Data Processing Agreement (DPA)
under Art. 28 of Regulation (EU) 2016/679 (GDPR) and § 34 of Act No. 18/2018 Coll.
Version: 1.0 · Effective date: 21 June 2026
This agreement forms an integral part of the Terms of Service for the ScopeCheck Service and applies where the uploaded brief contains personal data. It is concluded between:
- Controller: the Customer (the ScopeCheck service customer) who uploads a brief containing personal data.
- Processor: VisionEdge s. r. o., 29. augusta 1503/1A, 958 01 Partizánske, Company ID (IČO): 51962161, registered in the Commercial Register of the District Court Trenčín, Section Sro, Insert No. 37109/R.
For the avoidance of doubt: with respect to order data, contact and billing data, VisionEdge acts as an independent controller under the Privacy Policy; this DPA concerns only the personal data contained in the uploaded brief.
1. Subject matter and duration
1.1 The Processor processes the personal data contained in the brief on behalf of the Controller solely for the purpose of performing the brief audit under the Terms.
1.2 Processing lasts for the time needed to perform the audit. The uploaded brief is deleted 24 hours after the Report is delivered (see Art. 7).
2. Nature and purpose of processing
2.1 Nature: receiving, temporary storage, reading and assessment of the brief's content, and its deletion, carried out for the purpose of the audit.
2.2 Purpose: professional assessment of the brief (the audit) and preparation of the Report for the Controller.
2.3 Categories of data subjects and data: see Annex 1.
3. Controller's instructions
3.1 The Processor processes personal data only on the basis of the Controller's documented instructions; creating an order and these Terms/DPA are also deemed instructions.
3.2 If the Processor considers that an instruction infringes data protection regulations, it notifies the Controller without delay.
4. Processor's obligations
4.1 Confidentiality: persons authorised to process the data (consultants) are bound by confidentiality.
4.2 Security (Art. 32 GDPR): measures under Annex 3.
4.3 Assistance to the Controller: to a reasonable extent with data subject requests (Art. 12 to 23 GDPR) and obligations under Art. 32 to 36 GDPR; given the short retention period (24 hours after delivery), assistance is possible only within that period.
4.4 Personal data breach: notification to the Controller without delay, no later than within 48 hours of becoming aware, and cooperation.
4.5 Audit: making available the information necessary to demonstrate compliance with Art. 28 GDPR by prior arrangement.
5. Sub-processors
5.1 The Controller grants general authorisation to engage the sub-processors listed in Annex 2.
5.2 The Processor imposes equivalent data protection obligations on sub-processors and informs the Controller in advance of changes to their list, with the option to object.
6. Transfers to third countries
6.1 Transfers outside the EEA take place only where appropriate safeguards under the GDPR exist (in particular SCC). Current sub-processors and their locations are listed in Annex 2.
7. Deletion or return of data
7.1 The Processor deletes the uploaded brief and the personal data contained in it 24 hours after the Report is delivered (or without delay if the order is refunded), unless EU or Slovak law requires retention. This satisfies the return/deletion obligation under Art. 28(3)(g) GDPR.
8. Liability and final provisions
8.1 The liability of the parties is governed by the GDPR and the Terms. In the event of a conflict on matters of personal data processing, this DPA prevails and is governed by the law of the Slovak Republic.
Annex 1: Categories of data subjects and personal data
Categories of data subjects: persons whose data may appear in the brief (e.g. representatives of the Customer's client, project contact persons).
Categories of personal data: data contained in the brief, usually identification and contact data and project data. Special categories of data (Art. 9 GDPR) are not to be included in the brief — the Customer confirms this when ordering.
Annex 2: List of sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hosting provider | hosting and temporary storage of the brief | [fill in — EU] | [EEA / SCC] |
| Payment provider | processing the payment | [fill in] | [fill in] |
| Email provider | delivery of the confirmation and the Report | [fill in] | [fill in] |
We do not use an external AI provider. Before publishing, confirm the specific providers and their region.
Annex 3: Technical and organisational measures (Art. 32 GDPR)
- Encrypted transmission (HTTPS/TLS) and security headers.
- Access management for the administration interface (consultants) and confidentiality.
- Time-limited storage of the brief — deletion within 24 hours of delivery of the Report.
- Logical separation of orders and restriction of access to what is necessary.
- Operational monitoring and a controlled change-deployment process.
The measures are reviewed on an ongoing basis according to the state of the art.