Data Processing Agreement

Integral annex to the Minly Terms of Service (Article 28 GDPR)

Version effective from: 2 September 2026

All documents and terms

§1 Parties, conclusion of the agreement and definitions

This data processing agreement (the "DPA") is concluded between: (1) the Institution, that is the entity operating a kindergarten, nursery or other childcare institution which has created an account in the Service and accepted the Terms of Service (the "Controller"), and (2) Adrian Dudek, conducting sole proprietorship business under the name "Weblix Adrian Dudek", ul. Peckowskiego 2 lok. 2, 32-500 Chrzanow, Poland, Tax ID (NIP) 6282213418, REGON 384695065, e-mail: kontakt@minly.pl, tel. +48 791 748 958 (the "Processor" or the "Operator").

The DPA is an integral annex to the Minly Terms of Service, available on the Terms page. The DPA is concluded electronically upon acceptance of the Terms of Service when the Institution account is created, and at the latest when the first Entrusted Data is entered into the Service. No separate signature is required. Upon the Controller's request, the Operator will provide a copy of the DPA as a PDF file or, subject to separate arrangement, in written form.

Terms used in the DPA have the following meaning:

  • "GDPR": Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
  • "Terms of Service": the terms of service of the Minly Service, to which this DPA is annexed, together with the service agreement concluded on their basis (also the "Main Agreement").
  • "Service": the Minly cloud platform for managing waitlists, enrolments, parent communication and the administration of kindergarten and nursery institutions.
  • "Entrusted Data": the personal data referred to in §3, entered into the Service by the Controller or by persons acting at its invitation (staff, parents and guardians), processed by the Operator on behalf of the Controller.
  • "Sub-processor": another processor whose services the Operator uses when processing the Entrusted Data.

With regard to the Institution account data, billing data, marketplace Company data and data of users of the minly.pl website, the Operator acts as the controller; such data is governed by the Privacy Policy and not by this DPA.

§2 Subject matter, nature, purpose and duration of processing

The Controller entrusts the Operator with the processing of the Entrusted Data solely for the purpose of, and to the extent necessary for, providing the Service in accordance with the Terms of Service, in particular for: managing the waitlist and enrolments, handling communication between the institution and parents and guardians, attendance registration, calendar and activity planning, staff and group management, and providing technical support.

Nature of processing: processing in an IT system (SaaS), including in particular collection, recording, organisation, structuring, storage, consultation, use, disclosure to the Controller's authorised users, restriction, erasure, and the creation and storage of backups.

The DPA remains in force for the period during which the Service is provided to the Controller, that is for the term of the Main Agreement. Termination of the Main Agreement terminates the DPA, provided that the Operator's obligations under §5 (confidentiality) and §10 (return or deletion of data) remain in force until fully performed.

§3 Types of personal data and categories of data subjects

The processing concerns the following categories of data subjects:

  • children: children attending the institution and children on the waitlist,
  • parents and legal guardians of the children,
  • institution staff (employees and contractors of the Controller).

The processing covers the following types of personal data:

  • children's data: first and last name, date of birth, gender, sibling relations, waitlist status and planned start date, group assignment, attendance data, and other information entered by the Controller within the functionalities of the Service,
  • parents' and guardians' data: first and last name, e-mail address, phone number, home address, relation to the child, content of correspondence conducted through the Service, and parent portal login credentials,
  • staff data: first and last name, contact details, e-mail address, position and role in the institution, and login credentials (password stored in encrypted form).

Special categories of data (Article 9 GDPR)

Within the Service, the Controller may enter data concerning children's health, in particular information about allergies, medication, illnesses and special care or dietary needs. Such data constitutes special categories of personal data within the meaning of Article 9 GDPR and is covered by the enhanced protection measures described in Annex 1, including AES-256-CBC encryption.

The Controller warrants that it has a valid legal basis for processing the Entrusted Data, including a condition under Article 9(2) GDPR for health data, and that it enters such data into the Service only to the extent necessary for the care of the child. The Controller shall not enter into the Service personal data going beyond its functionalities and the purpose defined in §2.

§4 Processing on the documented instructions of the Controller

The Operator processes the Entrusted Data only on documented instructions from the Controller, including with regard to transfers of data to a third country or an international organisation, unless required to do so by European Union or Member State law to which the Operator is subject. In such a case, the Operator shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

The following are deemed documented instructions of the Controller: (a) the provisions of the Terms of Service and of this DPA, (b) the configuration of the Service and actions performed in the Service by the Controller and its authorised users, (c) instructions communicated to the Operator in at least documentary form (e-mail from the address assigned to the Institution account).

The Operator does not process the Entrusted Data for its own purposes. The Operator shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions; the Operator may suspend the execution of such an instruction until the matter is clarified.

The Entrusted Data is processed within the European Economic Area. A transfer outside the EEA may take place only on the documented instruction of the Controller and with the safeguards provided for in Chapter V GDPR (e.g. standard contractual clauses).

§5 Confidentiality

The Operator ensures that access to the Entrusted Data is limited to persons authorised by the Operator, to the extent necessary for the performance of their tasks (need-to-know principle).

The Operator ensures that every person authorised to process the Entrusted Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality. The confidentiality obligation continues after the end of employment or cooperation with the Operator and after termination of the DPA.

§6 Security measures (Article 32 GDPR)

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, the Operator implements and maintains appropriate technical and organisational measures to ensure the security of the Entrusted Data, as described in Annex 1 "Technical and organisational measures".

These measures include in particular: encryption in transit (TLS 1.3), encryption of health data using AES-256-CBC, role-based access control, isolation of each institution's data (tenant isolation), regular security updates, encrypted backups, and hosting on servers located in the European Union (Germany).

The Operator may update and develop the measures described in Annex 1, provided that the changes do not lower the overall level of protection of the Entrusted Data. The current version of Annex 1 is published on this page.

§7 Sub-processors

The Controller grants the Operator a general authorisation to use Sub-processors when processing the Entrusted Data. The current list of Sub-processors, including their names, purpose of use and processing location, constitutes Annex 2 to the DPA, is published on this page and is made available upon each request of the Controller (kontakt@minly.pl).

The Operator shall inform the Controller of any intended addition or replacement of a Sub-processor at least 14 days in advance, by e-mail to the address assigned to the Institution account or by a notice in the Service panel. The Controller may raise a justified objection to the change within 14 days of receiving the information. In the event of an objection, the parties shall attempt in good faith to find a solution; if this is not possible, the Controller may terminate the Main Agreement before the change takes effect, with a proportional refund of the fee for the unused period.

The Operator imposes on each Sub-processor, by way of a contract, the same data protection obligations as set out in this DPA, in particular the obligation to provide sufficient guarantees of implementing appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its obligations, the Operator remains fully liable to the Controller for the performance of that Sub-processor's obligations.

The categories of Sub-processors include: the hosting infrastructure provider (EU, Germany), the e-mail delivery provider and, where needed, providers of operational tools listed in Annex 2.

§8 Assistance to the Controller

Rights of data subjects

Taking into account the nature of the processing, the Operator assists the Controller, by appropriate technical and organisational measures and the functionalities of the Service (including access, rectification, export and deletion of data), in fulfilling the obligation to respond to requests of data subjects exercising their rights under Articles 12-23 GDPR.

If a data subject addresses a request directly to the Operator, the Operator shall forward it to the Controller without delay, no later than within 3 business days, and shall not respond to it on the merits without the Controller's instruction, unless a response is required by law.

Notification of personal data breaches

After becoming aware of a breach concerning the Entrusted Data, the Operator shall notify the Controller without undue delay, no later than within 24 hours of becoming aware of the breach, to the e-mail address assigned to the Institution account. The notification shall contain at least the information referred to in Article 33(3) GDPR, to the extent available to the Operator at the time of notification; information not immediately available shall be provided in phases, without undue delay.

The Operator documents breaches, takes containment and remedial actions, and cooperates with the Controller in assessing the risk, in any notification of the breach to the President of the Personal Data Protection Office (UODO) and in communication to data subjects. The decision to notify the supervisory authority rests with the Controller.

DPIA and prior consultation

Taking into account the nature of processing and the information available to it, the Operator assists the Controller in ensuring compliance with the obligations under Articles 32-36 GDPR, including security of processing, data protection impact assessments (DPIA) and prior consultation with the supervisory authority, in particular by providing a description of the applied security measures and processing architecture.

§9 Audits and inspections

The Operator makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR. The Operator fulfils this obligation primarily by answering questions and providing documentation of security measures and the results of reviews and audits carried out.

The Controller has the right to conduct audits, including inspections, itself or through an authorised auditor who is not a competitor of the Operator, on the following conditions: (a) notice at least 14 days in advance, (b) the audit is carried out on business days, during the Operator's working hours, in a manner that does not disrupt its operations or compromise the security of other institutions' data, (c) the persons participating in the audit enter into a confidentiality undertaking, (d) no more than once per calendar year, unless an audit is required by a supervisory authority or justified by an identified personal data breach.

Each party bears its own costs related to the audit. The scope of the audit does not cover data of other controllers, third-party trade secrets, or tests that could threaten the integrity or availability of the Service.

§10 Return or deletion of data after the end of processing

After the end of the provision of the Service, the Operator, at the choice of the Controller, returns the Entrusted Data to the Controller or deletes it. The return takes place by providing an export of the data in commonly used, machine-readable formats; the Controller may request the export before the end of the Service or within the period indicated in the next sentence.

In the absence of a different instruction from the Controller, the Operator deletes the Entrusted Data no later than within 30 days of the termination of the Main Agreement, in accordance with §5.3 of the Terms of Service, and deletes existing copies of that data, unless European Union or Member State law requires further storage.

Data contained in backups is deleted through the cyclical overwriting of backups, no later than within 30 days of the deletion of the data from the production system. Until overwritten, the backups remain encrypted and the data contained in them is not restored to processing, except in disaster recovery cases; in the event of such a restoration, data subject to deletion will be deleted again.

Upon the Controller's request, the Operator will confirm the deletion of the Entrusted Data in documentary form.

§11 Liability

Each party is liable for damage caused by processing in accordance with Article 82 GDPR. The Controller is liable in particular for the lawfulness of the collection of the Entrusted Data, the existence of legal bases for processing (including under Article 9(2) GDPR) and the content and lawfulness of the instructions it issues. The Operator is liable for processing the Entrusted Data in accordance with the DPA, the GDPR and the documented instructions of the Controller.

A party which has paid compensation for damage caused by processing is entitled to claim back from the other party that part of the compensation corresponding to the part of the damage for which that party is responsible, in accordance with Article 82(5) GDPR.

As between the parties, the limitations of the Operator's liability provided for in §9 of the Terms of Service apply to the extent permitted by mandatory provisions of law. These limitations do not exclude or limit liability towards data subjects or liability for administrative fines imposed on a party by a supervisory authority.

§12 Final provisions

The DPA is governed by Polish law. In matters not regulated herein, the GDPR, Polish data protection provisions and the Terms of Service apply. In the event of a conflict between the Terms of Service and the DPA, the DPA prevails with regard to the processing of the Entrusted Data.

Amendments to the DPA follow the procedure provided for amendments to the Terms of Service (§1 of the Terms of Service), with at least 30 days' notice, provided that an update of Annex 1 under §6(3) and of Annex 2 under §7 does not constitute an amendment of the DPA requiring that procedure.

Each version of the DPA is marked with its effective date. Archived versions are made available by the Operator upon request: kontakt@minly.pl. If any provision of the DPA proves invalid or ineffective, the remaining provisions remain in force and the parties shall replace the defective provision with a valid one closest to its purpose.

Annex 1: Technical and organisational measures

The Operator applies in particular the following technical and organisational measures to protect the Entrusted Data:

Technical measures

  • encryption in transit: all communication with the Service is encrypted using TLS 1.3,
  • encryption of sensitive data: children's health data (allergies, medication, illnesses) is encrypted using AES-256-CBC, so it remains unreadable even in the event of unauthorised access to the database,
  • role-based access control: each user sees only the data corresponding to their role, and parents see only the data of their own children,
  • tenant isolation: each institution's data is logically separated from the data of other institutions,
  • authentication: passwords stored only in encrypted form, with the option of enabling two-factor authentication,
  • event logging: critical actions in the system are logged for audit purposes,
  • regular security updates of the system and its components,
  • backups: daily, fully encrypted backups stored within the EU,
  • processing location: hosting on servers located in the European Union (Germany).

Organisational measures

  • data protection training of authorised persons,
  • access to the production environment limited to key, authorised persons,
  • procedures for handling personal data breaches,
  • regular reviews of the applied security measures,
  • all Sub-processors bound by data processing agreements.

Annex 2: List of Sub-processors

The Operator uses the following Sub-processors when processing the Entrusted Data:

Entity Purpose of processing Processing location
Hetzner Online GmbH Hosting of server infrastructure and backups Germany (EU)
Postmark (ActiveCampaign, LLC) Delivery of e-mail messages sent from the Service EU

Changes to the list follow §7 of the DPA (advance notice and right to object). The current list is always available on this page and upon request: kontakt@minly.pl.