Last updated: 2025.10.31
This Data Processing Agreement ("Agreement") forms part of the Terms of Service between the customer ("Controller") and Nodim (Tibor Tasi as representative), 1092 Budapest, Erkel street 14/A A/5/2, Hungary ("Processor"), together referred to as the "Parties".
This Agreement governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of Subtrakr ("Service").
For the purposes of this Agreement:
This Agreement governs the processing of Personal Data by the Processor in connection with providing the Subtrakr Service.
Processing begins when the Controller starts using the Service and continues until the Controller's account is deleted or terminated, including data deletion and backup retention as described in this Agreement.
The Processor will process Personal Data solely for the following purposes:
No processing will occur beyond these purposes unless required by law or explicitly authorized by the Controller.
Personal Data processed:
Categories of data subjects:
The Service does not process special categories of data (sensitive data) as defined under Article 9 of the GDPR.
The Processor agrees to:
The Processor shall not use Personal Data for its own purposes.
The Processor implements appropriate security measures to ensure the protection of Personal Data, including:
The Processor regularly reviews and updates these measures to maintain compliance with Article 32 of the GDPR.
The Controller authorizes the Processor to engage the following subprocessors to provide parts of the Service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting, database, and CDN | EU |
| Brevo | Email delivery | EU |
| Stripe | Payment processing | EU/US |
| Google Analytics | Usage analytics | Global |
| Microsoft Clarity | Session analytics | Global |
| Google Tag Manager | Tag management | Global |
| Facebook Pixel | Marketing analytics | Global |
| Headway | Product update notifications | EU/US |
| Featurebase | Feedback collection | EU/US |
The Processor may update this list by adding or replacing subprocessors. The Processor will notify Controllers of such changes in advance (e.g., via email or in-app notice). Controllers may object to the change if they have a justified reason related to data protection.
Personal Data is retained for as long as necessary to provide the Service.
When the Controller deletes their account or terminates the Service:
The Processor will assist the Controller in fulfilling obligations related to data subject requests under GDPR Articles 12–23, including:
Requests from data subjects received directly by the Processor will be forwarded to the Controller without undue delay.
In the event of a Personal Data breach, the Processor will:
The Processor's total liability arising under this Agreement shall not exceed the total amount paid by the Controller for the Service in the 12 months preceding the event giving rise to the claim.
Nothing in this Agreement limits liability for intentional or grossly negligent acts.
This Agreement is governed by the laws of Hungary.
Any disputes arising from or relating to this Agreement shall be resolved in English, in accordance with the arbitration clause defined in the Terms of Service.
This Agreement remains in effect as long as the Processor processes Personal Data on behalf of the Controller.
Upon termination, all data processing shall cease, and Personal Data will be deleted or returned as outlined above.
For privacy and data protection matters, please contact:
🏠 Nodim (Tibor Tasi as representative)
1092 Budapest, Erkel street 14/A A/5/2, Hungary