ChemReady

Data processing agreement (DPA) — template

Last updated: 10 August 2026

Working document — requires legal review before it is used with a customer.

This template was prepared from the actual state of the service (the subprocessor list matches reality and is consistent with the Privacy policy). It is not legal advice and has not been reviewed by a lawyer. We publish it so that a customer can see on what terms processing can be entrusted, and assess it before purchase.

A signable version is available on request: contact@chemready.eu.

Document version: en-2026-08-10. The Polish version at chemready.eu/pl/dpa/ is the source text; this English version is kept in semantic parity with it. The data processing agreement is concluded separately (see "How to conclude it") — it is not part of the acceptance taken at subscription purchase.

1. Parties and subject matter

Controller — the customer (the Company) using ChemReady.
Processor — LMW Jacek Kubas, ul. Rodzynkowa 30, 92-709 Łódź, Poland, VAT PL7272587939.

The Controller entrusts the Processor with processing personal data to the extent necessary to provide the ChemReady service, on the basis of Article 28 GDPR.

2. Scope, nature and purpose

ElementAgreed
Purposeproviding the ChemReady service: running the account, preparing and storing compliance documentation and making it available to the Controller. The notification to ECHA is filed by the Controller from the Controller's own ECHA account — the Processor does not act before ECHA on the Controller's behalf
Naturestorage, organisation, disclosure on instruction, erasure
Categories of data subjectsusers of the Controller's account; persons named as a contact in a notification (e.g. emergency contact)
Categories of dataname, business e-mail address, business telephone number, position/role in the account
Special categoriesnot entrusted; the Controller undertakes not to enter them
Durationthe term of the service agreement

3. Obligations of the Processor

  1. Processes data only on the documented instruction of the Controller — the instruction being the use of the service's functions and the content of the Terms of Service.
  2. Ensures that persons authorised to process data are bound by confidentiality.
  3. Applies the technical and organisational measures described in section 6.
  4. Does not engage a subprocessor without the Controller's general authorisation (section 4); notifies changes in advance, allowing objection.
  5. Assists the Controller in handling data subject requests and in the obligations under Articles 32–36 GDPR — to the extent appropriate to the nature of the processing and the information available.
  6. On termination of the service, erases the data or returns it to the Controller — at the Controller's choice — except data whose retention is required by law (e.g. accounting records).
  7. Makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows audits on the terms in section 7.
  8. Notifies the Controller of a personal data breach without undue delay and no later than within 24 hours of becoming aware of it.

4. Subprocessors

The Controller gives general authorisation for the following subprocessors:

SubprocessorRoleLocation
Hetzner Online GmbHapplication and database hostingGermany (EEA)
Cloudflare, Inc.CDN, attack protection, website hostingUSA / global network — standard contractual clauses
Stripe Payments Europe, Ltd.payments and invoicingIreland (EEA)
SeoHost.pl (Netster sp. z o.o.)outgoing mail serverPoland (EEA)
OpenAIreading the safety data sheet; independent re-extraction during validationregion still being established — see section 5
Anthropicindependent re-extraction during validation; product name suggestionsregion still being established — see section 5
Googleindependent re-extraction during validationregion still being established — see section 5

The list is current as at the date shown at the top of this page. The Processor gives 30 days' notice of an intention to add or change a subprocessor. The Controller may raise a reasoned objection; failing agreement, either party may terminate the service agreement.

ECHA is not a subprocessor. Data reaches ECHA on the Controller's express instruction (triggering a submission from the Controller's own ECHA account) and constitutes a separate disclosure of data, not entrustment.

5. Transfers outside the EEA

As regards infrastructure, transfer outside the EEA concerns Cloudflare, Inc. and relies on the European Commission's standard contractual clauses together with the provider's supplementary measures.

The large language model providers (OpenAI, Anthropic, Google) process the content of the safety data sheet and the product data supplied by the Controller. The processing region and retention terms on the side of those providers are still being established — until those points are settled, it should be assumed that processing may take place outside the EEA. We do not state a transfer basis here that we have not confirmed with the provider; once settled, we will complete this section together with the update date.

6. Security measures

7. Audit

Once per calendar year the Controller may request information confirming compliance with the obligations under Article 28 GDPR. An on-site audit requires a date agreed 30 days in advance, takes place during business hours and must not disrupt service continuity. The Controller bears the cost of the audit, unless the audit reveals a material breach.

8. Liability and duration

This agreement applies for the term of the ChemReady service and expires with it. Liability of the parties is governed by the GDPR and by the Terms of Service.

9. How to conclude it

Write to contact@chemready.eu with your company details — we will send back a version for electronic signature.