutory obligation of secrecy.
The confidentiality obligation shall include in particular Client Data, documents, case files, recordings, transcripts, law firm client data, data covered by professional secrecy, technical data and information concerning the Controller's Organisation.
The confidentiality obligation shall also remain in force after the end of cooperation with the person concerned and after the termination of the Data Processing Agreement.
14. Technical and organisational measures
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of infringement of the rights or freedoms of natural persons.
These measures shall include in particular, depending on the configuration and scope of the service: encryption of data in transit, encryption of data or files, access control, role and permission mechanisms, separation of Client data, User authentication, event logging, technical monitoring, backup copies, data recovery procedures, restriction of administrative access, incident management, security updates, testing and assessment of the effectiveness of safeguards, personnel access policies and data deletion procedures.
A detailed description of the technical and organisational measures is set out in Appendix No. 2 to the Data Processing Agreement.
The Controller acknowledges that the effectiveness of certain safeguards also depends on the actions of the Controller and Users, in particular on password protection, permission configuration, the use of up-to-date devices and browsers, and compliance with security rules.
15. Encryption and access to content
To the extent provided for by the architecture of BK, the Client's data and files are encrypted.
If a given BK feature is based on a mechanism under which decrypting data requires a password, key or action by the User, the Controller acknowledges that the loss of the password or key may prevent the recovery of access to the decrypted data.
The Processor should not request that Users provide a password, key or other authentication credentials enabling unauthorised access to data.
To the extent necessary for the operation of selected features, such as transcription, AI analysis, search, export, integrations or technical support, data may be processed in a form enabling the performance of the relevant feature, solely on the instruction of the Controller or User and in accordance with the Data Processing Agreement.
16. Subprocessors
The Controller grants general authorisation for the Processor to engage Subprocessors to the extent necessary to provide BK.
The Processor shall engage only such Subprocessors that ensure an appropriate level of data protection and undertake to process data on terms that are no less protective than those arising from this Data Processing Agreement.
The current list of Subprocessors constitutes Appendix No. 3 to the Data Processing Agreement.
The list of Subprocessors shall include at least: the name of the Subprocessor, the category of service, the location of processing, information on any transfer outside the EEA, where applicable, and a description of the type of processing.
The Processor shall inform the Controller of any intended change concerning the addition or replacement of a Subprocessor by publishing an updated list, by e-mail, by a notification in the Application or through another agreed channel.
The Controller may raise a reasoned objection to a new Subprocessor within 14 days of receiving information about the change if it demonstrates that the engagement of the Subprocessor concerned may pose a material risk to the protection of Personal Data.
In the event of a reasoned objection, the Parties shall enter into discussions to find a solution, in particular by disabling the function concerned, using an alternative provider, restricting the scope of processing or terminating the Main Agreement to the extent provided for in its provisions.
The Processor shall be liable to the Controller for the acts and omissions of Subprocessors as for its own acts and omissions, to the extent required by the GDPR.
17. Transfers of data outside the EEA
The Processor shall endeavour to ensure that Personal Data are processed within the European Economic Area.
If, in connection with the use of specific Subprocessors or functions, Personal Data are transferred outside the EEA, the Processor shall ensure the application of the mechanisms provided for by the GDPR, in particular a European Commission adequacy decision, standard contractual clauses or other required safeguards.
Information on transfers outside the EEA is set out in the list of Subprocessors.
The Controller acknowledges that the use of certain functions, in particular AI, transcription, e-mail, integration or external cloud service functions, may require data to be processed by the providers identified in the list of Subprocessors.
18. Assistance in the exercise of data subjects' rights
The Processor shall, insofar as technically and organisationally possible, assist the Controller in fulfilling its obligations relating to the rights of persons whose Personal Data are concerned.
Such assistance may include in particular: searching for data in BK, exporting data, deleting data, restricting processing, rectifying data, providing information on logs or operations, and providing technical support in handling a data subject's request.
If a data subject submits a request concerning Customer Data directly to the Processor, the Processor shall, provided that it is able to identify the relevant Controller, forward the request to the Controller or inform the person that they should contact the relevant Controller.
The Processor shall not independently handle requests concerning Customer Data unless it acts on the Controller's instructions or is required to do so by law.
19. Assistance with security obligations, DPIAs and consultations
Taking into account the nature of the processing and the information available to it, the Processor shall assist the Controller in fulfilling the obligations arising from Articles 32-36 of the GDPR, in particular with regard to: the security of processing, the assessment of a personal data breach, notification of a breach to the supervisory authority, communication to the data subject, a data protection impact assessment and prior consultation with the supervisory authority.
Such assistance shall be provided to the extent relating to BK and the information available to the Processor.
If the assistance goes beyond the standard technical support provided for in the Main Agreement, the Parties may agree separate organisational or financial terms for such assistance, unless otherwise provided by mandatorily applicable provisions of law.
20. Personal data breaches
The Processor shall inform the Controller without undue delay after becoming aware of a breach of the security of Personal Data processed on behalf of the Controller.
The breach notification should contain, to the extent that the information is available: a description of the nature of the breach, the categories and approximate number of data subjects concerned, the categories and approximate number of data records concerned by the breach, the possible consequences of the breach, the measures taken or proposed to address the breach, and the contact details of the person or team responsible for communications concerning the breach.
If complete information is not immediately available, the Processor may provide it in stages.
The Processor shall take measures aimed at mitigating the effects of the breach, securing the data and preventing similar breaches in the future.
Notification of a breach by the Processor shall not constitute an admission of liability for the breach.
The Controller shall be responsible for assessing whether the breach requires notification to the supervisory authority or communication to the data subjects, unless otherwise provided by law.
21. Audit and compliance information
The Processor shall make available to the Controller the information necessary to demonstrate compliance with the obligations arising from Article 28 of the GDPR.
In the first instance, an audit shall be carried out by: making security documentation available, making a description of the technical and organisational measures available, responding to a security questionnaire, providing information on Subprocessors, providing information on procedures and safeguards, and making reports, certificates or attestations available, if they exist and may be disclosed.
The Controller may conduct an audit or inspection concerning the processing of Personal Data by the Processor, provided that: the audit is justified by the scope of the processing entrusted, does not compromise the security of other customers' data, does not lead to the disclosure of trade secrets or confidential information of the Processor, does not unduly disrupt the operation of BK, is announced at least 30 days in advance, is conducted during the Processor's working hours, the auditor is bound by confidentiality, and the scope of the audit has been agreed in advance by the Parties.
An audit at the Processor's premises or within its infrastructure may be restricted for security, organisational or technical reasons. In such a case, the Parties should use an alternative verification method, e.g. a remote audit, a document-based audit or a technical meeting.
If the audit goes beyond the standard scope of information made available to customers or requires substantial involvement of the Processor's personnel, the Parties may agree that such an audit will be subject to a fee, unless the audit is necessary due to a personal data breach attributable to the Processor.
22. Deletion or return of data upon termination of the Agreement
Upon termination of the provision of BK, the Processor, at the Controller's discretion, shall delete or return the Personal Data processed on behalf of the Controller, unless European Union law or the law of a Member State requires further retention of the data.
The Controller should export the Customer Data before termination of the Main Agreement or within the period specified in the Main Agreement, the Terms and Conditions or the BK documentation.
After the expiry of the period provided for data export, the Processor may delete the Customer Data from active systems.
The data may remain for a limited period in backups, technical logs or security archives, in accordance with the technical retention cycle. In such a case, such data shall be secured and shall not be actively processed, unless this is necessary to restore the system, ensure security, comply with a legal obligation or defend against claims.
23. Logs and technical data
The Processor may process technical logs, security logs, metadata, session identifiers, IP addresses and information concerning User activity to the extent necessary to: ensure the security of BK, detect abuse, audit activities, diagnose errors, handle incidents, ensure system integrity and pursue or defend against claims.
Depending on the purpose and scope of the processing, the Processor may process some such data as a processor or as a separate controller if the processing serves its own legitimate purposes, such as infrastructure security, accountability or protection against abuse.
24. AI and transcription functions
If the Controller uses AI, transcription, speech recognition, summarisation or document analysis functions, the Processor shall process Personal Data to the extent necessary to perform the function activated by the Controller or User.
Depending on the configuration of BK, these functions may require data to be transferred to Subprocessors providing AI, transcription, speech recognition, natural language processing or computing infrastructure services.
The Processor shall identify such Subprocessors in the list of Subprocessors.
The Processor shall not use Customer Data to train AI models for general purposes or for the benefit of other customers without a separate, explicit legal basis or the Controller's consent.
The Controller shall be responsible for assessing whether the use of AI or transcription functions complies with the Controller's obligations, in particular information obligations, professional secrecy, rules of professional ethics and provisions of law.
25. Professional secrecy and confidentiality of law firm data
The Processor acknowledges that Customer Data may include information covered by professional secrecy, advocate's secrecy, attorney-at-law's secrecy, tax adviser's secrecy, trade secrecy or other confidentiality obligations.
The Processor undertakes to apply organisational and technical measures aimed at protecting the confidentiality of such data.
The Controller shall be responsible for assessing whether the use of BK within a given scope complies with the Controller's professional obligations and for duly informing its clients, employees, associates and other persons, where required.
26. Amendments to the Data Processing Agreement
The Processor may amend the Data Processing Agreement for valid reasons, in particular in the event of: changes in the provisions of law, changes to BK functions, changes to safeguards, changes to the system architecture, changes of Subprocessors, changes to the service provision model or the need to clarify the obligations of the Parties.
The Processor shall inform the Controller of material amendments to the Data Processing Agreement with appropriate advance notice, in particular by e-mail, a notification in the Application or publication of a new version of the document.
If the Controller does not accept the amendments, it may terminate the Main Agreement in accordance with the terms specified therein.
27. Order of precedence of documents
In the event of a conflict between the Data Processing Agreement and the Main Agreement with respect to personal data protection, the Data Processing Agreement shall prevail, unless the Main Agreement provides for a higher level of data protection or the Parties have expressly agreed otherwise.
In the event of a conflict between the Data Processing Agreement and mandatorily applicable provisions of law, the provisions of law shall prevail.
28. Liability
The liability of the Parties for a breach of the Data Processing Agreement, RODO or other data protection provisions shall be determined by the Main Agreement, RODO and the applicable provisions of law.
No provision of the Data Processing Agreement shall exclude or limit liability to the extent that this would be impermissible under mandatorily applicable provisions of law.
29. Final provisions
The Data Processing Agreement shall remain in force for the term of the Main Agreement and, following its termination, to the extent necessary to perform obligations concerning the deletion, return, safeguarding, accountability or retention of data.
In matters not regulated by the Data Processing Agreement, RODO, other applicable provisions of law, the Main Agreement, the Terms and Conditions and the BK documentation shall apply.
Appendix No. 1 - Scope of processing
Subject matter of the processing: processing of personal data as part of the provision of the Bezpieczna Kancelaria service, comprising a SaaS system for law firms and other professional entities.
Duration: for the term of the Main Agreement and for the period necessary to complete the service termination, export, deletion, backup retention and claim preservation procedures or to comply with legal obligations.
Nature of the processing: automated and partially manual processing, including in particular collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission as part of system functions, alignment, combination, restriction, erasure, destruction, encryption, decryption to the extent necessary to perform the functions, creation of backups and export.
Purpose of the processing: provision, maintenance, safeguarding and development of the Bezpieczna Kancelaria service and performance of functions activated by the Controller or Users.
Categories of data subjects: law firm clients, prospective law firm clients, parties to and participants in proceedings, witnesses, legal representatives, contractors, employees and associates, lawyers, trainee lawyers, assistants and law firm personnel, contact persons, persons participating in meetings and recordings and persons identified in documents, files, invoices, calendars or correspondence.
Categories of data: identification, contact, address, professional, financial, accounting and tax data, data concerning cases and proceedings, data contained in documents, recordings and transcripts, voice data, calendar data, invoice data, integration data, technical data, IP addresses, session identifiers, activity logs and other data entered by the Controller or Users.
Special categories of data: special categories of personal data and data concerning criminal convictions, prohibited acts or proceedings may be processed within BK if the Controller enters such data into BK or if such data arise from documents, recordings, transcripts, case files or other materials processed by the Controller.
Annex No. 2 - Technical and Organisational Measures
The Processor applies, in particular, the following technical and organisational measures, depending on the scope of the service, configuration and availability of functions.
Access control: individual User accounts, roles and permissions, separation of organisations, restriction of administrative access, principle of least privilege, ability to revoke access, logging of selected User activities.
Authentication: logging in using individual access credentials, passwords or other authentication mechanisms, session tokens, ability to use additional security mechanisms, session security.
Encryption: encryption of data in transit, encryption of data or files in accordance with the BK architecture, protection of keys or access mechanisms, restriction of access to decrypted data to the extent necessary for the operation of the functions.
Data separation: logical separation of Customer data, separation of organisation accounts, resource access control mechanisms, mitigation of the risk of unauthorised access between organisations.
Backups and restoration: creation of backups, storage of backups for a specified retention period, protection of backups, ability to restore data in the event of a failure, periodic testing of restoration procedures.
Monitoring and logging: technical logs, security logs, error monitoring, availability monitoring, detection of anomalies or abuse, incident analysis.
Organisational security: granting personnel access on a need-to-know basis, requiring personnel to maintain confidentiality, incident response procedures, request handling procedures, system update and maintenance rules, restriction of access to production environments.
Software development security: change control, test and production environments, code reviews or other quality control mechanisms, security updates, remediation of identified vulnerabilities according to risk priority.
Minimisation and retention: processing of data to the extent necessary for the provision of BK, ability to export data, data deletion procedures, retention of logs and backups in accordance with the documentation, restriction of active data processing following termination of the Agreement.
Incidents: procedure for identifying and classifying incidents, measures mitigating the effects of an incident, communication with the Controller, root cause analysis, remedial measures.
Annex No. 3 - List of Sub-processors
| Name of Sub-processor | Service category | Scope of processing | Location | Transfer outside the EEA | Safeguards |
|---|---|---|---|---|---|
| Hetzner Online GmbH | infrastructure / hosting | application hosting, databases, file storage | Germany (EEA) | no | data processing agreement |
| OpenAI | transcription / AI | recordings, transcriptions, prompts and outputs of AI functions | USA | yes | standard contractual clauses (SCC) |
| ElevenLabs | transcription / speech recognition | recordings, transcriptions | USA | yes | standard contractual clauses (SCC) |
The list may be updated in accordance with the "Sub-processors" section of the Data Processing Agreement. Categories such as transactional email, technical monitoring, payments and backups will be added after the relevant agreements with providers have been concluded.
Language
This document is available in Polish and English. The Polish version is the source text; in case of any discrepancy between the versions, the Polish version prevails. The English version is a translation provided for convenience only.