DPA — Data processing agreement
Version 1.0 · Effective 2026-09-20
This document is a data processing agreement (Art. 28 GDPR) between:
- Controller — the Customer using AXON Cloud (your company)
- Processor — AXON Cloud (AXON Cloud), — (adresa operatera / operator address), OIB —
It applies automatically to AXON Cloud as SaaS unless you signed a separate DPA.
1. Subject and duration
The Processor processes personal data only to provide the ERP / SaaS service, for the contract term and a reasonable period after (export / deletion).
2. Nature and purpose
Hosting, storage, display, export, backup and support for data the Controller enters into modules (e.g. partners, HR, RAC, hospitality, CRM, accounting).
3. Types of data and data subjects
Depending on modules: identity and contact data, contractual / accounting data, employees, guests, members, drivers / renters, etc. — as determined and entered by the Controller.
4. Processor obligations
The Processor shall:
- process data only on the Controller’s documented instructions (use of the software = instructions)
- ensure confidentiality of authorised persons
- implement appropriate technical and organisational measures — see Security
- engage sub-processors (hosting, email, backup) under equivalent duties; list on request
- assist with data-subject rights to a reasonable extent
- assist with security and breach notification
- delete or return data after end of service, per instructions and law
- make available information needed to demonstrate compliance (reasonable audit)
5. Controller obligations
The Controller warrants a lawful basis for entering data, informs data subjects, and will not instruct processing contrary to the GDPR.
6. International transfers
If the Processor or a sub-processor transfers data outside the EEA, a lawful transfer mechanism is used.
7. Contact
DPA / privacy: [email protected] · [email protected]
For a signed DPA PDF or sub-processor list: [email protected]