Imvora Data Processing Agreement
Effective date: 9.8.2026
This Data Processing Agreement (“DPA”) forms part of the Imvora Terms of Service between SAXA Real Košice s.r.o., Pri Teleku 1522/12, Košice - mestská časť Krásna, 04018, Slovakia (SK), 57459363 (“Imvora” or “Processor”) and the Customer accepting the Terms (“Controller”). It applies where Imvora processes Personal Data contained in Customer Data on behalf of the Controller in connection with the Service.
1. Definitions and scope
“GDPR” means Regulation (EU) 2016/679. “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given in the GDPR.
The subject matter, duration, nature, and purposes of processing, and the types of Personal Data and Data Subjects, are set out in Annex 1. This DPA applies for the duration of the Terms and until Personal Data is returned or deleted under clause 8.
2. Instructions and controller responsibilities
Imvora will process Personal Data only on documented instructions from the Controller, including the Terms, this DPA, and the Controller’s use of the Service, unless EU or Member State law requires otherwise. In that case, Imvora will inform the Controller before processing unless prohibited by law. Imvora will promptly notify the Controller if, in its opinion, an instruction infringes GDPR or other applicable data-protection law.
The Controller is responsible for the lawfulness of Personal Data and its instructions, providing required privacy notices, establishing a lawful basis, handling data-subject rights, and ensuring that its authorized users use the Service lawfully. The Controller must not instruct Imvora to process special-category data, criminal-offence data, or children’s data unless it has first obtained Imvora’s written agreement and supplied suitable safeguards.
3. Confidentiality and security
Imvora will ensure that persons authorized to process Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality. Imvora will implement appropriate technical and organizational measures required by GDPR Article 32, taking account of the state of the art, implementation cost, and the nature, scope, context, and purposes of processing and the risks to individuals. These measures are described in Annex 2 and may be updated, provided that the overall level of protection is not materially diminished.
4. Assistance and breach notification
Taking into account the nature of processing, Imvora will provide reasonable assistance through appropriate technical and organizational measures to help the Controller respond to requests by Data Subjects under GDPR Chapter III. Imvora will provide reasonable information and assistance for the Controller’s security, breach, DPIA, and prior-consultation obligations under GDPR Articles 32–36, to the extent required by law and taking account of the information available to Imvora.
Imvora will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Data and will provide information reasonably available to it to help the Controller meet its notification obligations. Imvora will not communicate with Data Subjects about such a breach except as instructed by the Controller or required by law.
5. Subprocessors
The Controller gives Imvora general written authorization to use the subprocessors in Annex 3. Imvora will impose data-protection obligations on each subprocessor that are materially consistent with this DPA. Imvora remains responsible for its subprocessors’ obligations to the extent required by GDPR.
Imvora may appoint or replace a subprocessor by giving at least 30 days’ prior notice by email or through the Service, except for urgent security, legal, or service-continuity reasons. The Controller may object in writing on reasonable data-protection grounds during that period. The parties will work in good faith on a solution. If no reasonable solution is available, the Controller may terminate the affected Service before the change takes effect and receive a refund of prepaid fees for the unused portion of that affected Service, unless the change is required for urgent security, law, or continuity.
6. International transfers
Imvora will not transfer Personal Data outside the EEA except on the Controller’s documented instructions or where permitted by GDPR Chapter V. Where a transfer requires an appropriate safeguard, the parties will use the applicable European Commission Standard Contractual Clauses or another valid transfer mechanism. The Controller authorizes transfers by Imvora and approved subprocessors that are necessary to provide the Service and comply with this clause.
7. Information, audits, and regulatory requests
On reasonable written request and subject to confidentiality, Imvora will make available information reasonably necessary to demonstrate compliance with this DPA. No more than once per 12-month period, the Controller may audit Imvora’s relevant processing controls on at least 30 days’ notice, during normal business hours, without unreasonable disruption, and at the Controller’s cost. Imvora may satisfy an audit request with current independent audit reports or equivalent documentation where sufficient. Audits must not access other customers’ data or compromise security.
If Imvora receives a request from a supervisory authority or a legally binding request for Customer Data, it will notify the Controller where legally permitted and reasonably practicable, and will not respond except as legally required or authorized by the Controller.
8. Return and deletion
At the Controller’s choice and upon termination of the Service or the Controller’s written request to [hello@imvora.app], Imvora will delete or return Customer Data, unless applicable law requires storage. Deletion from active systems will occur within [30 days] of the applicable request or termination. Personal Data may remain in encrypted backups until overwritten under Imvora’s ordinary backup cycle, not exceeding [90 days], and will not be actively processed except for restoration, security, or legal purposes.
9. Precedence and liability
If this DPA conflicts with the Terms regarding processing of Personal Data, this DPA prevails. Liability under this DPA is subject to the liability provisions in the Terms, except where GDPR requires otherwise.
Annex 1 — Processing details
Subject matter and duration. Provision, hosting, security, maintenance, and support of the Imvora CRM for the term of the Customer’s subscription and the deletion/backup period in clause 8.
Nature and purpose. Collection, storage, organization, consultation, use, transmission as directed by authorized users, support, security monitoring, troubleshooting, and deletion of Customer Data to provide the CRM.
Categories of Data Subjects. The Controller’s leads, prospective clients, clients, business contacts, listing-related contacts, and authorized users; any other individuals whose data the Controller chooses to upload.
Types of Personal Data. Names, email addresses, telephone numbers, business/contact details, CRM notes, lead/client/listing details, user account data, and other Personal Data submitted by the Controller. The Controller must not upload special-category data, criminal-offence data, or children’s data without written agreement.
Controller instructions. The Controller’s configuration and use of the Service, the Terms, this DPA, and written instructions sent to [hello@imvora.app], provided they are technically feasible and lawful.
Annex 2 — Technical and organizational measures
Imvora maintains measures appropriate to the Service and risk, including: role-based access controls; account authentication and session security; encryption in transit; access limitation for personnel and support; logging and monitoring appropriate to security operations; vulnerability and patch management; backup and recovery procedures; incident-response procedures; and supplier due diligence and contractual controls. The Controller is responsible for assigning user access appropriately, safeguarding credentials, and using available security settings.
Annex 3 — Approved subprocessors
| Subprocessor | Processing purpose | Location / transfer safeguard |
|---|---|---|
| OVHcloud | Hosting and infrastructure | [confirm data-centre location and applicable terms] |
| Cloudflare | Security, content delivery, and web performance | [confirm services enabled, processing locations, and transfer mechanism] |
| Resend | Transactional email delivery | [confirm processing location and transfer mechanism] |
| PostHog | Product analytics and service-improvement telemetry | [confirm deployment, processing location, and transfer mechanism] |
Stripe processes payment information for Imvora’s own billing relationship and is generally not a subprocessor of Customer CRM Data. If the Service sends Customer Data to Stripe, add Stripe to this Annex before doing so.