1. Agreement and roles of the parties
This Data Processing Agreement forms part of the Terms and Conditions and applies whenever the customer, as a controller or processor, uses Kruspin to process another person's personal data. By accepting the Terms and Conditions, the customer enters into this Agreement with Necktip s.r.o.
For data that the customer enters into a workspace or event about its clients, guests, suppliers, team members and other participants, the customer is typically the controller and Necktip s.r.o., the company operating Kruspin, is the processor. If the customer is itself a processor for its client, it confirms that it is authorised to engage Kruspin as a subprocessor.
Necktip s.r.o. may be an independent controller for data needed for its own account administration, sign-in, billing, security, abuse prevention, legal communications and its own operational monitoring. To the extent that monitoring or session recording processes customer data solely to provide, secure or support the service under the customer's instructions, this Agreement applies. A masked recording may still contain personal data.
2. Subject matter, duration, nature and purpose
The subject matter is the processing of personal data necessary to operate workspaces, events, RSVPs, guest websites, accommodation, seating plans, timelines, tasks, files, suppliers, working financial overviews, communications, client-facing and operational outputs, and support.
Processing continues for the duration of the customer account or agreed service and for the period necessary to return or delete the data. The nature of the processing includes storage, structuring, retrieval, display, transmission, backup, export, correction, restriction and deletion in accordance with the service features and the customer's instructions.
The purpose is to provide and secure the selected Kruspin function and carry out the customer's documented instruction. Identifiable Customer Content is not used to train models or create reusable evaluation datasets. Any future voluntary data-contribution programme would be separate, off by default and require its own terms and legal basis. The operator may use genuinely anonymised and aggregated information under the Terms and Conditions.
3. Data subjects and categories of data
4. Customer instructions and obligations
- The customer is responsible for the lawfulness of its instructions, the legal basis, obligations to provide information, data accuracy and the authorisation of people it invites to the service.
- Feature settings, imports, publication, sharing, export, deletion and a request submitted by an authorised person of the customer are documented instructions within the scope of this Agreement and the Terms.
- The customer must minimise allergies, health and accessibility needs, data about children, family notes and other sensitive data and enter it only where necessary for a specific purpose.
- The customer must configure roles, permissions, public pages, RSVP links and exports so that data is visible only to the intended recipients.
- The customer must not instruct the operator to carry out unlawful processing. If the operator reasonably considers an instruction to infringe data protection law, it will inform the customer and may suspend the instruction until the matter is clarified.
- If the customer processes data on behalf of another controller, it must obtain the necessary authorisation to engage Kruspin and pass on any stricter instructions that apply to the processing.
5. Operator obligations as processor
- Process personal data only in accordance with this Agreement, the service settings and the customer's other documented instructions, unless processing is required by EU or Member State law; in that case, inform the customer in advance unless the law prohibits this.
- Ensure that people authorised to process the data are bound by confidentiality and have access only to the extent required by their role.
- Adopt and maintain the appropriate technical and organisational measures set out below and adapt them to the risk, the state of the art and the nature of the service.
- Engage subprocessors only in accordance with this Agreement and impose substantially the same personal data protection obligations on them.
- Taking into account the nature of the processing, reasonably assist the customer with data-subject requests, security, incidents, data protection impact assessments and consultation with a supervisory authority.
- At the end of the service, return or delete all customer personal data and existing copies at the customer's choice unless continued retention is required by EU or Czech law.
- Provide the information needed to demonstrate compliance with Article 28 GDPR and permit a reasonable audit subject to the terms below.
- Inform the customer without undue delay if the operator becomes aware of a personal data breach affecting data processed on the customer's behalf.
6. Subprocessors and external services
The customer grants general written authorisation to engage the subprocessors listed below for the purposes described. Depending on the specific function, some services also act as independent controllers; their own terms are presented when the service is used or on the hosted page.
The operator will give at least 15 days' notice through the account or by email of an intended addition or replacement of a subprocessor that will materially process customer personal data, unless an urgent security or legal need requires a shorter period. The customer may raise a reasoned data-protection objection within 10 days. If the objection cannot reasonably be resolved, the parties may disable the affected optional feature or stop using it.
The operator will impose substantially the same data protection obligations on each subprocessor and remains responsible to the customer for the subprocessor's performance of its obligations to the extent required by GDPR.
7. International data transfers
The operator selects a European region or European endpoints where available. Some providers may nevertheless use global infrastructure or permit support access from outside the EU/EEA.
If personal data is transferred to a country without an adequacy decision, the operator will use an applicable mechanism under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses, and supplementary measures according to the risk. Information about the current mechanism for a specific provider will be supplied to the customer on request.
The customer instructs transfers to the extent necessary for the feature it has enabled and the approved providers listed above. This does not restrict the customer's right to object to a new subprocessor.
8. Technical and organisational measures
- Sign-in using a verified email address and short-lived one-time codes, secure HTTP-only sessions and server-side identity checks.
- Roles, memberships, permissions and separate outputs for client and public views that restrict access by workspace, event and output purpose.
- Encrypted transmission using HTTPS/TLS; encryption of stored data according to the capabilities and configuration of the database and object-storage providers; encrypted storage of selected integration tokens.
- Separation of production and development environments, server secrets kept out of the client, restricted support and administrator access, and auditing of security-significant actions.
- Input validation, same-origin protection, request rate limiting, short-lived tokens, session revocation and protection against common web application abuse.
- Minimisation of logs, analytics, monitoring and support artefacts; masking of text, inputs and attributes in session recordings and exclusion of console data, request headers and bodies, heatmaps and cross-origin iframes. The recording may nevertheless remain identifiable personal data.
- Backup and recovery procedures appropriate to the infrastructure provided, controlled database changes and restrictions on destructive production operations.
- A process to classify, contain, remediate and document security incidents and inform affected customers.
- Regular reassessment of the measures according to the nature of the data, the state of the art, costs and risk. No system can guarantee absolute security.
9. Data-subject rights, incidents and assistance
If the operator receives a request from an individual concerning customer personal data, it will not respond substantively without the customer's instructions unless required by law. It will forward the request to the customer or help identify the relevant controller and, where possible, provide the tools or information needed to respond.
In the event of a personal data breach, the operator will inform the customer without undue delay after becoming aware of it. Based on the information available, it will describe the nature of the incident, the categories affected, the likely consequences, the measures taken or proposed, and a contact for further assistance. The notice itself is not an admission of liability.
Taking into account the nature of the processing and the information available to it, the operator will reasonably assist with data protection impact assessments, prior consultations, security, notification duties and demonstrating compliance. Exceptional assistance beyond the ordinary scope of the service may be charged for unless the need was caused by the operator's breach of this Agreement.
10. Return, deletion, audit and order of precedence
At the end of the service, the operator will, at the customer's choice, return customer personal data in a reasonably available format or delete it unless continued retention is required by law. Export and deletion are currently handled through support; complete self-service export and account deletion are not available for all accounts.
After deletion from operational systems, copies may remain only in isolated technical backups for the time needed to complete a documented deletion cycle, no longer than 180 days, or where retention is required by EU or Czech law. During that period they are not used for ordinary operations; the Operator deletes them when the applicable period ends. Monitoring data processed on the customer's behalf is subject to the same rule; data for which Necktip s.r.o. is an independent controller is governed by the Privacy Notice.
The customer may request information reasonably necessary to verify this Agreement no more than once a year and also after a serious incident. If the materials are insufficient, the customer may, on at least 30 days' notice, conduct an audit itself or through an independent professional bound by confidentiality, during business hours and without access to other customers' data. This notice period does not apply where a shorter procedure is necessary because of an urgent incident or a supervisory authority's request. The customer bears the reasonable costs of the audit unless it demonstrates a material breach by the operator.
If documents conflict, this Agreement prevails for the processing of personal data on behalf of the customer; the Terms and Conditions prevail on other matters. A stricter individual written agreement prevails to the extent that it expressly varies this Agreement.
Questions, instructions, objections to a new subprocessor and requests for assistance should be sent to [email protected].