1. Roles of the parties
This agreement is between the customer named on the account ("controller") and SC OPERACK SYSTEMS SRL, Brașov, Romania ("processor"), and applies whenever we process personal data on your behalf under Article 28 of Regulation (EU) 2016/679.
For your own account data, such as the email you log in with and your invoices, we act as controller. That processing is described in the privacy policy and falls outside this DPA.
2. Scope of processing
3. Instructions
We process personal data only on your documented instructions. Your configuration in the dashboard and API, together with the terms of service, is the complete instruction set. We tell you if an instruction appears to breach data protection law, and we may refuse to carry it out.
Everyone at OPERACK SYSTEMS with access to customer data is bound by a written confidentiality obligation that survives the end of their engagement.
4. Subprocessors
You give general authorisation for the subprocessors listed in the privacy policy. We announce any addition or replacement at least 30 days in advance. If you object on reasonable data protection grounds within those 30 days, and we cannot offer an alternative, you may terminate the affected service and get a refund of anything prepaid.
Each subprocessor is bound by terms no less protective than this agreement, and we stay liable for their performance as if it were our own.
5. Security measures
We maintain the technical and organisational measures below, and will not reduce them during the term.
A personal data breach is reported to you without undue delay and within 72 hours of us becoming aware, with what we know at that point and updates as the picture clears.
6. International transfers
Data for domains in the EU zone stays in the European Union. Choosing the US zone is itself an instruction to transfer that domain's data to the United States. Where a transfer leaves the EEA, it runs on the European Commission's standard contractual clauses of 4 June 2021, module two, which are incorporated here by reference, together with a transfer impact assessment we make available on request.
7. Assistance
Export and deletion are self-service in the dashboard, which covers most data subject requests without our involvement. Where a request needs us, we help within 10 business days at no extra cost, and we forward any request a data subject sends us directly instead of answering it ourselves.
We also assist, taking into account the nature of the processing, with data protection impact assessments and prior consultation under Articles 35 and 36.
8. Audits
On request we provide our current security documentation and the summary of our annual external penetration test. If that is not enough for your obligations, you may audit us once per year with 30 days' notice, during business hours, without disrupting the service and under confidentiality. You cover your own costs; we cover ours unless the audit finds a material breach.
9. Return and deletion
You can export your configuration and analytics at any time in CSV or JSON. When the account closes, redirects stop immediately and all personal data is deleted within 30 days, including from backups on their normal rotation, except where law requires us to keep it. Deletion is confirmed in writing on request.
10. Contact
Write to dpa@redirectduck.com for a countersigned copy, the security documentation or the transfer impact assessment. Material changes to this DPA are announced 30 days before they take effect and every version stays in the archive.