Data Processing Agreement
Auronys.com --- Data Processing Agreement
Effective: 21 August 2026 • Slovak law / EU requirements
1. Scope and roles
This Data Processing Agreement ("DPA") applies where Auronys (Ján Danko - BitsLab.io, trading under the brand Auronys.com) processes Personal Data on behalf of a Client who acts as Controller in connection with a Service. For Auronys's own account, billing, security and legal compliance processing, Auronys acts as an independent Controller and this DPA does not apply.
The DPA is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 (GDPR). It is concluded by acceptance of the Terms when ordering a Service through which the Client processes Personal Data on its own behalf.
2. Subject matter, duration and purpose
Subject matter: hosting, storage, transmission, backup, technical support, infrastructure operation and security processing performed for the Client.
Duration: for the duration of the relevant Service and, after termination, only for the period required to return or delete Personal Data or to comply with applicable law.
Purpose: to provide and secure the Services according to the Client's documented instructions and the applicable contract.
3. Categories of data and data subjects
Data may include identifiers, contact details, account information, IP addresses, online identifiers, technical logs and other Personal Data that the Client chooses to store or process through the Service.
Data subjects may include the Client's customers, users, employees, contractors and other persons whose Personal Data the Client places in the Service.
The Client must not intentionally place special-category data or criminal-offence data in a Service unless the Client has a lawful basis and the Service is suitable for that processing.
4. Client instructions and responsibilities
The Client determines the purposes and means of processing of Personal Data for which it is Controller and is responsible for having a lawful basis, providing required notices and responding to data-subject requests.
Auronys processes Personal Data only on documented instructions from the Client, unless Union or Member State law requires processing.
The Client must not use the Service to process Personal Data in violation of applicable law.
5. Confidentiality and security
Auronys will ensure that persons authorised to process Personal Data are subject to confidentiality obligations.
Auronys will implement technical and organisational measures appropriate to the risk, taking into account the nature and scope of processing. Measures may include access controls, authentication, network security, logging, backups and recovery procedures, and incident-response processes.
No security measure can guarantee absolute security.
6. Subprocessors
The Client generally authorises Auronys to engage subprocessors that are reasonably necessary to provide the Services, including infrastructure, security, DDoS mitigation, storage, support and payment-related providers where applicable.
The current subprocessor list is maintained at auronys.com/legal/subprocessors. Auronys will inform the Client of an intended engagement or replacement of a subprocessor at least 14 days in advance by publication on that page; the Client may object within that period on justified data-protection grounds.
Auronys will impose data-protection obligations on subprocessors appropriate to the processing.
7. Assistance
Taking into account the nature of processing and information available to Auronys, Auronys will provide reasonable assistance with data-subject requests and with obligations concerning security, data breaches, impact assessments and consultations with the supervisory authority, to the extent required by Article 28 GDPR.
The Client is responsible for the substance and legality of its processing instructions.
8. Personal-data breaches
Auronys will notify the Client without undue delay after becoming aware of a Personal Data breach affecting Personal Data processed on the Client's behalf, to the extent required by law.
The Client remains responsible for assessing and, where applicable, notifying the competent supervisory authority and affected data subjects.
9. Return and deletion
At the Client's choice and subject to the Service's technical capabilities, Auronys will return or make available Client Personal Data for export at the end of the Service.
After the applicable deletion period (30 days after Service termination per Terms sec. 4), Auronys will delete Personal Data unless Union or Member State law requires its retention. Backups may be deleted according to normal backup rotation cycles.
10. International transfers
Where processing involves a transfer of Personal Data outside the EEA, Auronys will use a transfer mechanism permitted by GDPR, such as an adequacy decision or appropriate safeguards under Chapter V GDPR, where applicable. Per-recipient mechanisms are stated at auronys.com/legal/subprocessors.
11. Audit and compliance information
Auronys will make available information reasonably necessary to demonstrate compliance with Article 28 obligations and will cooperate with audits or inspections permitted by law, subject to reasonable notice, confidentiality, security requirements and protection of other customers.
An audit may not require access to unrelated customer data, secrets or systems where equivalent evidence can reasonably be provided in another form.
12. Order of precedence and effective date
If this DPA conflicts with a mandatory GDPR requirement, the GDPR requirement prevails.
If the main contract conflicts with this DPA on Personal Data processing performed by Auronys as processor, this DPA prevails to the extent necessary to satisfy Article 28 GDPR.
Effective date: 21 August 2026