Data Processing Agreement
(“DPA”, Data Processing Agreement pursuant to Article 28 GDPR)
Version: 1.0
Effective date: 18 April 2026
Who is this document for?
This Data Processing Agreement applies to business clients of SocialPlate (restaurants, venues, catering chains) who, in the course of using the Platform, transfer to it personal data of third parties — in particular photographs containing images of employees, guests, or other natural persons.
In such cases the Client remains the controller of that personal data, and Bytly sp. z o.o. acts as the processor. This Agreement governs that relationship.
Parties to the Agreement
Controller:
The end client using the SocialPlate Platform under the Terms of Service — a natural person conducting business, a legal person, or an organisational unit, identified by the details provided in the Account (hereinafter “Controller” or “Client”).
Processor:
Bytly spółka z ograniczoną odpowiedzialnością
- Registered office: ul. Wolna 11, 42-202 Częstochowa, Poland
- Registration court: District Court in Częstochowa, XVII Commercial Division of the National Court Register
- KRS: 0001135848
- NIP: 9492272400
- REGON: 540044350
- Share capital: PLN 5,000.00
- Contact: kontakt@socialplate.pl
hereinafter “Processor” or “SocialPlate”.
The Controller and the Processor are referred to collectively as the “Parties”.
§ 1. Definitions and acceptance
1.1 Definitions
Capitalised terms have the meanings given to them in the Terms of Service available at socialplate.pl/en/terms, in the Privacy Policy and in the GDPR. In addition:
- GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016
- Personal data — information about an identified or identifiable natural person within the meaning of Article 4(1) GDPR, transferred to the Processor by the Controller in the course of using the Services
- Services — services provided by the Processor to the Controller under the SocialPlate Platform Terms of Service
- Sub-processor — another processor engaged by the Processor to carry out specific processing activities on behalf of the Controller
- Personal data breach — a breach within the meaning of Article 4(12) GDPR
- Principal Agreement — the agreement for the provision of Services concluded under the SocialPlate Terms of Service
1.2 Method of conclusion
This Agreement forms an integral part of the Principal Agreement and enters into force upon acceptance by the Controller — through active confirmation in the Account panel, written acceptance, or actual commencement of use of the Services after the Agreement is published. The Parties may additionally conclude a separate written or electronically signed agreement; in the event of discrepancy, the document signed last shall prevail.
§ 2. Subject-matter and purpose of processing
2.1 Subject-matter
The Controller entrusts the Processor, and the Processor accepts for processing, the Personal data on the terms set out in this Agreement. The scope of entrustment covers operations necessary to perform the activities listed in § 2.2 (content storage, AI description generation, social media publication, statistics provision, Platform maintenance). The Processor shall not process Personal data for its own purposes beyond this Agreement, except for activities necessary to provide the Services, ensure security, fulfil legal obligations, and defend claims.
2.2 Purpose of processing
Personal data are processed solely for the purpose of providing the SocialPlate Services, in particular:
- Storing photographs and content uploaded by the Controller
- Generating post descriptions using artificial intelligence models
- Publishing content on the social media platforms designated by the Controller (Facebook, Instagram)
- Providing statistics and reports on published content
- Maintaining, securing, and backing up the Platform
2.3 Nature of processing and data location
Processing is automated within the IT environment of the Processor and its Sub-processors. It covers operations such as: collection, recording, storage, consultation, use, disclosure by transmission, restriction, erasure, or destruction.
Data location: The primary SaaS application infrastructure (database, file storage, application servers, backups) is located within the European Union. Data does not leave the EEA, except for transfers to Sub-processors outside the EEA listed in Annex 1, for which the safeguards in § 8 apply.
2.4 Duration of entrustment
This Agreement remains in force for the duration of the Principal Agreement. Upon its termination, § 14 (return/erasure of data) applies.
§ 3. Categories of data subjects and types of data
3.1 Categories of data subjects
- Employees and associates of the Controller (persons appearing in operational photographs of the premises, e.g. chefs, service staff)
- Guests of the premises visible in the background of photographs documenting dishes, décor, or atmosphere
- Persons tagged in the Controller's posts (e.g. partners, influencers)
- Followers and persons interacting with published posts, to the extent of statistics provided by Meta
3.2 Types of personal data
- Images (photographs), biometric data only to the extent of general likeness, without elements of biometric identification within the meaning of Article 9(1) GDPR
- First names, surnames, pseudonyms and social media identifiers, where provided in descriptions
- Contact details, where consciously entered by the Controller into post content
- Statistical data supplied by Meta platforms (reach, impressions, interactions, in aggregated or identified form)
Special categories of data (Article 9 GDPR): The Processor does not provide Services in respect of special categories of data (data revealing racial or ethnic origin, opinions, health data, sexual orientation, etc.). The Controller undertakes not to transmit to the Platform content containing such data.
Data of minors: The Controller undertakes not to transmit content enabling identification of persons under 16 years of age without the consent of their parents or legal guardians.
§ 4. Obligations of the Processor (Article 28(3) GDPR)
The Processor undertakes in particular to:
- process Personal data only on documented instructions from the Controller, including with regard to transfers of Personal data to a third country or an international organisation, unless required to do so by EU law or the law of a Member State to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on grounds of public interest
- ensure that persons authorised to process Personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
- implement all measures required pursuant to Article 32 GDPR (see § 6 of this Agreement)
- comply with the conditions for engaging sub-processors pursuant to § 5 of this Agreement
- taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests for exercising the data subject's rights laid down in Chapter III GDPR
- assist the Controller in ensuring compliance with the obligations set out in Articles 32–36 GDPR (security, notification of breaches, communication to data subjects, data protection impact assessments, prior consultation)
- at the choice of the Controller, delete or return all Personal data upon the termination of the provision of services relating to processing, and delete existing copies, unless EU law or the law of a Member State requires storage of the Personal data (see § 14 of this Agreement)
- make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller (see § 9 of this Agreement)
- immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions
- maintain a record of categories of processing activities pursuant to Article 30(2) GDPR
§ 5. Sub-processing
5.1 General authorisation
The Controller grants the Processor general prior authorisation to engage sub-processors within the meaning of Article 28(2) GDPR. The current list of sub-processors constitutes Annex 1 to this Agreement and is published in the Privacy Policy (§ 5.2).
5.2 Notification of changes
The Processor shall inform the Controller of any intended changes regarding the addition or replacement of sub-processors with at least 30 days' notice, by e-mail to the Account address or by notification in the Account panel. During this period the Controller may raise a reasoned objection.
5.3 Effect of objection
In the event of a reasoned objection the Parties shall attempt to find an alternative solution within 30 days. If agreement cannot be reached:
- the Processor may withdraw the planned change (continuing to provide the Services without it), or
- either Party may terminate the relevant part of the Principal Agreement, with the Controller retaining the right to a pro-rata refund of fees for the unused period
5.4 Liability for sub-processors
The Processor shall ensure that the same data protection obligations as those set out in this Agreement are imposed on sub-processors by contract or other legal act. Where a sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that sub-processor's obligations.
§ 6. Security of processing (Article 32 GDPR)
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. In particular the Processor:
Technical measures
- Transmission encryption (TLS 1.2+)
- Encryption of data at rest
- Passwords hashed with a salted hash function (bcrypt/Argon2)
- Regular backups
- Access monitoring and logging
- Separation of dev/staging/prod environments
Organisational measures
- Role-based access control (RBAC)
- Authorisations to process data
- Confidentiality clauses in personnel contracts
- Security and business-continuity policies
- Periodic access reviews
The Processor shall also ensure the ability to restore availability of and access to Personal data in a timely manner in the event of a physical or technical incident, and shall regularly test, assess, and evaluate the effectiveness of technical and organisational measures.
A detailed description of the current technical and organisational measures (TOM) constitutes Annex 2 to this Agreement.
§ 7. Personal data breaches
7.1 Notification to the Controller
The Processor shall notify the Controller of a discovered Personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, so that the Controller can meet its own 72-hour notification deadline to the President of the Personal Data Protection Office (UODO) (Article 33(1) GDPR). Where possible, the Processor shall aim to notify in a shorter period.
7.2 Content of notification
The notification shall contain, to the extent available at the time of notification, the information required by Article 33(3) GDPR, in particular:
- A description of the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned
- The name and contact details of the contact point from whom more information can be obtained
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach
Where full information is not available at the same time, the Processor shall provide it in phases as it becomes available.
7.3 Obligation to notify the supervisory authority
The obligation to notify the breach to the President of the Personal Data Protection Office (Article 33 GDPR) and, where necessary, to communicate the breach to the data subjects (Article 34 GDPR), rests with the Controller. The Processor shall provide appropriate assistance in this regard in accordance with § 4(6) of this Agreement.
§ 8. Transfers of data outside the EEA
Some Sub-processors are established outside the European Economic Area, in particular in the United States (details: Annex 1). Transfers of Personal data to third countries are made only with appropriate safeguards, namely:
- a European Commission adequacy decision (Article 45 GDPR), e.g. the EU–U.S. Data Privacy Framework for certified entities, or
- Standard Contractual Clauses (SCCs) adopted by Commission Decision 2021/914 of 4 June 2021 (Article 46(2)(c) GDPR), supplemented where necessary by additional measures in accordance with CJEU judgment C-311/18 (Schrems II)
A copy of the relevant safeguards shall be made available by the Processor to the Controller upon request.
§ 9. Audits and inspections
9.1 Right to audit
The Controller has the right to carry out an audit of the Processor's compliance with this Agreement no more than once per calendar year, with at least 30 days' prior written or e-mail notice, during the Processor's business hours and in a manner that does not disrupt its operations.
9.2 Extraordinary audit
Irrespective of § 9.1, an audit may be conducted at any time in the event of reasonable suspicion of a breach of this Agreement or the occurrence of a Personal data breach.
9.3 Alternative: documentation and certificates
In order to limit costs for both Parties, the Controller may instead of an audit review:
- a current internal or external security-measures review report
- certificates held by the Processor (e.g. ISO 27001, SOC 2)
- completed security questionnaires
9.4 Audit costs
Audit costs shall be borne by the Controller, unless the audit reveals material breaches on the part of the Processor, in which case the costs shall be borne by the Processor. The Processor may charge the Controller reasonable costs for the involvement of its personnel in connection with the audit, in accordance with its standard rate card.
9.5 Confidentiality
Persons participating in the audit shall be bound to keep confidential information obtained during the audit and may not acquire information constituting the Processor's trade secrets or Personal data of other controllers.
§ 10. Obligations of the Controller
The Controller undertakes to:
- have a valid legal basis (Articles 6 and, where applicable, 9 GDPR) for processing the data transferred to the Processor and for entrusting their processing
- fulfil information obligations towards data subjects (Articles 13–14 GDPR), including informing them of the transfer of their data to the Processor
- not transfer to the Processor special categories of data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR), unless separately agreed with the Processor in written form
- issue instructions to the Processor that comply with the GDPR and other applicable law
- respond promptly to notifications from the Processor, in particular those concerning breaches
- ensure that persons depicted in photographs (employees, guests) have given the necessary consent to the use of their image (as required by applicable law), where such consents are required
§ 11. Liability
11.1 General principle
Each Party shall be liable for its own acts and omissions in accordance with Article 82 GDPR and generally applicable law. Nothing in this Agreement limits liability arising from mandatory provisions of law.
11.2 Limitation of the Processor's liability
Subject to § 11.1 and cases of wilful misconduct or gross negligence, the Processor's total liability under this Agreement and the Principal Agreement, regardless of the legal basis (contractual, tortious, warranty), is limited to the amount of subscription fees paid by the Controller in the 6 months immediately preceding the event giving rise to the damage.
This limitation does not apply to liability towards a Controller who is a consumer or an entrepreneur with consumer rights (to the extent that such a limitation would not be effective against those entities).
Administrative fines (Article 83 GDPR): in the event of a fine imposed by a supervisory authority, the liability of the Party on whose side the infringement occurred is not subject to the limitation in this paragraph; it is settled in accordance with § 11.3 (recourse), subject to the proportionality principle under Article 83(2) GDPR. Clients requiring broader indemnification guarantees may negotiate an additional agreement individually.
11.3 Recourse
Where an administrative fine (Article 83 GDPR) or compensation (Article 82 GDPR) is imposed, the Parties shall apportion liability proportionately to the degree to which each contributed to the infringement.
§ 12. Confidentiality
The Parties undertake to keep confidential all confidential information obtained in connection with the performance of this Agreement, including Personal data, for the duration of the Agreement and for a period of 5 years after its termination. This obligation applies in particular to the employees and associates of the Parties.
§ 13. Term and termination
13.1 Term
This Agreement remains in force for the duration of the Principal Agreement and expires upon its termination.
13.2 Immediate termination
Either Party may terminate this Agreement with immediate effect in the event of a material breach by the other Party that is not remedied within 14 days of written notice.
§ 14. Return / erasure of data
Upon termination of the Services (expiry, termination, or withdrawal from the Principal Agreement), the Processor shall, at the choice of the Controller expressed in writing or through the mechanism in the Account panel within 30 days of termination:
- Return Personal data to the Controller in a structured, commonly used, machine-readable format (e.g. JSON, CSV, ZIP with image files), or
- Erase Personal data together with all copies
In the absence of instructions, the Processor shall erase the data 30 days after termination of the Principal Agreement.
Exceptions to erasure: The Processor is entitled to retain data to the extent and for the period required by mandatory law (in particular tax law, accounting law, and the pursuit or defence of claims until expiry of the applicable limitation period). Once those grounds cease to apply, the data shall be erased.
The Processor shall confirm erasure of the data by e-mail.
§ 15. Final provisions
15.1 Amendments
Amendments to this Agreement require documentary form (e-mail or notification in the Account panel) on pain of invalidity. The Processor shall notify the Controller of a planned change with at least 30 days' notice. Failure to object within 30 days of notification shall be deemed acceptance of the changes.
15.2 Severability
The invalidity of any provision of this Agreement shall not affect the validity of the remaining provisions. The Parties shall replace the invalid provision with a valid provision reflecting the original intent.
15.3 Precedence
In the event of conflict between this Agreement and the Principal Agreement on matters of personal data protection, this Agreement shall prevail. In all other matters, the Principal Agreement shall prevail.
15.4 Governing law and jurisdiction
This Agreement is governed by Polish law. Disputes shall be resolved by the court with jurisdiction over the Processor's registered office, subject to mandatory provisions applicable to consumers.
15.5 Language
This Agreement has been drawn up in Polish. In the event of translation into other languages, the Polish version shall be binding.
15.6 Entire agreement
This Agreement together with the Principal Agreement (Terms of Service), Privacy Policy, and Annexes constitutes the entire agreement of the Parties in respect of the entrustment of personal data processing and supersedes all prior oral and written understandings on that subject.
15.7 Notices
Notices required under this Agreement shall be deemed duly served when sent:
- to the Processor's e-mail address: kontakt@socialplate.pl, and correspondingly to the Controller's e-mail address provided in the Account panel, or
- via notifications in the Account panel (for communications sent by the Processor), or
- by registered post or courier with acknowledgement of receipt, to the registered address of the relevant Party.
Notices regarding Personal data breaches and material changes to Sub-processors shall be sent simultaneously by e-mail and via the Account panel.
15.8 Assignment
Transfer of rights and obligations under this Agreement requires the prior written consent of the other Party, save in the case of transfer by the Processor as part of a sale of the business or an organised part thereof, of which the Processor shall notify the Controller with at least 30 days' notice, with the Controller having the right to terminate.
Annex 1 — List of Sub-processors
The current list of sub-processors is set out in the Privacy Policy § 5.2 (socialplate.pl/en/privacy). As at the effective date of this Agreement it includes:
| Entity | Scope of processing | Location | Transfer basis |
|---|---|---|---|
| Cloud provider (SaaS application) | Application, DB, file and backup hosting | EU | N/A (EEA) |
| Netlify, Inc. | Marketing website and forms hosting | USA | SCC 2021/914 + DPF |
| Simple Analytics B.V. | Traffic analytics (cookie-free) | Netherlands (EEA) | N/A (EEA) |
| PayPro SA (Przelewy24) | Payment processing | Poland | N/A (EEA) |
| Meta Platforms Ireland Ltd. | Graph API integration (FB/IG) | Ireland / USA | SCC 2021/914 + DPF |
| Google Ireland Ltd. | AI, description generation | Ireland / USA | SCC 2021/914 + DPF |
| Accounting office | Bookkeeping, invoices | Poland | N/A (EEA) |
Details of each sub-processor are available on request: kontakt@socialplate.pl.
Annex 2 — Technical and Organisational Measures (TOM)
1. Pseudonymisation and encryption
- TLS 1.2+ transmission encryption for all connections
- At-rest encryption of files on storage discs on the infrastructure providers' side
- Passwords hashed with bcrypt or Argon2 with a unique salt
- Tokenisation and isolation of API access keys for external platforms
2. Confidentiality, integrity, availability and resilience of systems
- Role-based access control (RBAC) and the principle of least privilege
- Two-factor authentication (2FA) for administrative access
- Separated environments (dev / staging / prod)
- Network security: firewalls, DDoS protection from providers
- Security monitoring and alerting
- Access logs retained for ≥ 12 months
3. Restoring availability
- Regular backups (daily for the database, continuous for files)
- Redundancy in cloud infrastructure of providers
- Business continuity plan and recovery procedures
4. Testing and evaluating effectiveness
- Periodic backup restoration tests
- Access rights review at least once per year
- Security updates and system patches
- Vulnerability management in dependencies (dependency scanning)
5. Organisational measures
- Authorisations to process data for every person with access to data
- Written confidentiality commitments (NDA) for employees and contractors
- GDPR and information-security training
- Incident reporting policy (internal whistleblowing)
- Record of processing activities (Article 30 GDPR)
Acceptance of the Agreement
The Controller accepts this Agreement by:
- confirming in the Account panel (checkbox “I accept the Data Processing Agreement”), or
- signing the written version of the Agreement (available on request in PDF format), or
- actually commencing the transfer of data by using the Services after the effective date of this Agreement
To obtain a written version of the Agreement please contact: kontakt@socialplate.pl with the subject “DPA Request”.
© 2026 Bytly sp. z o.o., operator of the SocialPlate platform. All rights reserved.