Data Processing Agreement (DPA)
Annex to the Terms of Service
Version dated: 2026-08-24
This Data Processing Agreement (DPA) is an integral part of the Terms of Service and is accepted together with them upon organization sign-up. It governs how WeldStack processes personal data entered into the service by your organization (Art. 28 GDPR).
§1. Parties and subject matter
This agreement is concluded between the customer — the organization creating the account (the "Controller") and Michał Rymut WeldStack, ul. Rzeszowska 163B, 39-200 Dębica, Poland (the "Processor", "WeldStack"). Its subject matter is the processing of personal data entered by the Controller into the service for the purpose of providing it (Art. 28(3) GDPR). The agreement applies for the duration of the service, subject to §7.
§2. Nature, purpose and scope of processing
Nature and purpose: hosting and handling of welding documentation — personnel and qualification registers, WPS/WPQR/test documentation, inspections (including audio recordings and their transcriptions), files, PDF generation, import/export, sharing qualification data via QR codes at the Controller’s instruction, backups. Categories of data subjects: employees and contractors of the Controller (welders, inspectors, supervision personnel, document signatories). Types of data: identification data, qualification and certificate data, signature image, voice (recordings), inspection photos, document metadata. The Controller undertakes not to enter special categories of data (Art. 9 GDPR) unless necessary and lawful.
§2a. Controller obligations and rights
The Controller: (1) has the right to issue documented processing instructions to WeldStack and to exercise the rights set out in §5 (sub-processors) and §8 (audits); (2) is responsible for the lawfulness of the data it enters, including the existence of a legal basis for processing and the fulfilment of the information obligations (Art. 12–14 GDPR) towards the persons whose data it enters into the service; (3) bears sole responsibility for the content and consequences of an instruction to publicly share qualification data via a QR code, including the justification of the link validity period.
§3. Instructions and Processor obligations
WeldStack: (1) processes data only on the Controller’s documented instructions (instructions = the configuration and actions of the Controller’s users in the service and the provisions of the Terms), including with regard to transfers of data to a third country or an international organisation, unless required by EU or Member State law — in which case it informs the Controller before processing, unless prohibited by law; (2) ensures persons authorised to process data have committed to confidentiality; (3) implements technical and organizational measures appropriate to the risk (Art. 32 GDPR), described in the TOMs document available on request; (4) assists the Controller, insofar as possible, in fulfilling obligations towards data subjects (Art. 12–23) — requests addressed directly to WeldStack are forwarded to the Controller without undue delay; (5) assists the Controller in complying with the obligations set out in Art. 32–36 GDPR (security, breach notification, data protection impact assessments — DPIA, prior consultation), taking into account the nature of the processing and the information available to WeldStack; (6) makes available information necessary to demonstrate compliance with Art. 28 GDPR; (7) immediately informs the Controller if, in WeldStack’s opinion, an instruction issued infringes the GDPR or other Union or Member State data protection provisions; WeldStack may suspend the execution of such an instruction until the matter is clarified.
The assistance referred to in points (4)–(6) is provided taking into account the nature of the processing and the information available to WeldStack, primarily through the features of the service (export, search, data deletion). For assistance going beyond the standard features of the service and requiring significant effort, WeldStack may charge a reasonable fee at rates agreed with the Controller before the work begins; this does not apply to assistance in connection with a breach for which WeldStack is responsible.
§4. Personal data breaches
WeldStack notifies the Controller of a personal data breach concerning entrusted data without undue delay, no later than within 48 hours of establishing the breach. The notification includes at least: a description of the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point ([email protected]). Where it is not possible to provide all the information at the same time, WeldStack provides it in phases without undue further delay. Notifications to the supervisory authority and communications to data subjects are made by the Controller; WeldStack provides the necessary assistance.
§5. Sub-processing
The Controller gives general authorisation for the use of the sub-processors listed at weldstack.io/subprocessors. WeldStack gives at least 14 days’ advance notice of intended changes to the list (e-mail to the account owner). The Controller may object on reasonable grounds within that period; failing agreement, the Controller may terminate the main agreement before the change takes effect. WeldStack imposes the same data protection obligations on sub-processors and remains fully liable to the Controller for the performance of their obligations, as for its own acts.
§6. Transfers outside the EEA
Processing takes place in the EU region (Google Cloud, europe-central2). Exceptions — services indicated on the sub-processor list (in particular AI services, e-mail delivery and error monitoring) — rely on valid transfer mechanisms (EU-US Data Privacy Framework adequacy or Standard Contractual Clauses in the providers’ DPAs), in accordance with Chapter V GDPR.
§7. Deletion and return of data
1. During the term of the agreement the Controller exports data independently (XLSX/PDF/JSON export features).
2. After the agreement ends (trial expiry, subscription cancellation, account deletion) data is retained for 90 days (account recovery window) and then permanently deleted: the organization’s database schema and files are removed and the organization record is anonymised.
3. The export features available in the service constitute the mechanism for the return of data; upon a request made before the expiry of the period referred to in paragraph 2, WeldStack will make an export of the data available to the Controller, after which the data will be deleted in accordance with paragraph 2.
4. Exceptions to deletion (Art. 28(3)(g) in fine): billing metadata is retained by WeldStack to the extent and for the period required by a legal obligation (tax and accounting obligations, 5 years from the end of the tax year). The minimised proof of consents and the used-trial ledger entry are processed by WeldStack as an independent controller in order to demonstrate compliance and defend claims — as described in the Privacy Policy; this data does not constitute entrusted data.
5. Deleted data remains in backups until their natural rotation (approx. 7 days); backups are not selectively restored.
§8. Audits
1. WeldStack fulfils the Controller’s audit right primarily by making information available: a description of the technical and organizational measures, compliance documentation, confirmations of the data processing agreements with sub-processors, and written answers to the Controller’s reasonable questions (within 30 days of receipt).
2. If the information made available is, in the Controller’s reasonable opinion, insufficient to demonstrate compliance with Art. 28 GDPR, or an audit is required by a supervisory authority or follows an established breach, the Controller may carry out an on-site or remote inspection — itself or through an authorised auditor who is not a WeldStack competitor and is bound by a confidentiality obligation — upon a date agreed at least 14 days in advance, on business days, in a manner that does not disrupt the provision of the service and does not give access to data of other WeldStack customers, no more than once every 12 months (the frequency limitation does not apply to an audit following a breach).
3. The costs of an inspection referred to in paragraph 2, including documented, reasonable costs of involving WeldStack personnel, are borne by the Controller — except for an audit that revealed a material non-compliance of WeldStack with this agreement. A material non-compliance means in particular a non-compliance resulting in a personal data breach subject to notification (Art. 33 GDPR), a non-compliance established by a supervisory authority, or a breach of §3–§7 of this agreement not resulting from the Controller’s actions or instructions.
§9. Liability and final provisions
1. WeldStack’s liability towards the Controller under this agreement is subject to the limitations and exclusions of liability provided for in the Terms of Service (§11), to the fullest extent permitted by law. These limitations do not affect liability towards data subjects arising under Art. 82 GDPR, nor liability that cannot be limited under mandatory provisions of law. Recourse settlements between the parties under Art. 82(5) GDPR are made in proportion to responsibility for the damage. The limitations under §11 of the Terms of Service do not apply to recourse settlements under Art. 82(5) GDPR to the extent that their application would prevent the recovery of the part of the compensation corresponding to the other party’s responsibility.
2. Matters not regulated here are governed by the GDPR and Polish law. Amendments to this agreement follow the Terms of Service amendment procedure (acceptance of the new version in the service).
3. This agreement has been drawn up in Polish and made available in English, German, Spanish, French, and Italian translation; in the event of discrepancies, the Polish version shall prevail.