Data Processing Agreement (DPA)
Constituting an integral appendix to the LiteTMS.eu Terms of Service, concluded between:
The Client (Service Recipient), hereinafter referred to as the "Controller"
and
CodeJungle Sp. z o.o., Kawki 51, 42-140 Panki, NIP (Tax ID): 5742064222, KRS (National Court Register): 0000722231, REGON (National Business Registry): 369658794, hereinafter referred to as the "Data Processor" or "Processor".
§1. Subject Matter, Purpose, and Duration of Processing
- Pursuant to Art. 28 of the General Data Protection Regulation (GDPR), the Controller entrusts the Processor with the processing of personal data entered into the LiteTMS.eu system.
- Purpose of processing: provision of services comprising the access to and maintenance of transport management software (TMS) in the SaaS cloud model, in accordance with the provisions of the main Terms of Service.
- The Agreement is concluded for the term of the Terms of Service and shall be automatically terminated upon the expiration or termination of the main service.
§2. Scope of Data and Categories of Data Subjects
- The processing involves the following categories of data subjects: employees of the Controller, fleet drivers, collaborators, and contractors/carriers of the Controller.
- The types of entrusted personal data (standard data) include, in particular: identification data (first names, last names, company names), contact details (addresses, phone numbers, e-mail addresses), vehicle registration numbers, logistics documentation, and location history (geolocation).
- The Controller declares that they do not entrust special categories of personal data (e.g., health data) and bears sole responsibility for the legal basis for collecting data of their employees (including GPS data).
§3. Representations and Obligations of the Data Processor (CodeJungle)
- The Processor shall process personal data solely on documented instructions from the Controller (i.e., using the functionalities of the LiteTMS.eu system).
- The Processor ensures that persons authorized to process the personal data (e.g., CodeJungle engineers) have committed themselves to confidentiality.
- The Processor implements and maintains appropriate technical and organizational measures, including logical separation of databases (multi-tenancy) at the level of the instance assigned to the Client.
- The Processor shall notify the Controller without undue delay (where feasible, no later than 48 hours after becoming aware) of any personal data breach concerning the entrusted data, so as to enable the Controller to meet the deadline under Art. 33 GDPR.
- Taking into account the nature of the processing, the Processor assists the Controller, within reason: in responding to requests for the exercise of data-subject rights (including through appropriate System functions), and in complying with the obligations concerning the security of processing, breach notifications, data protection impact assessments (DPIAs), and prior consultations with the supervisory authority (Art. 32-36 GDPR).
- The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations laid down in this Agreement (Art. 28(3)(h) GDPR).
§4. Sub-processing
- The Controller grants general authorization for the engagement of verified sub-processors necessary for the technical maintenance of LiteTMS.eu.
- The approved list of sub-processors as of the date of concluding the agreement includes: OVH (main hosting), Cloudflare (security, proxy, R2 files), Amazon Web Services (backups), Stripe (transactions), Fakturownia.pl (accounting API), EmailLabs (e-mail), SMSAPI.pl (SMS), Google Firebase (notifications), and OpenRouter (AI aggregator).
- The Processor informs the Controller of the intended engagement of a new sub-processor with reasonable advance notice, by updating the sub-processor list in the Privacy Policy or by e-mail notification. The Controller may raise a justified objection to a new sub-processor; if the objection cannot be resolved, the Controller may terminate the service for the scope affected by the change.
- The Processor imposes on each sub-processor, by way of a contract, data-protection obligations equivalent to those set out in this Agreement (in particular as regards implementing appropriate technical and organizational measures) and remains fully liable to the Controller for the performance of the sub-processors' obligations (Art. 28(4) GDPR).
- Any potential transfer of data to third countries shall be carried out with strict adherence to the Standard Contractual Clauses (SCCs). We configure the AI features to limit the processing of entrusted data by external providers. Where possible, we select settings and models that limit prompt retention and do not use entrusted data for model training; the details are described in the sub-processor list and documentation.
§5. Right to Audit
- The Controller has the right to verify compliance with the Agreement, including the right to request information and conduct inspections at the Processor's premises.
- Audits shall take place during the Processor's working hours, upon prior notification of at least 14 days, and shall be carried out at the sole expense of the Controller.
§6. Deletion of Data and Limitation of Liability
- Upon the termination of services (taking into account a 30-day retention/soft-delete period), the Processor shall, at the Controller's choice, delete the entrusted personal data and existing copies thereof, or return them to the Controller using the agreed export mechanism (export functions compliant with the EU Data Act), unless the law requires their further storage. Data contained in backup copies expires with the backup rotation cycle (up to 12 months); until then, backups serve solely to restore the System after a failure and are not used to restore deleted data.
- The total, aggregate liability for damages of the Processor towards the Controller due to non-performance or improper performance of this DPA is limited to the equivalent of the fees paid by the Controller to the Processor in the 6-month period preceding the event. This limitation does not apply to situations caused by willful misconduct.
Annex 1: Technical and Organizational Measures (TOMs)
The Processor applies, in particular, the following technical and organizational measures:
- encryption of data in transit (TLS);
- access control and user authentication;
- a system of roles and permissions (role-based access control);
- two-factor authentication (2FA) available;
- audit logs of System activity;
- automated backups with a defined retention period (rotation, up to 12 months);
- tenant separation, a separate database for each Client (multi-tenancy);
- limited access of the Processor's staff to production data;
- a security-incident response procedure;
- baseline server-infrastructure security practices;
- a 30-day protective window (soft-delete) before permanent data deletion.