Data Processing Agreement
Version 2026-09-30, effective 2026-09-30
This Data Processing Agreement (DPA) forms part of the agreement between the customer (Customer, controller) and PE Klimovych Anastasiia, an individual entrepreneur (ФОП) registered in Ukraine, taxpayer number (RNOKPP) 3478811607, 18 Myru St., Vodychky village, Khmelnytskyi district, Khmelnytska region, 31334, Ukraine (Adminka, processor) for the Adminka Connect service under the Terms of Service (the Agreement). It applies to personal data that Adminka processes on the Customer's behalf and is accepted together with the Terms.
It is made to satisfy Article 28 of the GDPR and the Law of Ukraine "On Personal Data Protection" (the rules on processors).
1. Roles and instructions
1.1. The Customer is the controller of personal data in its CRM; Adminka processes that data as processor (or as sub-processor where the Customer is itself a processor).
1.2. Adminka processes Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA and the Customer's configuration of the Service (the CRM connected, the tables enabled, the reports it builds) are those instructions. Adminka informs the Customer if it believes an instruction infringes the law.
1.3. The subject matter, nature, purpose, data categories and duration are described in Annex I.
2. Confidentiality
Adminka ensures that everyone authorised to process Customer Personal Data is bound by confidentiality.
3. Security
Adminka implements the technical and organisational measures in Annex II and keeps them appropriate to the risk. Adminka may update them provided the overall level of protection is not reduced.
4. Sub-processors
4.1. The Customer gives general authorisation to the sub-processors listed in Annex III.
4.2. Adminka notifies the Customer by email at least 14 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of any prepaid, unused period.
4.3. Adminka imposes data protection obligations on each sub-processor equivalent to this DPA and remains responsible for its sub-processors.
5. International transfers
5.1. Customer Personal Data is hosted in Germany (EU). Adminka is established in Ukraine, which has no EU adequacy decision, and accesses the data from Ukraine to operate the Service.
5.2. To the extent the Customer is subject to the GDPR, the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) (or Module Three where the Customer is a processor), are incorporated into this DPA by reference, with the Customer as data exporter and Adminka as data importer, and with these choices:
- Clause 7 (docking clause) — applies;
- Clause 9(a) — option 2, general written authorisation, with the notice period in section 4.2;
- Clause 11 — the optional redress language does not apply;
- Clauses 17 and 18 — the law and courts of the EU Member State in which the data exporter is established (or, if none, Ireland);
- Annexes I–III of the Clauses are completed by Annexes I–III of this DPA.
5.3. If the Clauses conflict with this DPA or the Agreement, the Clauses prevail.
6. Personal data breaches
Adminka notifies the Customer without undue delay and in any case within 72 hours after becoming aware of a personal data breach affecting Customer Personal Data, with the information available (nature of the breach, categories and approximate numbers affected, likely consequences, measures taken), and updates the Customer as more becomes known.
7. Assistance
Taking into account the nature of the processing, Adminka assists the Customer with: responding to data subjects' requests (Adminka forwards any request it receives directly); security; breach notifications; data protection impact assessments and prior consultations. Adminka informs the Customer of any legally binding request for Customer Personal Data from an authority, unless the law forbids it.
8. Deletion and return
During the Agreement the Customer can disconnect its CRM or ask us to delete data at any time. When the Agreement (or an unpaid trial) ends, Adminka deletes Customer Personal Data within 30 days, unless the law requires storage; copies in backups are overwritten on rotation within 21 days. On request before the end, Adminka provides the data in a common machine-readable format.
9. Audits
Adminka makes available the information necessary to demonstrate compliance with this DPA and answers the Customer's reasonable written security questions. Where that is not sufficient, the Customer may carry out an audit (itself or through an independent auditor bound by confidentiality) once per year, with 30 days' notice, during business hours, at its own cost and without access to other customers' data.
10. Liability and precedence
Liability under this DPA is subject to the limitations of the Agreement, except where the law does not allow it. In case of conflict: the Standard Contractual Clauses, then this DPA, then the Agreement. This DPA runs as long as Adminka processes Customer Personal Data.
Annex I — Description of the processing
- Data exporter / controller: the Customer (identified by its Account); contact — the Account email.
- Data importer / processor: Adminka, info@adminka.pro.
- Subject matter and nature: reading data from the Customer's CRM via its API (read-only), storing it in a database dedicated to the Customer, transforming it into reporting tables, and delivering those tables to the Customer's Google Data Studio reports through the Adminka connector.
- Purpose: providing Adminka Connect to the Customer.
- Frequency: continuous; synchronisation once a day.
- Data subjects: the Customer's clients, leads and their contact persons; the Customer's employees and CRM users (e.g. deal owners, call participants).
- Categories of personal data: names; company names; phone numbers and email addresses; deal, order, lead and payment records linked to a person; call records (time, direction, duration, phone number); identifiers of CRM users; any data the Customer keeps in CRM custom fields that the Service reads.
- Special categories: none intended. The Customer must not store special categories of data in the CRM fields the Service reads.
- Duration: the term of the Agreement plus the deletion period in section 8.
- Competent supervisory authority: the authority of the EU Member State where the Customer is established.
Annex II — Technical and organisational measures
- Encryption in transit (HTTPS/TLS) for the Site, the Service API and the connector.
- CRM API keys encrypted at rest (AES-256) and never displayed after they are entered.
- Read-only use of CRM APIs; the Service never writes to the Customer's CRM.
- Logical isolation: a separate database per customer; every connector request is authorised by a customer-specific token.
- Administrative access restricted to named staff and possible only through a VPN; individual, least-privilege database accounts.
- Nightly backups, with an encrypted off-site copy.
- Input validation on all public endpoints; rate limiting and bot protection on public forms.
- Deletion of Customer data at the end of the Agreement (section 8).
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting, storage and backups | Germany (EU) |
Google Data Studio receives data at the Customer's own instruction, under the Customer's agreement with Google, and is not an Adminka sub-processor.
Parts of this DPA are adapted from the Common Paper Data Processing Agreement, available at commonpaper.com under the CC BY 4.0 licence.