Data processing agreement
This data processing agreement (the "Agreement") forms part of the contract for the provision of the Viacurso application and applies whenever the Provider, in providing the application, processes personal data for the Customer as a processor under Article 28 of the General Data Protection Regulation (GDPR).
The Provider (processor) is Dominik Žlebek, Company ID (IČO): 14244896, registered address Hlavní 62, 273 42 Stehelčeves, Czech Republic, registered in the Czech Trade Licensing Register, email info@viacurso.com (the "Provider"). The Customer (controller) is the taxi operator, municipality or other entity that uses the application on the basis of the service contract (the "Customer").
Viacurso is the trade name under which the Provider offers the application outside the Czech language; in Czech the same application is offered under the name Můj dispečink. Viacurso is not a separate legal entity — the processor under this Agreement is always Dominik Žlebek, Company ID (IČO) 14244896.
1. Roles of the parties
1.1. The Customer is the controller of the personal data that they enter, store, transfer or otherwise process through the Viacurso application. In relation to this data the Provider is the processor.
1.2. The Customer is responsible for the lawfulness of the processing, for the legal basis, for fulfilling information obligations towards data subjects, and for the instructions given to the Provider.
1.3. The Provider processes personal data only in accordance with this Agreement, the service contract, the settings of the application, the Customer's documented instructions, and the legal obligations that apply to the Provider.
2. Subject matter, duration, nature and purpose of the processing
2.1. The subject matter of the processing is the operation of the Viacurso application and related services, in particular the storage of data and making it available to the Customer's authorised users, backups and restoration, technical support, security and operational monitoring.
2.2. The processing lasts for the duration of the provision of the service and subsequently for the period necessary to erase the data, settle rights and obligations, restore from backups or fulfil legal obligations (see Article 9).
2.3. The nature of the processing includes storage, transmission, making available within the application, backup, restoration, deletion, availability monitoring, security logging and the technical operations necessary for the operation of the service.
2.4. The purpose of the processing is to enable the Customer to manage the operation of a taxi service (ride orders, assignment to drivers, records of customers and vehicles, reports) on the Provider's infrastructure, and to provide related technical support. The Provider does not use the data for any purpose of its own.
3. Categories of data and data subjects
3.1. The types of personal data are determined by the Customer according to what they enter into the application. Typically these are:
- transport clients (passengers): name, phone number, addresses
(including favourites), notes about transport and the monthly ride limit. The notes may contain information about health status or aids ("walking frame", "wheelchair", "hard of hearing", for example), and therefore special categories of personal data under Article 9 of the GDPR — the Customer decides on entering them and on the legal basis;
- users of the application at the Customer (dispatchers, drivers,
observers): name, username, email, role, and for drivers the position of the vehicle when sharing is switched on;
- call records (where telephony is switched on): phone number, time
and length of the call, and any link to a ride.
3.2. The categories of data subjects are determined by the Customer; these are in particular passengers (clients of the taxi service), employees or collaborators of the Customer, and persons whom the Customer enters into the application.
3.3. The Provider is not obliged to examine the content of the Customer's data and cannot assess whether the Customer stores special categories of personal data or data requiring a special legal regime in the application.
4. The Customer's instructions
4.1. The service contract, this Agreement, the settings made in the application, orders for services and written communication from the Customer to the Provider are deemed to be documented instructions. Use of the application itself is deemed to be an instruction to process data to the extent of its features.
4.2. If the Provider believes that an instruction infringes the GDPR or other legal regulations, it will notify the Customer, unless a legal regulation prevents it from doing so.
4.3. The Provider may refuse or suspend an instruction that would endanger security, the rights of third parties, the operation of the service or the Provider's legal obligations.
5. The Provider's obligations
5.1. The Provider will ensure that persons authorised to process personal data are bound by confidentiality or by an appropriate statutory obligation of confidentiality.
5.2. The Provider will implement technical and organisational measures appropriate to the risk, in particular:
- encrypted transmission (HTTPS) between the user and the application;
- role-based access control enforced on the server, including the option
to hide clients' contact details from the observer role;
- storage of passwords solely in an unreadable form using a modern
one-way method (argon2), and a limit on the number of sign-in attempts;
- an audit record of access and sensitive operations (who, what, when);
- daily automatic encrypted backups with verified restoration and
their rotation;
- automatic deletion of operational records (vehicle positions after 24
hours, call records after 90 days by default, audit records after 1 year);
- exclusion of personal data from operational logs;
- operation on a server in the Czech Republic.
5.3. The Provider will assist the Customer to a reasonable extent in fulfilling obligations relating to the rights of data subjects, security, notification of incidents, data protection impact assessment and consultations with the supervisory authority, taking into account the nature of the service and the information available to the Provider.
5.4. If a data subject's request concerns data that the Provider processes for the Customer, the Provider will pass it on to the Customer, or refer the data subject to the Customer as controller.
6. Sub-processors
6.1. The Customer grants the Provider general authorisation to engage other processors. The Provider will impose on sub-processors data protection obligations corresponding to this Agreement. If a sub-processor fails to fulfil its obligations, the Provider remains liable to the Customer for their performance.
6.2. The application's data (the content that the Customer enters into the application or operates within it, in particular the data of transport clients) is stored solely on the servers of a web hosting provider operated in a data centre in the Czech Republic. The application's data is not passed on to email or payment suppliers. The Provider uses in particular the following sub-processors:
| Sub-processor | Purpose | Data | Note |
|---|---|---|---|
| Roští.cz (web hosting) | Server operation, storage, backups | All application data | Servers in the Czech Republic; principal sub-processor |
| Provider of the Provider's email account | Delivery of emails (enquiry confirmation, password recovery, operational notifications) | Email addresses and the content of the messages sent | The content of the application database is not passed on |
6.3. With the email supplier, only the data needed to deliver the message concerned is processed (for example the email address of the Customer's user during password recovery). The subscription for the service is paid by bank transfer to the Provider's account; in doing so the Provider's bank processes the usual payment data (the payer's account number, the amount, the reference number) as a separate controller under the Payments Act, not as a sub-processor. The data of transport clients stored in the application is not passed on to the email supplier or to the bank.
6.4. The Provider will inform the Customer in an appropriate manner in advance of any material change of sub-processor. The Customer may raise a reasoned objection to the change; if the parties do not resolve it, the Customer may terminate the service concerned.
7. Security and incidents
7.1. The Provider protects the Customer's data against unauthorised or accidental access, alteration, loss, destruction and unauthorised disclosure, appropriately to the risk and the nature of the service (see the measures in Article 5.2).
7.2. If the Provider discovers a breach of the security of personal data processed for the Customer, it will notify the Customer without undue delay after becoming aware of it, and no later than within 48 hours, and will provide the Customer with the information available to the Provider.
7.3. The Customer is responsible for the security of their user accounts and access credentials, and for who is given access in the application and in what role. The Provider is not liable for an incident caused by the Customer's conduct or instruction, unless the Provider has itself breached its obligations as processor.
8. Audits and demonstrating compliance
8.1. The Provider will provide the Customer with information reasonably necessary to demonstrate compliance with the obligations under Article 28 of the GDPR, in particular a description of the technical and organisational measures, processes and sub-processors.
8.2. An audit or inspection must be agreed in advance, must not disproportionately endanger security, the confidentiality of other customers' data or the operation of the service, and may be subject to confidentiality. Where an audit is not prompted by a breach of the Provider's obligations, the Provider may require reimbursement of reasonable costs.
9. Return and erasure of data
9.1. The Customer may export their data from the application at any time using the application's own tools (monthly reports in PDF/XLSX, for example). After the service ends, the Customer is obliged to carry out the export in good time.
9.2. After the service ends, the Provider will, on the Customer's instruction, hand over the data and subsequently delete the application's active data. Backups are deleted in the normal backup cycle, at the latest within 60 days, unless a legal obligation or a security incident requires longer storage.
9.3. Where a legal regulation requires certain data to be retained, the Provider will retain it only to the necessary extent and for the necessary period.
10. Transfers outside the EU/EEA
10.1. The Provider will not transfer personal data processed for the Customer outside the EU/EEA. All application data is stored on a server in the Czech Republic and the Provider does not use foreign cloud or analytics services.
11. Final provisions
11.1. This Agreement is binding for as long as the Provider processes personal data for the Customer as a processor.
11.2. In matters not governed by this Agreement, the service contract and the GDPR apply. In the event of a conflict, this Data processing agreement prevails for the processing of personal data on the Customer's instructions.
11.3. This Data processing agreement forms an integral part of the terms and conditions of the Viacurso service and is concluded electronically together with them by ordering or using the service; a separately signed copy is not required. The current wording is always available on this page.