Data Processing Agreement
Last updated: 13 September 2026
This agreement forms part of the Terms of Service and applies between every customer of the CRM service (the "Controller") and Инсиде Кафе ДООЕЛ, tax number 4020010509977, registered at Бул. Македонски Просветители л. 12, Охрид (the "Processor"). By accepting the Terms of Service, the Controller also accepts this agreement.
1. Subject
The Processor processes the personal data the Controller enters into the Service, on the Controller's behalf and only to provide the Service, in accordance with the Law on Personal Data Protection.
2. Description of the processing
| Nature of processing | storage, organisation, search, display, transfer on the Controller's instruction, backup and erasure |
| Purpose | providing the CRM, invoicing, support and the other modules the Controller uses |
| Categories of data subjects | the Controller's customers, contacts, suppliers, employees and users |
| Categories of data | identification and contact data, business data, financial data, employee data the Controller enters |
| Duration | the subscription and the return and deletion period in section 8 |
The Controller does not enter special categories of personal data (health, religious belief and the like) unless it has a legal basis and doing so is necessary for its business.
3. Processor's obligations
The Processor:
- processes the data only on the Controller's documented instructions, which consist of these terms and the settings the Controller makes in the Service;
- ensures that persons with access to the data are bound by confidentiality;
- applies the technical and organisational measures in section 4;
- does not use the data for its own purposes and does not disclose it to third parties unless the law requires it;
- assists the Controller in responding to data subject requests and in meeting its obligations on security, breach notification and impact assessment.
4. Technical and organisational measures
- a separate database for each Controller;
- encrypted connections (HTTPS);
- passwords stored as secure hashes, two-factor authentication, encrypted keys and secrets;
- permissions by role and by user, and a log of changes and sign-ins;
- daily backups, kept for 14 days and at a separate location;
- monitoring of availability and errors;
- server access limited to authorised personnel of the Processor.
5. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors. At present this is Contabo GmbH, Munich, Germany, for the servers running the Service and email. Card payments are processed by Casys, which acts as an independent payment service provider for card data, not as a sub-processor. The Processor binds sub-processors to the same protection obligations. The Processor notifies the Controller of a new sub-processor at least 15 days in advance, and the Controller may object and cancel the subscription.
6. Security breach
The Processor notifies the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach. The notice describes the nature of the breach, the categories of data and data subjects affected, the likely consequences and the measures taken.
7. Transfers
The data is stored in Germany (European Union). The Processor does not transfer it outside the European Economic Area without the Controller's prior written approval.
8. Return and deletion
After the subscription ends, the Controller may export its data within 30 days. After that period the Processor deletes the data unless the law requires it to be kept. Backups are deleted when their 14-day period expires.
9. Audit
The Processor makes available to the Controller the information needed to demonstrate compliance with this agreement. The Controller may ask written questions. An on-site audit is agreed at least 30 days in advance, during business hours, at the Controller's expense.
10. Liability and governing law
The parties' liability is governed by the Terms of Service. This agreement is governed by the law of the Republic of North Macedonia, and disputes are decided by the competent court in Ohrid.
11. Data protection contact
Инсиде Кафе ДООЕЛ Бул. Македонски Просветители л. 12, Охрид Email: info@inside.com.mk · Phone: 046230980