Legal document
Data Processing Agreement (DPA)
This agreement sets out the terms under GDPR Article 28 for cases where the Customer (as controller) stores and processes personal data in the KKVzz web application (for example data of its own customers, leads or employees). With respect to such data, KKVzz acts as a processor on the Customer's documented instructions. The agreement is accepted by the owner acting on behalf of the Customer when the subscription is activated; the fact, time and version of acceptance are logged.
Effective: 22 June 2026 · v2026.06.22
Parties and roles
- Controller: the Customer (the organisation holding the KKVzz subscription), who determines the purposes and means of processing the personal data stored in the web application.
- Processor: Full AI Technology Kft. (KKVzz), processing such data on the Customer's behalf and solely on the Customer's documented instructions.
- For KKVzz's own subscription billing and account-activity data, KKVzz is an independent controller — this is governed by the privacy notice.
Subject matter, duration, nature and purpose
- Subject and purpose: storing and processing the personal data the Customer records in the KKVzz modules (for example CRM, HR, projects, warehouse) in order to provide the service.
- Duration: for the term of the subscription, until the data is returned or deleted.
- Nature: storage, organisation, retrieval, display, and transfer to integrations configured by the Customer.
Data subjects and categories of data
- Data subjects: natural persons recorded by the Customer (for example customers, leads, contacts, employees, drivers).
- Categories of data: identification and contact data, business and transactional data provided by the Customer, and other data arising from the nature of the modules. It is the Customer's responsibility to ensure an appropriate legal basis for any special-category data.
Obligations of the processor
- We process the data only on the Customer's documented instructions, including with regard to transfers to a third country.
- Confidentiality: persons with access to the data are bound by confidentiality.
- Security: we apply the technical and organisational measures required by GDPR Article 32 (encryption, access control, logging) — see the security statement for details.
- Assistance: we reasonably assist the Customer in fulfilling data subject requests and its obligations under Articles 32–36.
- Personal data breach: we notify the Customer without undue delay after becoming aware (per the process set out in the security statement).
- At the end of processing, at the Customer's choice, we return or delete the data, unless retention is required by law.
- Auditability: we make available the information needed to demonstrate compliance and allow for audits within reasonable limits.
Sub-processors engaged
The Customer gives a general authorisation to engage the sub-processors listed below. We will inform the Customer in advance of any new sub-processor, and the Customer may object.
- Google Cloud (Google Ireland Ltd.) – application hosting and encrypted database (EU, europe-west4 region), object storage (uploaded documents), and document recognition (Google Cloud Vision OCR).
- Google Vertex AI (Gemini, Google Ireland Ltd.) – the language model behind the AI features; processing takes place in an EU region (europe-west4). The model does not use the data to train itself.
- MailerSend (MailerLite Limited, Ireland) – transactional email delivery. Its privacy policy.
- Barion Payment Zrt. (Hungary) – processing of online card payments. Card data is handled directly by Barion (PCI-DSS).
- Error logging and web analytics: performed in our own system operated within the EU (Google Cloud); we do not engage a separate third-party error-monitoring or analytics processor.
The sub-processors above handle data within the EU. The up-to-date list of sub-processors and the safeguards between us form an annex to the individual service contract.
External integrations enabled by the Customer
At its own discretion, the Customer may enable external services to which the web application transfers data. Using them is optional and takes place on the Customer's (controller's) instruction and responsibility.
- Banking: Wise, Revolut – retrieving statements, initiating payments (access tokens are stored encrypted).
- E-signature: DocuSign – electronic signing of HR contracts.
- Email/calendar sync: Google (Gmail/Calendar), Microsoft (Outlook/Graph).
- Task/time sync: Jira (Atlassian), Azure DevOps (Microsoft), GitHub.
- State e-health: EESZT (e-prescription) – only for authorised Customers using the pharmacy modules; involves health (special-category) data.
By enabling these integrations the Customer determines the transfer of data to the relevant provider; that provider's own data processing terms (and, where applicable, safeguards under Chapter V of the GDPR) apply.
Transfers to third countries
Data is primarily processed within the EU. If any sub-processor were to process data outside the EU, we would do so only with the appropriate safeguards under Chapter V of the GDPR (for example an adequacy decision or EU Standard Contractual Clauses).
Contact
For questions about this agreement, please contact privacy@kkvzz.hu.