Data Processing Agreement (DPA) — Palladin
Polish version. The Polish version is legally binding.
Draft requiring review by qualified counsel before publication. The processing scope, subcontractors, transfers, erasure, audits and liability require particular review. These are draft launch terms. Before accepting data under them, supplier agreements, security measures and workable breach, return and erasure procedures must be confirmed. A complete account-erasure process and retention for all backups have not yet been verified.
1. Parties and application
- The parties are the Customer using Palladin for professional or organisational purposes and Patryk Roguszewski trading as Patryk Roguszewski IT Solutions (“Palladin”), whose details appear in the Terms of Service.
- This DPA covers personal data that Palladin processes on the Customer’s instructions from the start of that processing. It applies regardless of the Plan’s name or price, including free Organizations. A Customer acting as processor must be authorised by the controller to appoint Palladin as subprocessor.
- Within this DPA’s scope, the Customer is controller or processor and Palladin is processor or subprocessor. Holding the Organization administrator role in the application does not by itself determine these legal roles.
- Palladin’s own purposes, including the customer relationship, billing, protection of its own service and legal claims, are governed by the Privacy Policy, rather than the Customer’s instructions. The same identifier may be used in both capacities; the purpose determines the role. A separately agreed DPA may replace this document.
2. Purpose, operations and duration
- The purpose is to store, synchronise and share Organization data according to permissions set by the Customer, including approved Agent access and activity records. Operations include recording, organising, retrieving, transferring, restricting access, returning and erasing data.
- Processing continues while those services are provided and subsequently only as necessary for return and erasure under section 10 or legally required storage.
- Encrypted Vault content remains personal data where it relates to identifiable individuals. Encryption does not remove GDPR obligations. Palladin does not receive plaintext Entry secrets in the ordinary operation of the service; authorised clients decrypt them.
3. Individuals and data covered
| Scope | Description |
|---|---|
| Individuals | Organization users, the Customer’s employees, collaborators, customers and business contacts, and other individuals whose data the Customer lawfully enters. |
| Content | Encrypted Entries and their history, including credentials, notes and fields entered by the Customer. Palladin does not independently determine their contents. |
| Organization and access | Identifiers and names, memberships, roles, permissions, Agent configuration, access requests and reasons, decisions and audit events processed on the Customer’s behalf. |
| Entry metadata | Names, descriptions and website domains also support Entry discovery by Agents within the Organization. They are separate from encrypted secrets; secrets and unnecessary personal data should not be placed in these fields. |
| Particularly protected data | Where content includes data under GDPR Articles 9 or 10, the Customer ensures an appropriate legal basis and additional safeguards. Encryption alone does not mean that the service has been approved for every such use. |
4. Instructions and Customer obligations
- Palladin acts only on documented instructions, including for transfers outside the EEA. Instructions consist of the agreement, Organization configuration and verified Customer requests. An obligation under EU or Member State law takes precedence; Palladin informs the Customer before processing unless that law prohibits the information.
- Palladin promptly informs the Customer if it considers an instruction contrary to data protection law and suspends the disputed part pending clarification. It does not use entrusted data for its own advertising or AI model training.
- The Customer ensures legal bases, required information for individuals and authority to provide the data. It is responsible for selecting users, Agents and permissions and for securing devices and recovery materials. This does not relieve Palladin of its own obligations.
5. Confidentiality and safeguards
- Palladin ensures that individuals allowed to access entrusted data are bound by confidentiality, have access only as needed and understand data protection requirements.
- Safeguards include client-side encryption of secrets, authentication and permission controls, separation of Organizations and event recording. Metadata needed to provide the service may be readable by the backend. FULL access involves cryptographic trust in an Agent for the Vault; GRANULAR limits key delivery to an Entry. The Terms explain the details and effects of revocation.
- Palladin undertakes to maintain transmission and infrastructure safeguards appropriate to the risk, backups and recovery capability, vulnerability management, incident handling and periodic checks of safeguard effectiveness. Changes must not reduce the agreed level of protection. Implementation evidence is available under section 10; this document does not claim certification or a completed audit.
6. Subprocessors
- The Customer gives general written authorisation for subprocessors identified for the relevant service in the list of recipients and processors, made available before the DPA is concluded. This does not automatically authorise every recipient or independent controller on that list.
- Palladin gives at least 14 days’ notice before adding or replacing a subprocessor, stating its identity, task, processing locations and transfer basis. The Customer may raise a reasoned data protection objection within that period.
- The parties agree a solution before the disputed processing begins. If none is possible, Palladin does not provide the Customer’s data to that entity or allows termination of the affected service without penalty, with a proportionate refund for the unused period. Other statutory rights remain unaffected.
- Palladin contractually imposes the same entrusted-data protection obligations on the subprocessor and remains responsible to the Customer for their performance under GDPR Article 28(4).
7. Assistance
- Palladin assists with individuals’ rights and obligations under GDPR Articles 32–36, considering the nature of processing and information available. Inability to read plaintext content does not remove assistance duties concerning data Palladin holds.
- Requests concerning entrusted data are forwarded to the Customer without undue delay. Palladin responds independently only on the Customer’s instructions or where required by law. The parties coordinate action so the Customer can meet statutory deadlines.
- Any fees for non-standard assistance require advance agreement and must not prevent compliance with GDPR obligations. Remedying the consequences of Palladin’s own breach of duty is not a paid add-on.
8. Personal data breaches
- Palladin notifies the Customer without undue delay, no later than 24 hours after becoming aware of a breach or a credible suspicion that an incident concerns the Customer’s entrusted data. It does not wait for confirmation of the full impact or completion of the investigation. This contractual deadline does not extend the duty to act without undue delay.
- Initial information includes the known nature of the incident, affected data and individuals, possible consequences, measures taken or proposed and a contact point. Missing information follows without undue delay. Palladin preserves evidence and assists with assessment and notifications to the authority and individuals.
- Patryk Roguszewski is Palladin’s contact. The Customer maintains an up-to-date contact for urgent notices. Notification is not an admission of fault and does not replace the Customer’s own notification duties.
9. Processing locations and transfers
The recipient list identifies processing locations, entities and roles. Selecting AWS alone does not confirm the region of every service or absence of access from outside the EEA. Before a transfer, Palladin ensures a GDPR Chapter V basis, appropriate agreements and, where needed, a transfer assessment and supplementary safeguards. Information and copies of safeguards are available on request, with protection for others’ confidential information and data. This DPA does not replace transfer standard contractual clauses.
10. Return, erasure and audit
- When processing services end, the Customer chooses return or erasure of all entrusted data; following return, Palladin erases existing copies. Further storage required by law is an exception limited to the relevant data, purpose and duration. Palladin informs the Customer where legally permitted.
- Return and erasure timing are coordinated with the export and switching rules, without shortening the applicable retrieval period. Data needed for an ongoing agreed return must not be erased. The Customer may choose erasure without migration.
- Once the applicable retrieval period expires, or when carrying out a separate erasure instruction, Palladin erases data without undue delay. This obligation includes backups: until erasure they remain protected and unavailable for ordinary use; disaster recovery must reapply previous erasures. Before processing begins, the parties must have a documented and tested expiry schedule for all copies. The project requirement is a maximum of 90 days, but its implementation across the infrastructure has not been confirmed. On request, Palladin confirms the scope and completion of erasure.
- Palladin provides information needed to demonstrate compliance and enables audits and inspections by the Customer or its authorised auditor. Review may start with documentation, but this is not a condition for a necessary inspection. The parties agree proportionate scope, confidentiality and arrangements, protecting other customers’ data. There is no fixed one-audit-per-year limit; arrangements must not prevent scrutiny needed for GDPR compliance or restrict the authority’s powers.
11. Precedence and contact
- For entrusted data, this DPA takes precedence over the Terms; applicable transfer standard contractual clauses take precedence over this DPA. The agreement does not limit individuals’ rights or liability under mandatory law, including GDPR Article 82.
- Contact: patryk.roguszewski@palladin.io, phone +48 517 777 441. Requests should identify the Customer and Organization without passwords or keys. Palladin verifies the requesting person’s authority.
Legal basis: GDPR, particularly Article 28, Articles 32–36 and Chapter V.