Mivare Sites data processing agreement
The complete document in a clear HTML format — the same text as in the PDF.
1. Parties and conclusion of the agreement
The controller is the Customer of the Mivare Sites service — the entrepreneur who has registered a Company Account, hereinafter the “Controller”.
The processor is MIVARE GROUP PROSTA SPÓŁKA AKCYJNA, with its registered office in Krasnobród, KRS 0001268091, NIP 9223092251, REGON 545767254, operating under the Mivare Sites brand, hereinafter the “Processor” or “Mivare”.
This data processing agreement, hereinafter the “DPA”, is an agreement within the meaning of Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR). It is concluded in electronic form upon acceptance of the Mivare Sites Terms of Service (MWS-LEG-001) at registration of the Company Account and remains in force for the term of the Contract and until completion of the activities described in section 12.
Capitalised terms have the meanings given to them in the Terms of Service. In matters of personal data protection, the DPA takes precedence over the Terms of Service.
2. Subject matter, nature and purpose of processing
The Controller entrusts the Processor with the processing of personal data entered into the Application by the Controller, the Users and the Controller's clients using the public functions of the Application, solely for the purpose of providing the Mivare Sites service.
Processing comprises the operations necessary to provide the service: storage, organisation, structuring, retrieval, consultation, alteration and erasure of data on the Controller's instructions, displaying the data to Users, generating documents and summaries, recording the device's position when attendance is registered, sending e-mail messages to the Controller's clients triggered by Users or by the Application settings, operating the public functions of the Application, making backups, and access within technical support and the remedying of failures.
The Processor does not process the entrusted data for its own purposes, does not combine it with the data of other customers, does not sell it and does not use it for profiling or for training artificial intelligence models.
3. Categories of data subjects and data
Categories of data subjects:
- the Controller's clients — natural persons, including those conducting business activity, and contact persons of clients that are companies, of investors, and of facility managers and users;
- employees and co-workers of the Controller, crew members, including Users of the Application;
- subcontractors of the Controller and their contact persons;
- contact persons of suppliers and other contractors of the Controller;
- other persons whose data the Controller enters into the Application in accordance with its intended purpose.
Categories of personal data:
- identification and contact data: first name and surname, company name, address, correspondence address, telephone number, e-mail address, preferred contact channel and language;
- identifiers: NIP, REGON, KRS, EU VAT number and, where the Controller enters it, the PESEL number;
- facility and project data: addresses and locations of facilities, plans and floor plans, scope of work, schedules, tasks, notes on the progress of work, quotations, changes to the scope, acceptance protocols, defect reports and warranties;
- fire protection data of facilities: equipment, inspection dates and reports, and the persons performing the inspections;
- acceptances and signatures given in the Application or in its public functions;
- photographs and files attached by Users, including photographs from the construction site;
- consents and communication preferences of the Controller's clients and contact history;
- data of employees and co-workers: contact details, emergency contact, position, skills and qualifications, crew membership, form and period of cooperation, attendance records with the device's position at the start and end of work, timesheets, cost rates, equipment issued and schedule;
- technical data: IP address and timestamps of actions performed in the Application or in its public functions.
The Application is not intended for the processing of special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR), and the Controller does not entrust such data. If the Processor finds that such data has been entered, it informs the Controller accordingly.
4. Obligations of the Controller
The Controller is responsible for having a legal basis for processing, for the accuracy of the data entered, for fulfilling the information obligations towards data subjects and for obtaining the consents required for sending messages through the Application.
The Controller decides whether, and in respect of whom, to use attendance recording with device location, and is responsible for the compliance of that processing with labour law, including informing employees and co-workers of its purpose and scope.
The Controller configures the Application, including User permissions, the retention period of the activity log, the requirement of two-factor authentication and the public functions, in a manner appropriate to the risk of its processing.
5. Instructions of the Controller
The Processor processes data only on documented instructions from the Controller. The instructions consist of: the Terms of Service and the DPA, the configuration of the Application made by the Controller and the actions of Users in the Application, as well as instructions sent from the Account Administrator's e-mail address to support@mivaresites.com.
The Processor may process data without an instruction from the Controller only where required to do so by Union or Member State law; in such a case it informs the Controller of that legal requirement before processing begins, unless that law prohibits such information.
If, in the Processor's opinion, an instruction infringes the GDPR or other data protection provisions, the Processor immediately informs the Controller and may suspend its execution until the matter is clarified.
6. Confidentiality
The Processor grants access to the data only to authorised persons who need access in order to provide the service, technical support or remedy failures, and who have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
Access by the Processor's personnel to the data of a specific Company Account takes place only to the extent necessary to handle a request of the Controller, remedy a failure or ensure security.
7. Security of processing
The Processor applies the technical and organisational measures referred to in Article 32 GDPR, appropriate to the risk. Their implementation status as at the effective date of the DPA:
- encryption of data in transit using the TLS protocol — implemented;
- passwords stored solely in hashed form using the Argon2id algorithm, password strength requirements and checking against commonly known passwords — implemented;
- two-factor authentication (TOTP) available to all Users, with the option for the Controller to require it; two-factor authentication for the Processor's administrative accounts — implemented;
- limiting of login attempts, account lockout after failed attempts and automatic expiry of inactive sessions — implemented;
- logical separation of the data of each Company Account at application and database level — implemented;
- public functions of the Application accessible only through links with a random key and an expiry date, the key being stored in the database solely in hashed form — implemented;
- private files stored outside the server's public directory and made available only after authorisation — implemented;
- principle of least privilege for Users and the Processor's personnel — implemented;
- event logging in the Application (activity log) — implemented;
- automatic backups of the database and files, retained on a rotating basis for 14 days, with periodic restore testing — implemented;
- installation of updates and security patches — implemented;
- security incident handling procedure — implemented;
- encryption of data on server disks — not implemented, planned; until implementation, stored data is protected by access control, the principle of least privilege and event logging.
The Processor does not claim ISO or SOC certification. The Processor may change the security measures, provided that the change does not reduce the overall level of protection.
8. Sub-processing
The Controller grants the Processor general authorisation to engage sub-processors for further processing of the data. As at the effective date of the DPA, the Processor uses the following sub-processor:
- OVH Sp. z o.o. (OVHcloud group) — the server on which the Application runs, storage of data and backups, and sending of e-mail — data centres in the European Union — access to all categories of data within the scope of providing infrastructure services — no transfer outside the European Economic Area.
The Processor informs the Account Administrator by e-mail in advance of any intended addition or replacement of a sub-processor and publishes the current list in the DPA. The Controller may raise a reasoned objection within 14 days of receiving the information. If the parties do not agree on a solution, the Controller may terminate the Contract with effect from the day preceding the change and receives a refund of the fee for the unused period paid in advance.
The Processor imposes on each sub-processor data protection obligations no less protective than those arising from the DPA and remains liable to the Controller for the performance of the sub-processor's obligations.
The payment operator Stripe (Stripe Payments Europe, Limited) is not a processor: it handles only the Customer's payments for the service and has no access to the entrusted data.
9. Transfers of data outside the European Economic Area
The Processor processes the entrusted data exclusively within the European Economic Area. A transfer of data to a third country or an international organisation requires prior notice to the Controller in accordance with the procedure in section 8 and the use of a mechanism compliant with Chapter V GDPR.
10. Assistance to the Controller
The Processor assists the Controller in fulfilling its obligation to respond to requests from data subjects. The Application enables the Controller to independently access, rectify, export and erase data and to anonymise a client's data. If a data subject's request reaches the Processor directly, the Processor forwards it to the Controller without undue delay and does not respond to it itself, unless authorised to do so by the Controller.
Taking into account the nature of processing and the information available, the Processor assists the Controller in fulfilling the obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultations, by providing the information it holds about the Application and the measures applied.
11. Personal data breach
The Processor notifies the Controller of a personal data breach without undue delay, and no later than 48 hours after becoming aware of it, to the Account Administrator's e-mail address.
The notification contains, to the extent the information is available: a description of the nature of the breach, including the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, as well as the contact details of the person providing the information. The Processor provides any information not available at the time of notification in phases.
The Processor documents breaches and takes action to mitigate their effects. Notification of a breach to the supervisory authority and communication to the data subjects are the responsibility of the Controller; the Processor assists the Controller in doing so.
12. End of processing, return and deletion of data
The Controller may at any time download a copy of the data using the export function in the Application (a ZIP archive containing CSV files and attached files). After the end of the Contract, the Processor retains the data for 30 days to enable its export or resumption of the service and, at the Controller's request, delivers the export by electronic means during that time.
The Processor then deletes the entrusted data no later than 60 days after the end of the Contract. Copies of the data in backups are deleted in the rotation cycle, no later than 14 days after deletion of the data from the Application. At the Controller's request, the Processor confirms the deletion by electronic means.
The activity log is retained for the period set by the Controller, from 30 to 180 days. Copies of deleted records, kept for the purpose of restoring data deleted by mistake, are retained for no longer than 180 days and are deleted together with the deletion of the Company Account.
The Processor may retain the entrusted data for longer only where required by Union or Member State law, and only to the extent resulting from that obligation.
13. Information and audit
The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 GDPR, in particular answers to questions concerning the Application, the security measures and the sub-processors sent to hello@mivaregroup.com, within 14 days.
If the information provided is not sufficient, the Controller or an independent auditor bound by a duty of confidentiality may carry out an audit no more than once every 12 months, except for an audit following a personal data breach or at the request of a supervisory authority. An audit requires at least 30 days' prior notice, takes place on working days, may not disrupt the provision of the service or breach the confidentiality of other customers' data, and is carried out at the Controller's expense.
14. Liability and final provisions
The liability of the parties under the DPA is governed by Article 82 GDPR and the Terms of Service, provided that the limitations of liability do not apply where exclusion or limitation is not permitted by law.
Amendments to the DPA, including updates to the list of sub-processors, are made in accordance with the procedure provided for in the Terms of Service for amendments to documents, subject to section 8.
The DPA is governed by Polish law. It is made available in seven language versions; in the event of any discrepancy, the Polish version prevails. The current version is available at https://mivaregroup.com/en/legal/sites/dpa/
The DPA is effective from 1 October 2026.
MIVARE GROUP