← Privacy policy

Data Processing Agreement

Version 2 · effective 2026-06-17

This DPA is concluded electronically when an authorized representative of your organization accepts it during onboarding. An executable signed copy is available on request for enterprise customers. [email protected].

DATA PROCESSING AGREEMENT (DPA)

Service: Elevate — a multi-tenant service desk / helpdesk platform (ticketing, knowledge base, SLA tracking, reporting, optional AI assistant), available at elevate.dynaminds.pl (with per-tenant subdomains).

Version: 2 (replacing version 1) · Effective date: 17 June 2026


§1. Parties and manner of conclusion

  1. This Data Processing Agreement (the "Agreement" or "DPA") is concluded between:
  1. The Agreement constitutes a standard contractual template within the meaning of Article 384 of the Polish Civil Code and is concluded electronically (electronic form), in accordance with Article 28(9) GDPR, which permits a processing agreement to be in writing, including in electronic form. Conclusion occurs when a person authorized to represent the Controller checks an active, non-pre-ticked acceptance box next to a link to the exact, versioned text of this Agreement and submits a declaration of authority to represent the Controller. This act replaces a handwritten signature.
  2. Acceptance is recorded in an immutable (append-only) consent ledger comprising: the identity of the accepting person, the version and checksum (hash) of the accepted document, the timestamp, the IP address, the client identifier (user agent), and confirmation of acting in the capacity of an authorized signatory. This record constitutes evidence of conclusion of the Agreement.
  3. At the request of an enterprise Controller, Dynaminds may make available a signed counterpart of the Agreement on a durable medium; this is not, however, a condition of effective conclusion of the Agreement in electronic form.
  4. "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
  5. The following form an integral part of this Agreement: Annex 1 — Technical and Organisational Measures (TOM) and the Sub-processor List published and maintained at the address specified in §8. In the event of any discrepancy between this Agreement and the Sub-processor List as to the periods for notification of, and objection to, changes of sub-processors, the periods set out in §8(3) prevail (which are identical to the periods declared in the Sub-processor List).

§2. Roles of the parties

  1. The Controller (the Client organization) is the controller of personal data within the meaning of Article 4(7) GDPR with regard to personal data processed in the course of using the Elevate service.
  2. Dynaminds (B2B.net S.A.) is the processor within the meaning of Article 4(8) GDPR and processes the entrusted personal data solely on behalf of and for the Controller.
  3. This Agreement governs the processing of personal data by Dynaminds on behalf of the Controller and prevails over the provisions of the Terms of Service in matters of personal data protection in the event of any discrepancy.

§3. Subject-matter, nature, purpose and duration of processing (Article 28(3) GDPR)

  1. Subject-matter of processing: the processing of personal data necessary for Dynaminds to provide the Elevate service to the Controller, i.e. to make available and maintain the service desk / helpdesk platform.
  2. Nature of processing: automated and non-automated processing operations performed on personal data, in particular: collection, recording, storage, organization, structuring, alteration, retrieval, use, disclosure within the platform, restriction, erasure and destruction — in respect of features comprising ticket handling, knowledge base, SLA tracking, reporting and — if enabled by the Controller — the optional AI assistant.
  3. Purpose of processing: to enable the Controller to use the Elevate service for its intended purpose and in accordance with the Controller's documented instructions; Dynaminds does not process the entrusted data for its own purposes.
  4. Duration of processing: from the conclusion of this Agreement, for the entire term of the agreement for the provision of the Elevate service (the period during which the Controller's account is active), until the end of the provision of the service, subject to §11 (return or deletion of data) and §11 (retention periods).

§4. Type of personal data and categories of data subjects (Article 28(3) GDPR)

  1. Categories of data subjects: persons representing the Controller and its platform users (employees, contractors, account administrators), and persons whose data the Controller enters or which are contained in ticket content — in particular the Controller's end users, customers, employees or contractors who submit matters or to whom tickets relate.
  2. Type (categories) of personal data:
  1. Special categories of data (Article 9 GDPR) and data on criminal convictions (Article 10 GDPR):
  1. The Controller determines the scope of personal data actually entered through the manner in which it uses the platform; the Controller is responsible for the lawfulness of the entrusted data and for the accuracy and adequacy of its scope.

§5. Processing only on documented instructions of the Controller (Article 28(3)(a) GDPR)

  1. Dynaminds processes the entrusted personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which Dynaminds is subject; in such case Dynaminds informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  2. The following constitute documented instructions of the Controller: this Agreement, the Terms of Service, the configuration and settings made by the Controller in the platform, use of the platform's features for their intended purpose, and instructions given in writing (including by email) by persons authorized by the Controller.
  3. If, in Dynaminds' assessment, an instruction of the Controller infringes the GDPR or other data protection provisions, Dynaminds immediately informs the Controller.

§6. Confidentiality of authorized persons (Article 28(3)(b) GDPR)

  1. Dynaminds ensures that persons it authorizes to process the entrusted personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  2. Dynaminds grants authorizations to process personal data only to persons for whom access to the data is necessary to perform this Agreement (need-to-know principle, access minimization), and ensures that those persons receive appropriate data protection training.

§7. Security measures (Article 28(3)(c) and Article 32 GDPR)

  1. Dynaminds takes all measures required pursuant to Article 32 GDPR, i.e. taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons — it implements appropriate technical and organisational measures to ensure a level of security appropriate to that risk.
  2. The specific technical and organisational measures (TOM) applied by Dynaminds as at the effective date of this Agreement are set out in Annex 1 (Technical and Organisational Measures — TOM), which forms an integral part of the Agreement. These measures include in particular:
  1. Dynaminds may update Annex 1, provided that the level of security is not reduced. Dynaminds also makes available to the Controller, on request, a current and detailed description of the measures applied.

§8. Engagement of further processors — sub-processors (Article 28(2), (3)(d) and (4) GDPR)

  1. The Controller grants Dynaminds a general written authorisation to engage further processors (sub-processors) for the purpose of providing the Elevate service. The current list of sub-processors is published and maintained at: https://elevate.dynaminds.pl/legal/subprocessors (the "Sub-processor List") and forms an integral part of this Agreement.
  2. As at the effective date of this Agreement, Dynaminds uses the following sub-processors (each under its own data processing agreement ensuring an at least equivalent level of protection):

The legal bases for transfers outside the EEA for the above sub-processors are set out in §13.

  1. Dynaminds informs the Controller of any intended changes concerning the addition or replacement of sub-processors by updating the Sub-processor List and by notification (by email or an in-platform message) at least 30 days in advance of the new or changed sub-processor commencing processing, thereby giving the Controller the opportunity to object to such a change. The period for raising an objection is no less than 30 days from the date of notification. These periods are identical to the periods declared in the Sub-processor List. In the event of a justified objection, the parties will seek a solution in good faith; if no solution is reached, the Controller is entitled to terminate the affected part of the service.
  2. Dynaminds imposes on each sub-processor — by way of a contract or other legal act — the same data protection obligations as set out in this Agreement, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures.
  3. Dynaminds remains fully liable to the Controller for the performance of the sub-processor's data protection obligations.

§9. Assistance to the Controller (Article 28(3)(e) and (f) GDPR)

  1. Fulfilment of data subjects' rights (Articles 12–23 GDPR): taking into account the nature of the processing, Dynaminds assists the Controller, insofar as possible, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights (the rights of access, rectification, erasure, restriction of processing, data portability, objection, and rights related to automated decision-making). If such a request is received directly by Dynaminds, Dynaminds without undue delay, and no later than within 3 business days of receipt, forwards it to the Controller and does not respond without the Controller's instruction, unless required to do so by law. This period is intended to enable the Controller to meet its own deadlines under Article 12 GDPR.
  2. Charging for assistance: The assistance referred to in paragraphs 1 and 3, performed through standard platform features (self-service: export, correction, deletion of data by the Controller), is provided free of charge. Where a request requires non-standard, above-average effort by Dynaminds (e.g. extensive manual searching or bespoke engineering activities going beyond the platform's features), Dynaminds may charge the Controller reasonable, documented costs at a previously communicated, reasonable rate; before incurring such costs Dynaminds provides the Controller with an estimate and proceeds upon the Controller's approval.
  3. Support with obligations under Articles 32–36 GDPR: taking into account the nature of processing and the information available to it, Dynaminds assists the Controller in ensuring compliance with the obligations relating to:

§10. Notification of personal data breaches (Article 33 GDPR)

  1. Dynaminds notifies the Controller of any breach of the security of the entrusted personal data without undue delay after becoming aware of it, so as to enable the Controller to comply in a timely manner with its obligations under Articles 33 and 34 GDPR.
  2. The notification contains at least, to the extent available to Dynaminds: a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned), the likely consequences of the breach, the measures taken or proposed to address it, and the contact point from which more information can be obtained. Where it is not possible to provide all information at once, the information is provided in phases as it becomes available.

§11. Return or deletion of data after the end of processing (Article 28(3)(g) GDPR)

  1. After the end of the provision of the Elevate service, Dynaminds — at the Controller's choice — deletes or returns to the Controller all entrusted personal data and deletes existing copies, unless Union or Member State law requires storage of the data.
  2. Given the nature of the service, the following default retention periods apply, unless the Controller requests earlier return or deletion:
  1. At the Controller's request, Dynaminds confirms that the return or deletion of data has been carried out.

§12. Making information available and audits and inspections (Article 28(3)(h) GDPR)

  1. Dynaminds makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and in this Agreement.
  2. Dynaminds allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
  3. Audits take place after prior, reasonable notice (as a rule at least 14 days in advance), during business hours, in a manner that minimises disruption to Dynaminds' operations and respects the confidentiality of other clients' data and trade secrets. Dynaminds may first make available current certifications, audit reports or codes of conduct; if these do not demonstrate compliance to the required extent, the Controller is entitled to carry out an on-site or remote audit.
  4. Audit frequency: Unless the law, an instruction of the supervisory authority, or the occurrence of a personal data breach requires otherwise, the Controller is entitled to carry out an audit no more than once per calendar year. An additional audit beyond this limit is permissible, in particular: (a) following a significant personal data breach affecting the Controller's data, (b) at the justified request of a supervisory authority, or (c) following a material change to the manner of processing or to the set of sub-processors.
  5. Audit costs: Each party bears its own costs in connection with an audit. The provision of information and of the certifications/reports referred to in paragraphs 1 and 3, and cooperation within one annual audit to a reasonable extent, are free of charge. Where an audit (or an additional audit beyond the limit in paragraph 4) requires above-average effort by Dynaminds or the commitment of resources beyond a reasonable extent, Dynaminds may charge the Controller reasonable, documented costs at a previously communicated, reasonable rate, having first provided an estimate. The costs of an audit that reveals material failures by Dynaminds in performing this Agreement are borne by Dynaminds.

§13. Transfers to third countries (Chapter V GDPR)

  1. Transfers of entrusted personal data to third countries (outside the European Economic Area) take place only on documented instructions from the Controller or where they result from the use of the sub-processors listed in §8.
  2. To the extent that sub-processors process data outside the EEA (in particular Microsoft, Stripe, Cloudflare, Anthropic and Voyage AI), the transfer is carried out on the basis of at least one of the following mechanisms, consistently with the information contained in the Sub-processor List:
  1. Current information on which transfer mechanism (DPF or SCCs) applies to a given sub-processor is indicated in the Sub-processor List and, at the Controller's request, Dynaminds makes available detailed information on the mechanisms and safeguards applied. In the event of the invalidation or suspension of an adequacy decision (DPF), Dynaminds, without undue delay, ensures an alternative transfer basis compliant with Chapter V GDPR (in particular the SCCs).

§14. Data protection officer and contact point

  1. Dynaminds' contact point for matters concerning personal data protection is: [email protected]. The general service contact address is: [email protected].
  2. The Controller warrants that the person accepting this Agreement is duly authorized to represent the Controller and to incur obligations on its behalf under the Agreement.

§15. Liability

  1. Each party is liable for damage caused by processing in accordance with the principles set out in Article 82 GDPR and in generally applicable law.
  2. Dynaminds is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the lawful instructions of the Controller.

§16. Term and amendments

  1. The Agreement remains in force for the period during which the Elevate service is provided to the Controller and expires upon the end of that provision, subject to the provisions which by their nature should survive expiry (in particular §11 and §12).
  2. Dynaminds may amend this Agreement, in particular to align it with changes in law or supervisory authority practice. The Controller is informed of any new version, and its applicability requires renewed acceptance (re-consent) by a person authorized to represent the Controller in the manner set out in §1.
  3. This version 2 replaces earlier versions (including version 1) as of the effective date, i.e. 17 June 2026.

§17. Governing law and jurisdiction

  1. Matters not regulated by this Agreement are governed by Polish law and the GDPR.
  2. Disputes arising from the Agreement are settled by the common court having local jurisdiction over the registered office of Dynaminds (B2B.net S.A.).

§18. Prevailing language

This Agreement is drawn up in Polish and in an English translation. In the event of any discrepancy, the Polish version is binding.


Annex 1 — Technical and Organisational Measures (TOM) (Article 28(3)(c) in conjunction with Article 32 GDPR)

This Annex forms an integral part of the Agreement and describes the technical and organisational measures implemented by Dynaminds to ensure a level of security appropriate to the risk. The measures are reviewed periodically and may be updated, provided that the level of security is not reduced.

  1. Encryption and protection of data in transit and at rest
  1. Access control and authentication
  1. Data isolation in the multi-tenant architecture
  1. Confidentiality, integrity, availability and resilience
  1. Backups and recoverability
  1. Event logging and monitoring
  1. Development and deployment security
  1. Testing and effectiveness assessment
  1. Organisational
  1. Sub-processors and transfers

This Agreement is accepted electronically (Article 28(9) GDPR) by a person authorized to represent the Controller during onboarding. Checking the acceptance box constitutes conclusion of the Agreement and a declaration of authority to act on behalf of the Controller.