Data Processing Agreement

Effective: 8 June 2026. Governing version: Czech. This agreement forms part of the Terms of Service and applies where Roští.cz, s.r.o. processes personal data for the Customer as processor under Article 28 GDPR.

1. Roles

1.1. The Customer is the controller of personal data inserted, stored, transferred or otherwise processed through Roští.cz services. The Provider acts as processor for such data.

1.2. The Customer is responsible for processing lawfulness, legal basis, information duties towards data subjects and instructions given to the Provider.

1.3. The Provider processes personal data only under this agreement, the Terms of Service, service settings, documented Customer instructions and legal obligations applicable to the Provider.

2. Subject Matter, Duration, Nature and Purpose

2.1. The processing covers operation of hosting and related services, especially applications, stacks, databases, storage, DNS, backups, technical support, security, monitoring and operational recovery.

2.2. Processing lasts for the service term and afterwards for the time needed for deletion, settlement of rights and obligations, backup recovery or compliance with legal obligations.

2.3. The nature of processing includes storage, transmission, access through the administration interface, backup, restore, deletion, availability monitoring, security logging and technical operations necessary for service operation.

2.4. The purpose is to enable the Customer to operate its own applications, services and data on the Provider's infrastructure and to provide related technical support.

3. Categories of Data and Data Subjects

3.1. The types of personal data are determined by the Customer through its applications, databases, files, logs and communication. They may include identification, contact, authentication, operational, transactional, communication or other data, including special categories if inserted by the Customer.

3.2. Categories of data subjects are determined by the Customer and may include users, customers, employees, suppliers, website visitors, contact persons or other persons whose data the Customer processes through the service.

3.3. The Provider is not required to inspect Customer data and cannot assess whether the Customer stores special categories of data or data subject to special legal regimes.

4. Customer Instructions

4.1. Documented instructions include the Terms of Service, this agreement, settings made in the administration interface, API or MCP tools, service orders and written support communication.

4.2. If the Provider believes an instruction breaches GDPR or other law, it will inform the Customer unless prohibited by law.

4.3. The Provider may refuse or suspend an instruction that would threaten security, third-party rights, service operation or the Provider's legal obligations.

5. Provider Duties

5.1. The Provider ensures that persons authorised to process personal data are bound by confidentiality or an appropriate statutory duty of confidentiality.

5.2. The Provider applies technical and organisational measures appropriate to risk, including access control, environment separation, encrypted transmission, security updates, backups, logging, monitoring and internal rules for handling Customer data.

5.3. The Provider assists the Customer to a reasonable extent with data subject rights, security, breach notification, DPIAs and supervisory authority consultations where possible considering the service nature and information available to the Provider.

5.4. If a data subject request concerns data processed for the Customer, the Provider will forward it to the Customer or refer the data subject to the Customer where possible.

6. Sub-processors

6.1. The Customer grants the Provider general authorisation to engage sub-processors. The Provider will impose data protection obligations on sub-processors corresponding to this agreement. If a sub-processor fails to fulfil its data protection obligations, the Provider remains responsible to the Customer for their performance.

6.2. In connection with the services, the Provider uses or plans to use in particular the following suppliers and recipients. Hosted application data, meaning content uploaded by the Customer to the service or operated through the service, is stored only on servers operated by the Provider. The Provider's own servers are located in data centres in the Czech Republic. Hosted application data is not disclosed to e-mail, invoicing or payment suppliers.

SupplierPurposeDataRole
DigitalOceanDNS serversDNS records and technical domain dataTechnical supplier; does not store hosted application data
openprovider.comDomain registration and managementIdentification and contact details of the domain holder, administrative and technical domain dataRegistrar / independent controller or processor depending on the domain operation; does not store hosted application data
HetznerSupplementary technical infrastructure outside hosted application data storageTechnical operational data necessary for infrastructure operation; not hosted application dataInfrastructure supplier / potential sub-processor
MailgunE-mail deliveryE-mail addresses, headers and content of sent e-mailsE-mail communication processor
GoogleE-mail communicationE-mail addresses, headers and content of e-mail communicationProcessor or independent controller depending on the service used
FakturoidInvoicingIdentification and billing data, invoice itemsInvoicing processor
GoPayCard payments and payment gatewayPayment identifiers, amounts and payment statuses; card data are processed by GoPayPayment recipient / independent controller or processor depending on the payment operation
Fio bankaBank paymentsBank payment data, account number, amount and variable symbolBank / independent controller

6.3. E-mail, invoicing and payment suppliers process only data necessary for the relevant purpose. Customer data of hosted applications is not disclosed to these suppliers.

6.4. The Provider will inform the Customer of material sub-processor changes in an appropriate manner. The Customer may object on reasonable grounds; if the parties do not resolve the objection, the Customer may terminate the affected service.

7. Security and Incidents

7.1. The Provider protects Customer data against unauthorised or accidental access, alteration, loss, destruction and disclosure in a manner appropriate to risk and service nature.

7.2. If the Provider becomes aware of a personal data breach concerning data processed for the Customer, it will notify the Customer without undue delay and provide information available to the Provider.

7.3. The Customer is responsible for security of its applications, accounts, access credentials, deployed code and configuration. The Provider is not responsible for an incident caused by the Customer's application or instruction unless it breached its own processor duties.

8. Audits and Compliance Evidence

8.1. The Provider will provide information reasonably necessary to demonstrate compliance with Article 28 GDPR, especially descriptions of measures, processes and sub-processors.

8.2. Audits or inspections must be agreed in advance, must not unreasonably threaten security, confidentiality of other customers' data or service operation, and may require auditor confidentiality. Unless caused by the Provider's breach, the Provider may charge reasonable costs.

9. Return and Deletion

9.1. The Customer may export data using service tools where the service nature allows it. After service termination the Customer must perform export in time.

9.2. After service termination the Provider deletes active data according to technical service processes. Backups are deleted in the normal backup cycle, no later than 60 days, unless a legal obligation or security incident requires longer retention.

9.3. If law requires retention of certain data, the Provider will keep them only to the necessary extent and for the necessary period.

10. Transfers Outside the EU/EEA

10.1. The Provider will not transfer personal data processed for the Customer outside the EU/EEA without a GDPR transfer mechanism, especially an adequacy decision, standard contractual clauses or other safeguards.

10.2. If the Customer transfers data outside the EU/EEA through its application or configuration, the Customer is responsible for the legal basis and safeguards.

11. Final Provisions

11.1. This agreement is concluded electronically and is binding for as long as the Provider processes personal data for the Customer as processor.

11.2. Matters not covered by this agreement are governed by the Terms of Service and GDPR. For processing of personal data on Customer instructions, this Data Processing Agreement prevails.