Data Processing Agreement (DPA)
This DPA forms part of the Agreement based on the LiteTMS.eu Terms of Service between the Customer (the Controller) and CodeJungle Sp. z o.o., Kawki 51, 42-140 Panki, Poland, KRS: 0000722231, NIP: 5742064222, REGON: 369658794 (the Processor). Acceptance of the Terms also concludes this DPA in electronic form. It applies where CodeJungle processes personal data on the Customer's behalf.
§1. Scope, purpose, operations, and duration
- The subject matter is the processing needed to provide and secure the Customer's LiteTMS workspace, including hosting, storage, organisation, retrieval, display, transmission at the Customer's request, support, backup, deletion, and operation of activated integrations.
- The purpose is to provide the SaaS transport-management functions selected by the Customer. The nature of processing is automated and, where authorised support requires it, limited manual access.
- This DPA lasts for as long as the Processor holds Customer Personal Data. Termination, transition, return, retrieval, and deletion are governed by §7 and the Terms.
- For account administration, billing, fraud prevention, security records, and compliance duties where CodeJungle determines the purpose and means, CodeJungle acts as an independent controller under the Privacy Policy; those activities are outside this DPA.
§2. People and data covered
- Data subjects may include the Customer's authorised users, employees, drivers, candidates, representatives, contractors, carriers, suppliers, customers, recipients, senders, contacts, and other people identified in Customer Content.
- Data may include names and identifiers; contact, account, authentication, professional and employment data; signatures; communications; order, route, vehicle-linked and location data; financial and settlement data; documents, images, audio and attachments; device, usage, and audit data; and other data the Customer chooses to enter.
- The service is not intended for routine processing of special-category data or criminal-conviction data. The Customer must not enter it unless this is necessary and lawful, the Customer has assessed the risk and applicable Art. 9 or 10 GDPR condition, and the parties have agreed any additional safeguards reasonably required.
§3. Documented instructions
- The Processor acts only on the Customer's documented instructions, including for international transfers, unless EU or Member State law requires otherwise. In that case it will inform the Customer before processing unless the law prohibits notice on important public-interest grounds.
- The Terms, this DPA, the Customer's settings and use of System functions, support requests, and written directions accepted by the Processor are documented instructions. An instruction outside the agreed service may require a separate scope and fee.
- The Processor will promptly tell the Customer if, in its opinion, an instruction infringes data-protection law. It may suspend only the affected processing until the instruction is changed, confirmed lawful, or withdrawn.
- The Customer remains responsible for the lawfulness, fairness, accuracy, transparency, and minimisation of Customer Personal Data, for notices and data-subject requests, and for the instructions it gives. The Customer must configure permissions and retention appropriately and must not instruct unlawful processing.
§4. Processor duties and assistance
- The Processor ensures that people authorised to process Customer Personal Data are bound by confidentiality and receive access only as needed.
- Taking account of the state of the art, implementation costs, and the nature, scope, context, purposes, and risk, the Processor maintains measures appropriate under Art. 32 GDPR. The current core measures are listed in Annex 1.
- Taking account of the nature of processing and information available to it, the Processor reasonably assists the Customer with data-subject requests and compliance with Arts. 32–36 GDPR, including security, breach notification, impact assessments, and prior consultation.
- The Processor will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and, where feasible, aims to give initial notice within 48 hours. It will provide the information available about the nature and likely consequences, affected data and people, measures taken or proposed, and a contact point. Information may be supplied in phases. Notification is not an admission of fault.
- The Processor will make available information reasonably necessary to demonstrate compliance with Art. 28 GDPR and this DPA.
§5. Sub-processors and international transfers
- The Customer gives general written authorisation to use sub-processors needed for the service. Depending on activated features, the current categories and provider brands include: OVHcloud (hosting); Cloudflare (network security, Turnstile, and R2 storage); Amazon Web Services (backup/storage); EmailLabs (e-mail); SMSAPI.pl (SMS); Google Firebase Cloud Messaging (push); the configured Umami host (service analytics); HERE, Google Maps Platform, Mapbox, and the configured Protomaps source (maps/routing); Fakturownia.pl (invoicing); OpenRouter and its selected model provider (AI); and ElevenLabs (speech-to-text voice transcription and text-to-speech voice playback of translated messages, covering voice recordings and the message text sent for synthesis). Stripe generally acts as an independent controller for regulated payment processing rather than as a sub-processor under this DPA.
- The Processor will provide, before an applicable provider first processes Customer Personal Data, the provider's full legal identity, business address, contact point, function, processing location, and applicable transfer safeguard. It will keep that information current and make a copy available to the Customer at any time at contact@litetms.eu. A brand above may be supplied by a different group entity depending on the Customer's deployment and the provider account.
- The Processor will give at least 14 days' advance notice by e-mail or a durable System message before a new sub-processor starts processing Customer Personal Data, including its identity, function, and processing location. An urgent replacement may take effect sooner only where delay would create a material security or service-continuity risk; notice will follow without undue delay and the Customer retains the objection rights below.
- The Customer may object during the notice period, or without undue delay after an urgent notice, on reasonable, documented data-protection grounds. The parties will try in good faith to use a reasonable alternative. If none is available, either party may discontinue the affected feature; the Customer may terminate the affected service without penalty. Unless the urgent-replacement rule above applies, the new sub-processor will not begin processing before the objection period ends.
- The Processor imposes substantially the same data-protection obligations on each sub-processor by contract and remains liable to the Customer for the sub-processor's performance as required by Art. 28(4) GDPR.
- Core hosting and storage are in the EU. For a restricted transfer, the Processor uses a lawful GDPR Chapter V mechanism, such as an adequacy decision (including the EU-US Data Privacy Framework for a participating recipient) or the European Commission's Standard Contractual Clauses with supplementary measures where appropriate. On request, it will provide relevant safeguard information or a copy, subject to necessary redactions.
§6. Reviews and audits
- The Processor will first provide available security and compliance information, questionnaires, or independent reports where these reasonably meet the Customer's need.
- If further verification is reasonably necessary, the Customer or an independent auditor bound by confidentiality may conduct an audit. Unless a breach, regulator, or urgent risk justifies shorter notice, the Customer gives at least 14 days' notice. Audits occur during normal business hours, no more than once per year, and must avoid access to other customers' data, security compromise, or unreasonable disruption.
- The Processor bears its ordinary cost of demonstrating compliance. The Customer bears its auditor's costs and the Processor's reasonable, pre-agreed cost of exceptional, customer-specific work, unless the audit identifies a material Processor breach. Nothing in this paragraph restricts a competent authority or makes mandatory cooperation conditional on payment.
- The Customer will promptly provide the Processor with the audit findings. Each party protects the other's confidential and security-sensitive information.
§7. Return, transition, and deletion
- During the contract, the Customer may use available export functions. On termination it may choose return or deletion, subject to the transition and retrieval rights in §15 of the Terms. If it does not make a different lawful choice, the Processor keeps data available through the applicable retrieval period and then deletes it from active systems.
- The Processor deletes or returns Customer Personal Data and deletes existing copies after the agreed retrieval period, unless EU or Member State law requires retention. It will confirm completion on request.
- Data in disaster-recovery backups is put beyond ordinary use and access, is not restored except for disaster recovery, and expires under the documented rotation cycle, which may take up to 12 months. If a backup is restored, applicable deletions are reapplied.
§8. Liability and order of documents
- The liability rules in §16 of the Terms apply to this DPA. No limitation restricts a data subject's rights under Art. 82 GDPR, a regulator's powers, or liability that mandatory law does not allow the parties to limit. Administrative fines remain payable by the person on whom they are imposed.
- If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA prevails. An individually signed data-processing agreement prevails over this online DPA for its subject matter.
- Polish law governs, without prejudice to the GDPR or other mandatory law. The jurisdiction provision in the Terms applies.
Annex 1. Core technical and organisational measures
- TLS encryption for data in transit;
- logical tenant separation and access controls;
- individual authentication, role-based permissions, and two-factor authentication functionality;
- host-only, HttpOnly authentication cookies and controlled session lifetimes;
- audit and security logging;
- automated backups, restricted ordinary access, and a defined rotation cycle;
- limited staff access based on role and need;
- security-event and personal-data-breach handling;
- sub-processor review and contractual data-protection obligations;
- controlled deletion from active systems and isolation of backup copies until expiry.
Measures may evolve with risk and technology, provided the overall level of protection is not materially reduced during the contract.