Version 1.0 · Effective 18 September 2026
-
Parties, Conclusion and Definitions
- This Data Processing Agreement (“DPA”) is entered into between IT-Dev spółka z ograniczoną odpowiedzialnością, ul. gen. Władysława Sikorskiego 26, 53-659 Wrocław, Poland, entered in the register of entrepreneurs of the National Court Register (KRS) under number 0000252663, kept by the District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division of the National Court Register, tax ID (NIP) 8971713178, REGON 020240415, share capital PLN 60,000, operating under the Engagy360 brand (“Engagy”), and the Customer.
- “Customer” means the entity that orders the Services from Engagy under an Order or, where the Services are acquired through a Reseller, the entity identified in the Order as the end customer using the Services.
- This DPA forms part of the Engagy360 Terms of Service, published at https://engagy360.com/terms-of-service, and the applicable Order (together, the “Agreement”). It is concluded electronically when the Agreement is concluded, in the version in force on the date of the Order, and does not require a separate signature.
- The person placing the Order on behalf of Customer represents that they are authorised to enter into this DPA on Customer’s behalf.
- Customer enters into this DPA on its own behalf and on behalf of its Affiliates permitted to use the Services under the Agreement. Customer is the sole point of contact for Engagy and exercises all rights under this DPA on behalf of those Affiliates.
- Customer acts as the controller and Engagy as the processor of Personal Data. Where Customer acts as a processor on behalf of a third-party controller, Engagy acts as a subprocessor, and Customer warrants that it has obtained all authorisations from that controller required to give instructions under this DPA and to engage Engagy and its Subprocessors.
- This DPA does not cover the business contact and account data of Customer’s representatives (the person placing the Order, the licence contact, the Data Protection Contact and persons corresponding with Engagy on commercial or support matters). Engagy processes that data as a controller, for its own purposes of concluding and performing the Agreement, invoicing, accounting and service communication, on the basis of its legitimate interests and its legal obligations, and retains it for the term of the Agreement and for the period required by tax law and by the limitation periods for claims. Engagy informs those persons separately in accordance with Article 13 GDPR at https://engagy360.com/privacy-policy.
- Upon Customer’s request, Engagy will provide this DPA for signature in the same wording. Any deviating terms bind the parties only if agreed in a separate document signed by both parties.
- This DPA is executed in English. Any translation is for reference only and has no legal effect.
- Terms used in this DPA have the meanings given to them in Regulation (EU) 2016/679 (“GDPR”); capitalised terms not defined here have the meanings given in the Terms of Service. In addition:
- Services – the Engagy360 platform provided under the Agreement (the “Offerings” within the meaning of the Terms of Service), including the Cloud Control Panel, the SharePoint client application (SPFx), the Microsoft Teams app, the AI Features and the App.
- App – the EngagyApp mobile application together with its administration panel and related server-side services.
- AI Features – the features of the Services described in Section 4.
- Customer Tenant – Customer’s Microsoft 365 environment (including SharePoint Online, Microsoft Teams and Microsoft Entra ID).
- Customer Data Partition – Customer’s data held in Engagy’s infrastructure, comprising Customer’s dedicated Azure Storage Account, Customer’s records in Engagy’s central database and the data store of the App.
- Users – individuals using the Services within the Customer Tenant, including administrators, portal owners and contributors, site owners and editors, and Customer’s employees.
- Workers – individuals for whom Customer has created an account in the App.
- Data Protection Contact – the email address designated by Customer in the Order or in its account settings or, if none, the email address of the person who placed the Order.
- Subprocessor – any third party, including any Affiliate of Engagy, engaged by Engagy to process Personal Data on Customer’s behalf. Individuals engaged by Engagy under employment or service contracts who work within Engagy’s organisation and systems, under its instructions and bound by confidentiality, are persons authorised to process Personal Data under Article 29 GDPR and are not Subprocessors.
- Subprocessor List – the current list of Subprocessors published at https://engagy360.com/subprocessors.
- Personal Data Breach – a personal data breach as defined in Article 4(12) GDPR affecting Personal Data processed under this DPA.
-
Subject Matter, Purpose and Duration
- Customer engages Engagy to process Personal Data of Users and Workers to the extent and for the purposes described in Annex 1.
- Engagy processes Personal Data solely to provide the Services, in particular to: design, deploy and maintain intranet portals in the Customer Tenant; manage content, roles and portal governance (including access reviews and configuration audits); handle User reports and editorial tasks; send notifications and manage subscriptions; provide the AI Features; store the content Customer provides, deliver it to Workers in the App and record acknowledgements of required documents; and provide technical support, including processing of Support Data.
- Engagy does not process Personal Data for its own purposes, does not sell it and does not use it for advertising or marketing. Personal Data and Customer Data do not constitute Feedback within the meaning of the Terms of Service.
- Processing continues for the term of the Agreement and, after its termination, until the Personal Data is deleted or returned in accordance with Section 9.
- In the App, after an account is disabled, the Worker’s data is retained for 12 months and then deleted automatically. Customer may set a different period in the App settings and is responsible for aligning it with its legal obligations, including those relating to records of health and safety training.
- Customer may place an App account on legal hold, for example in connection with a legal claim or an investigation. While the hold is in place, the data is not deleted, even after the period in Section 2.5.
- The App is intended for adults only. Customer will create App accounts only for Workers aged 18 or over and is responsible for compliance with this restriction.
- Other Personal Data stored in the Customer Data Partition, including User reports and operation history, is retained for the term of the Agreement unless Customer deletes it earlier, and is then deleted in accordance with Section 9.8.
-
Customer Tenant and Third-Party Tools
- Engagy accesses the Customer Tenant only within the permissions granted by Customer’s administrator (administrator consent for the Engagy360 applications) and only to provide the Services.
- Outside the App, the Personal Data of Users that Engagy stores in the Customer Data Partition is limited to Microsoft Entra ID object identifiers together with the unstructured content that Users enter or that is generated for Customer, as listed in Annex 1, part A. Profile and directory data (including name, email address, job title, department, photo, group membership and site permissions) is retrieved from the Customer Tenant through Microsoft Graph when needed and is not persisted; it exists only in the server’s working memory, for no longer than 5 minutes, and in the browser cache on the User’s own device.
- Data stored in the Customer Tenant (including sites, content, documents, comments and the user directory) remains in the Customer Tenant. Microsoft provides Microsoft 365 services under its agreement with Customer and, in that capacity, is not a Subprocessor of Engagy. Content that Customer publishes to the App is an exception: articles and files, including files taken from SharePoint, are copied to the Customer Data Partition so that the App can display them to Workers. The originals remain in the Customer Tenant, and the copies are updated or deleted only through the App administration panel; deleting or changing the original in the Customer Tenant does not affect the copy.
- Google Analytics and Microsoft Clarity are Customer’s own tools. Engagy stores only the tracking identifiers provided by Customer and does not receive data collected by those tools. Customer is responsible for the legal basis, cookie consents and agreements with the providers of those tools.
- Customer may withdraw Engagy’s permissions at any time by removing the administrator consent and the Engagy360 applications from the Customer Tenant, in which case the Services will stop functioning.
-
AI Features
- The AI Features (including generation of draft information architecture, initial portal content and suggested notification text) process data provided by Customer: company information, uploaded source documents, Customer’s website address and article content.
- The AI Features use Microsoft Azure OpenAI Service in a regional deployment in Sweden Central. Microsoft does not use this data to train OpenAI or Azure OpenAI models and does not make it available to other services. Prompts and generated responses are retained by Microsoft for up to 30 days for abuse monitoring, to prevent misuse and the generation of harmful content.
- Source documents uploaded in the portal creation wizard are stored only until the portal is created or the portal draft is deleted, and are then removed. The output generated from them (the information architecture, initial article texts and the names and base definitions of Viva Engage communities to be created) is retained as Customer’s content and may contain Personal Data; Section 2.8 applies to it.
- Customer should not submit to the AI Features special categories of personal data (Article 9 GDPR) or any Personal Data not needed for the task. Outputs of the AI Features are suggestions that Customer reviews before publication.
-
Obligations of Engagy
Engagy will:
- Process Personal Data only on Customer’s documented instructions. Customer’s instructions are this DPA, the Agreement and Customer’s configuration of the Services; Customer may give additional instructions in writing or by email. If Union or Member State law requires other processing, Engagy will inform Customer before processing, unless that law prohibits it.
- Inform Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection law.
- Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement the technical and organisational measures described in Annex 2, appropriate to the risk (Article 32 GDPR). Engagy may update these measures provided that the overall level of protection is not reduced.
- Access the Customer Tenant for implementation work (including Tailor-Made packages and template-based portals) and technical support only at Customer’s request and within the agreed scope.
- Maintain a record of processing activities in accordance with Article 30(2) GDPR and make it available to Customer on request.
- Designate a contact for data protection matters: Grzegorz Łuszczyński, gluszczynski@it-dev.pl.
-
Subprocessors
- Customer grants general authorisation for Engagy to engage the Subprocessors on the Subprocessor List. The list as at the publication date of this version of the DPA is set out in Annex 3. Affiliates of Engagy may process Personal Data only if listed as Subprocessors.
- Engagy will give at least 30 days’ notice of any intended addition or replacement of a Subprocessor by updating the Subprocessor List and sending a notice by email to the Data Protection Contact. Customer is responsible for keeping that address up to date.
- Within the notice period, Customer may object on reasonable data protection grounds, stating those grounds in writing. Grounds are not reasonable where the new Subprocessor performs the same processing activity on the same categories of Personal Data, in a location offering an equivalent level of protection and under an equivalent transfer mechanism, and its technical and organisational measures are not less protective. Engagy will then make good-faith efforts to find a solution, which may include keeping Customer on the existing Subprocessor or offering an alternative configuration. If no solution is found, Customer may terminate the affected Services with effect from the date of the change, without penalty and notwithstanding any non-refund provisions of the Terms of Service, and Engagy will issue a credit for prepaid fees covering the unused period, applicable to future fees for the Services. Where the change moves processing of Personal Data outside the European Economic Area or relies on a transfer mechanism providing a lower level of protection, Customer may instead request a pro-rata cash refund of those prepaid fees, payable within 30 days of termination.
- If Customer does not object within the notice period, the change is deemed accepted.
- Where a replacement is urgently required for the continuity or security of the Services, Engagy may replace a Subprocessor immediately and will notify Customer no later than on the date of the change; Section 6.3 applies accordingly.
- Engagy will impose on each Subprocessor data protection obligations no less protective than those in this DPA and remains fully liable to Customer for the acts and omissions of its Subprocessors.
-
Assistance: Data Subject Rights, DPIA and Personal Data Breaches
Data subject rights
- Engagy assists Customer in responding to requests from data subjects (Articles 15–22 GDPR). In the App, the administration panel provides functions to edit data, disable accounts, apply legal hold, anonymise and export. In the other Services, User data originates from the Customer Tenant and is handled by Customer in Microsoft 365; on request, Engagy will locate and delete the identifiers and reports of a given User in the Customer Data Partition.
- Engagy will forward any request received directly from a data subject to the Data Protection Contact within 5 business days and will not respond to it on the merits without Customer’s instructions.
DPIA and prior consultation
- Engagy will provide Customer with information reasonably required for data protection impact assessments (Article 35 GDPR) and prior consultations with a supervisory authority (Article 36 GDPR). That information comprises the description of processing in Annex 1, the technical and organisational measures in Annex 2, the list of Subprocessors, and answers to Customer’s questions about the Services.
Personal Data Breaches
- Engagy will notify Customer of a Personal Data Breach without undue delay and in any event within 48 hours after becoming aware of it, by email to the Data Protection Contact.
- The notification will include at least: a description of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and the contact details of Engagy’s contact for data protection matters. Information not available at the time of notification will be provided in phases.
- Engagy will document each Personal Data Breach and assist Customer in notifying the supervisory authority and data subjects (Articles 33–34 GDPR). Engagy will not notify the authority or data subjects on Customer’s behalf without Customer’s instructions, unless required by law.
- Notification of a Personal Data Breach is not an acknowledgement of fault or liability by Engagy.
-
International Transfers
- Personal Data is stored and processed in data centres in the European Union, including processing by the AI Features in Sweden.
- Engagy itself makes no transfer of Personal Data outside the European Economic Area, with one exception: the transfer of a Worker’s phone number to Twilio Inc. to send an SMS activation code, and only where the Worker activates the App by that method.
- That transfer is based on Twilio Inc.’s certification under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023). Twilio’s data processing agreement provides for an alternative transfer mechanism should the certification lapse.
- Microsoft, as a Subprocessor, may access Personal Data from outside the EEA for support and security operations, under its own data processing terms, its EU Data Boundary commitments and, where applicable, the EU-U.S. Data Privacy Framework or the Standard Contractual Clauses.
- Any other transfer outside the EEA requires prior notice under Section 6.2 and appropriate safeguards under Chapter V GDPR. This Section prevails over any provision of the Terms of Service that subjects all transfers to the Standard Contractual Clauses.
-
Audits, Liability, Termination and Deletion
Audits
- Engagy will make available to Customer the information necessary to demonstrate compliance with Article 28 GDPR, primarily in the form of documentation, certifications and responses to security questionnaires.
- If that information is insufficient, Customer may conduct an audit, itself or through an auditor bound by confidentiality who is not a competitor of Engagy, no more than once a year, with 30 days’ prior notice, on business days and without disrupting the provision of services to other customers. The frequency limit does not apply after a Personal Data Breach affecting Customer’s data or where required by a supervisory authority.
- Customer bears all costs of the audit, including the fees of any auditor it appoints and Engagy’s reasonable costs of supporting the audit, charged at Engagy’s then-current professional services rates. Engagy may require that audits requested by several customers be carried out jointly. Where Engagy holds a current independent certification or audit report covering the Services, such as ISO/IEC 27001, Engagy may first provide it in response to an audit request, and an audit under Section 9.2 may then take place only to the extent the certification or report does not reasonably address Customer’s concerns.
- This Section supplements and, in matters of data protection, prevails over the provisions of the Terms of Service on GDPR and data protection audits.
Liability
- Each party’s liability under this DPA is subject to the limitations of liability in the Agreement, to the extent permitted by Data Protection Law. Nothing in this DPA limits either party’s liability to data subjects under Article 82 GDPR.
- No disclaimer or force majeure provision of the Agreement relieves Engagy of its obligations under Articles 28 and 32 GDPR and this DPA, including its responsibility for Subprocessors (including Microsoft Azure) and its obligation to notify Personal Data Breaches, including those caused by cyberattacks.
Termination, return and deletion
- Before the Agreement ends, Customer may export the acknowledgements recorded in the App using the export function available to users holding the Administrator or Communicator role. Account data is not available for export through the Services; Engagy will provide it on a request made no later than on the termination date.
- Engagy will delete the Customer Data Partition, including Customer’s dedicated Azure Storage Account and Customer’s records in Engagy’s central database, within 30 days after termination of the Agreement, unless Union or Member State law requires further storage. Data that Engagy processes as a controller under Section 1.7 is not covered by this Section. Portals, sites and content in the Customer Tenant are not deleted, and disconnecting them from the Services does not affect their content. Removing the Engagy360 applications and withdrawing administrator consent in the Customer Tenant is Customer’s responsibility.
- Engagy keeps no backup copies of Customer’s data outside the Azure services holding it. Backups maintained by the Azure services are deleted automatically within 35 days after deletion of the data, so the deletion under Section 9.8 covers all copies held by Engagy no later than 35 days after that deletion.
- Aggregated statistics that cannot be linked to Users or Workers may be retained.
- On request, Engagy will confirm the deletion by email.
-
Changes, Assignment and Final Provisions
- Notwithstanding the amendment provisions of the Terms of Service, Engagy may amend this DPA by publishing a new version at https://engagy360.com/dpa and notifying the Data Protection Contact at least 30 days before it takes effect. Previous versions remain available in an archive on that page.
- An amendment may not reduce the level of data protection or restrict Customer’s rights under the GDPR. Amendments required by law or by a decision of an authority may take effect earlier.
- A Customer that does not accept an amendment may, before it takes effect, terminate the Agreement with effect from the date the amendment takes effect, without penalty and notwithstanding any non-refund provisions of the Terms of Service, and Engagy will issue a credit for prepaid fees covering the unused period, applicable to future fees for the Services. Where the amendment would reduce the level of data protection or restrict Customer’s rights under the GDPR, Customer may instead request a pro-rata cash refund of those prepaid fees, payable within 30 days of termination. Continued use of the Services after the effective date constitutes acceptance of the amendment.
- Customer agrees that IT-Dev sp. z o.o. may transfer its rights and obligations under this DPA and the Agreement to an entity that takes over the business conducted under the Engagy360 brand, in particular as a result of its spin-off into a separate company (“Transferee”). Engagy will notify the Data Protection Contact at least 30 days in advance, providing the Transferee’s details. The transfer takes effect provided that the Transferee assumes all obligations under this DPA and the level of data protection is not reduced. Section 10.3 applies accordingly to a Customer that does not accept the transfer.
- Notices under this DPA may be given by email and such notices satisfy any requirement of written form under the Agreement.
- This DPA remains in force for the term of the Agreement and until the obligations under Sections 9.7–9.11 have been fulfilled.
- In matters of personal data protection, this DPA prevails over the other documents forming the Agreement, including the Terms of Service and the SLA, unless an Order expressly provides otherwise. Remedies under the SLA do not limit Customer’s rights under this DPA.
- This DPA is governed by the laws of the Republic of Poland. Disputes are resolved by the court competent under the Agreement.
Annex 1. Description of Processing
Categories of data subjects: Users (Customer’s Engagy360 and Microsoft 365 administrators, portal owners and contributors, site owners and editors, and Customer’s employees using the intranet); Workers using the App (including temporary workers and contractors) and their managers; individuals mentioned in content, documents, reports and Support Data.
Special categories of data (Article 9 GDPR): the Services do not require and are not intended for such data. The App does not collect reasons for absence. Customer will not submit such data in User reports or to the AI Features; Customer is responsible for content it publishes in the Customer Tenant.
Processing operations: collection, storage, retrieval, organisation, display, transmission, anonymisation and deletion, as necessary to provide the Services.
A. Data stored in the Customer Data Partition (Engagy360 platform)
| Category | Data elements | Purpose |
| User identifiers | Microsoft Entra ID object identifiers linked to portal roles, tasks, access reviews, subscriptions, operation history (Settings → Requests) and Site Score Audit reports | Operating the Services, portal governance, accountability of operations |
| User reports | Report title and content (free text), page address, date, identifiers of the submitter and assignees | Handling page issue reports and site requests |
| Notification content | Text of article notifications sent to Microsoft Teams | Notifications and subscriptions |
| Portal drafts and generated content | Information architecture, initial article texts and names and base definitions of Viva Engage communities to be created, to the extent they contain Personal Data | Creating portals from a draft |
| Uploaded files | Image files used to generate visual themes; source documents for the AI Features, stored only until the portal is created or the draft is deleted | Portal design and generation |
| SharePoint addresses and structures | Site and page addresses, site, list, library and group names | Score Cards reports, notifications, portal governance |
| Access tokens | Users’ access tokens used for long-running operations, stored in Azure Key Vault for the duration of the operation | Performing operations in the Customer Tenant on the User’s behalf |
| Support Data | Data provided in support requests or accessed with Customer’s authorisation during support | Technical support |
| Technical data | Operational and error logs. The logs are not used to identify Users and do not contain profile data; they may contain SharePoint site and page addresses | Operating and maintaining the Services |
B. Data retrieved on demand from the Customer Tenant (not persisted)
Name, user principal name (UPN), email address, job title, department, phone number, photo, group membership, site permissions, content view statistics and the names and identifiers of existing Viva Engage communities and their groups. This data is retrieved through Microsoft Graph and SharePoint interfaces when displayed or needed (including the Address Book, people cards, portal roles, access reviews and Teams notification recipients) and is not persisted (Section 3.2).
C. Data processed by the AI Features
Company information, source documents, content of Customer’s website and articles, to the extent they contain Personal Data. Processed in Azure OpenAI Service (Sweden Central, regional deployment) to generate the output, and retained by Microsoft for up to 30 days for abuse monitoring; not used to train models. Source documents are deleted once the portal is created or the draft is deleted (Section 4).
D. Data stored in the App (EngagyApp)
| Category | Data elements | Source | Purpose |
| Identification data | First name, last name, employee number | Customer (CSV import or panel) | Identifying the Worker in the App |
| Organisational data | Department, work site (site name), manager (Microsoft 365 account) | Customer | Content targeting, permissions, device pairing |
| Contact data | Phone number (optional) | Customer | SMS activation only |
| Authentication data | PIN (in non-reversible form), activation token, SMS code | Worker / system | Sign-in and activation |
| Device code | Code binding the account to the phone | Worker’s device | Restricting the account to one device |
| Account data | Status, creation and disabling dates, last activity, legal hold and anonymisation flags | System / Customer | Account management |
| Content published to the App | Text of articles and documents, files and images, and their metadata (author, version, date, category, target audience), to the extent they contain Personal Data | Customer (SharePoint integration or upload in the panel) | Making content available to Workers in the App |
| Acknowledgements | Worker, document, version, date and time of acknowledgement | Worker | Audit trail for required documents; visible by name to managers, content publishers and administrators on Customer’s side, including in exports |
| Read status | Which items the Worker opened | Worker | Marking new content in the App; Customer sees only the number of people who opened an item |
| Technical data | Error and performance logs | System | Operating the App only |
The App does not process device location, contacts, photos, files, calendar or microphone data and does not send notifications. The camera is used only to read the activation code; no image is stored.
Annex 2. Technical and Organisational Measures
Confidentiality and access control
- Encryption of data in transit and at rest, using platform-managed keys of the Azure services.
- Sign-in to the Cloud Control Panel through Customer’s Microsoft Entra ID, subject to Customer’s policies (including MFA and conditional access).
- Each customer’s data is held in its own dedicated Azure Storage Account; the central database holds licence and technical records identifying the customer.
- Access to the Customer Tenant limited to the Microsoft Graph and SharePoint permissions approved by Customer’s administrator; the full list, with examples of use, is published in the Engagy360 technical brochure. The broadest of them is the application permission Sites.FullControl.All in SharePoint.
- A reduced-permission mode is available, in which the Services use only the application permission Sites.Selected: read access to the SharePoint admin site and full control limited to the sites registered with the Services.
- The application permission Community.ReadWrite.All is used only to create Viva Engage communities and to read the list of communities; conversations and their content remain in the Customer Tenant.
- A Worker’s App account works only on the device on which it was activated.
- The PIN is not stored on the device; on the servers it is stored only in a form from which the PIN cannot be recovered.
- Activation tokens valid for 7 days and invalidated after use; SMS codes valid for 5 minutes.
- Role-based access in the App administration panel: Administrator, Deskless Team Manager, Deskless Staff Communicator.
- Access of Engagy personnel to the production environment through named accounts with MFA; privileges are granted and revoked through Azure Privileged Identity Management, which also records their use. Service accounts and the account used for DevOps operations have standing access.
Integrity
- Acknowledgements of documents cannot be modified and are linked to the document version.
- The mobile App does not connect directly to Customer’s systems (SharePoint, Microsoft 365); it receives only copies of content pushed through the integration.
Availability and resilience
- Hosting in Microsoft Azure data centres: West Europe for the database, storage accounts, service logs and key vault; Sweden Central for the AI Features.
- Engagy keeps no backup copies of Customer’s data outside the Azure services holding it, which maintain their backups and replicas within the European Union. Backups maintained by the Azure services are deleted automatically within 35 days after deletion of the data.
- Monitoring of operation and errors on Engagy’s servers only.
Data minimisation and privacy by design
- Outside the App, only Entra ID identifiers and content entered or generated for Customer are stored; profile and directory data is retrieved from the Customer Tenant at the time of use.
- Microsoft Graph data held in the server’s working memory for no longer than 5 minutes.
- Site Score Audit reports and operation history contain only User identifiers.
- Technical logs are not used to identify Users and do not contain profile data; they may contain SharePoint site and page addresses.
- Source documents for the AI Features deleted once the portal is created or the draft is deleted; data sent to Azure OpenAI is not used to train models and is retained by Microsoft for up to 30 days for abuse monitoring.
- No third-party analytics, advertising or crash-reporting libraries in the mobile App; no access to location, contacts, photos, files, calendar or microphone; no push notifications.
- Account anonymisation, legal hold and automatic deletion of App data after the period set by Customer.
Organisational measures
- Written authorisations and confidentiality undertakings for persons with access to Personal Data.
- Personal Data Breach response procedure and breach register.
- Record of processing activities (Article 30(2) GDPR).
- Assessment of Subprocessors before engagement and periodic review.
- Contact for data protection matters: Grzegorz Łuszczyński, gluszczynski@it-dev.pl.
Annex 3. Subprocessors – as at the publication date of this DPA version
The current list is maintained at https://engagy360.com/subprocessors and prevails over this Annex in case of any discrepancy (Section 6).
| Subprocessor | Scope | Data | Location | Transfer mechanism |
| Microsoft Ireland Operations Ltd. (Microsoft Azure) | Hosting of the Customer Data Partition and the App, data storage, technical logs | Annex 1, parts A and D | EU: West Europe | See Section 8.3 |
| Microsoft Ireland Operations Ltd. (Azure OpenAI Service) | AI Features | Annex 1, part C | Sweden (Sweden Central) | See Section 8.3 |
| Twilio Inc. (Twilio Verify) | Sending SMS activation codes in the App | Phone number, one-time code | United States | EU-U.S. Data Privacy Framework |
Microsoft, as the provider of Microsoft 365 for the Customer Tenant, is not a Subprocessor of Engagy (Section 3.3).