Provider: Envoo d.o.o., company no. 6195407000, VAT no. SI45695539
Registered office: Cesta dolomitskega odreda 10c, 1000 Ljubljana, Slovenia
Contact: info@relayplan.com
3.1. Subject matter and duration
- The Processor processes personal data on behalf of the Controller for the purpose of providing the RelayPlan Service for the duration of the contract.
3.2. Nature and purpose of processing
- Hosting, storage, organisation, access, transfer at the Controller’s request, backups and support.
3.3. Types of data and categories of data subjects
- Data on employees, contractors, system users (name, contact, working hours, assignments and so on), suppliers and others entered by the Controller.
3.4. Obligations of the Processor
- Processes exclusively in accordance with the Controller’s documented instructions.
- Ensures the confidentiality of persons involved in processing and appropriate technical and organisational measures (TOMs).
- Assists the Controller in meeting its obligations (data subject rights, security incidents, DPIA).
- On termination of the contract, at the Controller’s choice, returns or deletes personal data unless the law requires retention.
3.5. Sub-processors
- The Processor may engage sub-processors with prior notice to the Controller. All sub-processors must enter into written agreements with standards no lower than these.
- The current list is in Annex A.
3.6. Transfers outside the EEA
- Where a sub-processor or system entails a transfer outside the EEA, appropriate mechanisms are put in place (e.g. SCCs), together with a transfer risk assessment and supplementary measures where necessary.
3.7. Security incidents
- The Processor notifies the Controller without undue delay of a personal data breach, provides the information required under Article 33 GDPR and cooperates in managing the incident.
3.8. Audits
- The Controller may (reasonably and with prior notice) request compliance information or carry out an audit (once a year or on reasonable suspicion), without disclosure of trade secrets.
Annex A – List of sub-processors
- Stripe Payments Europe, Ltd. – billing and payments, EEA/USA (SCCs).
- Hetzner Online GmbH – hosting, EU/EEA.
- Google – email.
- Google – analytics.
Annex B – Technical and organisational measures (TOMs)
- TLS encryption, tenant separation, RBAC, 2FA, audit trails, regular backups, access control, least privilege, update security.