Data processing agreement (DPA) — template
Last updated: 10 August 2026
Working document — requires legal review before it is used with a customer.
This template was prepared from the actual state of the service (the subprocessor list matches reality and is consistent with the Privacy policy). It is not legal advice and has not been reviewed by a lawyer. We publish it so that a customer can see on what terms processing can be entrusted, and assess it before purchase.
A signable version is available on request: contact@chemready.eu.
Document version: en-2026-08-10. The Polish version at chemready.eu/pl/dpa/ is the source text; this English version is kept in semantic parity with it. The data processing agreement is concluded separately (see "How to conclude it") — it is not part of the acceptance taken at subscription purchase.
1. Parties and subject matter
Controller — the customer (the Company) using ChemReady.
Processor — LMW Jacek Kubas, ul. Rodzynkowa 30, 92-709 Łódź, Poland, VAT PL7272587939.
The Controller entrusts the Processor with processing personal data to the extent necessary to provide the ChemReady service, on the basis of Article 28 GDPR.
2. Scope, nature and purpose
| Element | Agreed |
|---|---|
| Purpose | providing the ChemReady service: running the account, preparing and storing compliance documentation and making it available to the Controller. The notification to ECHA is filed by the Controller from the Controller's own ECHA account — the Processor does not act before ECHA on the Controller's behalf |
| Nature | storage, organisation, disclosure on instruction, erasure |
| Categories of data subjects | users of the Controller's account; persons named as a contact in a notification (e.g. emergency contact) |
| Categories of data | name, business e-mail address, business telephone number, position/role in the account |
| Special categories | not entrusted; the Controller undertakes not to enter them |
| Duration | the term of the service agreement |
3. Obligations of the Processor
- Processes data only on the documented instruction of the Controller — the instruction being the use of the service's functions and the content of the Terms of Service.
- Ensures that persons authorised to process data are bound by confidentiality.
- Applies the technical and organisational measures described in section 6.
- Does not engage a subprocessor without the Controller's general authorisation (section 4); notifies changes in advance, allowing objection.
- Assists the Controller in handling data subject requests and in the obligations under Articles 32–36 GDPR — to the extent appropriate to the nature of the processing and the information available.
- On termination of the service, erases the data or returns it to the Controller — at the Controller's choice — except data whose retention is required by law (e.g. accounting records).
- Makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows audits on the terms in section 7.
- Notifies the Controller of a personal data breach without undue delay and no later than within 24 hours of becoming aware of it.
4. Subprocessors
The Controller gives general authorisation for the following subprocessors:
| Subprocessor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | application and database hosting | Germany (EEA) |
| Cloudflare, Inc. | CDN, attack protection, website hosting | USA / global network — standard contractual clauses |
| Stripe Payments Europe, Ltd. | payments and invoicing | Ireland (EEA) |
| SeoHost.pl (Netster sp. z o.o.) | outgoing mail server | Poland (EEA) |
| OpenAI | reading the safety data sheet; independent re-extraction during validation | region still being established — see section 5 |
| Anthropic | independent re-extraction during validation; product name suggestions | region still being established — see section 5 |
| independent re-extraction during validation | region still being established — see section 5 |
The list is current as at the date shown at the top of this page. The Processor gives 30 days' notice of an intention to add or change a subprocessor. The Controller may raise a reasoned objection; failing agreement, either party may terminate the service agreement.
ECHA is not a subprocessor. Data reaches ECHA on the Controller's express instruction (triggering a submission from the Controller's own ECHA account) and constitutes a separate disclosure of data, not entrustment.
5. Transfers outside the EEA
As regards infrastructure, transfer outside the EEA concerns Cloudflare, Inc. and relies on the European Commission's standard contractual clauses together with the provider's supplementary measures.
The large language model providers (OpenAI, Anthropic, Google) process the content of the safety data sheet and the product data supplied by the Controller. The processing region and retention terms on the side of those providers are still being established — until those points are settled, it should be assumed that processing may take place outside the EEA. We do not state a transfer basis here that we have not confirmed with the provider; once settled, we will complete this section together with the update date.
6. Security measures
- transport encryption (TLS) for all traffic to the application;
- encryption of the customer's ECHA access keys in the database (Fernet) — the key is never returned in the interface and never written to logs;
- passwords stored only as hashes (bcrypt);
- separation of customer data at database level (tenant identifier + access policies) together with application-side control;
- session authentication via an httpOnly cookie, optional two-factor (TOTP);
- an audit log of administrative events;
- a daily verified backup of the database and documents, with checksum control;
- access to the production environment limited to the service administrator.
7. Audit
Once per calendar year the Controller may request information confirming compliance with the obligations under Article 28 GDPR. An on-site audit requires a date agreed 30 days in advance, takes place during business hours and must not disrupt service continuity. The Controller bears the cost of the audit, unless the audit reveals a material breach.
8. Liability and duration
This agreement applies for the term of the ChemReady service and expires with it. Liability of the parties is governed by the GDPR and by the Terms of Service.
9. How to conclude it
Write to contact@chemready.eu with your company details — we will send back a version for electronic signature.