Data Processing Agreement
Preamble & Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Web Solution Jog690 S.R.L. ("Processor", "we") and the registered user of biolinks.info ("Controller", "you").
It governs the processing of personal data of your end users (biolink page visitors) carried out by us on your behalf pursuant to Art. 28 GDPR. In the event of conflict, this DPA takes precedence over the Terms of Service with respect to data protection matters.
By using the platform you accept this DPA. A signed copy can be downloaded below.
↓ Download DPA as PDFDefinitions
- "Controller" – the registered user who determines the purposes and means of processing personal data of their biolink page visitors.
- "Processor" – Web Solution Jog690 S.R.L., operating the biolinks.info platform.
- "Customer Data" – personal data of end users processed by the Processor on behalf of the Controller via the platform.
- "Sub-Processor" – any third party engaged by the Processor to process Customer Data.
- "Security Incident" – any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
- "GDPR" – EU Regulation 2016/679 and any applicable national implementations.
Nature of Processing
The Processor processes Customer Data solely to operate and provide the biolinks.info platform in accordance with the Terms of Service and the Controller's instructions. No processing beyond this scope takes place without a separate written instruction.
The Controller is solely responsible for ensuring a valid legal basis for any processing of personal data they initiate via the platform (e.g. through tracking pixels, embedded scripts, or contact forms).
Obligations of the Processor
Confidentiality
The Processor ensures that all personnel authorized to process Customer Data are bound by confidentiality obligations and access Customer Data only to the extent necessary for their tasks.
Instructions
The Processor processes Customer Data only on documented instructions from the Controller. If required by EU or national law to process beyond those instructions, the Processor will inform the Controller in advance unless legally prohibited.
Assistance
The Processor will assist the Controller in fulfilling obligations under the GDPR, including responding to data subject requests, data protection impact assessments, and breach notifications.
Sub-Processors
The Controller hereby grants general authorization for the engagement of the following sub-processors:
| Provider | Location | Purpose | Status |
|---|---|---|---|
| INWX GmbH & Co. KG Prinzessinnenstr. 30, 10969 Berlin, Germany |
Germany | Domain registration | Active |
| Cloudways Ltd. 52 Springvale, Pope Pius XII Street, Mosta MST2653, Malta |
Malta / EU | Platform hosting | Active |
| Wasabi Technologies LLC 111 Huntington Avenue, Boston, MA 02199, USA |
USA | Cloud storage | Planned |
The Processor will notify the Controller at least 30 days in advance before adding a new sub-processor. The Controller may object in writing within 14 days if there are demonstrable compliance concerns. If the objection cannot be resolved, the Controller may terminate the contract with 90 days' notice.
The Processor ensures each sub-processor is bound by data protection obligations equivalent to those in this DPA.
Data Subject Rights
The Processor will promptly notify the Controller of any requests received from data subjects regarding Customer Data and will not respond directly to such requests without the Controller's instruction, unless required by law.
The Processor will provide reasonable technical assistance to enable the Controller to fulfill data subject rights (access, rectification, erasure, restriction, portability) within the platform.
Security
The Processor implements appropriate technical and organizational measures pursuant to Art. 32 GDPR, including:
- SSL/TLS encryption for all data in transit
- Access control and user authentication
- Role-based access restrictions for personnel
- Regular backups and recovery testing
- Confidentiality agreements with all personnel with data access
- Logging of access and system events
In the event of a Security Incident, the Processor will notify the Controller within 72 hours of becoming aware, investigate the incident, and take remedial action.
International Data Transfers
Where Customer Data is transferred outside the EEA, the Processor ensures an adequate level of protection through one of the following mechanisms:
- EU Commission adequacy decision for the destination country
- EU Standard Contractual Clauses (SCCs) with the sub-processor
- Certification under the EU-US Data Privacy Framework (where applicable)
Wasabi Technologies LLC (USA, planned) – transfer covered by SCCs or DPF certification at time of activation.
Term & Deletion
This DPA remains in force for the duration of the Terms of Service. Upon termination of the account, the Processor will delete all Customer Data within 90 days, including data held by sub-processors, unless statutory retention obligations require otherwise.
The Controller may request written confirmation of deletion.
Annex – Processing Details (Art. 28(3) GDPR)
Subject Matter & Duration
Operation of the biolinks.info SaaS platform for the duration of the account.
Nature & Purpose
Hosting, storage, and transmission of data to provide biolink pages, URL shortening, click analytics, and related platform features.
Types of Personal Data
- End user IP addresses (anonymized in analytics)
- Browser and device information
- Referrer URLs and click data
- Any data embedded by the Controller via pixels, scripts, or forms
Categories of Data Subjects
Visitors to biolink pages and shortened URLs operated by the Controller.
Controller Obligations
The Controller is responsible for ensuring a valid legal basis for all processing of end user data they initiate via the platform, including maintaining their own privacy policy and obtaining any required consents.
Processor: Web Solution Jog690 S.R.L.
Strada Ion Slavici, Nr. 13 Cam. Nr. 1, Scara B, Ap. 18, 300539 Timișoara, Romania
Email: office@jog690.eu · VAT: RO38794995