DATA PROCESSING ADDENDUM (DPA)
28 August 2026
<p dir="ltr">This Data Processing Addendum forms an integral part of the principal service agreement or Terms of Use concluded between VÖEN 1202614302, which represents the AISALESPOS platform, and the customer.</p>
<h2 dir="ltr">1. Roles of the parties</h2>
<p dir="ltr">Within the framework of this Addendum:</p>
<ul> <li dir="ltr"> <p dir="ltr">The Customer acts as the controller of the personal data</p> </li> <li dir="ltr"> <p dir="ltr">The Company acts as the processor which processes that data for the purpose of providing the service</p> </li> </ul>
<p dir="ltr">If in certain cases the roles of the parties differ, the actual role applies in respect of that part.</p>
<h2 dir="ltr">2. Subject matter and purpose of processing</h2>
<p dir="ltr">The Company may process personal data for the following purposes:</p>
<ul> <li dir="ltr"> <p dir="ltr">to create and manage accounts</p> </li> <li dir="ltr"> <p dir="ltr">to process orders, sales and POS transactions</p> </li> <li dir="ltr"> <p dir="ltr">to store inventory and business data</p> </li> <li dir="ltr"> <p dir="ltr">to provide support and technical services</p> </li> <li dir="ltr"> <p dir="ltr">to carry out security and audit activities</p> </li> <li dir="ltr"> <p dir="ltr">to perform backup and restoration</p> </li> <li dir="ltr"> <p dir="ltr">to operate integrations</p> </li> <li dir="ltr"> <p dir="ltr">to comply with legal obligations</p> </li> </ul>
<h2 dir="ltr">3. Categories of personal data</h2>
<p dir="ltr">The data processed may include the following:</p>
<ul> <li dir="ltr"> <p dir="ltr">first name, last name</p> </li> <li dir="ltr"> <p dir="ltr">telephone</p> </li> <li dir="ltr"> <p dir="ltr">e-mail</p> </li> <li dir="ltr"> <p dir="ltr">address</p> </li> <li dir="ltr"> <p dir="ltr">customer order data</p> </li> <li dir="ltr"> <p dir="ltr">sales history</p> </li> <li dir="ltr"> <p dir="ltr">user roles and login logs</p> </li> <li dir="ltr"> <p dir="ltr">business transaction records</p> </li> <li dir="ltr"> <p dir="ltr">device and IP data</p> </li> </ul>
<h2 dir="ltr">4. Data subjects</h2>
<p dir="ltr">Data relating to the following persons may be processed:</p>
<ul> <li dir="ltr"> <p dir="ltr">the customer's end users</p> </li> <li dir="ltr"> <p dir="ltr">the customer's employees</p> </li> <li dir="ltr"> <p dir="ltr">cashiers and managers</p> </li> <li dir="ltr"> <p dir="ltr">branch and store staff</p> </li> <li dir="ltr"> <p dir="ltr">delivery and related persons</p> </li> <li dir="ltr"> <p dir="ltr">end purchasers</p> </li> </ul>
<h2 dir="ltr">5. Obligations of the processor</h2>
<p dir="ltr">The Company undertakes:</p>
<ul> <li dir="ltr"> <p dir="ltr">to process the data only in accordance with the controller's documented instructions</p> </li> <li dir="ltr"> <p dir="ltr">to protect the confidentiality of the data</p> </li> <li dir="ltr"> <p dir="ltr">to take appropriate security measures</p> </li> <li dir="ltr"> <p dir="ltr">to engage a sub-processor only where necessary</p> </li> <li dir="ltr"> <p dir="ltr">to support the controller, where possible, in relation to legal enquiries and data subject requests</p> </li> <li dir="ltr"> <p dir="ltr">to return, delete or anonymise the data upon termination of the service<br /> as set out above.</p> </li> </ul>
<h2 dir="ltr">6. Obligations of the controller</h2>
<p dir="ltr">The Customer is responsible for:</p>
<ul> <li dir="ltr"> <p dir="ltr">the lawful collection of personal data</p> </li> <li dir="ltr"> <p dir="ltr">the provision of notice to data subjects</p> </li> <li dir="ltr"> <p dir="ltr">obtaining consent where consent is required</p> </li> <li dir="ltr"> <p dir="ltr">the accuracy of the data</p> </li> <li dir="ltr"> <p dir="ltr">the provision of lawful instructions for processing<br /> as set out above.</p> </li> </ul>
<h2 dir="ltr">7. Security</h2>
<p dir="ltr">The Company takes reasonable technical and organisational measures. Such measures may include the following:</p>
<ul> <li dir="ltr"> <p dir="ltr">access restrictions</p> </li> <li dir="ltr"> <p dir="ltr">authentication</p> </li> <li dir="ltr"> <p dir="ltr">logging</p> </li> <li dir="ltr"> <p dir="ltr">encryption or appropriate security mechanisms</p> </li> <li dir="ltr"> <p dir="ltr">backup copies</p> </li> <li dir="ltr"> <p dir="ltr">monitoring</p> </li> <li dir="ltr"> <p dir="ltr">role-based access control</p> </li> </ul>
<h2 dir="ltr">8. Sub-processors</h2>
<p dir="ltr">The Company may use sub-processors for hosting, e-mail, SMS, analytics, support, monitoring and other necessary services. The Customer accepts this. Where possible, the Company endeavours to apply appropriate contractual obligations with such parties.</p>
<h2 dir="ltr">9. International transfers</h2>
<p dir="ltr">Personal data may be processed through infrastructure and service providers located in various countries. The Customer accepts this. Where necessary, appropriate contractual and protective mechanisms are applied.</p>
<h2 dir="ltr">10. Data subject requests</h2>
<p dir="ltr">If a data subject makes a request concerning access, erasure, rectification or other rights, the Company may, where possible, refer it to the controller or provide support in accordance with the controller's instructions.</p>
<h2 dir="ltr">11. Data breaches</h2>
<p dir="ltr">Where the Company detects a personal data breach, it will endeavour to inform the controller to the extent required by the applicable legislation.</p>
<h2 dir="ltr">12. Audit and evidence</h2>
<p dir="ltr">Where there is a substantiated security or legal necessity, the parties may share compliance evidence, policies or contractual confirmations within a reasonable framework. This process must not put at risk the Company's confidential information, its other customers or its security model.</p>
<h2 dir="ltr">13. Term and effect</h2>
<p dir="ltr">This DPA applies for as long as the principal agreement remains in force, and the parts relating to the processing of personal data may, where necessary, remain in force after the agreement ends.</p>
<h2 dir="ltr">14. Conflict</h2>
<p dir="ltr">If a conflict arises between this Addendum and the principal agreement regarding the processing of personal data, this Addendum prevails in respect of that part.</p>
<p><br /> <br /> </p>