Data Processing Addendum
DPA summary for support, licence and service processing connected with Plogins.
Last updated:
When this applies
These terms govern any processing of personal data that we carry out on your behalf, and they take effect between you as controller and WPPoland as processor when you contact us for support on a site you operate. They form the agreement required by Art. 28(3) GDPR. Where we decide our own purposes, for example our billing records, we act as controller and the privacy document applies instead.
Subject matter, duration, nature and purpose
Subject matter: personal data contained in the diagnostic material you send us, such as a log excerpt, a database row, a screenshot or a staging copy. Nature and purpose: reading and analysing that material solely to diagnose and fix a defect or to answer a configuration question about our plugin. Duration: for the length of the support case and the retention period stated in the privacy document, after which the material is deleted.
Types of data and categories of data subjects
Types of data: whatever your diagnostic material happens to contain, typically names, email addresses, postal addresses, order and invoice data, IP addresses and user account identifiers. Categories of data subjects: your customers, your site users and your own staff. Please send the minimum that lets us reproduce the problem, and redact or use test data where you can: we cannot control what you send us, and the smallest sample is both the safest and usually the fastest to work with.
We act only on your instructions
We process the material only on your documented instructions, including on any transfer to a third country, unless EU or Polish law requires otherwise; in that case we inform you before processing unless that law forbids it. Your support request, and what you attach to it, is the instruction. We tell you if in our view an instruction infringes the GDPR.
Confidentiality and security
Everyone authorised to process the material is bound by confidentiality. Our measures under Art. 32 GDPR are: access limited to the people working the case, multi-factor authentication on the accounts involved, encryption in transit, storage only in the systems named in the subprocessors document, and deletion once the case is closed and the retention period has run. WPPoland is a one-person business, so in practice the authorised person is the owner.
Subprocessors
You give general authorisation for the subprocessors listed in the subprocessors document. We announce any addition or replacement there before it starts processing, we impose the same data protection obligations on it, and we remain fully liable to you for its performance. You may object on reasonable data protection grounds, with the consequence described on that page.
Assistance, breaches and audits
We assist you, so far as we are able and given the nature of the processing, in answering data subject requests and in meeting your duties under Art. 32 to 36 GDPR. If we become aware of a personal data breach affecting your data we notify you without undue delay and in any event within 48 hours, with what we know and what we are doing. On request we make available the information needed to demonstrate compliance with this article and we allow and contribute to audits, including inspections, by you or an auditor you mandate.
Return and deletion
When the support case ends we delete the diagnostic material, or return it and delete our copies if you ask, unless EU or Polish law requires us to keep it. You can ask for deletion earlier at any time by writing to [email protected], and we confirm in writing once it is done.
This document is product information and does not replace individual legal advice.