1. Parties and subject
The subscribing organization is the controller and A.S.K. P.S.U. Sp. z o.o. is the processor for personal data entered by the organization into ASK Serwis Manager.
Processing lasts for the active service period and the technical deletion/return period following termination.
2. Nature and purpose
Processing is automated and manual as necessary to host, store, organize, display, secure, back up and operate system functions on the organization’s instructions.
3. Data subjects and data types
- customers and contact persons;
- employees, technicians and organization users;
- suppliers, subcontractors and persons referenced in service documentation;
- identification/contact data, equipment and job data, communications, notes, photos, attachments and other data entered by the organization.
4. Processor obligations
- process only on documented instructions unless Union or Member State law requires otherwise;
- ensure confidentiality of authorized persons;
- apply appropriate technical and organizational measures;
- reasonably assist the controller with data-subject rights, security obligations, impact assessments and breach handling;
- delete or return data after the service, subject to backups and legal retention;
- make compliance information available and permit justified audits on agreed terms.
5. Sub-processors
The organization grants general authorization for sub-processors needed to provide the service, such as hosting and infrastructure providers. The Operator will impose data-protection obligations corresponding to GDPR requirements.
SMTP and SMS providers configured by the organization are governed by the organization’s legal relationship with those providers; ASK Serwis Manager transmits data to them on the organization’s instruction.
6. Security
Measures may include tenant separation, roles and permissions, encryption of secrets, HTTPS, session protection, event logging, backups, restricted administrative access and security updates. Measures may evolve with technology and risk.
7. Breaches and cooperation
After becoming aware of a breach affecting entrusted data, the Operator will inform the organization without undue delay to the extent required by law and available information and will cooperate in assessing impact and mitigation.
8. Controller instructions
Actions performed by organization users in the system, integration settings, data entry, modification, export and deletion constitute documented instructions within the service functionality. Additional instructions require contact with the Operator and must not violate law or other customers’ security.