1. Parties
Controller: the client. Processor: MRJ (trading as baaark.com), registered in Poland (REGON 385160952, NIP PL7532455176), ul. Fabryczna 14d, 53-609 Wrocław, Poland.
2. Definitions
"GDPR" means Regulation (EU) 2016/679 and, for UK clients, the UK GDPR and Data Protection Act 2018. "Personal data", "processing", "sub-processor" and "data subject" have the meanings given there. "Services" means the services under the Terms of Service.
3. Subject matter and duration
The Processor processes personal data on the Controller's behalf to host and maintain the Controller's website, receive and store its enquiries, count its visits, provide support and keep it secure. This agreement lasts as long as the Services and for any agreed retention period after.
4. Nature and purpose
- Storing and forwarding enquiries and form submissions, including uploaded files
- Hosting page content and images the Controller publishes
- Counting visits with a first-party, cookie-free counter
- Technical support and security monitoring
5. Categories of data and data subjects
Contact details and message content of the Controller's prospects and customers; usage data of the Controller's visitors; account details of the Controller's staff who log in. No special-category data is processed unless specifically agreed in writing with additional safeguards.
6. Processor obligations
- Process data only on the Controller's documented instructions
- Ensure everyone with access is bound by confidentiality
- Apply the security measures in section 9
- Assist with data-subject requests: acknowledge within 48 hours, complete within 30 days
- Assist with the Controller's compliance obligations and, where required, impact assessments
- Delete or return all personal data at the end of the Services and delete existing copies unless law requires retention
7. Sub-processors
The Controller authorises these sub-processors: Vercel (hosting), Supabase (database and file storage), Resend (transactional email), Cloudflare (Turnstile bot protection), Stripe and SureCart (payments and subscriptions, where the Controller's site sells through them), Google Workspace (email correspondence). The Processor will give 30 days' notice of any change so the Controller can object.
8. International transfers
Where a sub-processor processes data outside the UK or EEA, the transfer relies on the EU Standard Contractual Clauses or the UK International Data Transfer Addendum, with transfer impact assessments where required.
9. Security
- TLS in transit; encryption at rest on the database and storage
- Row-level security so each site's data is isolated from every other tenant
- Private file storage with time-limited signed links
- Two-factor authentication on the Processor's accounts; least-privilege access
- Automated backups and regular dependency updates
- Logging, monitoring and an incident-response procedure
10. Personal data breaches
The Processor notifies the Controller without undue delay and in any case within 24 hours of becoming aware of a breach affecting the Controller's data, with the information needed for the Controller's own notifications, and takes immediate containment and remediation steps.
11. Audit
The Controller may audit compliance on reasonable notice, at its own cost, no more than once a year unless a breach has occurred. The Processor provides the information reasonably needed to demonstrate compliance.
12. Liability
Each party is liable under GDPR for its own failures. The limitations in the Terms of Service apply to the Processor's liability under this agreement except where the law does not allow it.
13. Law
Polish law governs this agreement, without prejudice to the mandatory data-protection law that applies to the Controller.
14. Execution
This agreement forms part of the Services agreement and takes effect when the Services begin. A signed copy is available on request.
Contact
For DPA matters: hello@baaark.com
MRJ (trading as baaark.com), ul. Fabryczna 14d, 53-609 Wrocław, Poland.



