Data Processing Agreement - RegisterBench (DORA RoI Builder)
Version 1.0, in force from 2026-09-28
Preamble
This Data Processing Agreement (the "DPA") is concluded in connection with the provision of the RegisterBench service by NORMFORT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (in short: Normfort sp. z o.o.). It forms an integral part of the Terms of Service and is concluded when the Terms of Service are accepted. It applies from the moment we start processing personal data on behalf of the client.
The service is used by financial entities for their own Register of Information and by advisory firms that maintain registers for their clients. A financial entity using the service for its own register acts as a controller, and we act as its processor. An advisory firm maintaining the register of its client may act as a processor of that client, and we then act as a sub-processor.
1. Definitions and subject matter
- Capitalised terms have the meaning given in the Terms of Service. The terms "controller", "processor", "processing", "personal data" and "personal data breach" have the meaning given in Article 4 of the GDPR.
- The parties are the client, who entrusts the data (acting as a controller or as a processor of its own client), and NORMFORT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (in short: Normfort sp. z o.o.), the Provider under the Terms of Service, who processes the data.
- The client entrusts to us the processing of the personal data described in Annex A only for the purpose and to the extent necessary to provide the service under the Terms of Service (Article 28(3) of the GDPR).
- This DPA is concluded for the term of the agreement under the Terms of Service and ends when the data have been returned or deleted under section 8.
2. Roles of the parties
- The nature, purpose and duration of the processing, the types of personal data and the categories of data subjects are set out in Annex A.
- For the register of a financial entity kept for its own purposes, the client acts as the controller and we act as the processor.
- Where the client maintains the register of its own client, the client declares that (a) it has an agreement with that client that entitles it to process the data as a processor, (b) it has obtained the general or specific authorisation of that client for the further entrustment of the processing to us in the scope of this DPA, and (c) it will give that client the information about us and our subprocessors required by Article 28 of the GDPR. In that case we act as a sub-processor, and the obligations that this DPA describes as those of the controller are performed towards us by the client, in its own name or in the name of its client.
- The client is responsible for the lawfulness of the instructions it gives us and for the existence of a valid legal basis for the processing on the side of the controller.
3. Our obligations as processor (Article 28(3) of the GDPR)
We undertake to:
- process the data only on the documented instructions of the client. The parties treat as documented instructions the Terms of Service, this DPA and the actions that authorised users take through the functions of the service (creating, editing, importing, validating, exporting and deleting data). This applies also to a transfer of data to a third country, unless we are required to make it by Union or Member State law, in which case we inform the client before the processing, unless that law prohibits it,
- ensure that the persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality,
- take the technical and organisational measures required under Article 32 of the GDPR, at least in the scope described in Annex C,
- respect the conditions for engaging another processor (section 4),
- taking into account the nature of the processing, assist the client by appropriate technical and organisational measures, insofar as this is possible, in responding to requests of data subjects (Chapter III of the GDPR), in particular through the functions of the service for export, correction and deletion of data, and forward to the client without undue delay any such request addressed to us directly,
- assist the client in ensuring compliance with the obligations under Articles 32 to 36 of the GDPR (security, notification of breaches, data protection impact assessment), taking into account the nature of the processing and the information available to us,
- at the end of the provision of the service, at the choice of the client, enable the export of the data and delete the personal data and existing copies under section 8, unless Union or Member State law requires their storage,
- make available to the client all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits under section 6,
- inform the client immediately if, in our opinion, an instruction infringes the GDPR or other data protection provisions.
4. Subprocessors
- The client gives us a general authorisation (Article 28(2) of the GDPR) to engage the subprocessors listed in Annex B.
- We inform the client of any intended change of that list (addition or replacement of a subprocessor) at least 30 days before the change, by an e-mail to the address of the account and by an update of the list.
- Within 30 days of receiving that information, the client may object to the intended change on reasonable grounds of data protection. The parties will then cooperate to find a suitable solution. If that is not possible, the client may end its use of the service under the Terms of Service.
- We impose on each subprocessor, by contract, the same data protection obligations as those set out in this DPA, in particular those of Article 32 of the GDPR, and we remain fully liable to the client for the performance of the obligations of our subprocessors (Article 28(4) of the GDPR).
5. Personal data breaches
- We notify the client of a personal data breach concerning the entrusted data without undue delay and no later than 48 hours after becoming aware of it, by an e-mail to the address of the account.
- The notification contains at least the information of Article 33(3) of the GDPR to the extent known to us: the nature of the breach, the categories and approximate number of data subjects and of records concerned, the likely consequences, the measures taken or proposed and a contact point. The information may be provided in phases.
- Assessing whether a breach must be notified to the supervisory authority (Article 33 of the GDPR) and communicated to the data subjects (Article 34 of the GDPR) is for the controller. We do not notify breaches to the supervisory authority on behalf of the client, unless the parties agree otherwise in writing.
- We document the breaches concerning the entrusted data and cooperate in clarifying them.
6. Audits
- The client may exercise its right of audit (Article 28(3)(h) of the GDPR) in the following order of means: (a) written questions and questionnaires, answered within 14 business days, (b) access to the documentation of the measures, (c) an on-site audit, announced at least 14 days in advance, carried out on business days, not more often than once in 12 months unless it follows a breach, and conducted in a way that does not affect the data of our other clients or our business secrets. The auditor must be bound by confidentiality.
- The costs of an on-site audit are borne by the client. If an audit requires our involvement beyond the reasonable cooperation under this DPA, the parties may agree how the additional reasonable costs are covered.
- An audit concerning a subprocessor takes into account the nature of the services of that subprocessor and the access rules of the relevant agreements.
7. Transfers outside the European Economic Area
- The entrusted data are stored in the European Union (Annex B, locations).
- We have our registered office in Poland.
- We inform the client of a change concerning our subprocessors or the manner of processing that may affect a transfer of data outside the European Economic Area in the way set out in section 4.
8. End of processing
- After the end of the provision of the service, at the choice of the client, we enable the export of the entrusted data and delete the personal data from our systems, in line with the Terms of Service and the applicable law. Export-all is available in every account state. An OrgAdmin can delete the organisation at any time, which removes all data of the organisation and its stored files.
- The data may remain in backups for the period of their rotation, and until they are deleted they stay protected by the measures of Annex C.
- The append-only audit log of the service is not removed by the deletion of an organisation. It records the changes made in the service, and the deletion adds to it a record of who deleted the organisation and when.
- On a written request of the client made before the deletion is completed, we take steps to delete the data earlier, unless a legal obligation or technical reasons related to the security of our systems prevent it.
- We may keep data whose storage is required by Union or Member State law, only in the required scope and for the required time and with confidentiality preserved.
- On request, the client receives a written confirmation of the deletion.
9. Liability and remuneration
- The liability of the parties in connection with this DPA is governed by the Terms of Service.
- The remuneration for the processing is included in the fee for the service. Additional activities beyond the standard scope of the service or of the obligations under this DPA may be carried out on separate arrangements of the parties for an additional fee.
10. Final provisions
- In the event of a conflict between this DPA and the Terms of Service, this DPA prevails in matters of data protection.
- Changes of this DPA follow the procedure for changes of the Terms of Service (section 22 of the Terms), except for changes of the list of subprocessors, which follow section 4.
- This DPA is governed by the law that governs the Terms of Service.
Annex A - Description of the processing (Article 28(3) of the GDPR)
| Element | Description |
|---|---|
| Subject matter | Provision of the service: storage and handling of the data the client enters into its registers in the service |
| Duration | The term of the agreement under the Terms of Service, plus the period of export and deletion (section 8) |
| Nature of the processing | Collection through the forms and the import of the service, storage, organisation, display, modification, validation, generation of the output packages, export, deletion, backups |
| Purpose | Provision of the service: preparing and maintaining the Register of Information under the DORA templates, validating it and producing the output packages |
| Categories of data subjects | Natural persons whose personal data appear in the register data the client enters |
| Types of personal data | The personal data that appear in the register data, such as names and business identifiers, to the extent the client enters them. By design the service holds only the ICT contract metadata required by the register templates |
| Excluded data | Special categories of data (Article 9 of the GDPR), data relating to criminal convictions and offences (Article 10 of the GDPR), transactional data and personal data of the end customers of the client. The service is not designed to process them |
Annex B - Subprocessors
Subprocessors: OVH (hosting of the application, the database and the operations host, in the EU), Scaleway (transactional e-mail, TEM, region PAR), Cloudflare (DNS, Pages for the public website, Email Routing for kontakt@, transitional analytics beacon).
Annex C - Technical and organisational measures (Article 32 of the GDPR)
- Tenant isolation: every organisation is a separate tenant. Isolation is enforced by the application and covered by automated tests, and a write across tenants is blocked.
- Encryption: transport is encrypted (HTTPS). Backups of the database and of the stored files are encrypted before they leave the host.
- Access control: role-based access in the service (OrgAdmin, Editor, Viewer), a minimum password length of 12 characters, lockout after repeated failed sign-ins, optional TOTP two-factor authentication that an organisation can require from all its members, and bearer tokens.
- Accountability: an append-only audit log of the changes of data and of business events, protected against update and deletion in the database, and a record of the acceptance of the legal documents (who, when, which version).
- Continuity: automatic backups with a rotation of daily and monthly copies, and an alert when the latest backup is older than the configured maximum age.
- Secure operation: error reports are scrubbed of credentials, cookies, query strings and e-mail addresses before they are sent, rate limits protect the sign-in and the other endpoints, and the responses of the sign-in do not reveal whether an account exists.
- Minimisation: working data and import files are purged after a final export (by default after 30 days), outbox messages and import jobs are kept for 90 days, validation runs are limited to the last 5 per register, and export and deletion are available as functions of the service.