Umowa powierzenia przetwarzania danychData Processing Agreement
Ostatnia aktualizacja: 15 września 2026Last updated: September 15, 2026
1. Strony i przedmiot
1. Parties and subject matter
Niniejsza umowa powierzenia przetwarzania danych osobowych (dalej: Umowa) zawierana jest pomiędzy Klientem — salonem korzystającym z usługi STRONICA Rezerwacje, występującym jako administrator danych — a STRONICA, osobą fizyczną prowadzącą działalność z siedzibą w Warszawie, występującą jako podmiot przetwarzający.
This data processing agreement (the Agreement) is concluded between the Client — the salon using the STRONICA Rezerwacje service, acting as the data controller — and STRONICA, an individual based in Warsaw, acting as the data processor.
Umowa zawierana jest na podstawie art. 28 ust. 3 RODO i stanowi integralną część Regulaminu usługi. Akceptacja Regulaminu przy zgłoszeniu oznacza zawarcie niniejszej Umowy.
The Agreement is concluded pursuant to Art. 28(3) GDPR and forms an integral part of the Terms of Service. Accepting the Terms at sign-up constitutes conclusion of this Agreement.
2. Zakres powierzenia
2. Scope of processing
Cel przetwarzania: obsługa rezerwacji online salonu Klienta — przyjmowanie, przechowywanie i wyświetlanie wizyt oraz wysyłka potwierdzeń e-mail.
Purpose: operating the Client's online booking — receiving, storing and displaying appointments and sending email confirmations.
Charakter przetwarzania: przechowywanie, porządkowanie, udostępnianie Klientowi w panelu, usuwanie.
Nature: storage, organisation, making available to the Client in the panel, erasure.
Rodzaj danych: imię (i ewentualnie nazwisko), numer telefonu i/lub adres e-mail, wybrana usługa, wybrany pracownik, data i godzina wizyty, opcjonalna uwaga od klienta, historia wizyt.
Type of data: first name (and possibly surname), phone number and/or email address, selected service, selected staff member, appointment date and time, optional note from the customer, visit history.
Kategorie osób: klienci salonu dokonujący rezerwacji oraz pracownicy salonu posiadający dostęp do panelu.
Categories of data subjects: the salon's customers making bookings and the salon's staff with panel access.
Czas trwania: na czas obowiązywania umowy o świadczenie usługi.
Duration: for the term of the service agreement.
Przetwarzanie nie obejmuje szczególnych kategorii danych (art. 9 RODO). Klient zobowiązuje się nie wprowadzać do systemu danych o zdrowiu ani innych danych wrażliwych — pole „uwagi” nie jest do tego przeznaczone.
Processing does not cover special categories of data (Art. 9 GDPR). The Client undertakes not to enter health data or other sensitive data into the system — the “notes” field is not intended for this.
3. Obowiązki podmiotu przetwarzającego
3. Obligations of the processor
STRONICA przetwarza dane wyłącznie na udokumentowane polecenie Klienta. Za polecenie uznaje się korzystanie z usługi zgodnie z Regulaminem oraz zgłoszenia wysyłane pocztą elektroniczną.
STRONICA processes data solely on documented instructions from the Client. Use of the service in accordance with the Terms, and requests sent by email, constitute such instructions.
Dostęp do danych ma wyłącznie właściciel STRONICA, zobowiązany do zachowania poufności. Żadne inne osoby nie mają dostępu.
Access to the data is limited to the owner of STRONICA, who is bound by confidentiality. No other persons have access.
STRONICA nie wykorzystuje danych Klienta do własnych celów, nie profiluje ich, nie sprzedaje i nie udostępnia podmiotom trzecim poza podprocesorami wskazanymi w pkt 5.
STRONICA does not use the Client's data for its own purposes, does not profile it, does not sell it and does not share it with third parties other than the sub-processors listed in section 5.
4. Bezpieczeństwo (art. 32 RODO)
4. Security (Art. 32 GDPR)
Stosowane środki: szyfrowanie połączeń (HTTPS/TLS), rozdzielenie danych między salonami na poziomie bazy danych (Row Level Security), oddzielne konta o różnych uprawnieniach dla właściciela i pracowników, codzienne szyfrowane kopie zapasowe wraz z okresową próbą odtworzenia, ograniczenie liczby zgłoszeń z jednego adresu IP oraz nagłówki bezpieczeństwa (CSP, HSTS).
Measures applied: encrypted connections (HTTPS/TLS), separation of data between salons at database level (Row Level Security), separate accounts with different permissions for the owner and staff, daily encrypted backups with periodic restore testing, rate-limiting of requests from a single IP address, and security headers (CSP, HSTS).
5. Podprocesorzy
5. Sub-processors
Klient wyraża ogólną zgodę na korzystanie z następujących podprocesorów:
The Client gives general authorisation for the following sub-processors:
Supabase Inc. — baza danych i uwierzytelnianie, serwery w Unii Europejskiej (Frankfurt).
Vercel Inc. — hosting stron, siedziba w USA.
Resend — dostarczanie wiadomości e-mail, siedziba w USA.
Supabase Inc. — database and authentication, servers in the European Union (Frankfurt).
Vercel Inc. — website hosting, based in the USA.
Resend — email delivery, based in the USA.
Vercel i Resend są certyfikowane w ramach EU-U.S. Data Privacy Framework, a ich umowy powierzenia zawierają Standardowe Klauzule Umowne (SCC) zatwierdzone przez Komisję Europejską.
Vercel and Resend are certified under the EU-U.S. Data Privacy Framework, and their processing agreements incorporate the Standard Contractual Clauses (SCCs) approved by the European Commission.
O zamiarze zmiany lub dodania podprocesora STRONICA informuje Klienta pocztą elektroniczną z 30-dniowym wyprzedzeniem. Klient może zgłosić sprzeciw w terminie 14 dni; w takim wypadku przysługuje mu prawo rozwiązania umowy bez dodatkowych opłat.
STRONICA notifies the Client by email 30 days in advance of any intended change or addition of a sub-processor. The Client may object within 14 days; in that case the Client may terminate the agreement with no additional charges.
6. Pomoc dla Klienta
6. Assistance to the Client
STRONICA pomaga Klientowi w realizacji żądań osób, których dane dotyczą (dostęp, sprostowanie, usunięcie, ograniczenie, przeniesienie, sprzeciw) — w terminie 5 dni roboczych od zgłoszenia.
STRONICA assists the Client in handling data subject requests (access, rectification, erasure, restriction, portability, objection) — within 5 working days of the request.
STRONICA pomaga również w wypełnieniu obowiązków z art. 32–36 RODO, w zakresie dostępnych informacji.
STRONICA also assists in fulfilling the obligations under Art. 32–36 GDPR, to the extent of the information available to it.
7. Naruszenie ochrony danych
7. Personal data breach
W razie stwierdzenia naruszenia ochrony danych STRONICA zawiadamia Klienta pocztą elektroniczną bez zbędnej zwłoki, nie później niż w ciągu 24 godzin od wykrycia, przekazując znany zakres naruszenia, jego prawdopodobne skutki i podjęte działania.
In the event of a personal data breach, STRONICA notifies the Client by email without undue delay and no later than within 24 hours of detection, providing the known scope of the breach, its likely consequences and the measures taken.
Zgłoszenie naruszenia organowi nadzorczemu (UODO) i osobom, których dane dotyczą, należy do Klienta jako administratora.
Notifying the supervisory authority (UODO) and the data subjects is the responsibility of the Client as controller.
8. Kontrola
8. Audit
Klient ma prawo do kontroli sposobu przetwarzania danych raz w roku kalendarzowym, po uprzednim zawiadomieniu z 14-dniowym wyprzedzeniem. Kontrola odbywa się zdalnie, w formie pisemnych pytań i odpowiedzi, chyba że strony ustalą inaczej.
The Client has the right to audit the processing once per calendar year, upon 14 days' prior notice. The audit is conducted remotely, in the form of written questions and answers, unless the parties agree otherwise.
STRONICA udostępnia Klientowi wszelkie informacje niezbędne do wykazania spełnienia obowiązków wynikających z art. 28 RODO.
STRONICA makes available to the Client all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR.
9. Zakończenie
9. Termination
Po zakończeniu świadczenia usługi STRONICA — zgodnie z wyborem Klienta — przekazuje mu dane w formacie CSV lub JSON albo je usuwa.
Upon termination of the service, STRONICA — at the Client's choice — hands over the data in CSV or JSON format, or deletes it.
Dane pozostają dostępne przez 90 dni od zakończenia; po tym terminie są trwale usuwane z systemów produkcyjnych, a z kopii zapasowych w cyklu ich rotacji.
Data remains available for 90 days after termination; after that period it is permanently deleted from production systems, and from backups as they rotate out.
Kod źródłowy, konfiguracja i know-how STRONICA nie stanowią danych Klienta i nie podlegają przekazaniu.
STRONICA's source code, configuration and know-how do not constitute the Client's data and are not subject to hand-over.
10. Postanowienia końcowe
10. Final provisions
W sprawach nieuregulowanych stosuje się RODO oraz prawo polskie. Umowa sporządzona jest w wersji polskiej i angielskiej; w razie rozbieżności wiążąca jest wersja polska.
Matters not covered here are governed by the GDPR and Polish law. This Agreement is drawn up in Polish and English; in case of discrepancies the Polish version prevails.
Kontakt w sprawach ochrony danych: info@stronica.eu.
Contact for data protection matters: info@stronica.eu.