WebConcept
Webconcept
Features How it Works Pricing Contact
EN|
Sign inGet Started
EN|

Legal

  • Terms of Service
  • Privacy Statement
  • Withdrawal
  • Data Processing Agreement

Data Processing Agreement

Version 1.0effective 1 October 2026

This English version is provided for convenience. The Polish version is the binding one and prevails in case of any discrepancy.

The data processing agreement (hereinafter: the "DPA") sets out the rules under which the Service Provider processes, on behalf of the Customer, personal data collected through the Customer Site, in particular data from the contact form. It is the agreement referred to in Article 28(3) of the GDPR.

Capitalised terms not defined in the DPA have the meaning given to them in the WebConcept Terms of Service (hereinafter: the "Terms").

I. Parties and conclusion of the agreement

  1. The DPA is concluded between:
    • a)CyberGorilla Sp. z o.o. with its registered office in Warsaw, address: ul. Marszałkowska 58, 00-545 Warszawa, Poland, entered in the register of entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division of the National Court Register under KRS number: 0001148248, NIP: 7011240065, REGON: 540611381, share capital: PLN 5,000, e-mail address: [email protected] – the Service Provider, acting as the Processor;
    • b)the Customer who has accepted the Terms – acting as the Controller.
  2. The DPA is concluded in electronic form upon acceptance of the Terms, forms part of the Agreement and remains in force for as long as the Customer holds an Account. As regards the processing of the Entrusted Data, the DPA prevails over the Terms.
  3. The terms used in the DPA have the following meanings:
    • a)Entrusted Data – personal data for which the Customer is the controller, processed by the Service Provider solely on behalf of the Customer: data collected through the Customer Site and personal data placed by the Customer in the Customer Content;
    • b)End User – a natural person visiting the Customer Site or transmitting data through it;
    • c)Sub-processor – an entity whose services the Service Provider uses in processing the Entrusted Data;
    • d)GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
  4. The DPA does not cover personal data for which the Service Provider is the controller, in particular data relating to the Account, payments and correspondence with the Customer. The rules for processing such data are set out in the Privacy Statement.
  5. The English version of the DPA is for information purposes; the Polish version is binding.

II. Subject matter, nature, purpose and duration of the processing

  1. The Controller entrusts the Processor with the processing of the Entrusted Data solely for the purpose of performing the Agreement, that is: publishing and maintaining (hosting) the Customer Site, storing and displaying the Customer Content, receiving and storing contact-form submissions, making a data export available to the Controller, making backups, providing technical support and ensuring the security of the Services. The processing is automated and comprises recording, storing, making available to the Controller and erasing data.
  2. The processing lasts for the term of the Agreement and ends in accordance with Chapter IV section 8.
  3. Contact-form submissions are saved in the database of the Customer Site. The Controller accesses them through the data export in the Panel (a ZIP archive with the submissions in a CSV file); submissions are not sent by e-mail. Individual submissions are erased on the Controller's instruction, and all of them – together with the deletion of the Customer Site.
  4. The Processor does not process the Entrusted Data for its own purposes, in particular for marketing purposes or for training artificial intelligence models. End Users' data are not transferred to providers of artificial intelligence systems.

III. Type of data and categories of data subjects

  1. The Entrusted Data concern:
    • a)End Users, in particular persons sending the contact form;
    • b)persons whose data the Controller has placed in the Customer Content;
    • c)persons editing the Customer Site on behalf of the Controller.
  2. The Entrusted Data comprise:
    • a)contact-form data: first name and surname or name, e-mail address, the content of the message and any data provided in it;
    • b)data contained in the Customer Content, in particular first names and surnames, positions, contact details and image;
    • c)End Users' IP addresses – processed transiently for security purposes, including the application of submission limits; the IP address is not saved with the submission;
    • d)the identifier of the person making a content change, saved in the change history of the Customer Site.
  3. The entrustment does not cover special categories of personal data (Article 9(1) of the GDPR) or data relating to criminal convictions and offences (Article 10 of the GDPR). The Controller undertakes not to collect them through the Customer Site.

IV. Obligations of the Processor

  1. The Processor processes the Entrusted Data only on documented instructions from the Controller, including with regard to transfers of data to a third country, unless required to process them by European Union or Polish law. The Processor informs the Controller of such a requirement before processing, unless that law prohibits it. The documented instructions are: the Terms, the DPA, the Controller's settings and actions in the Panel, and instructions sent to [email protected] from the address assigned to the Account.
  2. The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
  3. The Processor ensures that persons authorised to process the Entrusted Data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
  4. The Processor applies the measures required pursuant to Article 32 of the GDPR, described in Annex 2. It may change them provided that this does not lower the level of protection. The Controller considers these measures appropriate for the Entrusted Data.
  5. The Processor assists the Controller in fulfilling its obligation to respond to requests from data subjects, to the extent justified by the nature of the processing and the information available. A request addressed directly to the Processor is forwarded to the Controller without undue delay and is not answered by the Processor itself.
  6. To the same extent, the Processor assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 of the GDPR.
  7. The Processor notifies the Controller of a breach of the Entrusted Data without undue delay after becoming aware of it, at the e-mail address assigned to the Account, providing the information referred to in Article 33(3) of the GDPR to the extent it holds it. Notification of the breach to the supervisory authority and communication to data subjects are made by the Controller.
  8. The Processor erases the Entrusted Data together with the deletion of the Account or of the Customer Site, as set out in the Terms, unless European Union or Polish law requires their storage. Data recorded in backups are overwritten in the backup rotation cycle. Before that, the Controller may obtain the return of the data by downloading the data export in the Panel.
  9. The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it. An audit is announced with reasonable notice, takes place at the Controller's cost, not more than once a year unless a breach of the Entrusted Data has occurred, under confidentiality and without access to other customers' data.

V. Obligations of the Controller

  1. The Controller declares that it has a legal basis for processing the Entrusted Data.
  2. The Controller fulfils towards End Users the information obligations under Articles 13 and 14 of the GDPR, in particular by publishing its own data processing notice on the Customer Site, and responds to requests from data subjects.
  3. The Controller keeps the e-mail address assigned to the Account up to date; information provided for in the DPA is sent to that address.

VI. Sub-processors

  1. The Controller gives the Processor general authorisation to engage Sub-processors. Their current list is set out in Annex 1.
  2. The Processor informs the Controller of its intention to add or replace a Sub-processor by e-mail or in the Panel at least 14 days before the change. Before that period expires, the Controller may object by writing to [email protected]; the absence of an objection means acceptance of the change. If the objection cannot be accommodated, the Controller may terminate the Agreement as set out in the Terms. An update of Annex 1 made in this manner does not constitute an amendment of the DPA.
  3. The Processor imposes on each Sub-processor, by way of a contract, the same data protection obligations as those arising from the DPA and remains fully liable to the Controller for the performance of that Sub-processor's obligations.
  4. Providers that do not process the Entrusted Data, in particular the payment operator and the external-account sign-in provider, are not Sub-processors.

VII. Transfers of data outside the European Economic Area

  1. The servers on which the Customer Sites and their databases are maintained are located in the European Economic Area (EEA).
  2. Sub-processors established in the United States, indicated in Annex 1, may process the Entrusted Data outside the EEA. A transfer takes place only in accordance with Chapter V of the GDPR: on the basis of the European Commission's adequacy decision of 10 July 2023 (EU–US Data Privacy Framework) – where the entity participates in that programme, and otherwise on the basis of standard contractual clauses (Article 46(2)(c) of the GDPR).

VIII. Final provisions

  1. The liability of the parties towards data subjects is governed by Article 82 of the GDPR. As between the parties, liability is subject to the rules set out in the Terms.
  2. The DPA is amended in the manner provided for in the Terms for amending the Terms. In matters not regulated herein, the Terms apply, including as to governing law and jurisdiction.
  3. The DPA enters into force on 1 October 2026. Annexes 1 and 2 form part of it.

Annex 1 – List of sub-processors

List current as at 1 October 2026. The basis for transfers of data outside the EEA is set out in Chapter VII section 2.

Entity Scope of processing Location
OVH Sp. z o.o. (Wrocław, Poland) and OVH GmbH (Cologne, Germany) Servers on which the Customer Sites and their databases are maintained; all Entrusted Data Warsaw (Poland) and Germany – EEA
Cloudflare, Inc. (United States) DNS and the proxy layer for traffic to the Customer Site (including End Users' IP addresses); object storage for image files, export files and database backups Global infrastructure, including outside the EEA
GitHub, Inc. (United States) Private repository of the Customer Site's code with the texts and image files from the time of its creation, which may contain personal data provided by the Controller; form submissions do not reach it Global infrastructure, including outside the EEA
Anthropic, PBC (United States) The Brief only – to the extent the Controller has placed other persons' personal data in it; End Users' data are not transferred United States

Annex 2 – Technical and organisational measures

  1. Connections to the Customer Site and to the Panel are encrypted with TLS.
  2. The data of each Customer Site are stored in a separate database schema. The application uses the database through a role that cannot change its structure; the role for structural changes is separate.
  3. Access to the Panel and to editing the Customer Site requires authentication. Passwords are stored only as hashes computed with a password-hashing algorithm, and sessions rely on signed tokens with a limited validity period.
  4. The object storage is not publicly accessible; files are retrieved only through the application.
  5. Content saved on the Customer Site is checked against a list of allowed elements, and uploaded image files are re-encoded, which removes their metadata, including location data.
  6. The contact form is protected by a hidden honeypot field against bots and by submission limits counted per IP address and per Customer Site. These mechanisms reduce abuse but do not rule it out.
  7. The databases are covered by a periodic backup, stored in object storage without public access and rotated; restoring data from a backup has been tested. Files in the object storage are not additionally backed up.
  8. Access to the production infrastructure is limited to persons authorised by the Processor.
  9. The Processor maintains the record of categories of processing activities referred to in Article 30(2) of the GDPR.
WebConcept

AI website builder. Describe your business and AI builds a complete site. No coding, hosting included.

Product

  • Features
  • How it Works
  • Pricing
  • What is WebConcept?

Company

  • About
  • Contact

Legal

  • Terms of Service
  • Privacy Statement
  • Withdrawal
  • Data Processing Agreement

© 2026 WebConcept. All rights reserved.

Made with AI

WEBCONCEPT