ManagerSee.com

برنامج لمراقبة أجهزة الكمبيوتر الوظيفية في الشركة.

  • الرئيسية
  • كيف يعمل هذا؟
  • عن المنتج
  • التثبيت
  • قائمة الأسعار
  • تحميل
  • تسجيل الدخول

Version 1.0 · Effective from: October 2, 2026 · Annex 1 to the Terms of Service

Data Processing Agreement (DPA)

The Polish version of this DPA is legally binding; this English translation is provided for convenience.

This Agreement is concluded electronically, together with acceptance of the Terms of Service, by all Customers — Consumers, Quasi-consumers, and Businesses.

§ 1. Parties and subject matter

  1. Controller – the Customer within the meaning of the Terms of Service, regardless of Customer Status.
  2. Processor – GBLogic Grzegorz Banaś, ul. Węgrowska 1 m 118, 03-507 Warsaw, Poland, Tax ID (NIP) 6422893874.
  3. Under Article 28(3) GDPR, the Controller entrusts the Processor with the processing of personal data to the extent and for the purpose set out in § 2, solely for the purpose of providing the Service.
  4. The Controller represents that it has a valid legal basis for the processing and entrustment of Monitoring Data, and that it has fulfilled its information obligations towards Monitored Persons, in accordance with § 5 of the Terms. The Processor does not verify the legal basis for processing.
  5. Clause for Customers who are natural persons acting for purely private purposes. If the Customer is a natural person using the Service solely for personal or household purposes (e.g., monitoring their own child, a household member, or a close person with that person's consent), and the Customer's processing of a Monitored Person's data might fall outside the scope of the GDPR under Article 2(2)(c) GDPR (purely personal or household activity), the provisions of this Agreement assigning the Customer the role of "Controller" then apply as a contractual allocation of responsibility between the parties, rather than a determination of the Customer's status under the GDPR. Regardless of the foregoing, the Processor, in providing the Service as part of its business activity, complies with the obligations imposed on it directly by the GDPR with respect to such data.

§ 2. Scope of the entrustment

  1. Categories of data subjects: Monitored Persons (employees, contractors, household members, children, or other persons using the Device), persons whose data appears within Monitoring Data (e.g., correspondents), and users of the Controller's Account.
  2. Categories of data – as selected by the Controller in the configuration: Device identifier and name, Windows username, IP address, list of running processes and applications, window titles, activity time, browser history, information on downloaded files, screenshots and screen recordings, live screen view, keystroke logs, and clipboard content.
  3. The Controller acknowledges that, as a result of its configuration, Monitoring Data may include special categories of data (Article 9 GDPR), data relating to criminal convictions (Article 10 GDPR), authentication credentials, and the content of correspondence. The Controller is responsible for configuring the Service to avoid this, or for having an appropriate legal basis.
  4. Nature of processing: collection via the Agent, transmission, storage, presentation in the Panel, and deletion.
  5. Duration: for the term of the Agreement and the period set out in § 8.

§ 3. Controller's instructions

  1. The Processor processes data only on the Controller's documented instructions. Documented instructions include: the Terms and this Agreement, the Account and Agent configuration made by the Controller in the Panel (including enabling modules, selecting Devices, and setting retention), and instructions sent by email from the Account's address.
  2. If, in the Processor's assessment, a Controller's instruction infringes the GDPR, the Processor will promptly inform the Controller. The Processor is not obliged to conduct a legal analysis of instructions.
  3. Instructions going beyond the Service's standard functionality may be subject to a fee or declined.

§ 4. Processor's obligations

The Processor:

  1. ensures that persons authorized to process the data have committed to confidentiality,
  2. applies the technical and organizational measures described in Annex A,
  3. assists the Controller in fulfilling data subjects' rights (Articles 15–22 GDPR) — primarily through the review, export, and deletion functions available in the Panel,
  4. assists in meeting the obligations under Articles 32–36 GDPR, to the extent of information held by the Processor,
  5. maintains a record of categories of processing activities (Article 30(2) GDPR),
  6. notifies the Controller of a personal data breach without undue delay, and no later than 48 hours after becoming aware of it. Notifications to the supervisory authority and to data subjects are made by the Controller.

§ 5. Sub-processing

  1. The Controller gives general authorization for the Processor to engage further sub-processors. The current list is set out in Annex B.
  2. The Processor will inform the Controller of any intended addition or replacement of a sub-processor at least 14 days in advance (by email or in the Panel). The Controller may raise a reasoned objection; absent agreement, the Controller's sole remedy is to terminate the Agreement.
  3. The Processor enters into agreements with sub-processors providing a level of protection no less than this Agreement.

§ 6. Transfers outside the EEA

Monitoring Data is stored in data centers of the cloud infrastructure provider located within the European Union. Any transfer outside the EEA (e.g., in connection with vendor technical support or payment processing) may occur only on the basis permitted under Chapter V GDPR (an adequacy decision, including the EU-US Data Privacy Framework, or standard contractual clauses).

§ 7. Audit

  1. The Processor will provide the Controller with information necessary to demonstrate compliance with Article 28 GDPR — primarily in the form of written responses and documentation.
  2. An on-site audit is permitted only for Controllers who are Businesses, no more than once every 12 months, with 30 days' notice, conducted by an auditor bound by confidentiality. The Controller bears the cost of the audit.

§ 8. End of processing

  1. After the Service ends, the Processor will delete the entrusted data 30 days after termination of the Agreement (the period allowed for export by the Controller), unless the law requires further retention.
  2. Data in technical backups and logs may be retained until rotated, for no longer than 90 days.

§ 9. Liability

  1. The Controller bears sole responsibility for the lawfulness of processing Monitoring Data, including its legal basis, scope, purpose, retention period, and the information given to data subjects.
  2. The Processor is liable to the Controller only for damage caused by its failure to comply with obligations imposed directly on processors by the GDPR, or by acting outside, or contrary to, the Controller's lawful instructions.
  3. The Processor's liability under this Agreement is subject, as applicable, to §§ 13 and 14 of the Terms (for Businesses) and §§ 12a and 14 of the Terms (for Consumers/Quasi-consumers).
  4. Where the Processor and Controller are jointly and severally liable to a data subject, and the Processor pays compensation exceeding the share corresponding to its responsibility, the Processor is entitled to reimbursement from the Controller, subject to mandatory provisions protecting Consumers/Quasi-consumers.

§ 10. Final provisions

This Agreement remains in effect for the term of the Agreement for the provision of the Service, and thereafter until the data is deleted. Matters not regulated herein are governed by the Terms and the GDPR. In the event of a conflict between this Agreement and the Terms regarding data protection, this Agreement prevails.


Annex A – Technical and organizational measures

  • encryption of Agent ↔ API transmission (TLS, gRPC over HTTPS),
  • encryption of data at rest provided by the cloud infrastructure provider,
  • Agent authentication via JWT token; Panel authentication via ASP.NET Core Identity, with optional two-factor authentication,
  • protection of account personal data using the platform's built-in mechanisms (Identity personal-data protection),
  • rate limiting,
  • restricted administrative access to infrastructure, multi-factor authentication for cloud accounts,
  • short-lived, signed URLs for media files,
  • automatic deletion of data after the retention period.

Annex B – List of sub-processors

Entity Purpose Data location
Microsoft Ireland Operations Ltd. (Microsoft Azure) hosting, file storage, database, telemetry European Union
Provider's own server infrastructure (MediaMTX) live video streaming European Union
Sinch Mailjet SAS transactional emails (Account data only) European Union
Stripe Payments Europe Ltd. payment processing (Account/Customer data only) European Union / USA (under the Data Privacy Framework)
wFirma sp. z o.o. invoicing (Customer data only) Poland
  • سياسة الخصوصية
  • ترخيص
  • اتفاقية معالجة البيانات
  • سياسة ملفات تعريف الارتباط
  • إشعار الانسحاب
  • إعدادات ملفات تعريف الارتباط
  • الاتصال

نستخدم ملفات تعريف الارتباط الضرورية لتشغيل هذا الموقع، وملفات تعريف الارتباط التسويقية فقط بموافقتك لقياس أداء الإعلانات. لمزيد من التفاصيل راجع سياسة ملفات تعريف الارتباط.