Section 01
Roles of the parties
The Customer is the "controller" of personal data submitted to the Digisto service, and Digisto is the "processor" acting on the Customer's documented instructions. Where Digisto engages sub-processors, they act as sub-processors of Digisto.
Section 02
Scope & duration
This DPA applies for the duration of the Customer's subscription and covers all personal data submitted by or on behalf of the Customer through the service.
Section 03
Sub-processors
Digisto maintains an up-to-date list of authorized sub-processors on our Trust page. Customers may subscribe to change notifications and have 30 days to object to any new sub-processor.
Section 04
International transfers
For personal data transferred out of the EEA, UK, or Switzerland, the parties incorporate the applicable Standard Contractual Clauses (2021/914) and UK Addendum by reference. Digisto maintains transfer impact assessments for each sub-processor located in a third country.
Section 05
Security measures
Digisto implements industry-standard technical and organizational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control and mandatory 2FA for staff.
- Annual penetration testing and continuous vulnerability scanning.
- Employee background checks and security awareness training.
Section 06
Breach notification
Digisto will notify the Customer without undue delay, and no later than 72 hours, after becoming aware of a personal data breach affecting Customer data, providing information reasonably available at the time of notification.
Section 07
Audit rights
Digisto provides SOC 2 Type II and ISO 27001 reports on request under NDA. Customers may conduct additional audits no more than once per year, subject to reasonable notice and Digisto's security and confidentiality requirements.
Section 08
Assistance to the controller
Digisto provides reasonable assistance to the Customer in responding to data-subject requests, conducting data-protection impact assessments, and consulting with supervisory authorities.
Section 09
Return & deletion of data
Upon termination, Digisto deletes or returns all Customer personal data within 30 days, unless retention is required by law. Backups are purged on a rolling 35-day window.
Section 10
How to sign
This DPA is pre-executed by Digisto and incorporated by reference into every paid subscription. A counter-signed PDF is available on request at legal@digisto.si.
Questions about this document? Email legal@digisto.si or reach out via our contact page.