Data Processing Agreement (DPA)
Data Processing Agreement (DPA)
Parties and scope
The controller is the customer identified in the accepted UNI-PAD agreement. The processor is PDR QCS s.r.o., company identification number 04913469, Křižovnická 86/6, 110 00 Praha 1 – Staré Město, contact info@uni-pad.com. The DPA forms part of the service agreement.
The subject matter is storing, displaying, modifying, searching, transferring on instruction, OCR, backing up and erasing data for the operation of the customer's company. Processing lasts for the duration of the service and the termination arrangements below. It covers the controller's customers, contact persons, employees and suppliers; their identification and contact details, and data concerning vehicles, jobs, documents, payments, signatures and attachments. Special categories of data are not the subject of the processing ordinarily agreed.
Instructions, protection and assistance
The controller determines the purposes, scope and lawfulness of processing and users' access. The processor acts only on the controller's documented instructions, including for transfers to third countries. Where the law requires a departure from those instructions, the processor will give prior notice, if permitted by law. The processor will promptly inform the controller of any unlawful instruction.
The processor will bind authorised persons to confidentiality and ensure measures appropriate to the risk under Article 32 of the GDPR. The contractual minimum includes separation of companies, access controls, protection of transfers, backups and a recovery procedure; the specific scope of measures is set by the following contractual minimum: access only for authorised persons according to their role, separation of customer data, encrypted transmission, protection of access credentials, restricted access to backups, and a recovery procedure that reapplies erasures. The processor continually assesses the measures according to risks; this agreement does not promise certification or complete recording of all user actions.
The processor will assist the controller in handling individuals' rights, security incidents, impact assessments and consultations with the authority. The processor will notify the controller of a personal data breach without undue delay after becoming aware of it and provide the available information and subsequent updates. The ordinary two-day support response period does not apply to this obligation. The processor will provide evidence of compliance and allow inspections, including audits, by the controller or its appointed auditor while protecting other customers' data.
These contractual obligations draw on the Commission's official clauses for the controller–processor relationship; this text does not reproduce the standard clauses and is not an independent transfer safeguard.
Subprocessors
The controller authorises the following subprocessors within the stated scope. This list forms part of the DPA:
| Subprocessor | Purpose and scope | Location and conditions |
|---|---|---|
| WEDOS a.s., company identification number 28115694, Masarykova 1230, 373 41 Hluboká nad Vltavou | Application and database hosting, hosting backups and recovery; system email on the hosting service | The provider's agreement states that processing takes place mainly in the EU. This is not a guarantee of processing exclusively in the EU. Retention of hosting backups is governed by the Return and erasure section. |
| Anthropic Ireland, Limited | OCR through the API; the entire image or PDF selected by the user and the processing result | Processing may take place outside the EU/EEA. Anthropic's Data Processing Addendum and the applicable standard contractual clauses apply. Standard API retention and its exceptions are described in the Privacy Notice. |
The operator's own Synology device in the Czech Republic is not a separate external processor. Information about subprocessors engaged by the listed providers and copies of relevant transfer safeguards are available on request at info@uni-pad.com. An email service separately contracted by the customer for its own sending is not automatically authorised by this list as a service contractually provided by the UNI-PAD operator.
Engaging an additional processor or replacing one requires the controller's prior written authorisation. The processor will impose corresponding contractual obligations on the subprocessor and remains responsible to the controller for their performance. It will transfer data to third countries only where the applicable GDPR conditions and the controller's documented instructions are met.
Return and erasure
From definitive termination of the agreement, the controller has 30 calendar days for return of the agreed data and attachments. At the controller's choice, the processor will return the data and erase copies, or erase the data without returning it. Earlier erasure will be carried out upon a verified request by the controller. After this period, the processor will erase the data unless its retention is required by law. Erasure must also cover copies held by subprocessors.
For disaster recovery, we make daily encrypted backups on our own storage in the Czech Republic. We retain each backup for no more than 30 calendar days from its creation. After erasure from the operational application, data may remain only in separate backup copies for no more than a further 30 calendar days; it will then be removed from those copies too, including related storage snapshots. During this interim period, it is not available for ordinary use. During disaster recovery, erasures already carried out will be reapplied before the restored application is made available, so that erased data does not return to use.
The hosting provider's backup copies follow a separate regime. Under its agreement, they are erased periodically, no later than 180 calendar days from creation of the relevant backup. This does not extend the period of ordinary use of the data or the retention period of our own backups. Individual data items are not erased separately from hosting backups already created. Erasures already carried out are reapplied during recovery; this procedure also covers recovery performed by the hosting provider. The contractual maximum does not itself mean that every hosting backup exists for the full 180 days.
Non-payment alone does not trigger erasure. The processor's own statutory accounting documents are retained separately and do not justify retaining the controller's entire database. The obligations to protect data continue for as long as the processor retains it.
Effective from 1 October 2026.

CSEN