Zonno Dance
GENERAL TERMS AND CONDITIONS (GTC)
including the Data Processing Agreement (Annex No. 1)
Operator and Service Provider:
Wootera Digital Technologies, s.r.o.
Company ID: 19160526 | VAT ID: CZ19160526
Registered office: Oldřichova 255/20, Nusle, 128 00 Prague 2
Registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 382101
Contact: zonno@wootera.com
(hereinafter referred to as the “Provider”)
Article 1 – Introductory Provisions and Definitions
1.1 These General Terms and Conditions (hereinafter referred to as the “GTC”) govern the rights and obligations between the Provider and the User when using the software service Zonno Dance (hereinafter referred to as the “Service”).
1.2 The User shall mean a natural or legal person, typically a dance school, studio, academy, instructor, sports club or other similar entity, who creates an account in the Service, orders access to the Service or otherwise uses the Service for the management of its dance, sports, educational or similar activities (hereinafter also referred to as the “School”).
1.3 The Zonno Dance Service is a web application and related mobile applications for Apple iOS and Google Android intended primarily for managing the agenda of dance schools, courses, lessons, schedules, workshops, instructors, students, attendance, reports, statistics, financial overviews and other operational agenda of the School.
1.4 The Service is intended primarily for the internal operational management of the School and communication between the School, its instructors and students. The Service itself is not a dance school, educational institution, organizer of lessons, provider of dance instruction, nor a party to the contractual relationship between the School and its students or instructors.
1.5 The Agreement shall mean the contractual relationship established between the Provider and the User under the conditions set out in Article 2 of these GTC.
1.6 A Student shall mean a natural person who is registered by the User in the Service as a student, pupil, member, course participant, lesson participant, workshop participant or other similar participant in the User’s activities.
1.7 An Instructor shall mean a natural person who is registered by the User in the Service as an instructor, trainer, coach, teacher or other person providing instruction, lessons, workshops or similar activities of the User.
1.8 An End User shall mean a Student, Instructor or other person to whom the User enables access to the web or mobile part of the Service. The End User is not a contractual party in relation to the Provider, unless they conclude a separate agreement with the Provider.
1.9 Mobile Application shall mean the Zonno Dance mobile application available via the Apple App Store and Google Play, or by other similar means, intended primarily for Students, Instructors and other End Users.
1.10 Payment Gateway shall mean an external third-party service enabling payment for the use of the Service or, in the future, possibly payments between the Student and the School. The Provider is not a bank, payment service provider or payment institution.
Article 2 – Formation and Duration of the Agreement
2.1 The Agreement between the Provider and the User is established at the moment when the User:
a) completes registration in the Zonno Dance system and confirms agreement with these GTC,
b) orders a paid plan or other access to the Service,
c) begins to actually use the Service, if explicit completion of registration did not occur, or
d) otherwise confirms agreement with these GTC.
2.2 At this moment, the User declares that they have familiarized themselves with these GTC, including Annex No. 1, understand them and agree to them.
2.3 The Agreement is concluded for an indefinite period, unless agreed otherwise between the parties.
2.4 The User may terminate the Agreement at any time by sending a written notice to the e-mail zonno@wootera.com or by deleting the account via the Service interface, if such option is available. The Agreement terminates upon expiry of 30 days from delivery of the notice, unless the Provider sets a shorter period.
2.5 The Provider may terminate the Agreement with a 30-day notice period without stating a reason.
2.6 The Provider may terminate the Agreement with immediate effect or restrict access to the Service if the User seriously or repeatedly breaches these GTC, breaches legal regulations, interferes with the security of the Service, fails to pay due fees or uses the Service in a manner that may harm the Provider, other users, End Users or third parties.
Article 3 – Provision of the Service and Access
3.1 The Provider undertakes to make reasonable efforts to ensure that the Service is available and functional. The Provider does not guarantee uninterrupted availability of the Service.
3.2 The Provider reserves the right to carry out planned and unplanned downtime of the Service for the purposes of maintenance, updates, development, repairs or for security reasons.
3.3 Access to the Service is conditional upon registration and may be subject to a fee according to the current price list, order, plan or individual agreement between the Provider and the User.
3.4 A basic, testing, pilot or trial version of the Service may be provided free of charge or under preferential conditions. The Provider reserves the right to change, limit or terminate the scope of the free or testing version at any time.
3.5 Access credentials, in particular login name, password, tokens and other authentication means, are personal and non-transferable. The User is obliged to ensure their confidentiality and to inform the Provider without undue delay of their loss, leakage or suspicion of misuse.
3.6 The User is responsible for to whom they grant access rights within their account. The User is responsible for setting roles, permissions and access for their administrators, instructors, employees, collaborators, students and other persons.
3.7 The Mobile Application may be available via Apple App Store and Google Play. Availability, approval, operation and distribution of the Mobile Application may be affected by the rules of Apple, Google or other operators of distribution platforms. The Provider is not responsible for decisions of these third parties, in particular for delays in application approval, temporary removal of the application, changes in store rules or limitation of application availability in a particular country or region.
3.8 By using the Mobile Application, End Users may also be bound by the terms of the respective app store, operating system, device manufacturer or mobile service provider.
Article 3a – Service Level and Support
3a.1 The Provider makes reasonable efforts to achieve Service availability at the level of 99% measured monthly, excluding planned downtime, unplanned maintenance, force majeure events, third-party outages and circumstances beyond the reasonable control of the Provider. This value does not represent a contractually guaranteed service level and its failure does not give rise to any claim for discount, damages or other performance beyond these GTC.
3a.2 Technical support is provided exclusively electronically at zonno@wootera.com or via another communication channel designated by the Provider.
3a.3 The Provider undertakes to respond to requests on working days, typically within 3 working days from delivery. This period is not binding and does not give rise to a claim for damages if exceeded.
3a.4 The Provider does not provide telephone support, on-site support, training, implementation at the User’s premises or guaranteed response or service times, unless otherwise agreed in a separate written agreement.
3a.5 The Provider may provide recommendations for Service setup, process implementation or application use. However, the final setup of operational, legal, accounting, tax, labor-law and organizational processes of the User is solely the responsibility of the User.
Article 3b – Mobile Application and Third-Party Platforms
3b.1 The Zonno Dance Mobile Application is distributed through third parties, in particular Apple App Store and Google Play.
3b.2 The User and End Users acknowledge that:
a) these third parties are not a party to this Agreement,
b) the Provider is solely responsible for the Service and its content,
c) Apple and Google bear no responsibility for the operation of the Service, support or complaint handling.
3b.3 The use of the Mobile Application may also be subject to the terms of these third parties.
3b.4 The Mobile Application is only an interface for accessing the Service and does not provide a separate service independent of the web application.
Article 4 – Rights and Obligations of the User
4.1 The User undertakes to use the Service exclusively for the purposes for which it is intended, in particular for managing the agenda of a dance school, lessons, courses, workshops, students, instructors, attendance, schedules, reports, statistics, finances and related communication.
4.2 The User is responsible for ensuring that the Service is used in accordance with applicable legal regulations, these GTC, data protection rules, consumer protection rules, accounting and tax regulations and any other obligations applicable to their activities.
4.3 The User bears full responsibility for:
a) the accuracy, completeness and legality of data entered into the Service,
b) the legal relationship with their Students, Instructors, legal guardians of minors, employees, collaborators and other persons,
c) obtaining all necessary consents, legal bases, informing data subjects and fulfilling obligations under GDPR,
d) setting and managing user accounts, roles and permissions,
e) protection of access credentials and devices used to access the Service,
f) the content of communication sent through the Service, including emails and push notifications,
g) the accuracy of schedules, prices, payment information, attendance, statistics and reports,
h) fulfillment of obligations towards Students and Instructors, especially in the area of organization of lessons, safety, liability for damage, cancellation conditions, refunds and complaints,
i) verification of whether persons under 18 years of age may use the Service in accordance with the User’s rules and legal regulations, including obtaining consent of a legal guardian where necessary.
4.4 The User acknowledges that the Provider is not a party to any contract between the User and the Student, the User and the Instructor, the User and the legal guardian of a minor Student or between the User and any other third party.
4.5 The User is obliged to ensure that their Students, Instructors and other End Users use the Service in accordance with these GTC, legal regulations and general rules of decent and safe use of digital services.
4.6 The User is prohibited from:
a) using the Service for illegal purposes or in a manner harmful to the Provider, other users, End Users or third parties,
b) inserting unlawful, offensive, discriminatory, hateful, misleading or otherwise inappropriate content into the Service,
c) sending unsolicited commercial communications, spam or harassing communication via the Service,
d) copying, decompiling, reverse engineering, circumventing technical limitations or otherwise interfering with the source code of the Service,
e) reselling, renting or sublicensing access to the Service to third parties without prior written consent of the Provider,
f) attempting to disrupt the security, integrity or availability of the Service, including penetration testing without prior written consent of the Provider,
g) accessing the Service in an automated manner using bots, scrapers or other tools beyond normal operation without the Provider’s consent,
h) uploading malicious code, malware, viruses or content disrupting the operation of the Service,
i) circumventing tariff, licensing, technical or security limitations of the Service,
j) misusing the Service for tracking persons, harassment, unauthorized profiling or other disproportionate interference with the rights of persons.
4.7 The User acknowledges that the Service may also be used by persons under 18 years of age (students). The User undertakes to ensure that the processing of personal data of these persons is carried out in accordance with legal regulations, in particular that:
a) they have an appropriate legal basis for processing personal data of minors,
b) where necessary, they have obtained consent of a legal guardian,
c) they have fulfilled all information obligations towards these persons and their legal guardians.
The Provider does not verify the age of End Users nor the existence of consent of a legal guardian. The User is solely responsible for fulfilling these obligations.
Article 5 – Payments and Prices
5.1 The use of the Service may be subject to fees according to the current price list, order, plan or individual agreement between the Provider and the User.
5.2 Payments for the use of the Service are paid by the User to the Provider, typically via a payment gateway, bank transfer or another payment method designated by the Provider.
5.3 The Provider may offer monthly, annual, pilot, trial, free or other types of plans.
5.4 If the User fails to pay the due price for the use of the Service, the Provider is entitled to restrict, suspend or terminate the User’s access to the Service.
5.5 The User acknowledges that current payments of Students to the School may take place outside the Service, for example in cash, by card directly to the School, by transfer or by another method agreed between the Student and the School. The User is solely responsible for these payments, their records, tax and accounting processing, complaints, refunds and disputes.
5.6 If the Service in the future enables payments of Students or other End Users to the School via the application or system, the Provider will act only as a technical provider of a software interface or as a technical intermediary connecting to an external payment gateway. The Provider is not a payment service provider, bank, payment institution or recipient of payments intended for the School, unless explicitly agreed otherwise.
5.7 The User is solely responsible for the legal relationship between the School and the Student, including course, lesson and workshop pricing, cancellation conditions, refunds, complaints and obligations towards consumers.
5.8 The Provider is entitled to change prices, plans and the scope of paid features. The Provider will inform the User of any change in price or plan in an appropriate manner, in particular by e-mail or notification in the Service, at least 14 days before the change becomes effective, unless the change is in favor of the User.
5.9 The Service currently does not enable processing of payments between Students and the User.
5.10 If functionality enabling payments via the Service is introduced in the future, such services will be governed by separate terms.
5.11 The Provider is not a provider of payment services under applicable laws, unless explicitly stated otherwise.
Article 6 – Intellectual Property
6.1 All intellectual property rights to the Zonno Dance Service, including software, database structure, graphical interface, mobile application, web application, logo, trade name, documentation, know-how and related materials, belong exclusively to the Provider or are lawfully used by the Provider.
6.2 Under these GTC, the User does not acquire any ownership rights to the Service. The User is granted only a non-exclusive, non-transferable, time-limited license to use the Service for the duration of the Agreement, exclusively for the User’s internal operational purposes.
6.3 Data entered by the User into the Service, in particular data about the School, Students, Instructors, lessons, courses, workshops, schedules, attendance, payments, reports and statistics, remain under the control of the User. The Provider processes them only to the extent necessary for operation of the Service, performance of the Agreement, protection of the Provider’s rights and in accordance with Annex No. 1.
6.4 The User grants the Provider authorization to technically process, store, back up, transfer and display data entered into the Service to the extent necessary for provision of the Service.
6.5 The Provider is entitled to use anonymized or aggregated data from which it is not possible to identify the User, School, Student, Instructor or any other specific person, for the purposes of improving the Service, analytics, security, development and business decision-making.
6.6 The User has the right to request export of their data stored in the Service during the duration of the Agreement or within 30 days after its termination.
6.7 Data export will be provided in a commonly used format (e.g. CSV, JSON or another technically suitable format).
6.8 The Provider reserves the right to charge a reasonable fee for extensive or repeated data exports.
Article 7 – Provider’s Liability
7.1 The Service is provided “as is”. The Provider provides no warranties regarding suitability of the Service for a particular purpose, error-free operation, uninterrupted operation or achievement of a specific business, organizational, financial or educational result of the User.
7.2 The Provider is not liable for:
a) loss of profit, loss of revenue, loss of business opportunities, loss of reputation, loss of data or any indirect or consequential damages incurred by the User or third parties,
b) damages caused by outage, error, limitation or unavailability of the Service,
c) accuracy of data entered by the User, their employees, Instructors, Students or other End Users,
d) legal relationships between the User and their Students, Instructors, employees, collaborators, legal guardians of minors or other persons,
e) quality, availability, safety or execution of lessons, courses, workshops or other activities of the User,
f) payments made outside the Service or directly between the Student and the School,
g) tax, accounting, labor-law, consumer or other legal obligations of the User,
h) damages caused by unauthorized access by third parties, phishing, password misuse, loss of device, cyberattack or other security incident, if the Provider has taken reasonable technical and organizational measures,
i) damages caused by failure of third-party infrastructure, in particular hosting providers, cloud services, payment gateways, email services, push notification services, distribution platforms Apple App Store and Google Play, analytical tools or internet connection.
7.3 The total cumulative liability of the Provider for all damages arising in connection with the Service during any 12 consecutive months is limited to the amount of fees paid by the User for the last 2 billing months preceding the occurrence of the damaging event.
7.4 In the case of a free, testing, pilot or trial version of the Service, the Provider’s liability is excluded to the maximum extent permitted by law.
7.5 The above limitations do not apply to damages caused intentionally or by gross negligence of the Provider, nor to harm to the natural rights of a person, to the extent that liability cannot be limited under applicable law.
Article 8 – Force Majeure
8.1 The Provider is not liable for failure to perform or delay in performance of obligations caused by circumstances excluding liability within the meaning of Section 2913(2) of the Civil Code, in particular natural disasters, war conflicts, riots, epidemics, decisions of public authorities, large-scale energy outages, internet outages, cloud infrastructure outages, cyberattacks, payment gateway outages, outages of third-party services or interventions by Apple, Google or other distribution platforms.
Article 9 – Changes to the Terms and Conditions and the Service
9.1 The Provider is entitled to amend these Terms and Conditions unilaterally. The User shall be informed of any changes by e-mail sent to the address provided during registration or by a notice in the Service interface, at least 14 days before the changes take effect.
9.2 If the User does not agree with the changes, the User is entitled to terminate the Agreement in accordance with Article 2.4 by the effective date of the changes. By continuing to use the Service after the effective date of the changes, the User accepts the new Terms and Conditions.
9.3 The Provider reserves the right to change, expand, restrict, modify, suspend or terminate the Service at any time, with reasonable advance notice depending on the situation, but at least 30 days before the complete termination of the Service, except in cases of force majeure, security incidents, legal obstacles, interventions by third parties or a serious breach of the Terms and Conditions by the User.
9.4 The Provider is entitled to change the functions of the Service, the user interface, the availability of functions in individual plans, the technical solution, the method of login, the method of notifications, the availability of the mobile application and third-party integrations.
Article 10 – Communication, E-mails and Push Notifications
10.1 The Service may enable the sending of system e-mails, transactional e-mails, operational notices, informational messages and push notifications to Students, Instructors, administrators and other End Users.
10.2 The Provider may ensure the technical sending of these messages; however, the User is responsible for their content, recipient settings, legal basis, frequency and compliance with legal regulations if the messages are sent on behalf of the User or within the scope of the User’s operations.
10.3 The User is obliged to ensure that communication sent through the Service does not violate legal regulations, in particular rules concerning personal data protection, electronic communication, unsolicited commercial communications and consumer protection.
10.4 The Provider is entitled to send the User operational, technical, security and contractual information relating to the Service.
10.5 The availability of push notifications may depend on the settings of the End User’s device, the operating system, Apple, Google or other third-party services. The Provider does not guarantee the delivery of every push notification.
Article 11 – Google Analytics and Analytical Tools
11.1 The Service may use Google Analytics or similar analytical tools for the purpose of measuring traffic, use of the Service, technical operation and improving the user experience.
11.2 The scope and method of using analytical tools is described in the Provider’s Privacy Policy, or, where required by legal regulations, in the cookie banner or another information mechanism.
11.3 The User acknowledges that if the User independently enters personal data into the Service or allows End Users access, the User is responsible for fulfilling its information obligations towards those persons.
Article 12 – Governing Law and Dispute Resolution
12.1 These Terms and Conditions and all relationships arising from them are governed by the legal order of the Czech Republic, in particular Act No. 89/2012 Coll., the Civil Code, as amended.
12.2 All disputes arising in connection with these Terms and Conditions shall be decided by the competent courts of the Czech Republic. The locally competent court for resolving disputes shall be the court competent for the registered office of the Provider.
12.3 If the User considers itself to be a consumer, the User has the right to contact the Czech Trade Inspection Authority or the competent court. However, the Service is intended primarily for entrepreneurs, schools, organizations and professional operators of activities, not for personal consumer use.
Article 13 – Final Provisions
13.1 If any provision of these Terms and Conditions proves to be invalid or unenforceable, this shall not affect the validity of the remaining provisions. The invalid provision shall be replaced by a valid provision that most closely corresponds to the meaning and purpose of the original provision.
13.2 These Terms and Conditions, together with Annex No. 1, constitute the entire agreement between the Provider and the User concerning the subject matter of the Agreement, unless otherwise agreed between the parties.
13.3 These Terms and Conditions are executed in the Czech language.
13.4 Communication between the parties takes place primarily electronically. A notice sent to the e-mail address of the other party provided during registration or in these Terms and Conditions shall be deemed duly delivered.
13.5 These General Terms and Conditions take effect on 1 April 2026.
ANNEX NO. 1 TO THE TERMS AND CONDITIONS
Personal Data Processing Agreement
pursuant to Article 28 of the GDPR Regulation
This Personal Data Processing Agreement (hereinafter the “DPA Agreement”) forms an integral part of the Terms and Conditions and is concluded at the moment the User accepts the Terms and Conditions.
Controller: The User, meaning the School or another entity identified by the registration data in the Service.
Processor: Wootera Digital Technologies, s.r.o., Company ID No.: 19160526, with its registered office at Oldřichova 255/20, Nusle, 128 00 Prague 2.
DPA Article 1 – Subject Matter and Purpose of Processing
1.1 The Processor processes personal data on behalf of and on the instructions of the Controller for the purpose of operating the Zonno Dance Service, in particular for the purpose of technically ensuring the management of a dance school, user accounts, students, instructors, lessons, schedules, workshops, attendance, communication, reports, statistics and financial overviews.
1.2 Processing takes place for the duration of the Agreement pursuant to the Terms and Conditions.
1.3 The Controller determines the purpose and means of processing personal data of persons recorded in the Service, in particular Students, Instructors, employees, administrators and other persons. The Processor processes personal data only to the extent necessary for providing the Service and in accordance with the Controller’s instructions.
1.4 The Processor is not responsible for whether the Controller has a valid legal basis for entering and processing personal data in the Service. The Controller is responsible for fulfilling information obligations towards data subjects.
DPA Article 2 – Categories of Personal Data and Data Subjects
2.1 Within the Zonno Dance Service, in particular the following categories of personal data may be processed:
| Data Subject | Categories of Data | Purpose |
|---|---|---|
| School Administrators | first name, surname, e-mail, telephone, role, login details, activity logs | management of the School account, security, audit |
| Instructors | first name, surname, e-mail, telephone, photograph, role, schedule, assigned lessons, attendance, activity in the system | management of instructors, lesson planning, communication |
| Students | first name, surname, date of birth, e-mail, telephone, photograph, gender, attendance, assignment to courses, lessons and groups, payment and financial records maintained by the School | student records, organization of teaching, communication, operation of the School |
| Legal representatives of minor students | first name, surname, e-mail, telephone, relationship to the Student | communication, management of participation of minors, operational agenda of the School |
| Other persons recorded by the Controller | identification and contact data according to the Controller’s settings | operational purposes of the Controller |
2.2 The Service may further process technical data, in particular IP address, device identifiers, device type, operating system, application version, login time, activity logs, security records and data necessary for the delivery of e-mails and push notifications.
2.3 The Service is not intended for the processing of special categories of personal data under Article 9 GDPR, in particular data concerning health, religion, political opinions, biometric data for the purpose of uniquely identifying a person or other sensitive data, unless expressly agreed otherwise between the parties and all legal conditions are met.
2.4 If the Controller enters special categories of personal data or other sensitive data into the Service without prior agreement with the Processor, the Controller does so at its own responsibility.
2.5 The Service may also be used to keep records of persons under 18 years of age. The Controller is responsible for ensuring that the processing of personal data of minors is carried out in accordance with legal regulations, including any consent of a legal representative, if required.
DPA Article 3 – Obligations of the Processor
3.1 The Processor undertakes to:
a) process personal data exclusively on the basis of documented instructions from the Controller and in accordance with this DPA Agreement,
b) ensure that persons authorized to process personal data are bound by an obligation of confidentiality,
c) adopt appropriate technical and organizational security measures pursuant to Article 32 GDPR,
d) inform the Controller without undue delay of any personal data breach that becomes known to the Processor,
e) assist the Controller in fulfilling its obligations pursuant to Articles 32 to 36 GDPR to the extent reasonably available to the Processor,
f) assist the Controller in handling requests from data subjects, where technically possible and reasonable,
g) at the end of the contractual relationship, delete or return personal data according to the Controller’s choice, unless legal regulations require their further retention,
h) keep reasonable documentation of processing to the extent required by GDPR.
3.2 The Processor is not obliged to assess the legality of the Controller’s instructions, unless their unlawfulness is obvious.
3.3 If the Processor believes that a particular instruction of the Controller violates GDPR or other legal regulations, the Processor shall notify the Controller thereof.
DPA Article 4 – Obligations of the Controller
4.1 The Controller undertakes to:
a) process personal data in the Service only in accordance with legal regulations,
b) have a valid legal basis for processing personal data of Students, Instructors, administrators, legal representatives and other persons,
c) fulfill the information obligation towards data subjects,
d) ensure the accuracy and up-to-dateness of personal data entered into the Service,
e) set access permissions only for persons who need the personal data for the performance of their activities,
f) ensure that data which is not necessary for the purpose of using the Service is not entered into the Service,
g) inform the Processor of specific requirements or risks that may affect the security or legality of processing.
4.2 The Controller is responsible for the legal relationship with Students, Instructors, legal representatives of minors and other persons recorded in the Service.
4.3 The Controller is responsible for ensuring that the use of e-mails, push notifications and other communication through the Service is in compliance with legal regulations.
DPA Article 5 – Sub-processors
5.1 The Controller hereby grants the Processor general prior authorization to use sub-processors necessary for the operation of the Service, in particular providers of cloud, hosting, database, e-mail, notification, analytical, payment and security services.
5.2 The current list of sub-processors is available upon request at zonno@wootera.com.
5.3 The Processor shall inform the Controller of planned changes to sub-processors at least 14 days in advance, whereby the Controller shall have the right to raise a justified objection.
5.4 If the Controller raises an objection against the engagement of a specific sub-processor and it is not possible to properly provide the Service without that sub-processor, the Provider is entitled to terminate the Agreement.
5.5 The Processor enters into agreements with sub-processors that impose on them personal data protection obligations corresponding to the obligations set out in this DPA Agreement.
DPA Article 6 – Rights of Data Subjects
6.1 The Processor assists the Controller in ensuring the fulfillment of requests from data subjects concerning the exercise of their rights under GDPR, in particular the right of access, rectification, erasure, restriction of processing, data portability and objection, to the extent technically available to the Processor.
6.2 The Controller is primarily responsible for handling requests from data subjects.
6.3 If a data subject contacts the Processor directly with a request concerning data processed on behalf of the Controller, the Processor shall generally refer the data subject to the Controller or, where applicable, forward the request to the Controller if the Controller is identifiable.
6.4 Requests concerning processing may be sent to the Processor at: zonno@wootera.com.
DPA Article 7 – Security of Processing
7.1 The Processor adopts reasonable technical and organizational measures to protect personal data, in particular measures aimed at protecting the confidentiality, integrity, availability and resilience of systems.
7.2 These measures may include in particular:
a) management of access permissions,
b) user authentication,
c) encryption or other appropriate security of data transmission,
d) backups,
e) logging of selected activities,
f) separation of data of individual Users,
g) updates and security maintenance of systems,
h) internal rules for access to personal data,
i) protection against unauthorized access, loss, destruction or damage to data.
7.3 The Controller acknowledges that the overall security of processing also depends on measures on the Controller’s side, in particular the management of passwords, access permissions, devices, internal processes and training of persons who use the Service.
DPA Article 8 – Transfers of Data to Third Countries
8.1 The Processor does not transfer personal data to third countries outside the European Economic Area without appropriate safeguards pursuant to Chapter V of GDPR, unless such transfer is necessitated by the use of a specific sub-processor or third-party service.
8.2 If personal data is transferred to a third country, the Processor shall ensure that such transfer is carried out on the basis of an appropriate legal mechanism, in particular an adequacy decision, standard contractual clauses or another suitable instrument under GDPR.
8.3 The Controller acknowledges that certain third-party services, in particular analytical, cloud, notification or distribution services, may involve processing outside the European Economic Area.
DPA Article 9 – Audits and Inspections
9.1 The Processor shall provide the Controller with information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, to a reasonable extent.
9.2 The Controller is entitled to carry out an audit or inspection of personal data processing if the Controller requests this with reasonable advance notice, the audit does not unreasonably disrupt the Processor’s operations and security and confidentiality conditions are maintained.
9.3 Audits and inspections are carried out at the Controller’s expense, unless legal regulations provide otherwise.
9.4 Instead of a physical audit, the Processor may provide reasonable documentation, a security description, an affidavit, certification or another similar document if this is sufficient to demonstrate compliance.
DPA Article 10 – Termination of Processing
10.1 After termination of the Agreement, the Processor shall delete or return the personal data to the Controller according to the Controller’s choice, unless legal regulations require further retention.
10.2 If the Controller does not request the export or return of data within 30 days from termination of the Agreement, the Processor is entitled to delete the data in accordance with its technical and retention processes.
10.3 Backup copies may be retained for a limited period within the Processor’s standard backup cycle, provided that they are not routinely accessed and are protected by appropriate security measures.
DPA Article 11 – Final Provisions of the DPA
11.1 This DPA Agreement is governed by the legal order of the Czech Republic.
11.2 In the event of a conflict between this DPA Agreement and the main text of the Terms and Conditions, this DPA Agreement shall prevail in matters of personal data processing.
11.3 This DPA Agreement takes effect at the moment the Agreement between the Provider and the User is formed.
These General Terms and Conditions take effect on 1 April 2026.