Data Processing Agreement (DPA)
under Art. 28 of Regulation (EU) 2016/679 (GDPR) and § 34 of Act No. 18/2018 Coll.
Version: 1.0 · Effective date: 21 June 2026
This agreement forms an integral part of the Terms of Service for the Resio Service and is concluded between:
- Controller: the Customer (the Resio service customer) who enters personal data into the Service. Identification according to the Customer's account data.
- Processor: VisionEdge s. r. o., 29. augusta 1503/1A, 958 01 Partizánske, Company ID (IČO): 51962161, registered in the Commercial Register of the District Court Trenčín, Section Sro, Insert No. 37109/R (the "Processor").
1. Subject matter and duration
1.1 The Processor processes personal data on behalf of the Controller solely for the purpose of providing the Resio service under the Terms, in particular for the purpose of validating the uploaded template, generating the package in the xBRL-CSV format and storing the living register.
1.2 Processing lasts for the duration of the agreement on provision of the Service. After its termination, Art. 7 applies. In account-free use, processing is transient and limited to the time necessary to perform validation and generate the package.
2. Nature and purpose of processing
2.1 Nature: collection, storage, structuring, display, modification, validation, generation of outputs, transfer (among processors), backup and deletion of personal data carried out by automated means within the Service.
2.2 Purpose: preparation and validation of the register of information under DORA and its generation into the xBRL-CSV format for the Controller.
2.3 Categories of data subjects and data: see Annex 1.
3. Controller's instructions
3.1 The Processor processes personal data only on the basis of the Controller's documented instructions. The use of the Service by the Controller and these Terms/DPA are also deemed instructions.
3.2 If the Processor is required to process data under EU or Slovak law, it informs the Controller, unless the law prohibits this.
3.3 If the Processor considers that an instruction infringes the GDPR or other regulations, it notifies the Controller without delay.
4. Processor's obligations
4.1 Confidentiality: The Processor ensures that persons authorised to process the data are bound by confidentiality.
4.2 Security (Art. 32 GDPR): The Processor implements appropriate technical and organisational measures under Annex 3.
4.3 Assistance to the Controller: The Processor assists the Controller, to a reasonable extent, in fulfilling its obligations to respond to data subject requests (Art. 12 to 23 GDPR) and in fulfilling its obligations under Art. 32 to 36 GDPR (security, breach notification, impact assessment).
4.4 Personal data breach: The Processor notifies the Controller of any personal data breach without delay, and no later than within 48 hours of becoming aware of it, and provides cooperation in addressing it.
4.5 Audit: The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for an audit or inspection to a reasonable extent and by prior arrangement, while maintaining the confidentiality and security of other customers.
5. Sub-processors
5.1 The Controller grants the Processor general authorisation to engage the sub-processors listed in Annex 2.
5.2 The Processor imposes on sub-processors data protection obligations equivalent to those it has under this DPA.
5.3 The Processor informs the Controller in advance of any intended change to the list of sub-processors and allows the Controller to object.
6. Transfers to third countries
6.1 Transfers to countries outside the EEA take place only where appropriate safeguards under the GDPR exist, in particular on the basis of the standard contractual clauses (SCC) adopted by the European Commission. Current sub-processors and their locations are listed in Annex 2.
7. Deletion or return of data
7.1 Upon termination of the provision of the Service, the Processor, at the Controller's choice, returns or deletes the personal data and existing copies, unless EU or Slovak law requires further retention. The period and procedure are aligned with the Terms (Art. 11.5): export is available for 30 days after termination. In account-free use, transiently processed data is deleted after processing ends.
8. Liability and final provisions
8.1 The liability of the parties is governed by the GDPR and the Terms. In the event of a conflict on matters of personal data processing, this DPA prevails over the Terms.
8.2 This DPA is governed by the law of the Slovak Republic.
Annex 1: Categories of data subjects and personal data
Categories of data subjects:
- contact persons and representatives of ICT service providers and other third parties listed in the register of information,
- ICT service providers who are natural persons (e.g. self-employed persons),
- users to whom the Controller has granted access,
- other persons whose data the Controller enters into the Service.
Categories of personal data:
- identification and contact data (name, email, telephone, role),
- business and identification data of natural persons — entrepreneurs (business name, address, identifiers),
- data contained in the register of information, in the uploaded template, in generated packages and in communications,
- operational data (logs, identifiers).
Special categories of data (Art. 9 GDPR) are not to be entered into the Service.
Annex 2: List of sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | hosting of server infrastructure | EU | within the EEA |
| Clerk, Inc. | authentication and user identity management | USA | standard contractual clauses (SCC) |
| Resend, Inc. | sending transactional emails | USA | standard contractual clauses (SCC) |
The storage of documents and packages (MinIO) is operated within our own infrastructure on Hetzner servers in the EU.
Annex 3: Technical and organisational measures (Art. 32 GDPR)
- Transmission encryption: all communication via HTTPS/TLS; security HTTP headers (HSTS and others).
- Data isolation: logical isolation of individual customers' data; operational roles without permissions to bypass isolation.
- Transient processing: in account-free use, content is processed transiently and is not stored in a persistent register.
- Access management: authentication managed by an identity provider, role and permission management, employee access only to the extent necessary.
- Backup and recovery: regular encrypted backups of stored data with a defined retention; tested recovery.
- Availability and monitoring: operational monitoring and access logging.
- Change management: a controlled process for deploying changes and updates.
The measures are reviewed and updated on an ongoing basis according to the state of the art.