Skip to content

Data Processing Agreement

Last updated: 2026-06-26

This Data Processing Agreement (DPA) forms an integral part of the Service Agreement and governs the conditions of personal data processing under Article 28 of Regulation (EU) 2016/679 (GDPR).

Parties and their roles

The Data Controller under Art. 4(7) GDPR is the Customer, who determines the purposes and means of processing personal data of workers.

The Data Processor under Art. 4(8) GDPR is Version Two s.r.o. (the Provider), which processes personal data solely on the instructions of the Customer.

Subject and duration of processing

The Processor processes personal data to the extent necessary to operate the StaffIo platform – including account management, attendance records, GPS location during active shifts, and in-platform communications. Processing lasts for the duration of the Service Agreement.

Controller instructions

The Processor processes personal data solely on the basis of documented instructions from the Controller. If the Processor is required to process data under EU or member-state law, it will inform the Controller in advance unless the law prohibits this.

Approved sub-processors

The Controller grants general authorisation for the use of sub-processors. Current list:

VPS hosting – data centre in the EU (Germany).

Amazon SES eu-central-1 – transactional email.

Wasabi eu-central-1 – object storage (attachments, voice recordings).

Sentry – error monitoring; data is anonymised before transmission.

Cloudflare Turnstile – protection of forms against automated attacks.

LiveKit – push-to-talk voice communications.

Google Firebase – push notification delivery.

Stripe – payment processing (stores only payment metadata, not card numbers).

The Processor will notify the Controller of any change to the sub-processor list at least 10 days in advance. The Controller may object to the change.

Technical and organisational security measures

The Processor implements measures in accordance with Art. 32 GDPR:

Encrypted transit: TLS 1.3 for all client-server communication.

Encrypted content: AES-256 for data stored on server and in the mobile app.

Access control: RBAC with an audit log of every permission change.

Pseudonymisation of GPS records after an event ends (within 90 days).

Regular backup and recovery testing.

Data subject rights

Upon receiving a data subject request (access, rectification, erasure, portability, objection) the Processor will assist the Controller in fulfilling the request to the extent technically and procedurally within its scope. Requests are handled within 30 days of receipt.

Personal data breach

In the event of a personal data breach under Art. 33 GDPR the Processor will notify the Controller without undue delay and at most within 72 hours of becoming aware of the breach. The notification will include a description of the incident, the categories and estimated number of affected individuals, likely consequences, and measures taken.

Return and deletion of personal data

Upon termination of the Service Agreement the Processor will, at the Controller's instruction, delete or return all personal data and destroy existing copies, unless EU law requires retention. Deletion will be confirmed in writing within 30 days.

Audit and inspection rights

The Controller or an auditor appointed by it may carry out an audit of compliance with this DPA with at least 30 days' notice. The Processor may, in lieu of an audit, provide a valid ISO 27001 certificate or equivalent independent security audit.

Duration of the DPA

This DPA is valid for the duration of the Service Agreement. Termination of the Agreement results in termination of this DPA; obligations relating to data deletion remain in force.