Data Processing Agreement

The agreement under which Sloneek processes personal data on the customer’s behalf.

1. Introductory provisions

1.1 This Data Processing Agreement (the “DPA”) is part of Sloneek Europe s.r.o.’s Terms & Conditions available at [www.sloneek.com]; or, if applicable, of any other written agreement entered into between the Customer and the Provider to govern the engagement and use of the Service (collectively, the “Agreement”).

1.2 This DPA is concluded, and becomes an inseparable part of the Agreement, automatically upon the Customer’s acceptance of the Terms & Conditions, without the need for any further action by either Party.

1.3 Capitalised terms used in this DPA and not otherwise defined herein shall have the meaning given to them in the Terms & Conditions.

1.4 For the purposes of this DPA, the following terms shall have the following meaning:

  • a) Controller means the Customer, i.e. the entity that determines the purposes and means of the processing of Personal Data under the Agreement. Any person who creates a user account on behalf of the Customer or is authorised by the Customer to access or use the Service is considered a User of the Service and, by doing so, confirms that they are aware of the Customer’s role as Controller, together with the rights and obligations arising from that role, and grants explicit informed consent to this DPA on the Customer’s behalf;
  • b) Processor is the company Sloneek Europe s.r.o., Táborská 8, 040 01 Košice, ID number 53 319 737, a company registered in the Commercial Register kept at the Municipal Court of Košice, section sro, insert 49934 / V (“Company”). The Company may entrust the management and processing of Personal data to a sub-processor for the purpose of operating and administering the Service, in accordance with Article 8 (“Sub-processors”) of this DPA;
  • c) Personal data means any information relating to an identified or identifiable natural person (Data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  • d) Data subject means the natural person to whom Personal data relates, in particular the Controller’s employees, other Users of the Service, as well as any other natural person whose personal data is provided to the Processor by the Controller or a User of the Service in connection with the use of the Service;
  • e) GDPR means Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data;
  • f) Party of the DPA means either Controller or Processor (collectively, the “Parties”).

2. Definition of processed Personal data

2.1 Based on the Agreement, the Processor processes Personal data on behalf of the Controller to the following extent:

Purpose of ProcessingScope of Personal dataSpecial categories of Personal dataCategories of Data subjects
HR agenda managementName and surname of a natural person; date of birth of natural person, sex, job position, internal employee number, work mobile and / or fixed telephone number; work email; photo; the date of joining the company, the date of leaving the company, the type of employment and the type of employment relationship.noemployees
Management of the agenda of holidays and other types of absenceDates of drawing on absence events (holidays, sick days, benefit days, etc. – other events according to the system settings by the employer)noemployees
Registration and calculation of employee meal vouchersThe amount of the right to a meal voucher in a given monthnoemployees
Shift planning, work activity planningDates of work activities based on the definition of activities by the employer (e.g. work in the office, work at the client / customer, etc.)noemployees
Employee attendance recordsIn the case of using the Sloneek mobile application for entering arrival and departure to work (this is an optional functionality), the application stores the GPS coordinates of the mobile device at the time of entering arrival or departure. Records of the employee’s hours worked within his working days.noemployees
Library of labour law documentsThis is a repository of documents in which employees and the employer can store their labour law documents. The user who saved the document is responsible for saving these documents to Sloneek.noemployees
Signing documentsEmployees confirm documents with their electronic signature.noemployees
Administration of the employee’s profileIn addition to the employee’s identification data, the employee can also upload his / her images.noemployees
Google Calendar EventsThe Service automatically handles events recorded in Google Calendar.noemployees
User and application supportData stored in the Sloneek applicationnoemployees
Setting up a trial accountName and surname of a natural person, work email, mobile and / or fixed telephone number.noEmployee setting up a trial account

2.2 The Processor will process Personal data in electronic form in accordance with this Agreement.

2.3 The Processor undertakes to process Personal data with professional care.

3. Independence of the Processor and instructions of the Controller

3.1 The Processor will process Personal data separately in order to achieve the specified purpose of processing according to the Article 2.1. and, with the exercise of professional care, to independently decide on the execution of individual acts within the processing of personal data, which must be performed in accordance with the applicable legal regulations.

3.2 The Processor processes the Personal data only on documented instructions from the Controller, including with regard to transfers of Personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.3 Instructions for the processing of Personal data may be communicated on behalf of the Controller and accepted by the authorized person on behalf of the Processor, in written (electronic) form.

3.4 Processors are not bound by the Controller’s instructions, which are:

  • 3.4.1 made by a person other than the authorized person and addressed to a person other than the authorized person,
  • 3.4.2 made in a form other than written (electronic),
  • 3.4.3 contrary to the applicable law.

3.5 If any case arises where the Processor is not bound by the Controller’s instruction, the Processor is obliged to inform the Controller of such a fact without undue delay.

4. Storage and security of Personal data

4.1 The Processor undertakes to store and process Personal data securely and to use all reasonable security systems and procedures suitable for the processing of Personal data.

4.2 The Processor undertakes to prevent or take all possible steps to prevent unauthorized access, copying, modification, storage, reproduction, publication or distribution of Personal data

4.3 The Processor declares that it has adopted and complies with the technical and organizational measures for the protection of Personal data defined in Annex No. 1 to this DPA.

4.4 If the Processor uses the security elements in connection with the provision of the Services, it is obliged to maintain confidentiality about the security elements, it is not entitled to share them with third parties, transfer or otherwise misuse them.

4.5 The Processor creates backup copies of databases (weekly database backup), we save the last 4 backups. Restoration of data from the backup is charged at 1 200EUR. This fee shall not apply where the need for restoration arises from a failure, error or omission attributable to the Processor.

4.6 In the event that either Party finds that:

  • 4.6.1 there has been an unauthorized or illegal processing of Personal data;
  • 4.6.2 the Personal data has been lost, damaged or destroyed or otherwise degraded;
  • 4.6.3 there has been a case of security breach;
  • 4.6.4 a third party has gained unauthorized access to any of the security features;

it is obliged to notify the other Party without undue delay and to provide maximum co-operation for redress.

4.7 In providing quality Services, we are assisted by processors who work in accordance with European standards of personal data protection. The processing of Personal data by these third parties is governed by their own terms of service.

5. Declarations by Parties

5.1 The Processor declares and warrants to the Controller that

  • 5.1.1 fulfils all legal obligations arising for him from the GDPR and other legal regulations;
  • 5.1.2 will process personal data for the Controller for the entire duration of the Agreement in accordance with the GDPR and applicable national data protection laws implementing the GDPR, including, where applicable, Act No. 18/2018 Coll. on Personal Data Protection, as amended;
  • 5.1.3 will keep proper records of Personal data processing activities within the meaning of Article 30 of the GDPR for the entire duration of the Agreement;
  • 5.1.4 will process only Personal data in relation to defined Data subjects in accordance with this Agreement to the extent and for the purpose specified by the Controller or in accordance with the purpose of this Agreement;
  • 5.1.5 will always process Personal data on the basis of a valid legal ground, in accordance with the Controller’s instructions or as otherwise required by applicable law.

6. Personal data collection Services by the Processor

6.1 The Processor declares to the Controller that

  • 6.1.1 will process accurate Personal data in accordance with this Agreement and will update it regularly. Personal data that are inaccurate with regard to the purposes for which they are processed shall be deleted or corrected by the Processor after the prior instruction of the Controller;
  • 6.1.2 will store Personal data for the necessary time according to the Controller’s instruction. The Processor undertakes to regularly check the deadlines for the liquidation of Personal data and to ensure the liquidation of Personal data, if the conditions are met;
  • 6.1.3 guarantees that during the processing of Personal data on behalf of the Controller it will not act in such a way as to reduce the level of Personal data protection ensured by the GDPR.

7. Declarations by the Controller

7.1 The Controller declares and guarantees to the Processor that:

  • 7.1.1 at the time of the transfer of Personal Data, the Personal Data is current and there is a valid legal title for their processing;
  • 7.1.2 is not aware of any risk of violation of valid legal regulations in connection with the current processing of Personal Data;
  • 7.1.3 agrees to allow further processing of personal data by other processors who undertake to protect personal data to the minimum extent provided for in this contract. To the same extent as regards the purpose of processing and to the minimum extent as regards ensuring the security of the processing of personal data processed.

8. Sub-processors

8.1 The Controller grants the Processor a general written authorisation to engage sub-processors for the processing of Personal data under this DPA.

8.2 The current list of sub-processors, including their category, the purpose of processing, the processing location and, where applicable, the transfer mechanism used for personal data transfers outside the European Economic Area, is published and kept up to date at www.sloneek.com/subprocessors/ (the “List of Sub-processors”).

8.3 By accepting this DPA, the Controller authorises the engagement of all Mandatory and Optional Sub-processors set out in the List of Sub-processors.

8.4 The Processor shall inform the Controller of any intended addition or replacement of a Mandatory or Optional Sub-processor by updating the List of Sub-processors and providing notice through the website, in-app notification, e‑mail or other appropriate communication, giving the Controller the opportunity to object to such change within fifteen (15) days of the notification, on reasonable data protection grounds. If the Controller does not object within this period, the change is deemed accepted. If the Controller objects to the engagement of a Mandatory Sub-processor and the Parties are unable to resolve the objection, either Party may terminate the Agreement in relation to the affected part of the Service.

8.5 In relation to Sub-processors, the Processor shall comply with the requirements of Article 28 of the GDPR.

8.6 The Processor is not liable for the acts or omissions of third-party providers, integrations, application programming interfaces or external services that are not Sub-processors engaged by the Processor but are independently selected, configured or connected by the Controller. The Controller’s use of such third-party services is governed by the Controller’s own agreement with the relevant third party.

9. Cooperation

9.1 Co-operation in fulfilling the Controller’s obligation to respond to requests for the exercise of data subjects’ rights.

9.2 The Processor undertakes to provide the Controller with the necessary cooperation, which can be fairly requested, especially in the case of:

  • 9.2.1 implementation and maintenance of appropriate technical and organizational measures to secure personal data;
  • 9.2.2 security breach reporting;
  • 9.2.3 assessment of the impact of processing on the protection of Personal data, if the Controller decides that an assessment of the impact of processing within the meaning of Article 35 of the GDPR is necessary;
  • 9.2.4 fulfilment of the obligations of prior consultation with the supervisory authority (the Office for Personal Data Protection) within the meaning of Article 36 of the GDPR in the event of legal conditions.

9.3 At the request of the Controller, the Processor undertakes to provide, within a specified period of time, which may not be less than thirty (30) working days, the necessary information necessary to prove that the processing of personal data under the Agreement is carried out in accordance with applicable law.

9.4 The Processor undertakes to allow the Controller and his representatives, at his request, within a reasonable period of time, which may not be less than thirty (30) working days:

  • 9.4.1 access to records on Personal data processing activities;
  • 9.4.2 check the technical and organizational security measures of the Personal data.

10. Duration of processing

10.1 The Parties have agreed that the Processor will process Personal data under this DPA for a definite period of time for the duration of the Agreement on the use of the Service. If the Controller does not continue to use the Service after the end of the trial period, the Processor will process the personal data of the person setting up the trial account within 30 days from the end of the trial period.

10.2 Upon termination of this Agreement, the Processor shall, at the choice of the Controller, delete or return to the Controller all Personal data and delete existing copies thereof, unless applicable Union or Member State law requires storage of the Personal data. The Controller may exercise this choice, including by exporting Personal Data from the Service in a structured, commonly used and machine-readable (standard) format, at any time before the end of the applicable notice period set out in the Terms & Conditions; in the absence of an express instruction from the Controller within that period, the Processor shall delete the Personal data.

11. Confidentiality

11.1 The contracting Parties declare that all data, information and facts related to the performance of this DPA and the provision of Services under this DPA, in particular Personal data processed under the DPA and the technical and organisational security measures implemented by the Processor, constitute confidential information (“Confidential Information”), except for:

  • 11.1.1 information that is or becomes publicly available other than in breach of this DPA;
  • 11.1.2 information held by the relevant Party prior to its receipt from the other Party; and
  • 11.1.2 the text of this DPA and of the Terms & Conditions, which are published by the Processor and do not constitute Confidential Information.

11.2 The Parties undertake not to provide the Confidential Information to a third party and not to use it for any purpose other than the performance of this DPA, except:

  • 11.2.1 to their advisers bound by professional secrecy to the same extent as the Parties; or
  • 11.2.2 to the competent national and other administrative authorities and courts, where the Parties are required by generally binding rules to provide them with this information.

11.8 The Processor undertakes to bind its employees and other associates in a contractual relationship with the Processor who perform activities related to this DPA and its performance and provision of Services under this DPA to confidentiality obligations.

11.9 The obligation of confidentiality under this DPA continues even after the termination of this DPA. The Parties are not entitled to disseminate or use confidential information within the meaning of this DPA in any way after the termination of the DPA or to enable their dissemination or use.

12.1 This DPA is available in Czech and English language versions. In case of any discrepancies between the language versions, the English version shall prevail.

12.2 The Processor has appointed a Data Protection Officer (DPO) in accordance with Article 37 of the GDPR. The DPO can be contacted at jan.verespej@sloneek.com

Last update on 19.9.2026

Annex No. 1 – List of Technical and organizational measures taken to protect Personal data

The Processor implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, in accordance with Article 32 of the GDPR. A detailed, continuously updated description of the specific technical implementation of these measures shall be made available to the Controller upon written request.

Physical and infrastructure security

Measures taken to prevent unauthorised physical access to the premises and facilities where Personal data is processed or stored, and to ensure the resilience of the underlying infrastructure. This includes hosting Personal data with a reputable cloud infrastructure provider within the European Union, together with physical access controls, environmental safeguards and infrastructure redundancy maintained by that provider.

System and network access control

Measures taken to prevent unauthorised access to computer systems and networks. This includes user identification and authentication mechanisms, password policies, encrypted network communication (SSL/TLS) for data in transit, network segmentation, and restricted, logged access to server administration.

Data access control

Measures taken to prevent authorised users from accessing data beyond their authorised access rights, and to prevent unauthorised introduction, reading, copying, modification, or disclosure of data. This includes role-based access control (RBAC), differentiated access rights based on user roles, and token-based session authentication with limited validity.

Encryption

Measures taken to protect the confidentiality and integrity of Personal data. This includes encryption of data at rest in the database layer and encryption of data in transit between the Customer’s or User’s device and the Processor’s servers.

Disclosure and transfer control

Measures taken to prevent unauthorised access, alteration or deletion of data during transfer, and to ensure that all data transfers are secure and, where applicable, logged.

Availability and business continuity

Measures established to ensure the protection of Personal data against accidental loss, destruction or damage. This includes regular backups, the ability to restore systems following an interruption, and monitoring for faults and security incidents.

Access logging and accountability

Measures established to ensure that significant user actions and data operations are recorded, enabling verification of who accessed, entered, modified or deleted specific data and when.

Segregation of processing

Measures established to allow for the separate processing of data collected for different purposes, including segregation of test and production environments.

Organizational measures

Measures established to ensure that only authorised personnel have access to Personal data, based on job function, and that access to systems is subject to internal approval processes. Non-electronic records containing Personal data, if any, are stored in lockable and secured areas.