K klubtár

Data Processing Agreement (DPA)

Effective from: [DATE] — an integral annex of the Terms of Service

Draft: the bracketed [DETAILS] must be filled in, and the text requires legal review before publication — until then it is not a binding document.

This English translation is provided for convenience only — the Hungarian version prevails.

1. Subject matter and parties

This Data Processing Agreement (Article 28(3) GDPR) is concluded between [COMPANY NAME], operator of the Klubtár platform (the Processor), and the Partner using the Platform (the Controller), as an integral annex of the Terms of Service — it is accepted together with the Terms upon registration.

For personal data provided on the Partner's website and web shop (in particular customer data), the Partner is the controller; the Provider acts solely on the Partner's behalf as processor.

2. Nature, purpose and duration of processing

Nature: operating the Platform as a service (SaaS) — storage, display, order management, e-mail delivery, backups. Purpose: running the Partner's website and web shop.

Duration: the term of the Partner agreement. Upon termination the Partner may request an export of its data within [30] days; afterwards the Processor deletes or irreversibly anonymises the data, except where retention is required by law.

3. Categories of data and data subjects

Data subjects: customers and registered account holders of the Partner's web shop; visitors of the Partner's website; persons appearing in content uploaded by the Partner (e.g. players, athletes).

Data categories: customer identification data (name, e-mail, phone), shipping address, order and payment status data, customer account data; visitor analytics is cookie-free and uses technical data unsuitable for direct identification; personal data contained in media/content uploaded by the Partner.

4. Obligations of the Processor

The Processor processes personal data only on the Controller's documented instructions (primarily embodied by the use of the Platform's features) and informs the Controller immediately if an instruction appears to infringe the law.

Staff with access are bound by confidentiality. The Processor applies technical and organisational measures under Article 32 GDPR: partner-level data isolation in the database (row-level access protection), encrypted storage of payment and integration secrets, role-based access control, tamper-evident audit logging, and regular backups.

5. Sub-processors

The Controller gives general authorisation for engaging sub-processors. Current sub-processors: hosting and infrastructure: [HOSTING PROVIDER NAME, ADDRESS]; transactional e-mail delivery: [E-MAIL PROVIDER NAME]; backup storage: [BACKUP STORAGE PROVIDER NAME].

The Processor notifies the Partner in advance by e-mail of intended changes to the list; the Partner may object within [15] days.

Providers that the Partner contracts with DIRECTLY and uses with its own account through the Platform (e.g. SimplePay for web shop payments, Billingo for invoicing, Meta for social posting) are NOT sub-processors of the Provider — they are the Partner's own processors or independent controllers, disclosed in the Partner's own privacy policy.

6. Assisting with data subject rights

Taking the nature of processing into account, the Processor assists the Controller with appropriate technical means in fulfilling data subject requests (access, rectification, erasure, portability); the Platform provides built-in self-service data export and account deletion (anonymisation) for web shop customers.

Requests received directly by the Processor are forwarded to the Controller without delay.

7. Personal data breaches

The Processor notifies the affected Partner of a personal data breach without undue delay, at the latest within [48] hours of becoming aware of it, and provides all information necessary for the Controller to comply with Articles 33–34 GDPR.

8. Audits

The Processor makes available the information necessary to demonstrate compliance and allows audits at most once a year, with at least [15] days' prior coordination, conducted so as not to endanger the operation of the service or the security of other partners' data.

9. Termination

Upon termination of the Partner agreement the Processor — at the Controller's choice — returns (exports) or deletes the personal data and deletes existing copies, unless storage is required by law (in which case retention is limited to that obligation and purpose).