Data Processing Agreement

Last updated: 13 September 2026

This agreement forms part of the Terms of Service and applies between every customer of the CRM service (the "Controller") and Инсиде Кафе ДООЕЛ, tax number 4020010509977, registered at Бул. Македонски Просветители л. 12, Охрид (the "Processor"). By accepting the Terms of Service, the Controller also accepts this agreement.

1. Subject

The Processor processes the personal data the Controller enters into the Service, on the Controller's behalf and only to provide the Service, in accordance with the Law on Personal Data Protection.

2. Description of the processing

Nature of processing storage, organisation, search, display, transfer on the Controller's instruction, backup and erasure
Purpose providing the CRM, invoicing, support and the other modules the Controller uses
Categories of data subjects the Controller's customers, contacts, suppliers, employees and users
Categories of data identification and contact data, business data, financial data, employee data the Controller enters
Duration the subscription and the return and deletion period in section 8

The Controller does not enter special categories of personal data (health, religious belief and the like) unless it has a legal basis and doing so is necessary for its business.

3. Processor's obligations

The Processor:

4. Technical and organisational measures

5. Sub-processors

The Controller gives general authorisation for the Processor to engage sub-processors. At present this is Contabo GmbH, Munich, Germany, for the servers running the Service and email. Card payments are processed by Casys, which acts as an independent payment service provider for card data, not as a sub-processor. The Processor binds sub-processors to the same protection obligations. The Processor notifies the Controller of a new sub-processor at least 15 days in advance, and the Controller may object and cancel the subscription.

6. Security breach

The Processor notifies the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach. The notice describes the nature of the breach, the categories of data and data subjects affected, the likely consequences and the measures taken.

7. Transfers

The data is stored in Germany (European Union). The Processor does not transfer it outside the European Economic Area without the Controller's prior written approval.

8. Return and deletion

After the subscription ends, the Controller may export its data within 30 days. After that period the Processor deletes the data unless the law requires it to be kept. Backups are deleted when their 14-day period expires.

9. Audit

The Processor makes available to the Controller the information needed to demonstrate compliance with this agreement. The Controller may ask written questions. An on-site audit is agreed at least 30 days in advance, during business hours, at the Controller's expense.

10. Liability and governing law

The parties' liability is governed by the Terms of Service. This agreement is governed by the law of the Republic of North Macedonia, and disputes are decided by the competent court in Ohrid.

11. Data protection contact

Инсиде Кафе ДООЕЛ Бул. Македонски Просветители л. 12, Охрид Email: info@inside.com.mk · Phone: 046230980