Data processing agreement
Last updated 2026-10-06
This agreement applies where you use Pairanha to process personal data, and satisfies Article 28 of the GDPR. It forms part of our terms of service and takes effect automatically when you create an account, so there is nothing to sign before you can start.
If your procurement process needs a countersigned copy, email [email protected] and we will provide one.
1. Roles
You are the controller of the personal data you put into the service. We are the processor, and process it only on your documented instructions. Using the service is such an instruction.
2. Subject matter and duration
We process personal data for as long as you have an account, plus any retention period required by law. On termination we delete it as set out in clause 8.
3. Nature and purpose
Hosting, storage, transmission and display of the data you enter, so that we can provide the service described in our terms.
4. Categories of data and data subjects
Whatever you choose to enter. Typically the contact details of your own users and customers, and the business records you create in the product. Data subjects are typically your staff and your customers.
Do not put special category data (health, biometrics, political or religious views, and the rest of Article 9) into the service. It is not designed for it and we have not assessed it for it.
5. Our obligations
- We process personal data only on your instructions.
- Everybody we allow to access it is bound by a duty of confidentiality.
- We implement appropriate technical and organisational measures, described in clause 9.
- We assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with a supervisory authority.
- We notify you without undue delay after becoming aware of a personal data breach.
- We make available the information needed to demonstrate compliance with this clause.
6. Subprocessors
You give general authorisation for us to engage subprocessors. The current list is published at subprocessors. We will give at least 30 days notice by email before adding or replacing one, and you may object on reasonable data protection grounds, in which case you may terminate without penalty.
Each subprocessor is bound by terms no less protective than these.
7. International transfers
Data is stored in the EU. Where a subprocessor processes it outside the EEA, the transfer relies on the European Commission's standard contractual clauses, together with any supplementary measures required.
8. Deletion and return
You can export everything at any time from your settings page. On termination we delete the workspace and its contents, except where we are required by law to retain a record, principally billing records for tax purposes.
9. Security measures
- Encryption in transit for all traffic.
- Passwords stored only as scrypt hashes, never recoverable.
- Strict tenant isolation, enforced in the application and at the database query layer.
- Role-based access inside a workspace.
- An audit log of significant actions, visible to you.
- Rate limiting and abuse detection on authentication endpoints.
- Personal data scrubbed from diagnostic logs before they are stored.
- Managed, backed-up database hosting inside the EU.
- Access to production limited to the people who need it.
10. Audits
On reasonable written notice, and no more than once a year unless a supervisory authority requires otherwise, we will answer a reasonable security questionnaire or provide available third-party reports.
11. Contact
VICTUM GROUP, s. r. o., Stropkovská 3, 821 03 Bratislava, Slovakia. Privacy contact: [email protected].