← Privacy policyData Processing Agreement
Version 2 · effective 2026-06-17
This DPA is concluded electronically when an authorized representative of your organization accepts it during onboarding. An executable signed copy is available on request for enterprise customers.
[email protected].
DATA PROCESSING AGREEMENT (DPA)
Service: Elevate — a multi-tenant service desk / helpdesk platform (ticketing, knowledge base, SLA tracking, reporting, optional AI assistant), available at elevate.dynaminds.pl (with per-tenant subdomains).
Version: 2 (replacing version 1) · Effective date: 17 June 2026
§1. Parties and manner of conclusion
- This Data Processing Agreement (the "Agreement" or "DPA") is concluded between:
- the Controller — the organization (a business entity) on whose behalf a person authorized to represent it accepts this Agreement during the organization account creation (onboarding) process on the Elevate platform (the "Controller" or "Client"); and
- the Processor — Dynaminds, a brand operated by B2B.net S.A., with its registered office at Aleje Jerozolimskie 180, 02-486 Warsaw, Poland, entered in the register of entrepreneurs of the National Court Register under number 0000387063, tax ID 5711707392 (the "Processor" or "Dynaminds").
- The Agreement constitutes a standard contractual template within the meaning of Article 384 of the Polish Civil Code and is concluded electronically (electronic form), in accordance with Article 28(9) GDPR, which permits a processing agreement to be in writing, including in electronic form. Conclusion occurs when a person authorized to represent the Controller checks an active, non-pre-ticked acceptance box next to a link to the exact, versioned text of this Agreement and submits a declaration of authority to represent the Controller. This act replaces a handwritten signature.
- Acceptance is recorded in an immutable (append-only) consent ledger comprising: the identity of the accepting person, the version and checksum (hash) of the accepted document, the timestamp, the IP address, the client identifier (user agent), and confirmation of acting in the capacity of an authorized signatory. This record constitutes evidence of conclusion of the Agreement.
- At the request of an enterprise Controller, Dynaminds may make available a signed counterpart of the Agreement on a durable medium; this is not, however, a condition of effective conclusion of the Agreement in electronic form.
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
- The following form an integral part of this Agreement: Annex 1 — Technical and Organisational Measures (TOM) and the Sub-processor List published and maintained at the address specified in §8. In the event of any discrepancy between this Agreement and the Sub-processor List as to the periods for notification of, and objection to, changes of sub-processors, the periods set out in §8(3) prevail (which are identical to the periods declared in the Sub-processor List).
§2. Roles of the parties
- The Controller (the Client organization) is the controller of personal data within the meaning of Article 4(7) GDPR with regard to personal data processed in the course of using the Elevate service.
- Dynaminds (B2B.net S.A.) is the processor within the meaning of Article 4(8) GDPR and processes the entrusted personal data solely on behalf of and for the Controller.
- This Agreement governs the processing of personal data by Dynaminds on behalf of the Controller and prevails over the provisions of the Terms of Service in matters of personal data protection in the event of any discrepancy.
§3. Subject-matter, nature, purpose and duration of processing (Article 28(3) GDPR)
- Subject-matter of processing: the processing of personal data necessary for Dynaminds to provide the Elevate service to the Controller, i.e. to make available and maintain the service desk / helpdesk platform.
- Nature of processing: automated and non-automated processing operations performed on personal data, in particular: collection, recording, storage, organization, structuring, alteration, retrieval, use, disclosure within the platform, restriction, erasure and destruction — in respect of features comprising ticket handling, knowledge base, SLA tracking, reporting and — if enabled by the Controller — the optional AI assistant.
- Purpose of processing: to enable the Controller to use the Elevate service for its intended purpose and in accordance with the Controller's documented instructions; Dynaminds does not process the entrusted data for its own purposes.
- Duration of processing: from the conclusion of this Agreement, for the entire term of the agreement for the provision of the Elevate service (the period during which the Controller's account is active), until the end of the provision of the service, subject to §11 (return or deletion of data) and §11 (retention periods).
§4. Type of personal data and categories of data subjects (Article 28(3) GDPR)
- Categories of data subjects: persons representing the Controller and its platform users (employees, contractors, account administrators), and persons whose data the Controller enters or which are contained in ticket content — in particular the Controller's end users, customers, employees or contractors who submit matters or to whom tickets relate.
- Type (categories) of personal data:
- account data: email address, first and last name, organization membership, role within the organization;
- ticket content: title, description, comments and attachments in tickets and knowledge base articles, which may contain personal data of the Controller's end users or staff entered by the Controller;
- technical data: IP address (in transit), browser data, and crash/diagnostic data.
- Special categories of data (Article 9 GDPR) and data on criminal convictions (Article 10 GDPR):
- a) The Controller undertakes not to enter into the platform special categories of personal data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR), unless necessary, lawful and based on a valid legal ground for which the Controller is responsible. The parties acknowledge that, given the nature of the helpdesk service, ticket content entered by the Controller's end users may incidentally contain such data (e.g. health data or employment-related data).
- b) Where the data referred to in point (a) is nevertheless entered into the platform, Dynaminds processes it in the same manner as the other entrusted personal data, on the terms of this Agreement and applying the technical and organisational measures set out in Annex 1, without performing any separate processing operations on it.
- c) Where Dynaminds becomes aware of systematic or significant entry of such data, it informs the Controller without undue delay, and the parties — within no more than 30 days of such notice — agree in good faith on additional measures proportionate to the elevated risk (e.g. access restriction, additional encryption, reduced retention, a DPIA). The Controller is responsible for ensuring a legal basis and for the lawfulness of the data entered; until the agreed measures are implemented, Dynaminds is not obliged to extend the scope of processing of such data beyond what results from the normal operation of the platform.
- The Controller determines the scope of personal data actually entered through the manner in which it uses the platform; the Controller is responsible for the lawfulness of the entrusted data and for the accuracy and adequacy of its scope.
§5. Processing only on documented instructions of the Controller (Article 28(3)(a) GDPR)
- Dynaminds processes the entrusted personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which Dynaminds is subject; in such case Dynaminds informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- The following constitute documented instructions of the Controller: this Agreement, the Terms of Service, the configuration and settings made by the Controller in the platform, use of the platform's features for their intended purpose, and instructions given in writing (including by email) by persons authorized by the Controller.
- If, in Dynaminds' assessment, an instruction of the Controller infringes the GDPR or other data protection provisions, Dynaminds immediately informs the Controller.
§6. Confidentiality of authorized persons (Article 28(3)(b) GDPR)
- Dynaminds ensures that persons it authorizes to process the entrusted personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Dynaminds grants authorizations to process personal data only to persons for whom access to the data is necessary to perform this Agreement (need-to-know principle, access minimization), and ensures that those persons receive appropriate data protection training.
§7. Security measures (Article 28(3)(c) and Article 32 GDPR)
- Dynaminds takes all measures required pursuant to Article 32 GDPR, i.e. taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons — it implements appropriate technical and organisational measures to ensure a level of security appropriate to that risk.
- The specific technical and organisational measures (TOM) applied by Dynaminds as at the effective date of this Agreement are set out in Annex 1 (Technical and Organisational Measures — TOM), which forms an integral part of the Agreement. These measures include in particular:
- encryption of personal data in transit and at rest;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- role-based access control, authentication, and logical separation (isolation) of each client's data in the multi-tenant architecture, including row-level security (RLS) mechanisms in the database;
- the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident (backups);
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing;
- event logging (audit logs) and monitoring of errors and incidents.
- Dynaminds may update Annex 1, provided that the level of security is not reduced. Dynaminds also makes available to the Controller, on request, a current and detailed description of the measures applied.
§8. Engagement of further processors — sub-processors (Article 28(2), (3)(d) and (4) GDPR)
- The Controller grants Dynaminds a general written authorisation to engage further processors (sub-processors) for the purpose of providing the Elevate service. The current list of sub-processors is published and maintained at:
https://elevate.dynaminds.pl/legal/subprocessors (the "Sub-processor List") and forms an integral part of this Agreement. - As at the effective date of this Agreement, Dynaminds uses the following sub-processors (each under its own data processing agreement ensuring an at least equivalent level of protection):
- Supabase — database (EU region / Frankfurt);
- Microsoft Azure / Microsoft 365 — email handling (Microsoft Graph), EU tenant;
- Stripe — payments and tax (EU and US);
- Hetzner — hosting (EU region / Nuremberg);
- Cloudflare — CDN/WAF (global edge network);
- Sentry — error monitoring (EU region / Frankfurt);
- Anthropic — AI assistant (US — only where the AI feature is enabled by the Controller);
- Voyage AI — embeddings (US — only where the AI feature is enabled by the Controller).
The legal bases for transfers outside the EEA for the above sub-processors are set out in §13.
- Dynaminds informs the Controller of any intended changes concerning the addition or replacement of sub-processors by updating the Sub-processor List and by notification (by email or an in-platform message) at least 30 days in advance of the new or changed sub-processor commencing processing, thereby giving the Controller the opportunity to object to such a change. The period for raising an objection is no less than 30 days from the date of notification. These periods are identical to the periods declared in the Sub-processor List. In the event of a justified objection, the parties will seek a solution in good faith; if no solution is reached, the Controller is entitled to terminate the affected part of the service.
- Dynaminds imposes on each sub-processor — by way of a contract or other legal act — the same data protection obligations as set out in this Agreement, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures.
- Dynaminds remains fully liable to the Controller for the performance of the sub-processor's data protection obligations.
§9. Assistance to the Controller (Article 28(3)(e) and (f) GDPR)
- Fulfilment of data subjects' rights (Articles 12–23 GDPR): taking into account the nature of the processing, Dynaminds assists the Controller, insofar as possible, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights (the rights of access, rectification, erasure, restriction of processing, data portability, objection, and rights related to automated decision-making). If such a request is received directly by Dynaminds, Dynaminds without undue delay, and no later than within 3 business days of receipt, forwards it to the Controller and does not respond without the Controller's instruction, unless required to do so by law. This period is intended to enable the Controller to meet its own deadlines under Article 12 GDPR.
- Charging for assistance: The assistance referred to in paragraphs 1 and 3, performed through standard platform features (self-service: export, correction, deletion of data by the Controller), is provided free of charge. Where a request requires non-standard, above-average effort by Dynaminds (e.g. extensive manual searching or bespoke engineering activities going beyond the platform's features), Dynaminds may charge the Controller reasonable, documented costs at a previously communicated, reasonable rate; before incurring such costs Dynaminds provides the Controller with an estimate and proceeds upon the Controller's approval.
- Support with obligations under Articles 32–36 GDPR: taking into account the nature of processing and the information available to it, Dynaminds assists the Controller in ensuring compliance with the obligations relating to:
- security of processing (Article 32),
- notification of a personal data breach to the supervisory authority (Article 33) and communication to data subjects (Article 34),
- data protection impact assessment — DPIA (Article 35),
- prior consultation with the supervisory authority (Article 36).
§10. Notification of personal data breaches (Article 33 GDPR)
- Dynaminds notifies the Controller of any breach of the security of the entrusted personal data without undue delay after becoming aware of it, so as to enable the Controller to comply in a timely manner with its obligations under Articles 33 and 34 GDPR.
- The notification contains at least, to the extent available to Dynaminds: a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned), the likely consequences of the breach, the measures taken or proposed to address it, and the contact point from which more information can be obtained. Where it is not possible to provide all information at once, the information is provided in phases as it becomes available.
§11. Return or deletion of data after the end of processing (Article 28(3)(g) GDPR)
- After the end of the provision of the Elevate service, Dynaminds — at the Controller's choice — deletes or returns to the Controller all entrusted personal data and deletes existing copies, unless Union or Member State law requires storage of the data.
- Given the nature of the service, the following default retention periods apply, unless the Controller requests earlier return or deletion:
- active tickets — retained for the period during which the Controller's account is active;
- closed tickets — archived after 1 year, anonymized after 3 years;
- audit log — retained for 2 years;
- backups — retained for up to 30 days, after which they are overwritten/deleted as part of the backup rotation cycle;
- diagnostic events (Sentry) — retained for 90 days.
- At the Controller's request, Dynaminds confirms that the return or deletion of data has been carried out.
§12. Making information available and audits and inspections (Article 28(3)(h) GDPR)
- Dynaminds makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and in this Agreement.
- Dynaminds allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
- Audits take place after prior, reasonable notice (as a rule at least 14 days in advance), during business hours, in a manner that minimises disruption to Dynaminds' operations and respects the confidentiality of other clients' data and trade secrets. Dynaminds may first make available current certifications, audit reports or codes of conduct; if these do not demonstrate compliance to the required extent, the Controller is entitled to carry out an on-site or remote audit.
- Audit frequency: Unless the law, an instruction of the supervisory authority, or the occurrence of a personal data breach requires otherwise, the Controller is entitled to carry out an audit no more than once per calendar year. An additional audit beyond this limit is permissible, in particular: (a) following a significant personal data breach affecting the Controller's data, (b) at the justified request of a supervisory authority, or (c) following a material change to the manner of processing or to the set of sub-processors.
- Audit costs: Each party bears its own costs in connection with an audit. The provision of information and of the certifications/reports referred to in paragraphs 1 and 3, and cooperation within one annual audit to a reasonable extent, are free of charge. Where an audit (or an additional audit beyond the limit in paragraph 4) requires above-average effort by Dynaminds or the commitment of resources beyond a reasonable extent, Dynaminds may charge the Controller reasonable, documented costs at a previously communicated, reasonable rate, having first provided an estimate. The costs of an audit that reveals material failures by Dynaminds in performing this Agreement are borne by Dynaminds.
§13. Transfers to third countries (Chapter V GDPR)
- Transfers of entrusted personal data to third countries (outside the European Economic Area) take place only on documented instructions from the Controller or where they result from the use of the sub-processors listed in §8.
- To the extent that sub-processors process data outside the EEA (in particular Microsoft, Stripe, Cloudflare, Anthropic and Voyage AI), the transfer is carried out on the basis of at least one of the following mechanisms, consistently with the information contained in the Sub-processor List:
- a) an adequacy decision (Article 45 GDPR) — in particular, with respect to US providers certified under the EU–U.S. Data Privacy Framework (DPF), for which the DPF constitutes an active transfer mechanism; and
- b) appropriate safeguards within the meaning of Article 46 GDPR, in particular the standard contractual clauses (SCCs) adopted by the European Commission — used as the transfer basis for providers not covered by the DPF, or as a supplementary/fallback mechanism for the others — supplemented, where necessary, by additional protective measures (e.g. encryption, pseudonymisation, key management).
- Current information on which transfer mechanism (DPF or SCCs) applies to a given sub-processor is indicated in the Sub-processor List and, at the Controller's request, Dynaminds makes available detailed information on the mechanisms and safeguards applied. In the event of the invalidation or suspension of an adequacy decision (DPF), Dynaminds, without undue delay, ensures an alternative transfer basis compliant with Chapter V GDPR (in particular the SCCs).
§14. Data protection officer and contact point
- Dynaminds' contact point for matters concerning personal data protection is: [email protected]. The general service contact address is: [email protected].
- The Controller warrants that the person accepting this Agreement is duly authorized to represent the Controller and to incur obligations on its behalf under the Agreement.
§15. Liability
- Each party is liable for damage caused by processing in accordance with the principles set out in Article 82 GDPR and in generally applicable law.
- Dynaminds is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the lawful instructions of the Controller.
§16. Term and amendments
- The Agreement remains in force for the period during which the Elevate service is provided to the Controller and expires upon the end of that provision, subject to the provisions which by their nature should survive expiry (in particular §11 and §12).
- Dynaminds may amend this Agreement, in particular to align it with changes in law or supervisory authority practice. The Controller is informed of any new version, and its applicability requires renewed acceptance (re-consent) by a person authorized to represent the Controller in the manner set out in §1.
- This version 2 replaces earlier versions (including version 1) as of the effective date, i.e. 17 June 2026.
§17. Governing law and jurisdiction
- Matters not regulated by this Agreement are governed by Polish law and the GDPR.
- Disputes arising from the Agreement are settled by the common court having local jurisdiction over the registered office of Dynaminds (B2B.net S.A.).
§18. Prevailing language
This Agreement is drawn up in Polish and in an English translation. In the event of any discrepancy, the Polish version is binding.
Annex 1 — Technical and Organisational Measures (TOM) (Article 28(3)(c) in conjunction with Article 32 GDPR)
This Annex forms an integral part of the Agreement and describes the technical and organisational measures implemented by Dynaminds to ensure a level of security appropriate to the risk. The measures are reviewed periodically and may be updated, provided that the level of security is not reduced.
- Encryption and protection of data in transit and at rest
- All communication with the platform uses encryption in transit (TLS, at least version 1.2).
- Data at rest (database, backups, attachments) is encrypted at the data store level.
- Keys and secrets are stored in a dedicated secrets store (env vault), not in source code or container images.
- Access control and authentication
- Role-based access control (RBAC) following the need-to-know and least-privilege principles.
- User authentication (including password login, one-time email code (OTP), and federated SSO login), with the possibility of multi-factor authentication on the identity-provider side.
- Restricted and logged administrative access by Dynaminds staff; access only for persons bound by confidentiality.
- Data isolation in the multi-tenant architecture
- Logical separation of each client's data, including row-level security (RLS) mechanisms in the database.
- Mechanisms preventing one client from accessing another client's data.
- Confidentiality, integrity, availability and resilience
- Architecture providing environment separation and monitoring of service availability.
- Edge protection (WAF/CDN) and abuse-mitigation mechanisms (rate limiting).
- Backups and recoverability
- Regular backups with the ability to restore data after a physical or technical incident.
- Backups retained for up to 30 days and subject to a regular rotation cycle (overwriting/deletion).
- Event logging and monitoring
- An audit log of events relevant to security.
- Monitoring of errors and incidents (with anonymisation/masking of sensitive data where feasible).
- Development and deployment security
- Access control to code repositories, code review, and scanning for secrets and vulnerabilities in the CI/CD process.
- Deployments with version verification (healthcheck) and the ability to roll back a change.
- Testing and effectiveness assessment
- Regular testing, measurement and evaluation of the effectiveness of the technical and organisational measures.
- Organisational
- Confidentiality undertakings and data protection training for staff with access to data.
- A procedure for handling personal data breaches and notifying the Controller (in accordance with §10 of the Agreement).
- Oversight of sub-processors in accordance with §8 of the Agreement.
- Sub-processors and transfers
- Use only of sub-processors ensuring an at least equivalent level of protection (§8) and application of transfer mechanisms compliant with Chapter V GDPR (§13).
This Agreement is accepted electronically (Article 28(9) GDPR) by a person authorized to represent the Controller during onboarding. Checking the acceptance box constitutes conclusion of the Agreement and a declaration of authority to act on behalf of the Controller.
DATA PROCESSING AGREEMENT (DPA)
Service: Elevate — a multi-tenant service desk / helpdesk platform (ticketing, knowledge base, SLA tracking, reporting, optional AI assistant), available at
elevate.dynaminds.pl(with per-tenant subdomains).Version: 2 (replacing version 1) · Effective date: 17 June 2026
§1. Parties and manner of conclusion
§2. Roles of the parties
§3. Subject-matter, nature, purpose and duration of processing (Article 28(3) GDPR)
§4. Type of personal data and categories of data subjects (Article 28(3) GDPR)
§5. Processing only on documented instructions of the Controller (Article 28(3)(a) GDPR)
§6. Confidentiality of authorized persons (Article 28(3)(b) GDPR)
§7. Security measures (Article 28(3)(c) and Article 32 GDPR)
§8. Engagement of further processors — sub-processors (Article 28(2), (3)(d) and (4) GDPR)
https://elevate.dynaminds.pl/legal/subprocessors(the "Sub-processor List") and forms an integral part of this Agreement.The legal bases for transfers outside the EEA for the above sub-processors are set out in §13.
§9. Assistance to the Controller (Article 28(3)(e) and (f) GDPR)
§10. Notification of personal data breaches (Article 33 GDPR)
§11. Return or deletion of data after the end of processing (Article 28(3)(g) GDPR)
§12. Making information available and audits and inspections (Article 28(3)(h) GDPR)
§13. Transfers to third countries (Chapter V GDPR)
§14. Data protection officer and contact point
§15. Liability
§16. Term and amendments
§17. Governing law and jurisdiction
§18. Prevailing language
This Agreement is drawn up in Polish and in an English translation. In the event of any discrepancy, the Polish version is binding.
Annex 1 — Technical and Organisational Measures (TOM) (Article 28(3)(c) in conjunction with Article 32 GDPR)
This Annex forms an integral part of the Agreement and describes the technical and organisational measures implemented by Dynaminds to ensure a level of security appropriate to the risk. The measures are reviewed periodically and may be updated, provided that the level of security is not reduced.
This Agreement is accepted electronically (Article 28(9) GDPR) by a person authorized to represent the Controller during onboarding. Checking the acceptance box constitutes conclusion of the Agreement and a declaration of authority to act on behalf of the Controller.