Data Processing Agreement (DPA)
Last updated: July 29, 2026
This Data Processing Agreement governs the processing of personal data carried out by Povoljni Sajtovi ("Processor") on behalf of the customer ("Controller") when delivering MaxDesign SEO services and platform access. It forms part of the Terms of Service.
1. Roles of the parties
The Controller determines the purposes and means of processing. The Processor processes personal data only on documented instructions from the Controller, including transfers to third countries, unless required to do otherwise by Serbian or EU law.
2. Subject matter, duration and nature of processing
Processing covers SEO analytics, content generation, reporting and publication management. It lasts for the duration of the agreement, extended by the backup retention period described in section 8.
3. Types of data and categories of data subjects
- Account contact data: name, business email, role, interface language.
- Technical data: IP address, sign-in time, session identifier, action logs.
- Content supplied by the Controller: URLs, keywords, copy, media files.
- Aggregated analytics about visitors to the Controller's websites (GA4, Search Console).
- Categories of data subjects: the Controller's staff and contractors, and visitors to the Controller's websites.
4. Processor obligations
- Process data only on the Controller's instructions and flag instructions believed to infringe applicable law.
- Ensure persons authorised to process data are bound by confidentiality.
- Implement the technical and organisational measures listed in section 5.
- Assist the Controller with data subject requests and data protection impact assessments.
- Delete or return all personal data at the Controller's choice when services end.
- Make available the information needed to demonstrate compliance and allow audits.
5. Technical and organisational measures
- Encryption in transit (TLS 1.2+) and encryption of sensitive database fields.
- Role-based access control with separate zones for internal operators and customer accounts.
- Two-factor authentication for internal administrative accounts.
- Audit logging with timestamps and user identity.
- Regular database backups and restore testing.
- Automated vulnerability scanning of application dependencies.
- Application-level tenant isolation with mandatory tenant scoping on data access.
6. Sub-processors
The Controller grants general written authorisation for the use of sub-processors. The Processor notifies the Controller of any intended change at least 30 days in advance, and the Controller may object.
Current sub-processors: EU infrastructure provider (Germany), transactional email provider, payment provider, AI model providers used for content generation, and analytics providers.
7. International transfers
Data is primarily processed on infrastructure located in the European Union. Where a transfer to a third country is necessary, it relies on Standard Contractual Clauses or another appropriate safeguard.
8. Retention
Operational data is retained for the term of the agreement. After termination, data is deleted within 30 days, and backups rotate out no later than 90 days.
9. Personal data breaches
The Processor notifies the Controller without undue delay and at the latest within 48 hours of becoming aware of a personal data breach, describing its nature, likely consequences and the measures taken.
10. Audit
The Controller may audit once per calendar year with 30 days' notice, during business hours and without disrupting the Processor's operations. Costs of additional audits are borne by the Controller.
11. Contact
Data protection enquiries: office@maxdesign.rs.