Legal information
Data Processing Addendum (DPA)
Terms for processing customer personal data in the service under Article 28 GDPR.
Working copy updated: 27 September 2026.
Registration creates an account and workspace without a licence; online checkout is not available yet.
Legal information
Terms for processing customer personal data in the service under Article 28 GDPR.
Working copy updated: 27 September 2026.
This DPA forms part of the contract between the customer as controller and Martin Kučera, Company ID 00959324, as processor where the customer sends personal data through the service and determines its purposes and means. It applies for the duration of the relevant feature.
The subject matter is processing connected WordPress-site data for enabled audits, hosted generation, support, licensing, and operational features. Documented instructions consist of the contract, customer settings, API calls, and written requests within the agreed scope.
The processor processes data only on documented instructions unless EU or Member State law requires otherwise; it will inform the customer before such processing unless the law prohibits notice. It will flag an apparently unlawful instruction and may suspend its execution.
The customer gives general written authorisation to use subprocessors. They currently comprise ACTIVE 24, s.r.o. / WebSupport s.r.o. for hosting, infrastructure, backups, and system email delivery, and Stripe to the extent it acts as a processor during future approved use of payment services. Public checkout remains disabled. No external AI provider is enabled.
The processor will impose substantially the same data protection duties on a subprocessor. It will give at least 15 days’ prior notice of an intended addition or replacement where practicable. The customer may raise a reasoned objection; if it cannot be resolved, the customer may terminate the affected feature.
Data will be transferred outside the EU/EEA only on documented instructions and under a valid Chapter V GDPR mechanism, particularly an adequacy decision or Standard Contractual Clauses. On request, the processor will identify the mechanism to the extent permitted by contractual and security obligations.
The processor will first provide available documentation and answers. The customer may request a reasonable audit no more than annually, or following a serious incident, with at least 30 days’ notice, during business hours, without endangering other customers, and at its own cost unless a material breach is established.
Retention follows the Privacy Policy. The verified erasure process deletes operational records and anonymises necessary links; Stripe and other provider data is handled through their processes. Liability follows the main contract and applicable law without restricting duties that cannot lawfully be limited.