Data Processing Addendum
8.1 Purpose
This Data Processing Addendum applies where Efiko.pro processes personal data on behalf of a user, business, professional, customer, or tenant in connection with the platform.
8.2 Roles of the Parties
Depending on the context:
-
The user may act as a controller of visitor, customer, appointment, or profile data.
-
Efiko.pro may act as a processor when processing such data on the user’s behalf.
-
Efiko.pro may act as an independent controller for account, billing, security, compliance, and platform administration data.
For GDPR-covered processing, Article 28 requires processor arrangements to be governed by a contract or other legal act setting out matters such as subject matter, duration, purpose, data types, categories of data subjects, and obligations of the controller.
8.3 Subject Matter of Processing
Processing relates to the provision of Efiko.pro services, including professional profiles, tenant websites, CVs, vCards, QR codes, bookings, customer panels, analytics, domains, and dashboards.
8.4 Duration of Processing
Processing continues for the duration of the user’s account, subscription, or service relationship, and for any required retention period after termination.
8.5 Nature and Purpose of Processing
Efiko.pro may collect, store, host, transmit, display, secure, analyse, back up, delete, or otherwise process data to provide the platform.
8.6 Categories of Data Subjects
Data subjects may include:
-
Users.
-
Visitors.
-
Customers.
-
Appointment requesters.
-
Subscribers.
-
Support contacts.
-
Professional referees.
-
Credential subjects.
-
Billing contacts.
8.7 Types of Personal Data
Personal data may include:
-
Names.
-
Email addresses.
-
Phone numbers.
-
Profile photos.
-
Biographies.
-
Professional history.
-
Credentials.
-
CV details.
-
Booking information.
-
Customer records.
-
IP addresses.
-
Technical logs.
-
Payment-related records.
-
Communication records.
8.8 Efiko.pro Obligations
Efiko.pro will:
-
Process personal data only for platform purposes or documented instructions.
-
Apply reasonable security measures.
-
Limit access to authorised personnel.
-
Assist with data subject requests where reasonably possible.
-
Notify users of relevant data incidents where required.
-
Use subprocessors where necessary to deliver the platform.
-
Maintain reasonable confidentiality obligations.
-
Delete, return, or anonymise data where required and technically feasible.
8.9 User Obligations
Users must:
-
Have lawful grounds to collect and process visitor/customer data.
-
Provide appropriate privacy notices.
-
Obtain consent where required.
-
Avoid uploading unlawful or excessive personal data.
-
Keep account access secure.
-
Respond to visitor/customer privacy requests where applicable.
-
Comply with relevant privacy and data protection laws.
8.10 Subprocessors
Efiko.pro may use subprocessors such as hosting providers, email providers, payment processors, analytics services, security tools, support platforms, and plugin providers.
8.11 Security
Efiko.pro will maintain reasonable technical and organisational measures appropriate to the platform’s nature, risk, and scale.