Data Processing Agreement
Last updated: 27 August 2026
This standard agreement governs cases where sajdoko:: processes personal data for a client during development, hosting, maintenance or technical support.
1. Parties, roles and processing
The client is the “Controller” and sajdoko:: is the “Processor”, unless the project document states otherwise. Each party meets its obligations under Albanian Law no. 124/2024 on personal-data protection and, where applicable, the GDPR.
| Subject matter and duration | The services and period specified in the project document. |
|---|---|
| Nature and purpose | Development, migration, testing, hosting, backup, maintenance, support or other described work. |
| Data categories | Contact, account and technical data, form contents, and other categories identified by the client. |
| Data subjects | Visitors, customers, users, employees, contractors or other people identified by the client. |
The client confirms that its instructions, data and purposes are lawful and that it has supplied required information to data subjects.
2. Instructions, purpose limitation and personnel
We process and transfer personal data only on the client’s documented instructions, including the agreement, quote, support requests and approved configuration. If law requires other processing, we notify the client beforehand where legally permitted.
People with access receive only the access they need, follow instructions and remain bound by confidentiality after their engagement ends.
3. Technical and organisational measures
We apply measures appropriate to the risk and project scope, which may include:
- individual access, least privilege and strong authentication;
- encryption in transit and, where infrastructure supports it, at rest;
- security updates, network protection and technical logging;
- backup and restoration only where included in the ordered service;
- access reviews, incident handling and secure deletion;
- environment separation and avoiding live personal data in testing where practical.
Specific frequencies and boundaries are documented in the quote, architecture or service levels.
4. Subprocessors and transfers
The client gives general written authorisation for subprocessors identified in the subprocessor list and project document. We provide prior notice of additions or replacements and a reasonable opportunity to object on data-protection grounds.
Each subprocessor receives protection obligations no less protective for the relevant service. We remain responsible to the client for their performance. International transfers occur only with a lawful basis and safeguards permitted by applicable law.
5. Rights, compliance and incidents
Taking account of the processing and information available to us, we assist the client with:
- requests for access, correction, deletion, restriction, objection or portability;
- impact assessments and regulator consultation where required;
- security, documentation and information needed to demonstrate compliance.
We notify the client without undue delay after becoming aware of a breach affecting client data and provide available information about its nature, effects and mitigation. The client decides and makes its legal notifications as controller unless it has authorised us otherwise in writing.
6. Return, export and deletion
After services end, at the client’s choice, we return or delete the personal data and copies under our control unless law requires retention. Export format, timing, backups and migration costs are defined in the quote or exit plan.
7. Information, audit and precedence
We provide reasonable information demonstrating compliance and cooperate with necessary audits on notice, during business hours and without compromising security, confidentiality or other clients. Costs and procedure are defined in the project agreement, unless an audit establishes our material breach.
If an instruction appears to breach data-protection law, we notify the client and may pause it while the issue is clarified. In a conflict, this DPA prevails for processing matters; the project document prevails for the specific service description.
To incorporate this DPA into a project, email [email protected].