Data Processing Agreement

Version 1.3 · Last updated: 2026-08-05
Concluded as an integral part of the Terms of Service between the Client (controller) and the Operator (processor). The binding version is the Polish one.

1. Subject and roles

The Client (controller) entrusts the Operator (processor) - Bartecki Group sp. z o.o., ul. Franciszka Ilskiego 2B/8, 04-479 Warsaw, KRS 0000720383, NIP 5223114944 - with the processing of personal data of the Client's End Users, to the extent necessary to provide the TenTermin Service, under Art. 28 GDPR.

2. Scope, nature and purpose

Categories of data: identification and contact data of End Users (name, phone, e-mail), booking and visit history. Where the Client uses the health-data feature, the entrusted data also include special categories of data concerning health (Art. 9(2)(a) GDPR): e.g. allergies, contraindications, medications, pregnancy and treatment notes - processed by the Operator solely for storage and presentation within the Service, on the basis of the End User's explicit consent obtained and documented by the Client (controller). Categories of persons: the Client's clients (End Users). Purpose: provision of the booking and management Service. Duration: for the term of the main Agreement.

For data concerning health the Operator applies heightened safeguards: encryption at rest, access restricted to authorized staff on a need-to-know basis, and access logging - proportionate to the elevated risk (Art. 9 and Art. 32 GDPR).

3. Processor's obligations

4. Sub-processors

The Client grants general authorization (Art. 28(2) GDPR) to engage sub-processors that support the Service, on data-protection terms no less protective than this Agreement. The current sub-processor list - with legal name, purpose, processing location and transfer safeguards - is maintained and available to the Client in the salon panel (section "Data subprocessors").

The Operator will actively notify the Client of any intended addition or replacement of a sub-processor (by e-mail to the address in the panel and by an in-panel notice) at least 30 days before the new sub-processor starts processing. The Client may raise a reasoned objection within 30 days of the notice; no objection within that period is deemed acceptance. In case of objection, the parties will seek a solution in good faith; if none is possible, the Client may terminate the Agreement with respect to the services requiring the disputed sub-processor.

The payment provider (Paynow - the online payment system of mBank S.A., operated by mElements S.A.) is NOT a sub-processor - it acts as a separate, independent controller of payment data. The Operator imposes the same data-protection obligations on its sub-processors.

5. Audit

The Operator makes available information necessary to demonstrate compliance and enables audits, including inspections, conducted by the Client or an authorized auditor, with reasonable notice.

6. Personal data breaches

The Operator notifies the Client of a personal data breach without undue delay after becoming aware of it, providing the information needed for the Client's notifications.

7. Liability and final provisions

Allocation of liability. Under Article 82(2) GDPR the Processor is liable for damage caused by processing only where it has not complied with obligations that the GDPR directs specifically at processors, or where it acted outside or contrary to the Controller's lawful instructions. The Controller is responsible for the lawfulness of its instructions, for the legal basis of processing, for the scope and content of the entrusted data, for fulfilling the information obligation towards data subjects, and for consents to marketing communication.

Recourse. Where one Party has compensated damage or paid an administrative fine in the part corresponding to the other Party's responsibility, it is entitled to recourse for that part (Article 82(5) GDPR). A fine imposed by the supervisory authority is borne by the Party whose infringement caused it.

Relation to the Terms. Between the Parties, the limitations of liability set out in the Terms of Service (sections 9 and 9a) apply. Those limitations do not apply to liability towards data subjects or towards the supervisory authority; such liability cannot be excluded or limited by contract.

Matters not regulated herein are governed by the GDPR and the Polish Personal Data Protection Act. The binding language version is Polish.