Data Processing Addendum
Version: 1.2
Effective date: 12 August 2026
Last updated: 12 August 2026
Applies to: Business Customers only
Public brand and client-facing platform: Registry Intelligence
Product: CPSC eFiling CSV Checker & Builder
Legal operator, service provider and contracting party: Natallia Vasilyeva, carrying on business as NATALLIA VASILYEVA – Poland Documents
Pre-production release condition. This Addendum must not be activated for live Customer Personal Data or public paid sales until: (a) the production data-flow register and Subprocessor List identify every production hosting, storage, database, backup, transactional-email, security, malware-screening, support, monitoring, logging and optional OCR provider that can Process Customer Personal Data, together with its legal entity, locations and transfer mechanism; (b) the measures and deletion controls in Annexes 2–3 have been implemented and evidenced; (c) the no-account acceptance, verified-email, recovery, Subprocessor-notice and applicable Chapter V/SCC workflows have passed legal and technical release testing; and (d) the relevant country, subdivision and business-purchaser route has been expressly approved and enabled. Until those conditions are satisfied, the Application must remain unavailable for live file uploads and public paid sales.
This Data Processing Addendum (the “DPA”) forms part of the agreement governing use of the CPSC eFiling CSV Checker & Builder (the “Application”), a distinct product of Registry Intelligence, between the business, sole trader, professional or other organization identified in the electronic acceptance record (“Customer”) and Natallia Vasilyeva, carrying on business as NATALLIA VASILYEVA – Poland Documents, a sole proprietor registered in the Republic of Poland (“Poland Documents”). Registry Intelligence is the public brand and client-facing platform. Poland Documents is the Application’s legal operator, service provider and contracting party.
This DPA is intended to satisfy Article 28 of Regulation (EU) 2016/679 (the “GDPR”) where Poland Documents processes personal data on behalf of Customer. It is an electronic written agreement for purposes of Article 28(9) GDPR.
1. Scope, formation and precedence
1.1 When this DPA applies
This DPA applies only to Customer Personal Data processed by Poland Documents on behalf of Customer through the Application or in related support. It applies whether Customer acts as a Controller or as a Processor for another Controller. If a Job contains no Personal Data, the operational and security provisions of the Agreement continue to apply, but this DPA does not create a processor relationship for non-personal data.
This DPA does not apply to personal data that Poland Documents processes as an independent Controller for its own legitimate purposes, as described in Section 16.
This DPA is available only in the business Controller/Processor route. It is not Consumer privacy consent, does not replace the Privacy Policy, and does not determine or waive any consumer-contract protection that mandatory law may extend to a sole trader or other individual. Business Customers may be located globally, but no country, subdivision or business-purchaser route may accept live Customer Personal Data until that route and every required transfer, privacy, security, payment and contract control have been approved and enabled.
This is a European data-processing addendum centered on Article 28 GDPR. It does not, by itself, purport to supply every service-provider or contractor term required by U.S. state privacy law. Before the Application accepts Customer Personal Data governed by such a law, the parties must apply a then-current U.S. State Privacy Law Addendum or other written terms satisfying the applicable mandatory requirements. Mandatory law applies regardless of whether it is named in the Agreement.
1.2 Electronic acceptance before upload
Because free validation begins processing before payment, Customer must accept this DPA before the first file or file content is transmitted to the Application. Poland Documents makes a standing offer to enter into this DPA on the published terms. Acceptance by an authorized representative through the pre-upload workflow binds both parties; a separate handwritten or qualified electronic signature is not required unless mandatory law requires one.
The Application must not accept an upload until it has verified the representative’s Job email, recorded the acceptance evidence specified in Annex 5, and made this DPA and the then-current Subprocessor List available in a durable, downloadable form.
1.3 Agreement and precedence
The “Agreement” consists of the Application Terms and License, this DPA, the Pricing, Limits & Retention Schedule, the Refund & Delivery Policy, the transaction-specific confirmation and any other document expressly incorporated into the Application contract.
If documents conflict concerning Customer Personal Data, the following order applies:
- any applicable Standard Contractual Clauses, but only for the Restricted Transfer they govern;
- this DPA;
- the Pricing, Limits & Retention Schedule, solely for non-conflicting operational detail;
- the Application Terms and License; and
- the general Terms of Use.
Nothing in the Agreement reduces a right of a Data Subject, a power of a Supervisory Authority or an obligation that cannot lawfully be limited.
1.4 Duration
This DPA takes effect when Customer accepts it and continues while Poland Documents processes Customer Personal Data. Sections that by their nature must survive—including confidentiality, deletion, audit evidence, liability, regulatory cooperation and transfer obligations—survive termination for as long as relevant Customer Personal Data or protected compliance evidence remains.
2. Definitions
Capitalized terms not defined here have the meanings given in the GDPR, the Application Terms or the Pricing, Limits & Retention Schedule, as applicable.
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR.
“Business Day” means Monday through Friday, excluding public holidays in the Republic of Poland.
“Customer Personal Data” means Personal Data contained in or derived from Customer Data that Poland Documents processes on behalf of Customer. It includes Personal Data in source CSV, XLSX, PDF and ZIP files; directly extracted PDF text; OCR-derived values and provenance; mappings; corrections; confirmations; validation results; intermediate files; the prepayment Readiness Report and related free-review results; each paid Output Package component; the complete ZIP; direct CPSC CSV copies; and substantive Customer Data reproduced in or attached to a support request. It does not include Controller Data described in Section 16.
“Data Protection Law” means the GDPR and applicable national legislation implementing or supplementing it and, only to the extent applicable to the relevant Processing, the UK GDPR, the Swiss Federal Act on Data Protection or another mandatory data-protection law expressly identified in the Agreement.
“Documented Instructions” means the instructions described in Section 4.
“EEA” means the European Economic Area.
“Restricted Transfer” means a transfer of Personal Data that requires a safeguard under Chapter V GDPR or corresponding applicable Data Protection Law.
“Standard Contractual Clauses” or “SCCs” means the unmodified standard contractual clauses set out in European Commission Implementing Decision (EU) 2021/914 that are in force and lawfully incorporated for the relevant Restricted Transfer. A successor instrument applies only after it has been validly selected, completed and incorporated.
“Subprocessor” means a further Processor engaged by Poland Documents to Process Customer Personal Data on behalf of Customer. A provider is not a Subprocessor merely because it processes payment, billing, tax, website analytics or business-contact data for Poland Documents as an independent Controller or as Poland Documents’ Processor outside the scope of Customer Personal Data.
“Subprocessor List” means the then-current CPSC eFiling CSV Checker & Builder Subprocessor List made available with the Application, including its version history and processing-location information.
3. Roles and allocation of responsibility
3.1 Customer as Controller
Where Customer determines the purposes and essential means of Processing Customer Personal Data, Customer is the Controller and Poland Documents is its Processor.
3.2 Customer as Processor
Where Customer processes Personal Data on behalf of another Controller, Customer is a Processor and Poland Documents is Customer’s Subprocessor. Customer confirms that its Controller has authorized Customer to appoint Poland Documents and the Subprocessors listed in the current Subprocessor List. Customer must communicate to Poland Documents only instructions it is entitled to give and remains the single point of contact for the relevant Controller unless the parties agree otherwise in writing.
For each such Job, Customer must identify the relevant ultimate Controller by full legal name, country and privacy contact so that Poland Documents can maintain the Processor records required by Article 30(2) GDPR. If a Job covers more than one Controller, each must be identified and the scope attributable to each must be documented before upload.
Customer must communicate before Processing all upstream instructions and Article 28 obligations that apply to Poland Documents. Customer represents that this DPA and the disclosed instructions impose on Poland Documents, in substance, the same applicable obligations that Customer owes to the relevant Controller. Poland Documents is not required to accept undisclosed or conflicting upstream terms.
Customer will forward to the relevant Controller without undue delay all incident, Data Subject request, Subprocessor, transfer and compliance notices received from Poland Documents. Customer may designate the relevant Controller or its independent auditor to exercise the audit mechanism in Section 14, subject to the same confidentiality, security and scope safeguards; Customer remains Poland Documents’ contractual point of contact unless the parties agree otherwise.
3.3 Poland Documents’ obligations
Poland Documents will:
- Process Customer Personal Data only on Documented Instructions, unless law requires otherwise;
- ensure that Processing remains within the subject matter, duration, nature and purpose described in Annex 1;
- maintain the technical and organizational measures in Annex 2;
- assist Customer as required by this DPA and Article 28 GDPR; and
- remain responsible for its compliance with obligations directly applicable to Processors under Data Protection Law.
Poland Documents does not become a Controller of Customer Personal Data merely because it selects non-essential technical means needed to provide, secure or maintain the Application. If Poland Documents determines an independent purpose or essential means for Customer Personal Data outside Customer’s instructions, it will be treated as a Controller for that Processing to the extent required by Article 28(10) GDPR.
4. Documented Instructions and purpose limitation
4.1 Instructions
Customer instructs Poland Documents to Process Customer Personal Data only to:
- receive and securely stage supported CSV, XLSX, PDF and ZIP files within the exact limits stated in the Pricing, Limits & Retention Schedule;
- parse, map, validate, normalize, correct and revalidate Customer-selected data;
- extract text directly from a text-based PDF and perform OCR on a scanned PDF only where that specific workflow is enabled and its provider or verified local route, locations, retention and safeguards are disclosed before upload;
- calculate readiness and Job status;
- generate, package and provide protected access to the Output Package;
- troubleshoot and support the Job at Customer’s request;
- secure the Application, prevent unauthorized access and maintain limited operational evidence; and
- return, restrict or delete Customer Personal Data in accordance with Customer’s choices and Annex 3.
The Agreement, Customer’s upload, mapping and correction choices, validation and generation commands, download and deletion choices, support requests, and other written instructions accepted by Poland Documents constitute Documented Instructions. Poland Documents is not instructed to submit data to CPSC, CBP, ACE, the CPSC Product Registry, Amazon, a laboratory, a customs broker or another third party.
Version 1 supports the following inputs subject to the current Schedule: CSV up to 250 MB per file; XLSX up to 100 MB per file and 20 worksheets; PDF up to 50 MB and 200 pages per file; and ZIP up to 250 MB compressed, 1 GB expanded, 100 files and a 20:1 expansion ratio, containing only CSV, XLSX or PDF files. Nested, encrypted, password-protected, macro-enabled, executable, externally linked, symbolic-link, unsafe-path or damaged archives and files are rejected. OCR is limited to 1,000 pages per Job. These are internal Application controls, not CPSC limits.
OCR is included in Version 1 product scope but remains disabled in production until the actual provider or verified local route, Processing locations, safeguards, retention and Subprocessor disclosures are approved. If OCR is unavailable for a Job, a scanned PDF is rejected before paid checkout rather than silently omitted. Every OCR-derived value must retain the source document, page number, source fragment, confidence and review status; low-confidence values are marked Review Required; and the Customer must confirm or correct every OCR-derived value before it can become Ready. The Application does not infer certificate type, citation code, requirement applicability, manufacturer or testing laboratory.
Before payment, the Application provides the free review: the Readiness Report, errors and warnings, missing confirmations, Ready Record count, selected records, mappings and corrections, and the exact final price. The free review does not include a paid CPSC CSV or paid Output Package.
The standard paid Output Package consists only of: (a) one or more CPSC-formatted CSV files named CPSC_Upload_{SEQUENCE_3_DIGITS}.csv; (b) the Validation Summary, Validation_Summary.pdf; (c) the Correction Ledger, Correction_Ledger.xlsx; (d) the Ruleset & Provenance Receipt, Ruleset_and_Provenance_Receipt.json; and (e) the README, README.pdf. Each output CPSC CSV contains no more than 10,000 Selected Ready Records and is sharded by Product Collection and volume where required. The complete paid Output Package is supplied as one ZIP through the protected control “Download Complete Output Package (ZIP)”. The separate protected control “Download CPSC CSV” supplies the single CPSC CSV or a CSV-only set when batching creates multiple sequentially numbered CPSC CSV files. “Protected” describes the access channel and does not mean that the ZIP itself is encrypted unless expressly stated. The Readiness Report, each paid component, the complete ZIP, direct CPSC CSV copies and validation results remain subject to this DPA to the extent they contain Customer Personal Data. The Application prepares the required format; it does not guarantee acceptance by CPSC or another third party.
4.2 No independent exploitation
Poland Documents will not sell Customer Personal Data; use it for behavioral advertising; add it to city-intelligence modules, public datasets or unrelated customer products; or use it to train, fine-tune or evaluate a general-purpose or third-party artificial-intelligence model. Aggregated operational statistics may be used only where they do not contain Personal Data and cannot reasonably be used to identify Customer, a Data Subject or a Job.
4.3 Legally required Processing
If Union or Member State law requires Poland Documents to Process Customer Personal Data other than on Customer’s instructions, Poland Documents will inform Customer of the legal requirement before Processing unless the law prohibits notice on important grounds of public interest.
4.4 Unlawful or unsafe instructions
Poland Documents will immediately inform Customer if, in Poland Documents’ opinion, a Documented Instruction infringes the GDPR or other applicable Union or Member State data-protection law. Poland Documents may suspend the affected Processing while the parties clarify or lawfully modify the instruction. This does not relieve Poland Documents of obligations directly applicable to it and does not authorize indefinite retention.
4.5 Verified email and no-account access
No general Application account or reusable password is required. The representative’s Job email must be verified before any document upload. The current browser continues through a protected Secure, HttpOnly session while that session remains valid.
From a new device, protected Job access requires either: (a) a fresh one-time magic link sent only to the verified email after the Job ID is supplied, expiring 30 minutes after issue and becoming invalid after successful use; or (b) the Job ID together with the independently issued Recovery Code. A new magic link may be requested until automatic Job deletion. The Recovery Code contains at least 128 bits of cryptographic entropy, is displayed once, is stored server-side only as a keyed hash, remains valid until automatic Job deletion, and is not sent in the same message as the magic link. Issue, resend and validation attempts are rate-limited and use neutral responses.
The 30-minute magic-link period is separate from the seven-calendar-day paid-output entitlement measured from Delivery Time. A Job ID alone, Stripe payment reference, billing detail, purchaser or business fact, or identity document is not an authentication factor. If the Customer loses access to both the verified email and the Recovery Code and has no valid authorized browser session, support cannot reset either factor, change the verified email, disclose Job data, restore downloads or issue replacement access. Support may address billing complaints or refunds without granting Job access.
5. Customer obligations and prohibited data
Customer is responsible for:
- having an appropriate legal basis for the Processing and providing required notices to Data Subjects;
- ensuring that Customer and its representative have authority to submit the data and issue instructions;
- limiting Personal Data to what is necessary for the CPSC certificate-data preparation purpose;
- the accuracy, quality and lawfulness of Customer Personal Data and instructions;
- responding to Data Subjects and deciding whether notification, consultation or a data-protection impact assessment is required; and
- securely controlling its devices, email, recovery details, Job links and downloaded files.
Unless Poland Documents expressly agrees in a separately signed written addendum before upload, Customer must not submit:
- special categories of Personal Data under Article 9 GDPR;
- criminal-conviction or offence data under Article 10 GDPR;
- Personal Data about children as children;
- Social Security numbers or equivalent government identifiers;
- complete payment-card or bank-account credentials;
- health, credit, background-check or biometric data;
- passwords, API keys, authentication tokens or private keys; or
- Personal Data whose Processing presents materially higher risks than the business-contact and trade-party information described in Annex 1.
An accidental prohibited-data submission does not remove that data from the protections of this DPA. Poland Documents may isolate the Job, notify Customer, reject further Processing and securely delete the affected content unless preservation is legally required. Customer must not resend prohibited data through ordinary email support.
6. Confidentiality and personnel
Poland Documents will ensure that each person authorized to Process Customer Personal Data:
- accesses it only where necessary for an authorized purpose;
- is bound by an appropriate contractual or statutory duty of confidentiality;
- receives proportionate privacy and security instructions; and
- loses access promptly when access is no longer required.
Poland Documents will not disclose Customer Personal Data to another person except as permitted by this DPA, on Customer’s Documented Instructions or as required by law.
7. Security of Processing
7.1 Risk-based measures
Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of Processing, as well as risks to Data Subjects, Poland Documents will implement and maintain measures appropriate to the risk in accordance with Article 32 GDPR. The baseline measures are set out in Annex 2.
7.2 Changes to measures
Poland Documents may update technical and organizational measures to address evolving threats, providers, law and technology, provided that the update does not materially reduce the overall security of Customer Personal Data while any such data remains under Processing, including in active systems, logs, backups or a valid hold. A material reduction requires prior notice and Customer’s written authorization or an appropriate suspension, termination and refund remedy.
7.3 No unsupported certification claim
Unless expressly identified in current written materials, Poland Documents does not represent that the Application or Poland Documents is certified to ISO 27001, SOC 2, PCI DSS or another independent standard. Use of a certified infrastructure provider does not make Poland Documents itself certified.
8. Subprocessors
8.1 General written authorization
Customer specifically authorizes the active entries in the Subprocessor List version accepted for the Job and grants general written authorization for new or replacement Subprocessors appointed strictly under Sections 8.2–8.3. A proposed Subprocessor becomes authorized only after the notice period expires without timely objection or after an objection is resolved in writing. An optional provider is authorized only after Customer affirmatively enables the feature that requires it. The list must identify every Subprocessor in the relevant Processing chain by legal name, address and contact person, together with its service, purpose, data categories, Processing and access locations, applicable transfer mechanism and effective date.
Poland Documents will perform proportionate due diligence to determine whether each Subprocessor provides sufficient guarantees. The depth of review may vary with risk, but every Subprocessor must be reviewed and bound by a written agreement imposing, in substance, the same data-protection obligations that apply to Poland Documents, insofar as applicable to the entrusted Processing.
Upon reasonable request, Poland Documents will provide a copy of the relevant Subprocessor agreement and amendments, redacted only as necessary to protect unrelated Personal Data or genuine confidential information and not so extensively as to prevent Customer’s compliance assessment.
8.2 Changes and direct notice
Poland Documents will provide at least 30 calendar days’ prior notice before a new or replacement Subprocessor begins Processing Customer Personal Data. Direct notice applies to every affected Customer whose Customer Personal Data has not been fully deleted from active systems and expired from backups, or remains subject to a documented hold based on Customer’s lawful instruction or a binding retention requirement under Union or Member State law applicable to Poland Documents. Notice will be sent to the verified Job privacy contact; merely posting an updated list is not sufficient. Poland Documents will retain that verified notice channel at least until all Customer Personal Data has been deleted. Customer may also subscribe to prospective notices as described in the Subprocessor List.
The notice period begins on successful electronic delivery. A bounced or undeliverable message is not effective notice. The notice will identify the proposed Subprocessor, Processing activity, locations, transfer mechanism, planned effective date and associated change in risk. The proposed Subprocessor will not Process an affected Customer’s data until the notice period expires without objection or the objection is resolved.
No emergency permits engagement without the authorization required by Article 28(2) GDPR. If the 30-day period is impracticable because of a verified urgent security or legal necessity, Poland Documents will, before engagement, either obtain the affected Customer’s specific written authorization or refrain from using the proposed Subprocessor for that Customer’s Personal Data and suspend or terminate the affected Processing. Notice after engagement does not constitute authorization.
8.3 Objection and remedy
Customer may object during the 30-day notice period on reasonable, documented data-protection grounds. The parties will work in good faith to address the concern, including by applying additional safeguards, disabling an optional feature, using a reasonable alternative or deleting the affected Job data.
If no reasonable resolution is available, the proposed Subprocessor will not Process any affected Customer Personal Data, including retained, logged and backup copies. At Customer’s Documented Instruction and subject to Section 12, Poland Documents will return and/or delete the affected data, suspend or terminate the affected Processing, and refund any prepaid amount for materially affected paid service that has not been conformingly performed, without limiting another remedy required by law. An objection does not require Poland Documents to provide a service that is technically impossible without the proposed Subprocessor.
8.4 Responsibility for Subprocessors
Poland Documents remains fully liable to Customer for performance of each Subprocessor’s data-protection obligations to the same extent as if Poland Documents performed the delegated Processing itself.
8.5 Providers outside this Section
A payment provider, bank, card network, tax platform, public authority, Customer-selected recipient or analytics provider that is technically prevented from receiving Customer Personal Data is not a Subprocessor for that data. Its separate role, if any, is described in the Privacy Policy or Subprocessor List. If any such provider begins receiving Customer Personal Data on behalf of Customer, Poland Documents must classify and authorize it under this Section before that Processing begins.
9. Data Subject requests
9.1 Customer control
Customer is responsible for responding to requests by Data Subjects. Taking into account the nature of Processing, Poland Documents will assist Customer through appropriate technical and organizational measures, insofar as possible, with requests to access, rectify, erase, restrict, port or object and with other Chapter III GDPR rights.
9.2 Requests received by Poland Documents
If Poland Documents receives a request relating to Customer Personal Data, it will notify Customer without undue delay and, where reasonably practicable, within three Business Days. Poland Documents will not respond substantively without Customer’s Documented Instructions, except to confirm referral to Customer or where law requires a response. Poland Documents may take reasonable steps to verify the requester and avoid disclosing data to an unauthorized person.
9.3 Assistance after scheduled deletion
Assistance is limited by the Application’s short retention periods. Poland Documents is not required to reconstruct Customer Personal Data that was lawfully deleted before it received a preservation or assistance request. Customer must therefore notify Poland Documents promptly and before the displayed deletion time where continued availability is necessary.
10. Personal Data Breaches
10.1 Notice to Customer
Poland Documents will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it and, in any event, within 48 hours. Awareness occurs when Poland Documents has a reasonable degree of certainty that a security incident has compromised Customer Personal Data; notice will not await final confirmation or completion of the investigation. Notice will be sent to the verified Job security or privacy contact.
Initial notice will not be delayed because all facts are not yet known. Information may be provided in phases and will include, to the extent then available:
- the nature of the breach;
- the categories and approximate number of affected Data Subjects and records;
- likely consequences;
- measures taken or proposed to contain, investigate and mitigate the breach;
- the name and contact details of the incident contact; and
- information reasonably needed for Customer’s Articles 33 and 34 GDPR assessment.
10.2 Response and cooperation
Poland Documents will take reasonable steps to contain, investigate, remediate and document the breach and will cooperate with Customer. Customer controls notifications to its Supervisory Authority and Data Subjects unless law requires Poland Documents to notify directly. A notice or cooperation does not constitute an admission of fault or liability.
10.3 Customer notice
Customer will promptly notify Poland Documents at inbox@polandoc.com if it becomes aware that a Job link, recovery method, source file, Output Package or Customer credential has been compromised or disclosed without authorization.
11. Compliance assistance
Taking into account the nature of Processing and information available to Poland Documents, Poland Documents will assist Customer with:
- security obligations under Article 32 GDPR;
- breach assessment and notifications under Articles 33 and 34;
- data-protection impact assessments under Article 35;
- prior consultation under Article 36; and
- inquiries or lawful requests from a competent Supervisory Authority relating to Customer Personal Data.
Poland Documents will maintain the records of Processing required from a Processor under Article 30(2) GDPR and will cooperate with competent Supervisory Authorities in accordance with Article 31 GDPR. The parties will not rely on the Article 30(5) small-organization exception where the conditions for that exception are not met.
Standard assistance reasonably necessary for compliance with Article 28 is included in the service. Material bespoke work beyond ordinary Application functionality may be subject to a reasonable fee only where permitted by law, disclosed in advance and agreed in writing, and never where charging would prevent Poland Documents from fulfilling its own mandatory obligation.
12. Return, deletion and retention
12.1 Customer’s choice
At the end of Processing, Customer may choose return of then-existing Customer Personal Data through the protected download method followed by deletion, or deletion without further return. Customer may also request early deletion while a Job remains active, acknowledging that deletion may make validation, delivery, support or regeneration impossible.
If Customer gives no separate end-of-service instruction, Customer’s use of the temporary Application and acceptance of Annex 3 constitutes a Documented Instruction to make the purchased Output Package available for the stated download period and then delete Customer Personal Data under the default schedule.
12.2 Active systems and backups
Poland Documents will delete all Customer Personal Data and existing copies after the applicable period, unless Union or Member State law requires storage. Irreversible anonymization may substitute for deletion only on Customer’s Documented Instruction and only where the resulting information is demonstrably no longer Personal Data. Active-system deletion begins at expiry and is completed within 24 hours. Encrypted backup remnants are automatically overwritten or deleted no later than 30 days after active-system deletion and are not restored for ordinary customer access. If a backup is restored for disaster recovery, deletion markers and expiry controls must be reapplied.
12.3 Legal preservation
Where law or binding legal process requires preservation, Poland Documents will isolate the minimum necessary data, restrict Processing to the preservation purpose, protect it and delete it when the requirement ends. Poland Documents will inform Customer unless legally prohibited.
12.4 Evidence of deletion
On reasonable written request, Poland Documents will provide available evidence of the applicable deletion event or a written confirmation of deletion. Such evidence need not reveal another customer’s information or compromise security and does not require retention of the deleted content.
12.5 Controller Data
Deletion of Customer Personal Data does not require deletion of Controller Data that Poland Documents lawfully retains for payment, tax, security, fraud prevention, contract evidence, legal claims or regulatory compliance, provided that source-file and substantive record content are not retained under that classification.
13. International transfers
13.1 Transparency and documented locations
Poland Documents will identify in the Subprocessor List the countries in which Customer Personal Data is stored, processed or remotely accessed. Remote access from a third country is treated as a potential Restricted Transfer where Data Protection Law so requires.
13.2 Transfer hierarchy
Poland Documents will not make a Restricted Transfer except on Customer’s Documented Instructions and under a valid Chapter V mechanism. The following hierarchy applies where legally available:
- an applicable European Commission adequacy decision;
- for a U.S. recipient, the EU–U.S. Data Privacy Framework only while the exact recipient is actively certified for the relevant data and Processing;
- the applicable SCC module, completed before the transfer, together with a documented transfer assessment and supplementary measures where required; or
- another lawful safeguard under Articles 46 or 47 GDPR.
Derogations under Article 49 will not be used for repetitive or structural Application transfers.
13.3 Onward Subprocessor transfers
Where Poland Documents, acting as a Processor in the EEA, transfers Customer Personal Data to a Subprocessor outside the EEA that is not covered by adequacy, Poland Documents will enter into the applicable SCCs, ordinarily Module Three, and will assess and document the transfer as required. Upon reasonable request, Poland Documents will make available information necessary for Customer to assess the transfer, subject to appropriate redactions for security and third-party confidentiality.
13.4 Return to a non-EEA Customer
Before making any Customer Personal Data or record-level validation result available to a non-EEA Customer—including through an on-screen display, API response, download, support disclosure or access link—Poland Documents will determine and record the applicable Chapter V mechanism. Where Decision (EU) 2021/914 applies, the official SCC text, applicable Module and options, and all required Annexes must be completed, made available in durable form and electronically accepted before the first such availability.
Where Customer is the non-EEA Controller, the SCCs will ordinarily use Module Four. Where Customer is a non-EEA Processor acting for another Controller, the SCCs will ordinarily use Module Three. Customer must provide the party information and accept the completed SCC selections electronically. This DPA does not replace or alter the mandatory text of the SCCs.
Before relying on Decision (EU) 2021/914, the parties will determine whether the non-EEA recipient is subject to the GDPR for the relevant Processing and whether that Decision is available for the transfer. If the standard mechanism does not cover the actual roles or legal position, the affected transfer will not begin until another valid Chapter V solution is documented.
13.5 UK and Switzerland
Where UK or Swiss transfer law applies, the parties will use the then-current UK International Data Transfer Addendum or Agreement, Swiss adaptations to the SCCs, or another valid mechanism as applicable. No transfer addendum applies unless the corresponding law governs the transfer.
13.6 Conflict and invalidation
The SCCs control over this DPA for the Restricted Transfer they govern. If a transfer mechanism becomes invalid or unavailable, Poland Documents will suspend the affected transfer until a lawful alternative is implemented or will terminate the affected Processing and provide any refund required under Section 8.3 and the Refund & Delivery Policy.
14. Information, audits and inspections
14.1 Compliance information
Poland Documents will make available all information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, Annex 2, the Subprocessor List, relevant policies, a proportionate security questionnaire and available independent assurance materials.
14.2 Audit sequence
Customer should first review the information made available under Section 14.1. If that information is reasonably insufficient, Customer may conduct or appoint an independent auditor to conduct a proportionate remote audit and, where remote evidence remains insufficient, an inspection.
Except after a Personal Data Breach, where Customer has reasonable documented grounds to suspect material non-compliance, or where a Supervisory Authority requires otherwise, an audit may occur no more than once in any 12-month period. Customer must give reasonable advance notice, define a proportionate scope, minimize disruption and ensure that its auditor is competent, independent, bound by confidentiality and not a direct competitor of Poland Documents.
14.3 Safeguards and costs
An audit must not expose another customer’s data, weaken security, access source code or vulnerability details beyond what is reasonably necessary, or require Poland Documents to violate law or a third-party duty. Poland Documents may provide equivalent evidence or a supervised review where appropriate, but documentary evidence is not the exclusive means of audit where Article 28(3)(h) requires more.
Customer bears reasonable audit costs unless the audit identifies a material breach of this DPA by Poland Documents, in which case Poland Documents bears its reasonable internal cooperation costs. Audit fees and cost allocations must not be excessive, disproportionate or dissuasive. Poland Documents will not charge Customer for an audit required by a Supervisory Authority or reasonably triggered by a Personal Data Breach, credible evidence of non-compliance or Poland Documents’ breach. Each party remains responsible for its own legal advisers unless law requires otherwise.
14.4 Regulatory inspection
The annual limit and cost allocation do not restrict a competent Supervisory Authority or prevent Customer from meeting a binding regulatory requirement.
15. Government and third-party requests
Poland Documents will not disclose Customer Personal Data solely on the basis of a judgment, order or request from an authority of a third country unless an international agreement or another legal basis recognized by applicable Union or Member State law makes the disclosure lawful. Unless prohibited by law, Poland Documents will promptly inform Customer of a request. Poland Documents will assess the applicable legal basis and Chapter V requirements, disclose only the minimum legally required information and, where reasonable grounds exist, challenge an unlawful or disproportionate request and seek available interim relief. Nothing requires Poland Documents to violate law or compromise an ongoing investigation.
Poland Documents will maintain a process for documenting such requests and will provide available information relevant to Customer’s compliance assessment where legally permitted.
16. Poland Documents as independent Controller
Poland Documents acts as an independent Controller, not Customer’s Processor, for the following limited “Controller Data”:
- Customer representative name, professional role, business contact and contracting details;
- Job identifier, DPA and Terms acceptance evidence, document versions and integrity hashes;
- payment, refund, invoice, tax and accounting information, excluding complete card credentials;
- service-delivery, download and deletion-event evidence that does not retain full uploaded content;
- security, fraud, abuse, rate-limit and access logs designed not to contain raw Customer Personal Data; and
- ordinary business correspondence and legal-claim records, except source-file content or substantive record extracts supplied for support.
Poland Documents processes Controller Data for contracting, billing, tax, security, fraud prevention, legal compliance, service administration and establishment or defense of legal claims under the Privacy Policy and applicable law. Poland Documents will not relabel source files, extracted certificate records or Output Packages as Controller Data to avoid this DPA.
17. Suspension and termination
Customer may suspend affected Processing until compliance is restored and may terminate it if compliance is not restored within a reasonable period not exceeding one month, if Poland Documents commits a substantial or persistent breach, or if Poland Documents fails to comply with a binding decision of a competent authority. Poland Documents may terminate affected Processing if Customer persists in an unlawful instruction after notice. Poland Documents may also suspend Processing where necessary to prevent a Personal Data Breach, comply with law or protect Data Subjects, but will notify Customer where legally and operationally possible.
On termination, Sections 12 and 13 apply. Termination does not eliminate an accrued delivery, correction, refund or mandatory legal remedy.
18. Liability
As between the parties, liability arising from this DPA is governed by the liability provisions of the Agreement to the extent enforceable. No contractual limitation or exclusion applies to:
- rights or remedies of Data Subjects under Data Protection Law;
- powers of a Supervisory Authority;
- third-party rights or liability that cannot be limited under applicable SCCs;
- liability that applicable law does not permit the parties to exclude or limit.
Nothing in this DPA changes the allocation of liability to Data Subjects under Article 82 GDPR or excludes Poland Documents’ responsibility under Article 28(4) for a Subprocessor’s performance. Any interparty monetary limitation applies to a Subprocessor-related claim only to the extent consistent with those Articles and other applicable law.
19. Notices and changes
Notices under this DPA will be sent to the verified Job privacy contact and to inbox@polandoc.com for Poland Documents. Customer must keep its contact details current until all Customer Personal Data has been deleted from active systems and expired from backups or any binding hold has ended. If a notice cannot be delivered, a proposed Subprocessor will not Process that Customer’s data until an alternative verified notice channel or specific written authorization is established.
Poland Documents may update this DPA prospectively to reflect law, providers, security or product changes. The version accepted for a Job continues to govern that Job unless the change is required by mandatory law, improves protection without materially impairing Customer’s rights, or Customer accepts the later version. A materially changed Job may require acceptance of a new version before Processing continues.
20. Governing law and competent authority
This DPA is governed by the laws of the Republic of Poland, without prejudice to mandatory Data Protection Law. The parties submit business disputes to the competent courts in Warsaw, Poland, except where mandatory law or applicable SCCs provide otherwise.
For Processing subject to the GDPR by Poland Documents in Poland, the competent Supervisory Authority is generally the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), without limiting a Data Subject’s or Customer’s right to approach another competent authority under the GDPR.
21. Operator and privacy contact
Service provider and contracting party
Natallia Vasilyeva, carrying on business as
NATALLIA VASILYEVA – Poland Documents
Sole proprietor registered in the Republic of Poland
Operating brand: Registry Intelligence
NIP: 9512533744
REGON: 521062093
Business and legal correspondence address: ul. Ogrodowa 58, lok. 29, 00-876 Warszawa, Poland
Privacy and DPA email: inbox@polandoc.com
Telephone: +48 501 335 073
Website: https://polandoc.com/
Do not send complete card details, passwords, authentication secrets, special-category data or unnecessary source-file content by ordinary email.
Annex 1 — Processing details
| Required Article 28 detail | Description |
|---|---|
| Subject matter | Temporary receipt and secure staging of supported CSV, XLSX, PDF and ZIP files; parsing, mapping, validation, correction, expressly enabled PDF text extraction/OCR, generation, packaging, protected delivery, support and deletion for a Customer-directed CPSC eFiling preparation Job. |
| Duration | From first accepted transmission after DPA acceptance until deletion under Annex 3, including any documented support or legal-preservation hold. |
| Nature of Processing | Collection from Customer; recording; organization; structuring; parsing; comparison to implemented rules; mapping; transformation; correction at Customer’s direction; direct PDF text extraction or OCR where expressly enabled; generation; encryption; storage; retrieval; protected transmission to Customer; restriction; necessary support access; and deletion. No filing with CPSC or another authority. |
| Purpose | To provide and secure the Application functions requested by Customer and return the resulting Output Package. No advertising, sale, public-dataset use or AI-model training. |
| Frequency | One-time or episodic per Job, including revalidation and support while the Job remains active. |
| Data Subjects | Employees, officers, contractors and representatives of Customer; importers; manufacturers; private labelers; testing laboratories; certifiers; points of contact; suppliers; customs or compliance professionals; trade partners; and other business contacts whose information is included in the authorized certificate-data workflow. |
| Personal Data | Name; professional title or role; business email and telephone; organization affiliation; business address or location; importer, manufacturer, laboratory, certifier and point-of-contact information; certificate, product, test and manufacture information linked to an identifiable person; source-document, page, source-fragment, confidence and review-status provenance; user instructions; and Job metadata that relates to a person. |
| Sensitive data | Not intended or permitted. Article 9 data, Article 10 data, children’s data, government identifiers, health, credit, biometric and authentication-secret data are prohibited unless a separately signed written addendum is completed before upload. |
| Accepted inputs and limits | CSV up to 250 MB; XLSX up to 100 MB and 20 worksheets; PDF up to 50 MB and 200 pages per file; OCR up to 1,000 pages per Job; ZIP up to 250 MB compressed, 1 GB expanded, 100 files and a 20:1 expansion ratio, containing CSV, XLSX or PDF only. Unsafe, nested, encrypted, password-protected, macro-enabled, executable, externally linked, symbolic-link or damaged content is rejected. |
| OCR and extraction provenance | Text-based PDFs use direct text extraction. Scanned PDFs use OCR only when the production workflow is enabled. Each OCR-derived value carries source document, page, source fragment, confidence and review status and requires Customer confirmation or correction before Ready status. The Application does not infer certificate type, citation code, requirement applicability, manufacturer or testing laboratory. |
| Customer categories | Global business Customers, including importers, manufacturers, private labelers, customs brokers, laboratories, compliance professionals, consultants, sole traders and other businesses or professionals authorized to prepare the relevant data. This DPA is not Consumer privacy consent. |
| Processing locations | The EEA; locations identified in the accepted Subprocessor List; and Customer’s identified country solely for an authorized return or delivery under Section 13.4, after the applicable route and Chapter V mechanism are approved. No other storage, Processing, support or remote-access location is authorized. |
| Return and deletion | Protected return and deletion under Sections 12 and Annex 3. |
| Customer rights and obligations | Customer gives and may amend lawful instructions; authorizes and may object to Subprocessors; may request assistance, return, deletion, compliance information and audits; and may suspend or terminate affected Processing as stated in Sections 3–5, 8–9, 11–14 and 17. Customer’s compliance duties are stated principally in Section 5. |
Annex 2 — Technical and organizational measures
Poland Documents will implement the following baseline measures before production activation and maintain them throughout Processing:
A. Governance and access
- documented data-flow, asset, provider, Subprocessor, retention and access registers;
- role-based least-privilege access limited to persons with a current need;
- multifactor authentication for privileged administrative access capable of reaching Customer Personal Data;
- confidentiality commitments, security instructions and prompt access revocation;
- periodic review of privileged accounts and provider access; and
- separation of the Application processing environment from ordinary public website administration to the extent reasonably practicable.
B. Encryption and credentials
- HTTPS/TLS protection for data in transit;
- strong provider-supported encryption for active storage and encrypted backups;
- secrets and encryption keys stored separately from uploaded content where reasonably practicable;
- verified representative email before any document upload and a protected Secure, HttpOnly current-browser session;
- fresh one-time email magic links that expire 30 minutes after issue and become invalid after successful use;
- a Recovery Code with at least 128 bits of cryptographic entropy, displayed once, stored only as a keyed hash, valid until automatic Job deletion and never sent with the magic link;
- Job ID alone, Stripe payment reference, billing details, purchaser or business facts and identity documents never authorize download, support access, early deletion, role changes or disclosure of transfer documents;
- no support reset of the verified email or Recovery Code and no restoration of expired or deleted content;
- separation of the 30-minute authentication-link period from the seven-calendar-day paid-output entitlement measured from Delivery Time;
- no complete payment-card data stored by Poland Documents; and
- credential invalidation when access expires or a compromise is suspected.
C. File and parser safety
- allow-listed CSV, XLSX, PDF and ZIP inputs with the exact file, worksheet, page, archive-expansion and processing limits stated in Section 4.1 and the Pricing, Limits & Retention Schedule;
- rejection or isolation of encrypted, password-protected, executable, macro-enabled, malformed, malicious or unexpectedly complex content;
- decompression-bomb, path-traversal, formula-injection and unsafe external-reference controls;
- restricted parsers and worker processes with minimum required permissions;
- malware or content screening appropriate to the supported formats; and
- OCR or external document processing disabled unless the specific production workflow, provider or verified local route, Processing locations, retention and safeguards have passed privacy and security review and are disclosed before upload;
- source-document, page-number, source-fragment, confidence and review-status provenance retained for each OCR-derived value; and
- low-confidence and all OCR-derived values blocked from Ready status until Customer confirmation or correction.
D. Application and infrastructure security
- secure development and change-review practices proportionate to the Application;
- dependency inventory, vulnerability review and timely risk-based patching;
- production configuration and release gates for security, retention, regulatory freshness and provider changes;
- protection against unauthorized Job enumeration, cross-Job access, replay, payment-state manipulation and download bypass;
- rate, concurrency, abuse and integrity controls; and
- tested rollback or suspension procedures for unsafe releases.
E. Logging and monitoring
- logging designed to exclude raw source rows, full uploaded content, authentication secrets and complete download tokens;
- redaction of sensitive parameters from errors and support diagnostics;
- monitoring for unauthorized access, abnormal processing, malware, provider failure and integrity events;
- restricted log access and documented log retention; and
- time-synchronized event records sufficient to investigate incidents and evidence deletion without retaining full content.
F. Availability, backup and deletion
- encrypted backups on a fixed, documented rotation no longer than Annex 3 permits;
- restoration controls that reapply deletion markers and access restrictions;
- reasonable recovery procedures for material infrastructure incidents;
- automatic expiry, credential invalidation and active-system deletion jobs;
- deletion verification and exception monitoring; and
- separation and restricted Processing of any legally preserved copy.
G. Assurance and incident management
- provider due diligence and written data-processing obligations before access;
- documented incident classification, containment, escalation, notification and remediation procedures;
- periodic risk review and testing of material controls;
- reasonable cooperation with Customer audits and Supervisory Authorities; and
- corrective-action tracking after a material incident or control failure.
Annex 3 — Retention and deletion instructions
Part A — Customer Personal Data: default Documented Instructions
The following periods are Customer’s default Documented Instructions for Customer Personal Data. A shorter period may be selected where the Application supports it. A longer period requires a documented delivery or refund case extension in 30-day increments, Customer’s express Documented Instruction with a specified expiry, or a binding preservation requirement under Union or Member State law applicable to Poland Documents. It may not be created by a silent policy change.
| Data or Job state | Default instruction |
|---|---|
| Failed upload; no Job created | Delete every active copy—including temporary objects, queues, parser workspaces and failed-upload staging—within 24 hours. |
| Free or unpaid Job | Delete after 7 consecutive days of inactivity and, in all cases, no later than 30 days from Job creation, unless an authorized hold applies. |
| Paid Job before Delivery | Retain until Delivery, cancellation resolution or refund resolution. |
| Paid Job not delivered | Within 14 calendar days after verified payment: Deliver, obtain a documented written extension, or initiate a full refund. |
| Source CSV, XLSX, PDF and ZIP files | Retain for 7 calendar days from Delivery Time. |
| Extracted files, OCR text and provenance, mappings, confirmations, corrections and intermediate data | Retain for 7 calendar days from Delivery Time. |
| CPSC CSV files, Complete Output Package and protected output access | Retain for 7 calendar days from Delivery Time. |
| Delivery or refund case | Retain only the necessary data for a base period of 30 calendar days. Each extension is one additional 30-day period and requires a documented reason and necessity review. |
| Application or support logs that unexpectedly contain Customer Personal Data | Minimize and delete as soon as practicable and no later than 90 days, absent an authorized hold. Raw source rows, full uploaded content and complete tokens must not be intentionally logged. |
| Customer Personal Data subject to an authorized legal or Customer-instructed hold | Isolate and retain only the minimum necessary content until the specified hold ends, review necessity periodically, then delete under Section 12. Source files and substantive record content do not become Controller Data merely because they may be evidence. |
| Encrypted backup remnants | Delete or overwrite no later than 30 days after active-system deletion, absent an authorized legal-preservation copy. Reapply deletion after restoration. |
At expiry, protected access ends immediately and active-system deletion is completed no later than 24 hours afterward.
Part B — Poland Documents Controller Data: information only
The periods below are not Customer’s Processor instructions. They describe separate Controller Data Processing under Section 16, the Privacy Policy and applicable law. Complete source files, extracted records, substantive row content and Output Packages are excluded from these categories.
| Controller Data category | Information about expected retention |
|---|---|
| Ordinary application, access, rate-limit and security logs without raw uploaded content | Exactly 90 days from creation, unless a documented fraud, security, legal-claim or binding preservation reason requires restricted retention. |
| Minimized fraud, chargeback or security-incident evidence | 12 months after the case closes. Customer Personal Data does not become Controller Data under this row. |
| Contract, price, payment, Delivery and deletion evidence without source files | 6 years after the later of payment, Delivery, cancellation or refund. |
| Ordinary support correspondence without source-file or substantive record content | 3 years after the matter closes. |
| Invoices and Polish tax records | The applicable Polish statutory period. |
| Structured invoices in KSeF | 10 years from the end of the calendar year in which the invoice was issued. |
Annex 4 — Subprocessor and transfer authorization
The Subprocessor List version identified in the electronic acceptance record forms part of this DPA. Customer specifically authorizes the entries marked active for the applicable Application component and grants the general written authorization for later additions or replacements only through the notice-and-objection procedure in Sections 8.2–8.3. A proposed Subprocessor becomes authorized only after that procedure is completed. An optional provider is authorized only if Customer affirmatively enables the feature that requires it.
No production Subprocessor may Process Customer Personal Data unless the list includes:
- exact legal name, registered address and privacy contact;
- Application component, subject matter, nature and purpose;
- categories of Personal Data and Data Subjects;
- storage, Processing and remote-access countries;
- relevant onward-processing chain;
- applicable transfer mechanism and, where relevant, active DPF status or SCC module;
- effective date and change notice; and
- available security and privacy materials.
For a Module Four return to a non-EEA Controller or Module Three return to a non-EEA Processor, the transfer intake and Annex 1 supply transaction-specific information for completion of the SCC annexes. Every mandatory SCC selection and annex must be completed, shown and accepted before the first record-level result or other Restricted Transfer; the official SCC text must not be modified.
Annex 5 — No-account electronic acceptance and evidence
A. Required customer fields before first upload
The pre-upload workflow must collect and validate:
- Customer’s full legal name and organizational form, or sole trader’s legal name;
- registered or principal business address and country;
- representative’s full name, professional role and business email;
- confirmation of representative authority;
- whether Customer acts as Controller or Processor for the submitted Personal Data;
- where Customer acts as Processor, the relevant Controller’s full legal name, country and privacy contact, together with confirmation that the Controller authorized the appointment; and
- a security or privacy notice email if different from the Job email.
Before any record-level result is made available to a non-EEA Customer, the workflow must also collect or determine:
- the exact data importer legal entity, registered or principal address, country and privacy contact;
- the importer’s Controller or Processor role and the identity of the relevant Controller where applicable;
- whether the importer’s relevant Processing is subject to the GDPR under Article 3(2);
- the exact adequacy decision or, for DPF reliance, the certified legal entity, covered data and scope, and verification date;
- the applicable SCC Module, options and official version;
- completed Annex I.A, Annex I.B, Annex I.C, Annex II and, where required, Annex III; and
- any UK or Swiss transfer instrument and required selections where those laws apply.
B. Required role selection
The user must select one option:
- “The Customer is the Controller of any Customer Personal Data submitted for this Job.”
- “The Customer is a Processor acting for another Controller and is authorized to appoint Poland Documents and the listed Subprocessors.”
C. Required unchecked acceptance checkbox
Immediately before the first upload control, display a separate checkbox, unchecked by default:
Required checkbox text:
“I confirm that the Controller/Processor role selected above is accurate and that I am authorized to act for {CUSTOMER LEGAL NAME}. On the Customer’s behalf, I instruct Poland Documents to process Customer Personal Data for this Job in accordance with, and accept, the CPSC eFiling CSV Checker & Builder Data Processing Addendum (version {DPA VERSION}). I specifically authorize the active Subprocessors identified in the CPSC eFiling CSV Checker & Builder Subprocessor List (version {LIST VERSION}) and grant general written authorization for the addition or replacement of Subprocessors in accordance with Sections 8.2–8.3 of the DPA, including the prior-notice and objection procedure.”
The linked Data Processing Addendum and Subprocessor List must be fixed, downloadable and reproducible. Keep this DPA control separate from the universal pre-upload, Privacy Policy, Terms and marketing controls; no accept-all is permitted. Show it only in the B2B Controller/Processor branch, never as Consumer privacy consent. Keep the upload interface and server-side API disabled until Customer and representative fields and role selection are complete, the control changes from false to true, and the acceptance record and fixed DPA/List snapshot are committed. Changing Customer legal name, role, relevant ultimate Controller, DPA version or accepted List version resets the control and requires fresh acceptance.
D. Evidence record
For each acceptance, Poland Documents must retain without the full uploaded content:
- Customer legal name, address and country;
- representative name, role, business email and authority confirmation;
- selected Controller/Processor role;
- stable control identifier; exact placeholder-resolved checkbox and role-selection text; language and placement; initial false state; displayed-at and false-to-true checked-at UTC events; UI version; and Job and acceptance-snapshot identifiers;
- immutable DPA and Subprocessor List bytes; document names, versions, URLs, object identifiers and SHA-256 hashes;
- Job identifier;
- UTC timestamp;
- verified representative-email method and time; confirmation-PDF identifier and SHA-256 hash; provider send, message, delivery and bounce evidence; and correction or reverification events;
- any applicable adequacy or DPF entity, scope, status and verification date; and
- any applicable SCC or other transfer instrument, Module, options, fully completed annexes, official version, URL, content hash, UTC acceptance timestamp and party details.
The contract and acceptance evidence in this Annex is retained for 6 years after the later of payment, Delivery, cancellation or refund, without retaining source files, extracted content, Output Packages, clear access tokens or Recovery Codes beyond their applicable temporary periods.
Immediately after acceptance, Poland Documents must provide through the protected Job page and send to the pre-verified representative email the same immutable PDF or content-addressed snapshot containing the accepted DPA and exact Subprocessor List, selected role, placeholder-resolved checkbox text, UTC acceptance time, versions and hashes. A mutable URL is insufficient. The evidence record must retain the provider send, message, delivery and bounce status. A known bounce pauses Processing until the notice channel is reverified and the snapshot is reissued, or the Job is cancelled; both versions and correction or reverification events are retained immutably.