Adatfeldolgozási szerződés

A résztvevői adatok feldolgozása az ügyfél nevében (DPA)

Utoljára frissítve: 18 June 2026|13 szakasz
Minden dokumentum 6 nyelven érhető el: spanyol, angol, olasz, észt, francia és német. Eltérés esetén az angol változat az irányadó.
01

Parties, subject matter and framework

1.1. Parties

This Data Processing Agreement (hereinafter, the "Agreement" or "DPA") is entered into between:

  • The customer —the presenter, organisation or professional who contracts Votinova and creates or runs interactive voting sessions— in its capacity as controller (hereinafter, the "Controller" or the "Customer"); and
  • Atbion OÜ, a private limited company (Osaühing) incorporated under Estonian law, with registry code 16890390 and VAT number EE102728154, with registered office at Ahtri tn 12, Kesklinna linnaosa, Tallinn 15551, Harju maakond, Estonia, operator of the Votinova product (votinova.com), in its capacity as processor (hereinafter, the "Processor" or "Atbion OÜ").

The Controller and the Processor are referred to jointly as the "Parties".

1.2. Subject matter of the Agreement

This Agreement governs the processing of the personal data of participants —the audience that joins and responds in the Customer's sessions— carried out by Atbion OÜ on behalf of and in accordance with the documented instructions of the Customer within the framework of the provision of the Votinova service. It is entered into in compliance with Article 28 of Regulation (EU) 2016/679 (hereinafter, "GDPR") and Estonian data protection legislation (Isikuandmete kaitse seadus).

1.3. Relationship with the other contractual documents

This Agreement is incorporated into the Terms of Service and forms an integral part of the service contract between the Customer and Atbion OÜ. It applies whenever the Customer processes personal data of participants through Votinova.

In relation to the account data —the data of the presenter and of the members of the organisation (name, email address, credentials, billing data, security logs, among others)—, Atbion OÜ acts as controller in its own right, and such processing is not governed by this Agreement, but by the Privacy Policy. This Agreement is confined to participant data in respect of which Atbion OÜ is the processor.

02

Definitions

For the purposes of this Agreement, the following terms have the meaning attributed to them by the GDPR:

TermDefinition
ControllerThe natural or legal person who determines the purposes and means of the processing of personal data. In this Agreement, the Customer in respect of participant data.
ProcessorThe natural or legal person who processes personal data on behalf of the controller. In this Agreement, Atbion OÜ.
SubprocessorThe third party engaged by the Processor to carry out specific processing activities on behalf of the Controller.
Data subjectThe identified or identifiable natural person whose personal data are processed; in this Agreement, the participant in the Customer's sessions.
Personal dataAny information relating to an identified or identifiable natural person, in accordance with Article 4(1) of the GDPR.
ProcessingAny operation performed on personal data, whether or not by automated means (collection, recording, storage, consultation, disclosure, erasure, among others).
Personal data breachAny breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data, or the unauthorised disclosure of, or access to, such data, in accordance with Article 4(12) of the GDPR.
Documented instructionsThe Controller's instructions relating to the processing, set out in this Agreement, in the Terms of Service, in the service configuration chosen by the Customer and in any subsequent direction given in writing.
Supervisory authorityThe independent public authority competent in matters of data protection; for Atbion OÜ, the Andmekaitse Inspektsioon (AKI) of Estonia.
03

Subject matter, duration, nature and purpose of the processing

3.1. Nature and purpose

Atbion OÜ processes the personal data of participants for the sole purpose of providing the Votinova service on behalf of the Controller: enabling the audience to join the Customer's sessions, submit responses and votes, take part in open questions and Q&A, and have the results aggregated and displayed in real time. The processing comprises the technical operations necessary for this (collection, recording, aggregation, temporary storage, disclosure to the session audience and erasure).

3.2. Types of data and categories of data subjects

The categories of personal data processed and the categories of data subjects (participants in the Customer's sessions) are summarised below and detailed in Annex I. By default, participants are anonymous; the Customer decides, by means of the session configuration, whether to enable the identified or authenticated mode and, therefore, which data are collected.

3.3. Duration

The processing takes place throughout the term of the service contract between the Customer and Atbion OÜ and ends in accordance with clause 9 of this Agreement.

04

Obligations of the Processor

Atbion OÜ, in its capacity as Processor, undertakes the following, in accordance with Article 28(3) of the GDPR:

4.1. Processing in accordance with documented instructions

To process the personal data only following the documented instructions of the Controller, including those relating to international transfers, unless Union or Estonian law requires Atbion OÜ to do otherwise, in which case it shall inform the Controller of that legal requirement before the processing, unless legally prohibited. If Atbion OÜ considers that an instruction infringes the GDPR or another data protection rule, it shall notify the Controller without delay.

4.2. Confidentiality of personnel

To ensure that the persons authorised to process the personal data have undertaken to respect confidentiality or are under a statutory obligation of confidentiality, and that access is limited to the personnel who need it in order to provide the service.

4.3. Security measures (Art. 32 GDPR)

To implement the appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. Such measures are described in Annex II and are reviewed and updated periodically.

4.4. Assistance with data subjects' rights

To assist the Controller, by means of appropriate technical and organisational measures and insofar as possible, so that it can respond to requests for the exercise of the rights of data subjects (access, rectification, erasure, restriction, portability, objection) provided for in Chapter III of the GDPR. If a participant addresses a request directly to Atbion OÜ, the latter shall forward it without delay to the Controller and shall not respond on its own behalf, save on the Controller's instruction.

4.5. Assistance with security, impact assessments and prior consultations

To assist the Controller in complying with the obligations of Articles 32 to 36 of the GDPR (security of processing, notification and communication of breaches, data protection impact assessment and prior consultation of the supervisory authority), taking into account the nature of the processing and the information available to Atbion OÜ.

4.6. Notification of personal data breaches

To notify the Controller, without undue delay after becoming aware of it, of any personal data breach affecting the personal data processed on behalf of the Controller. The notification shall include, insofar as possible, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or proposed to remedy it. Atbion OÜ shall cooperate with the Controller so that the latter can comply, where applicable, with its obligations to notify the supervisory authority and to communicate with the data subjects (Articles 33 and 34 of the GDPR).

4.7. Erasure or return of data

At the Controller's choice, to erase or return all the personal data once the provision of the service has ended, and to erase the existing copies, unless Union or Estonian law requires their retention, in accordance with clause 9.

4.8. Demonstration of compliance

To make available to the Controller all the information necessary to demonstrate compliance with the obligations of Article 28 of the GDPR and to allow for and contribute to the audits and inspections provided for in clause 7.

05

Subprocessors

5.1. General authorisation

The Controller grants Atbion OÜ a general authorisation to engage subprocessors for the purpose of providing the service. The list of verified subprocessors as at the effective date is set out in Annex III.

5.2. Guarantees required of subprocessors

Atbion OÜ shall impose on each subprocessor, by contract, the same data protection obligations as those established in this Agreement, in particular the implementation of appropriate technical and organisational measures (Article 28(4) of the GDPR). Atbion OÜ shall remain fully liable to the Controller for the performance by the subprocessor of its obligations.

5.3. Prior notice of changes and right to object

Atbion OÜ shall inform the Controller of any intended change concerning the addition or replacement of subprocessors, giving the Controller the opportunity to object to such changes on reasonable grounds relating to data protection. If the Controller objects and the Parties do not reach a solution, the Controller may terminate the service in respect of the affected part in accordance with clause 9.

06

International transfers

6.1. Principle: processing in the European Union

The processing of participant data is carried out primarily within the European Union: computing and storage are hosted on AWS (EU region) and the main database resides in a MongoDB Atlas cluster in the EU (see Annex II).

6.2. Guarantees for transfers to third countries

Where a subprocessor processes personal data outside the European Economic Area, such transfer shall be covered by a valid transfer mechanism in accordance with Chapter V of the GDPR, in particular:

  • The standard contractual clauses (SCCs) adopted by the European Commission, supplemented, where appropriate, with additional measures; and/or
  • The EU-U.S. Data Privacy Framework (DPF) in respect of United States providers certified for that purpose, where applicable.

The details of the location of each subprocessor and of the applicable transfer mechanisms are set out in Annex III.

07

Audits and inspections

7.1. Right to audit

Atbion OÜ shall make available to the Controller the information necessary to demonstrate compliance with Article 28 of the GDPR and shall allow for and contribute to the conduct of audits and inspections, including those carried out by the Controller or by an independent auditor appointed by it and subject to confidentiality.

7.2. Modalities

Audits shall be carried out with reasonable prior notice, during working hours, without undue interruption to Atbion OÜ's operations and with a reasonable frequency (as a general rule, no more than once a year, unless there is a substantiated security incident or a supervisory authority so requires). Atbion OÜ may satisfy the right to audit by providing certifications, third-party audit reports or equivalent documentation on its measures and those of its subprocessors, where such documentation reasonably responds to the Controller's request.

08

Liability

Each Party is liable for the damage caused by processing that infringes the GDPR, under the terms of Article 82 of the GDPR. No provision of this Agreement —or of the Terms of Service— limits or excludes the liability of the Parties to the extent that such limitation or exclusion is prohibited by the GDPR or by mandatory data protection rules. The limitations of liability agreed in the service contract are without prejudice to the foregoing.

09

Duration and termination

9.1. Duration

This Agreement enters into force on the date indicated at the beginning or, if later, on the date on which the Customer begins to process participant data through Votinova, and remains in force for as long as Atbion OÜ processes personal data on behalf of the Controller. Its duration is linked to the term of the service contract.

9.2. Return or erasure of data on termination

On termination of the service, and at the Controller's choice, Atbion OÜ shall return or erase the personal data of participants processed on behalf of the Controller, and shall erase the existing copies, unless Union or Estonian law requires their retention. Data stored temporarily in the real-time infrastructure are deleted automatically once the technical retention periods have elapsed; the encrypted backups are overwritten in accordance with their rotation cycle.

9.3. Survival

The confidentiality obligations, the guarantees relating to transfers and the provisions on liability survive termination to the extent necessary to protect the data subjects.

10

Final provisions

10.1. Applicable law

This Agreement is governed by Estonian law and by the GDPR and other European Union data protection legislation.

10.2. Hierarchy

In the event of a contradiction between this Agreement and the Terms of Service as regards the processing of participants' personal data, this Agreement prevails. In all other respects, the Terms of Service govern.

10.3. Amendments

Atbion OÜ may update this Agreement to reflect legal, technical or organisational changes, notifying material changes with reasonable prior notice. The related documents are available in the legal centre: https://votinova.com/legal.

10.4. Data protection contact

For any query relating to this Agreement or to the processing of personal data, you may contact privacy@votinova.com. The competent supervisory authority is the Andmekaitse Inspektsioon (AKI) — Tatari 39, Tallinn 10134, Estonia — info@aki.eehttps://www.aki.ee.

11

Annex I — Details of the processing

SectionDetail
Categories of data subjectsParticipants making up the audience of the Customer's sessions (anonymous, identified or authenticated, according to the configuration chosen by the Customer).
Categories of personal dataEphemeral participant identifier; responses and votes submitted; text of open responses and audience questions (Q&A); name and email address when the Customer enables the identified mode; IP address used for rate limiting and fraud prevention; session metadata (timestamps, join code, technical connection data).
Special categories of dataNot requested or required. The Customer is responsible for not collecting special categories of data (Article 9 of the GDPR) unless it has its own legal basis for doing so.
Purpose of the processingTo provide the real-time interactive voting and presentation service on behalf of the Controller: joining the session, submission and aggregation of responses, moderation of Q&A and open responses, and display of results to the audience.
Nature of the processingCollection, recording, real-time aggregation, temporary storage, disclosure to the session audience, assisted moderation and erasure.
Duration of the processingTerm of the service contract between the Customer and Atbion OÜ; erasure or return in accordance with clause 9.
12

Annex II — Technical and organisational measures (Art. 32 GDPR)

Atbion OÜ applies, as a minimum, the following measures, which it reviews and updates periodically. Sensitive parameters whose publication could facilitate attacks are not disclosed.

MeasureDescription
Credential protectionPasswords are stored by means of an industry-standard memory-hard key derivation function (Argon2); never in clear text.
Encryption in transitAll communication is encrypted by means of TLS.
Encryption at restStored data are encrypted at rest, including the main database and the backups.
Role-based access controlRole-based access and the principle of least privilege; personnel access is limited to what is necessary to provide the service.
EU hostingThe computing and storage infrastructure is hosted on AWS (EU region) and the main database resides in a MongoDB Atlas cluster in the EU.
Encrypted backupsPeriodic, encrypted backups, with a controlled rotation cycle.
Activity loggingActivity logging and security monitoring for the detection of and response to incidents.
Automated moderation with human reviewAssisted content filtering by means of automated services (image and text analysis) before contributions are shown to the audience, with human review available (presenter moderation).
Personnel trainingPeriodic training of personnel in data protection and information security.
Subprocessor managementSelection, contracting and oversight of subprocessors with equivalent guarantees (clause 5).
13

Annex III — List of subprocessors

SubprocessorServiceLocation / transfer
Amazon Web Services EMEA SARLComputing, storage, CDNEU region (data in the EU)
Amazon Web Services (SES)Transactional email deliveryEU (EU region)
Amazon Web Services (Rekognition)Automated image moderationEU
Amazon Web Services (Comprehend)Automated text moderationEU
MongoDB (Atlas)Main databaseCluster in the EU
Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.)Payments, billing and taxesEU + U.S. (DPF + standard contractual clauses)
Functional Software, Inc. (Sentry)Error and performance trackingU.S. (standard contractual clauses; personal information is minimised)
Google (Firebase Cloud Messaging)Push notifications (mobile application)EU / U.S. (DPF / standard contractual clauses)

Note: Stripe, Google ("Sign in with Google") and Apple ("Sign in with Apple") act, in certain operations, as independent controllers in respect of account data, which is governed by the Privacy Policy and not by this Agreement.

Atbion OÜ — Estonian Commercial Register 16890390 — VAT EE102728154 — Votinova (votinova.com).

Utoljára frissítve: 18 June 2026

Atbion OÜ — Votinova (votinova.com)