[ DATA PROCESSING AGREEMENT ]
Table of contents
§1. Parties and Definitions §2. Subject Matter and Scope of Processing §3. Obligations of the Data Processor §4. Obligations of the Data Controller §5. Sub-processing §6. Security Measures §7. Data Breach Notification §8. Data Subject Rights §9. Audit and Verification §10. Duration and Termination §11. Liability §12. Final Provisions§1. Parties and Definitions
Data Controller — the client company using the KS-CYBER OPS platform that entrusts the processing of its employees' personal data.
Data Processor — KS-CYBER Sp. z o.o. (limited liability company), ul. Marcina Kasprzaka 31/119, 01-234 Warsaw, Poland, Tax ID (NIP): 5273177065, REGON: 542451510, KRS: 0001188597, operator of the platform at ops.ks-cyber.pl.
Platform — the KS-CYBER OPS information system available at ops.ks-cyber.pl, used for delivering cybersecurity training.
GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
Employee Personal Data — any data processed by the Platform on behalf of the Controller relating to persons invited to the Platform by the Controller.
Sub-processor — a third party to whom the Data Processor entrusts the processing of personal data on behalf of the Controller, in accordance with Art. 28(4) GDPR and the conditions set out in §5 of this Agreement.
§2. Subject Matter and Scope of Processing
2.1. Purpose of Processing
The Controller entrusts the Processor with the processing of the Controller's employees' personal data solely for the purpose of providing the cybersecurity e-learning platform service, including:
- User account management (creation, modification, deactivation)
- Conducting training and certification exams
- Storing training results and progress
- Generating completion certificates
- Providing analytics and reports to the Controller
- Ensuring system security and exam integrity
2.2. Categories of Personal Data
| Category | Specific Data | Collection Basis |
|---|---|---|
| Identification data | First name, last name, email address | Invitation by the Controller |
| Authentication data | Password hash (Argon2id), FIDO2/WebAuthn keys, physical access tokens | User registration |
| Training data | Exam results, scores, duration, answers given, certificates | Platform activity |
| Behavioral data | Browser tab switch count (tab_switches), paste events (paste_events) — during exams only | Anti-cheat mechanism |
| Technical data | IP addresses, session logs, login/logout timestamps | System security |
| Employment data | Organization membership, join/leave date, role (admin/user) | Access management |
2.3. Categories of Data Subjects
- Employees of the Controller invited to the Platform
- Organization administrators designated by the Controller
- Frontline workers using physical access tokens (without email accounts)
2.4. Purpose Limitation
§3. Obligations of the Data Processor
The Processor undertakes to:
- Process data only on documented instructions from the Controller.
- Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures in accordance with Art. 32 GDPR (details in §6).
- Comply with the conditions for engaging another processor (§5).
- Assist the Controller, insofar as possible, in fulfilling the obligation to respond to data subject requests (§8).
- Assist the Controller in ensuring compliance with obligations under Art. 32–36 GDPR (security, breach notification, DPIA).
- Upon termination of the services — delete or return all personal data in accordance with §10.
- Make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR obligations.
§4. Obligations of the Data Controller
The Controller represents and undertakes that:
- It has a valid legal basis for processing the entrusted data and for entrusting it to the Processor.
- It has informed employees (data subjects) about the fact of data entrustment and the purposes of processing by the Platform — in accordance with Art. 13/14 GDPR.
- Behavioral data (
tab_switches,paste_events) will be disclosed in the Controller's internal privacy policy or employment regulations, and employees will be informed before taking their first exam. - It will not issue instructions to the Processor that are incompatible with the GDPR or applicable law.
- It will promptly inform the Processor of any changes to the scope of processed data.
§5. Sub-processing
The Controller grants general authorization for the Processor to engage the following sub-processors:
| Sub-processor | Location | Role |
|---|---|---|
| Amazon Web Services EMEA SARL | Luxembourg (data in EU Frankfurt) | Cloud infrastructure hosting and database (EU region) |
| Cloudflare, Inc. | Global (EU DPA / SCCs) | CDN, WAF, DDoS protection, Cloudflare Tunnel — processes HTTP traffic metadata and IP addresses |
| Stripe Payments Europe, Ltd. | EU (Ireland) / USA (DPF) | Payment processor — processes transactional data of the ordering party, not employees |
| Google Ireland Limited | EU (Ireland) | SMTP relay (Google Workspace) — transactional email delivery (invitations, certificates) |
| Functional Software, Inc. (Sentry) | USA (EU-US Data Privacy Framework) | Application error monitoring — processes HTTP request metadata (no user PII, PII scrubbing enabled) |
The Processor undertakes to inform the Controller of any intended addition or replacement of a sub-processor at least 14 calendar days in advance. The Controller has the right to raise a reasoned objection within this period. If an objection is raised, the parties shall negotiate; if no agreement is reached within 30 days, the Controller is entitled to terminate the Agreement with immediate effect, without penalties. Each sub-processor is required to meet the same data protection requirements as the Processor.
§6. Security Measures
The Processor has implemented the following measures in accordance with Art. 32 GDPR:
Technical Measures
- Data-in-transit encryption — TLS 1.2+
- Password hashing — Argon2id (with PBKDF2-SHA256 fallback)
- Database in a private VPC network (no direct internet access)
- Automated encrypted database backups (7-day retention window)
- Multi-factor authentication (TOTP/FIDO2) for administrator accounts
- IP allowlisting for physical access tokens
- CSRF protection on all forms
- Access and operation audit logs
Organizational Measures
- Principle of least privilege — data access limited to authorized personnel only
- Regular code security reviews
- Breach notification procedure (§7)
- Confidentiality agreements with sub-processors
§7. Data Breach Notification
In the event of a personal data breach, the Processor undertakes to:
- Notify the Controller without undue delay, no later than 48 hours after becoming aware of the breach — via email to the address registered as the organization's primary contact.
- The notification shall include:
- Description of the nature of the breach (categories and approximate number of persons and records affected)
- Contact details of the person responsible for handling the breach
- Description of the likely consequences of the breach
- Description of measures taken or proposed to address the breach
- If complete information is not available within 48 hours, the notification may be provided in phases — supplementary information will be communicated as soon as it becomes available.
§8. Data Subject Rights
The Processor assists the Controller in fulfilling the obligation to respond to data subject requests (Art. 15–22 GDPR):
- The Controller can export user data through the organization admin panel.
- For erasure requests — the Controller deactivates the account via the admin panel; KS-CYBER deletes the data in accordance with §10, paragraph 3.
- Requests requiring technical intervention by the Processor will be fulfilled within 30 days of notification by the Controller.
§9. Audit and Verification
The Controller has the right to verify the Processor's compliance with this Agreement by:
- Requesting documentation regarding security measures (infrastructure provider certificates, security policies)
- Conducting an audit or inspection — upon prior arrangement (minimum 14 business days' notice) and acceptance of confidentiality terms
- Audit costs, including auditor fees, are borne by the Controller. If the audit confirms a breach by the Processor of obligations under §3, §5, or §6 of this Agreement, the Processor shall reimburse the Controller's documented audit costs within 30 days of receiving the statement — however, not exceeding the equivalent of one month's net fees payable to the Processor.
The Processor may, instead of an audit, provide results of an audit conducted by an independent third party (e.g., ISO 27001 certificate, SOC 2 report), provided that the document is no older than 12 months and confirms compliance with the requirements of this Agreement. The Controller retains the right to conduct its own audit no more than once every 24 months, regardless of any substitute certificates provided.
§10. Duration and Termination
This Agreement remains in force for the duration of the Controller's use of the KS-CYBER OPS Platform.
Upon Termination
Within 30 days of subscription termination, the Processor shall:
- Allow the Controller to export data in JSON/CSV format via the admin panel (for the first 14 days after subscription ends).
- Delete employee data from the production database after the export period expires.
- Anonymize training results (remove personal data, retain aggregate statistical data that cannot be linked to any individual).
- Retain billing data (organization data, payment history) for 5 years in accordance with tax regulations.
Upon request, the Controller may receive written confirmation of data deletion.
§11. Liability
The liability of the parties is governed by Art. 82 GDPR:
- The Controller is liable for damages resulting from processing that is not in compliance with this Agreement or the GDPR, where the breach is attributable to its decisions or instructions.
- The Processor is liable for damages resulting from failure to comply with obligations imposed by the GDPR or this Agreement.
- The Processor is exempt from liability if it proves that it is in no way responsible for the event giving rise to the damage.
The total liability of the Processor under this Agreement is limited to the amount of fees paid by the Controller in the 12 months preceding the event, unless the breach was the result of gross negligence or willful misconduct.
§12. Final Provisions
- This Agreement is governed by Polish law and the GDPR.
- Any disputes shall be resolved by the court having jurisdiction over the Processor's registered office.
- In matters not regulated by this Agreement, the provisions of the GDPR and the Polish Civil Code shall apply.
- Amendments to this Agreement require written or electronic form (update of the document on the Platform with email notification at least 14 calendar days in advance). Failure by the Controller to submit a written objection within this period constitutes acceptance of the changes. In the event of an objection, the Controller is entitled to terminate the Agreement effective at the end of the current billing period.