01
Scope and parties
These Data Processing Terms ("DPT") form part of the agreement ("Agreement") between the Customer and ECoding Slovakia s. r. o. ("ECoding") for Scanverion. They apply where ECoding processes personal data contained in Customer Content on behalf of Customer.
Customer is the controller and ECoding is the processor. If Customer processes data for another controller, Customer is a processor and ECoding is its subprocessor; Customer confirms that its instructions and appointment of ECoding are authorized. Each party remains an independent controller for account, billing, business-contact, security, and compliance data it determines to process for its own purposes, as explained in the Privacy Policy.
02
Definitions and precedence
"Customer Personal Data" means personal data in Customer Content processed by ECoding for Customer. "Data Protection Law" means the EU GDPR and applicable EEA or national privacy law. "Subprocessor" means a third party appointed by ECoding to process Customer Personal Data. GDPR terms such as controller, processor, processing, personal data, and personal data breach have their statutory meanings.
If this DPT conflicts with the Agreement regarding Customer Personal Data, this DPT prevails. A signed, negotiated data-processing addendum prevails over this online DPT where it expressly replaces it.
03
Instructions and lawful processing
ECoding will process Customer Personal Data only on Customer's documented instructions, including the Agreement, API calls, dashboard settings, support requests, and lawful written instructions, unless EU or Member State law requires otherwise. In that case ECoding will inform Customer before processing unless law prohibits notice.
ECoding will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Law and may pause the affected processing while the parties resolve it. ECoding is not required to provide legal advice or follow an instruction that is unlawful, technically impossible, or outside the Service without an agreed change.
Customer is responsible for the lawfulness, fairness, transparency, accuracy, minimization, retention, and legal basis of Customer Personal Data and instructions, including notices and rights concerning data subjects.
04
Details of processing
Subject matter: provision, security, support, and maintenance of Scanverion document and image analysis and related API services.
Duration: the Agreement plus the limited return, deletion, backup, incident, and legal-retention periods described below.
Nature and purpose: receiving, transmitting, validating, temporarily storing where required, detecting, classifying, extracting, comparing, transforming, returning, metering, troubleshooting, securing, and deleting Customer Content according to Customer's selected operations.
Data subjects: Customer users and personnel; Customer's clients, applicants, policyholders, claimants, suppliers, visitors, and end users; individuals shown in or identified by submitted documents, images, forms, vehicles, barcodes, addresses, or other content.
Data types: images and documents; names, contact and address data; dates and places of birth; nationality; identity-document data and identifiers; signatures; faces and visual characteristics; vehicle and registration data; barcodes; form fields; transaction or case references; technical metadata; and any other data Customer chooses to submit.
Sensitive data: Customer may submit special-category or criminal-offence data only where supported by the Service, necessary, lawful, and protected by appropriate safeguards. Customer must not submit data beyond what is necessary for the selected operation.
05
Confidentiality and security
ECoding will ensure persons authorized to process Customer Personal Data are bound by confidentiality and receive appropriate privacy and security guidance. Access is limited according to role and need.
Taking account of the state of the art, implementation costs, and processing risks, ECoding will maintain measures appropriate under GDPR Article 32, including secure transmission; access control and least privilege; credential and secret management; logging and monitoring; development and production separation; vulnerability and patch management; backup and recovery appropriate to stored data; incident response; provider diligence; and periodic review of safeguards.
Customer is responsible for secure integration, endpoint and network security, account roles, API-key scope and rotation, lawful input selection, and secure storage of source files and returned outputs.
06
Subprocessors
Customer gives general authorization for ECoding to use Subprocessors. Planned core providers include Amazon Web Services (eu-central-1, Frankfurt) for EU cloud infrastructure and Google Cloud hosted in the EU for supported cloud or AI workloads. Other providers may support monitoring, communications, security, or service delivery; payment and analytics providers do not process Customer Content unless specifically configured to do so.
Before a new Subprocessor processes Customer Personal Data, ECoding will impose data-protection obligations no less protective in substance than this DPT and remain responsible for the Subprocessor's performance as required by law. ECoding will publish or otherwise provide the current production list and give reasonable advance notice of material additions or replacements.
Customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, Customer may stop the affected feature or terminate the affected Service without penalty for future periods.
07
Processing location and transfers
ECoding will configure primary Customer Content processing in the European Union unless the applicable order states otherwise. ECoding will not transfer Customer Personal Data outside the EEA without a valid GDPR Chapter V mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, plus supplementary measures where required.
Where the Standard Contractual Clauses apply, they are incorporated by reference with Customer as data exporter, ECoding or the relevant Subprocessor as data importer, Module Two or Three as appropriate, optional docking enabled, and Slovak law and Slovak supervisory authority selected where the clauses require a choice.
08
Data-subject and compliance assistance
Considering the nature of processing, ECoding will provide reasonable technical and organizational assistance for Customer to respond to data-subject requests. If ECoding receives a request relating to Customer Personal Data, it will direct the requester to Customer and will not respond substantively unless instructed or legally required.
ECoding will reasonably assist Customer with security obligations, breach notifications, data-protection impact assessments, and prior consultation under GDPR Articles 32 to 36, taking account of information available to ECoding. Assistance beyond standard Service capabilities may be charged at agreed reasonable rates unless caused by ECoding's breach.
09
Personal data breaches
ECoding will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification will include available information needed under GDPR Article 33(3), such as the nature of the breach, likely consequences, affected data and individuals, contact point, and measures taken or proposed. Information may be supplied in phases as it becomes available.
ECoding will investigate, mitigate, document, and reasonably cooperate with Customer. Notification is not an admission of fault. Customer is responsible for notifications to authorities and data subjects unless law assigns that duty to ECoding.
10
Return, retention, and deletion
Scanverion is designed for synchronous processing. ECoding will not retain Customer Content longer than necessary to complete requested processing, provide agreed transient downloads or support, protect the Service, or satisfy documented instructions and law. ECoding will not use Customer Personal Data to train general-purpose or shared AI models unless Customer expressly agrees in writing.
At termination or Customer's written request, ECoding will delete or return Customer Personal Data, at Customer's choice, unless law requires retention. Data in protected backups may remain until overwritten under the applicable backup cycle; it will remain protected, isolated from ordinary use, and deleted in due course. ECoding may retain minimal evidence of deletion, security events, and processing instructions where legally necessary.
Specific production retention windows, if any, will be stated in the applicable order, documentation, or configurable Service setting before Customer Content is stored beyond transient processing.
11
Information and audits
ECoding will make available information reasonably necessary to demonstrate compliance with GDPR Article 28, which may include current policies, architecture summaries, Subprocessor information, security questionnaires, and independent reports when available.
Customer may conduct one audit per year, and additional audits after a material breach or regulator request, on at least 30 days' notice where practicable. Audits must occur during business hours, avoid disruption, protect other customers and confidential systems, and use an independent auditor bound by confidentiality. ECoding may satisfy an audit through recent independent evidence where it adequately addresses the request and may charge reasonable costs for excessive or bespoke audits.
12
Liability and term
This DPT starts when Customer accepts the Agreement or first submits Customer Personal Data and continues while ECoding processes it. Liability under this DPT is subject to the Agreement's limitations to the extent permitted by Data Protection Law; no term limits a data subject's rights or liability that cannot lawfully be limited.
Changes needed for law, regulators, security, or provider arrangements may be made with notice. A material reduction in protection will not apply during a current paid term unless required by law or agreed with Customer.
13
Contact and governing law
Privacy and DPT requests may be sent to gdpr@ecoding.sk or through the contact page. Notices should identify the Customer workspace and a suitable privacy or security contact.
This DPT follows the governing law and jurisdiction in the Agreement. The Slovak version is legally binding. This English translation is provided for convenience only, and the Slovak version prevails in case of any inconsistency.