English translation of the prepared Spanish document, version 2026-09-06.3. This is not a new contract version or a record of acceptance. Read the Spanish source

Data processing agreement — version 2026-09-06.3

Status: prepared; full identification of the parties, a specific annex and acceptance are required before real data is used.

The customer is the controller for contacts in its workspace; the provider identified in the proposal is the processor. The purpose is to receive, record, store, organise, consult, export and erase commercial opportunities under the customer's instructions. Data subjects are the customer's contacts and users. Data includes identification, business contact details, messages, company, assigned staff, notes and actions; unauthorised high-risk data is excluded.

The processing lasts for the service and the agreed return/erasure period. The annex specifies source, volume, categories, operational retention and grace period. Historical pilot values of 90/30 days do not automatically become an obligation for all customers or prove automatic execution.

The processor:

- Processes data only under documented instructions, including transfers; informs the customer of an instruction it considers contrary to the GDPR. If a rule requires it to process differently, it communicates that requirement unless legally prohibited. - Requires confidentiality from authorised persons and limits their permissions to necessary work; documents support access. - Maintains measures appropriate to risk: workspace isolation, authentication, permissions, protected transport, secrets management, minimised records, backups and recovery, deletion controls and incident controls. The annex must describe the actual configuration and its limits without claiming non-existent certifications. - Does not engage subprocessors without documented specific or general authorisation. With general authorisation, it notifies planned changes to allow reasoned objections and resolve them before the affected processing. It imposes equivalent obligations and remains responsible to the customer for their fulfilment. - Assists with rights, impact assessments, prior consultations and security according to the available information and nature of the processing. - Notifies the controller of a personal data breach without undue delay, supplying known information about its nature, affected parties, consequences, measures and contact, and completing the information progressively. The controller's 72-hour deadline for notification to the authority is not interpreted as permission to wait before notifying the customer. - On termination, returns or erases data according to the customer's documented choice, including copies according to their verified cycle, unless legal retention is required. Records the result and exceptions. - Provides the information needed to demonstrate compliance and allows audits and inspections consistent with the GDPR, protecting other customers and legitimate secrets without negating that right.

The customer determines the legal basis, informs its contacts, limits data and maintains instructions and authorised users. The processor forwards data-subject requests to the controller without handling them independently unless instructed or legally required.

Providers are individually identified in the annex: entity, role, data, region, access from third countries, accepted contract/DPA, transfer safeguards, retention of logs/backups and evidence. Finding a public provider page is not enough. Polar may act as an independent controller for payments and its own obligations; it is not automatically classified as a subprocessor for all data.

For its own purchasing, account and support contacts and legal obligations, the provider acts as controller under its privacy notice. That role is not extended to customer data for incompatible purposes.

Annex to be completed for each customer: controller/processor identification; workspace and source; operators; volume; data; purpose; duration; retention and grace period; providers and evidence; measures; incident channel and responsible persons; export/erasure; version, date and acceptance by both parties.