This agreement is entered into between the Client and the Provider identified in the Individual Agreement or the Trial Access Confirmation for Movemar. For the purposes of this DPA, the Provider acts as a processor of personal data and is hereinafter referred to as the “Processor”.

1. ROLES AND APPLICABILITY

1.1. In respect of personal data for which the purposes and means are determined by the Client, the Client is the controller and the Processor is the processor. Where the Client processes data on behalf of another controller, the Client is a processor and the Processor is a subprocessor; the Client warrants that it is entitled to engage the Processor and to give the instructions under this DPA.

1.2. This DPA applies only to personal data processed by the Processor through the Platform on behalf of the Client. It does not apply to processing for which Promotino independently determines the purposes and means and acts as a controller; information about such processing is provided in the applicable Privacy Notice.

1.3. “Applicable Data Protection Law” means Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act and applicable mandatory laws of the Republic of Bulgaria and the European Union.

2. SUBJECT MATTER, DURATION, NATURE AND PURPOSE

2.1. The subject matter is the processing of personal data for the provision of the Movemar Platform as a software service, including during Trial Access, and covers:

(a) creation and management of Accounts;

(b) collection and synchronisation of location data;

(c) recording, storage, display and reporting of assignments, visits, working days, tasks and reports;

(d) technical support;

(e) security;

(f) Backups;

(g) export; and

(h) deletion.

2.2. The processing operations include:

(a) receipt and collection;

(b) recording, organisation and structuring;

(c) storage;

(d) retrieval and consultation;

(e) use;

(f) transmission to authorised Subprocessors;

(g) restriction;

(h) export;

(i) restoration; and

(j) deletion.

2.3. Processing shall continue for the term of the Individual Agreement or Trial Access and thereafter only to the extent necessary for:

(a) the agreed return of the data;

(b) its deletion;

(c) completion of the Backup cycle; or

(d) compliance with a legal obligation.

3. CATEGORIES OF DATA AND DATA SUBJECTS

CategoryScope
Data SubjectsUsers of the Platform and other employees or contractors of the Client whose data is processed through Movemar, as well as other natural persons in respect of whom the Client enters personal data into the Platform.
Identification and Contact DataName, business email address, Account identifier and Platform Role.
Location DataPrecise GPS coordinates, route points and associated timestamps, to the extent that they can be linked to a specific User.
Work Activity and Usage DataAssigned sites and routes; the start, pause and end of working days and visits; completed tasks, statuses, mileage, forms, photographs, notes and reports, to the extent that they are associated with a specific User.
Technical and Diagnostic DataIP address; the User’s internal Movemar identifier (user_id); application, installation or device identifiers; operating system, browser and application version; timestamps, access and security logs, crash, performance and diagnostic events, to the extent that they can be associated with a specific User.

Photographs within the standard functionality must not contain identifiable natural persons.

The Platform is not intended for the processing of special categories of personal data or data relating to criminal convictions and offences. The Client shall not enter such data into the Platform.

4. INSTRUCTIONS AND CLIENT OBLIGATIONS

4.1. The Client’s documented instructions include the Individual Agreement or Trial Access Confirmation, this DPA, configuration within the available settings and lawful use of the standard Platform. Movemar is a standardised SaaS service. An additional instruction shall apply only if accepted by the Processor and compatible with the functionality, security and architecture of the Platform; its implementation may be subject to separately agreed timing and costs.

4.2. The Client shall be responsible for the lawfulness, accuracy and minimisation of data, the legal basis, transparency towards Data Subjects, retention periods, rights requests and the lawfulness of processing location data and any personal data entered by the Client outside the standard purpose of the fields and object photographs.

4.3. The Client shall not give an instruction that infringes Applicable Data Protection Law. If the Processor considers that an instruction infringes such law, it shall immediately notify the Client and suspend performance until the Client amends or withdraws the instruction or provides sufficient evidence of its lawfulness.

5. PROCESSOR OBLIGATIONS

5.1. The Processor shall process personal data only on documented instructions, unless otherwise required by the law of the European Union or the Republic of Bulgaria; in such case, it shall inform the Client in advance unless prohibited by law.

5.2. The Processor shall ensure that persons authorised to process the personal data have access only where necessary and have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3. Taking into account the nature of the processing, the Processor shall assist the Client through the available functionalities and reasonable technical and organisational measures in relation to:

(a) Data Subject requests;

(b) security of processing;

(c) notification of Personal Data Breaches;

(d) data protection impact assessments; and

(e) prior consultations.

5.4. If the Processor directly receives a request from a Data Subject concerning the Client’s data, it shall not respond substantively without an instruction but shall forward the request to the Client, unless otherwise required by law.

5.5. Assistance requiring substantial manual work outside the standard functionality and not caused by a breach by the Processor may be provided at reasonable costs agreed in advance.

6. TECHNICAL AND ORGANISATIONAL MEASURES

6.1. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing and the risk to the rights and freedoms of natural persons, the Processor shall implement appropriate measures, including:

MeasureImplementation
Encryption in TransitSecure communication protocols for transmission between the supported applications, web interface and server components.
Accounts, Permissions and Administrative AccessIndividual User Accounts and Platform Roles, permission controls and enhanced authentication for administrative access.
Logical SegregationLogical segregation of client environments and data at the application and access-control levels.
Data Minimisation and External IntegrationsOnly data necessary for the relevant functionality is transmitted to external services.
Logging and MonitoringLogging of access and technical events to the extent necessary for security, diagnostics and evidence of actions.
Restricted Staff AccessAccess by authorised staff bound by confidentiality only where necessary for administration, support, security or performance of an instruction.
Software MaintenanceSupported components and dependencies are updated according to operational needs; identified technical vulnerabilities are assessed and prioritised according to risk.
Backups and RestorationThe Backup policy and cycle are specified in the General Terms and Conditions; Backups are used only for disaster recovery or where required by law.
Incident ManagementInternal escalation, containment, analysis and notification of the Client in accordance with Section 7.
Review of MeasuresPeriodic review and updating in accordance with changes in technology, processing and the assessed risk.

6.2. The Processor may update the measures in line with developments in technology and risk, provided that the overall level of protection is not materially reduced.

7. PERSONAL DATA BREACH

7.1. The Processor shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting personal data processed on behalf of the Client.

7.2. To the extent that the information is available, the notification shall describe:

(a) the nature of the breach;

(b) the categories and approximate number of affected Data Subjects and records;

(c) the likely consequences;

(d) the measures taken or proposed; and

(e) a contact point for further information.

The information may be provided in phases without undue delay.

7.3. The Client shall determine whether and how to notify the Bulgarian Commission for Personal Data Protection, any other competent Supervisory Authority and the Data Subjects. The Processor shall not make any external notification on behalf of the Client without an instruction, unless required by law.

8. SUBPROCESSORS

8.1. The Client gives general prior authorisation for the use of the following Subprocessors to the extent that the relevant services are used to provide the Platform:

SubprocessorCountryFunction
UAB Interneto Vizija (Time4VPS), company No. 126350731LithuaniaVPS and infrastructure hosting
UAB Rakrėjus, company No. 303126701 (through UAB Interneto Vizija, where applicable)LithuaniaBackup infrastructure and storage
Microsoft Ireland Operations Limited (Azure)IrelandFile storage
Cloudflare, Inc.USAProxy, CDN, WAF and DNS
Google LLC (Firebase)USACrash diagnostics, push notifications, remote configuration and performance monitoring
Functional Software, Inc. d/b/a SentryUSAError monitoring and diagnostics

8.2. The Processor shall bind each Subprocessor by a written agreement imposing data protection obligations substantively equivalent to the applicable requirements of Article 28 GDPR. The Processor shall remain liable to the Client for the Subprocessor’s performance of those obligations.

8.3. The Processor shall notify the Client at the contractual email address of any intended addition or replacement of a Subprocessor at least 14 calendar days in advance. The Client may object within that period on specific data-protection grounds. Pending resolution of a timely and justified objection, the new Subprocessor shall not process the Client’s personal data. If the objection cannot be resolved, the Processor may refrain from using the new Subprocessor for the Client’s data, offer a reasonable alternative or discontinue the affected functionality.

9. TRANSFERS TO THIRD COUNTRIES

9.1. Where the use of an authorised Subprocessor results in the transfer of personal data outside the European Union/European Economic Area, the Processor shall ensure an applicable mechanism under Chapter V GDPR, including:

(a) an adequacy decision;

(b) Standard Contractual Clauses adopted by the European Commission; or

(c) another permitted mechanism.

Where necessary, the Processor shall also implement supplementary measures.

10. INFORMATION AND AUDITS

10.1. The Processor shall make available the information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits and inspections by the Client or an auditor mandated by the Client, subject to this Section.

10.2. Documentary and remote review shall be the primary audit method. A scheduled audit may be conducted no more than once in any 12-month period, on at least 30 days’ written notice, during normal business hours and without undue disruption to the Platform. The frequency and notice limitations shall not apply in the event of a Personal Data Breach, a reasonable suspicion of a material breach or a binding request from a competent Supervisory Authority.

10.3. An on-site inspection shall be permitted only where documentary review is objectively insufficient or where required by a competent Supervisory Authority. It shall be limited to processes and systems under the Processor’s control and to the processing of the Client’s data.

10.4. The auditor must be independent, must not be a competitor of the Processor and must be bound by confidentiality. An audit shall not provide access to source code, access credentials, data of other clients, information whose disclosure would weaken security or infrastructure of external providers. The Client shall bear the reasonable costs of the audit unless the audit establishes a material breach by the Processor.

11. RETURN AND DELETION

11.1. Following termination of access to the Platform, the Processor shall, at the Client’s choice:

(a) return the personal data and delete the available copies; or

(b) delete the personal data and the available copies.

Deletion shall cover all personal data and copies thereof processed on behalf of the Client, except to the extent that retention is required by the law of the European Union or the Republic of Bulgaria.

11.2. Personal data in Backups shall be erased through automatic overwriting in accordance with the cycle specified in the General Terms and Conditions. Until overwritten, it shall not be used for any purpose other than disaster recovery or where otherwise required by law.

11.3. After Trial Access expires, access to the personal data shall be suspended for 14 calendar days. If an Individual Agreement is signed within that period, processing shall continue under that agreement and this DPA. Otherwise, the Client may exercise its choice under Clause 11.1 by the end of that period. If it gives no other instruction, by accepting this DPA the Client instructs that the data be deleted. Data in Backups shall be erased under Clause 11.2.

12. LIABILITY, PRECEDENCE AND TERM

12.1. The allocation of contractual liability between the Parties is governed by the contractual documents, including the limitation of liability in the General Terms and Conditions, to the extent permitted by Applicable Data Protection Law. This shall not restrict the rights of Data Subjects or the powers of a Supervisory Authority.

12.2. The DPA shall remain in force until processing is completed. In the event of a conflict concerning personal data, it shall prevail over the other contractual documents.

12.3. The DPA shall become binding when signed separately or when expressly incorporated and accepted through a signed Individual Agreement or Trial Access Confirmation. A separate signature on the DPA shall not be required where its acceptance is evidenced in this manner.