EN
This is an archived version of this document, kept for reference. See the version currently in force.
This Data Processing Agreement ("DPA") is entered into between Eurhosting SHPK, Sallmone, Shijak, 2001 Durrës, Albania, NIPT M52305043P ("Processor", "we", "us") and the customer identified in the account registration ("Controller", "you").
This DPA forms part of, and is incorporated by reference into, the deliveru.eu Terms of Service. It applies to all processing of personal data carried out by us on your behalf in connection with the Service. It is effective from the date you accept the Terms of Service or first use the Service, whichever is earlier, and no separate signature is required. Where you require a signed counterpart for your own records, contact legal@deliveru.eu.
In the event of a conflict between this DPA and the Terms of Service in respect of the processing of personal data, this DPA prevails.
"GDPR" means Regulation (EU) 2016/679. The terms "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in the GDPR.
"Subscriber Data" means the personal data of your subscribers, contacts and recipients that you upload to, or generate through, the Service.
You are the Controller in respect of Subscriber Data. We are the Processor and act only on your documented instructions.
Where you use the Service to provide email or SMS marketing services to your own clients (as a Reseller), you remain the Controller towards us. Your relationship with your own clients, including any controller-to-processor arrangement between you and them, is your responsibility and is not governed by this DPA.
In respect of your own account data — your name, email address, company details, billing records and login activity — we act as Controller, and our processing of that data is described in our Privacy Policy.
Subject matter: the provision of the deliveru.eu email and SMS marketing platform.
Duration: for the term of your subscription, plus the retention periods set out in section 11.
Nature and purpose: storage, organisation, retrieval, transmission and deletion of Subscriber Data for the purpose of enabling you to create, send, and measure email and SMS marketing campaigns, and to manage your contact lists.
Categories of data subjects: your subscribers, contacts and recipients; your team members with access to your account.
Categories of personal data: email addresses; telephone numbers; first and last names; company names; any custom fields you choose to populate; consent records and timestamps; campaign interaction data such as opens, clicks, bounces, unsubscribes and delivery outcomes; IP addresses associated with those interactions.
Special categories of data: the Service is not designed for, and must not be used to process, the special categories of personal data listed in Article 9 GDPR, nor data relating to criminal convictions and offences under Article 10. You must not upload such data to the Service.
We shall:
We will inform you if, in our opinion, an instruction from you infringes the GDPR or other Union or Member State data protection law.
You are responsible for:
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, we implement the following technical and organisational measures pursuant to Article 32 GDPR:
We may update these measures over time, provided that the level of protection is not reduced.
You give us general authorisation to engage sub-processors for the provision of the Service. Each sub-processor is bound by a written agreement imposing data protection obligations no less protective than those in this DPA.
Our current sub-processors are:
We will inform you of any intended addition or replacement of a sub-processor by email at least 30 days before the change takes effect. You may object on reasonable data protection grounds within that period; if we cannot accommodate your objection, you may terminate your subscription without penalty in respect of the affected services.
We remain fully liable to you for the performance of our sub-processors' obligations.
The Service provides functionality allowing you to access, correct, export and delete Subscriber Data directly, which in most cases will be sufficient for you to respond to a data subject request without our involvement.
Where a request cannot be satisfied through the Service, we will provide reasonable assistance on request. If we receive a request directly from one of your subscribers, we will not respond to it substantively, and will refer the request to you without undue delay.
You may export and delete Subscriber Data at any time through the Service while your account is active.
Export on termination. For 30 days following termination you may request a complete export of your data by writing to legal@deliveru.eu from the email address registered on the account. We will provide it in a structured, commonly used, machine-readable format within a reasonable period of receiving your request. Requests received after that 30-day window may no longer be capable of being fulfilled, as deletion will already have begun.
Deletion. Your account data and Subscriber Data are deleted within 90 days of termination, subject only to the exceptions set out below.
Retention while the account is active. The following periods apply:
Records we are required to retain. Invoices and the accounting records supporting them are retained for the period required by applicable tax law, being at least 10 years, and are not deleted on termination. This is permitted by Article 17(3)(b) GDPR. Where an invoice relates to a terminated account, we retain only the billing identity necessary for the document to remain valid: company name, VAT number, address and country.
Audit records of the deletion itself. Audit log entries evidencing that a deletion took place are retained as proof of compliance. Those entries record identifiers and actions, not the personal data that was deleted.
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Subscriber Data. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures taken or proposed.
We will assist you in meeting your own notification obligations under Articles 33 and 34 GDPR. Notifying your supervisory authority and, where required, your data subjects remains your responsibility as Controller.
On written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, we will provide the information reasonably necessary to demonstrate compliance with this DPA.
Where you require an on-site audit, it must be arranged with reasonable notice, conducted during normal business hours, and carried out in a manner that does not disrupt our operations or compromise the confidentiality of other customers' data. You bear the costs of any such audit unless it reveals a material breach of this DPA.
Subscriber Data is stored on servers located in Germany, within the European Union.
We are established in Albania, which is not the subject of an adequacy decision by the European Commission. Our authorised personnel access the production infrastructure remotely from Albania for the purposes of administration, maintenance and support. Such access constitutes a transfer of personal data to a third country for the purposes of Chapter V GDPR, and is subject to appropriate safeguards under Article 46 GDPR. Details of the safeguards in place, and a copy of the applicable Standard Contractual Clauses, are available on request at legal@deliveru.eu.
Subscriber Data is not otherwise transferred outside the European Economic Area.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, save to the extent that such limitation is not permitted by applicable law.
This DPA remains in force for as long as we process Subscriber Data on your behalf.
We may amend this DPA where required by changes in applicable law, guidance from supervisory authorities, or changes to the Service. We will notify you of material changes by email at least 30 days before they take effect.
This DPA is governed by the laws of the Republic of Albania, without prejudice to any mandatory provision of Union or Member State data protection law applicable to you. Disputes are subject to the jurisdiction set out in the Terms of Service.
For all matters relating to this DPA, including data export requests, requests for a signed counterpart, the current sub-processor list, or the applicable transfer safeguards: legal@deliveru.eu
Eurhosting SHPK · Sallmone, Shijak · 2001 Durrës, Albania · NIPT M52305043P