Data Processing Agreement (DPA)
This DPA forms part of the VirtualGarage agreement and applies where TopSoft OÜ processes personal data on the Customer’s behalf.
VirtualGarage (the “Service”) is a cloud service for managing business operations, provided by TopSoft OÜ.
Customer means a natural or legal person using VirtualGarage in the course of their professional or business activities. User means a natural or legal person authorised by the Customer to use VirtualGarage within its account. Legal persons act through their authorised representatives.
1. Parties and roles
“Controller” means the Customer identified in the VirtualGarage account on whose behalf personal data is processed. “Processor” means TopSoft OÜ, registry code 12252115, Tallinn, Estonia. The Processor’s current registered address and contact details are published in the Privacy Policy. The person accepting this DPA for the Customer confirms authority to do so.
A change to the Processor’s registered address or contact details, with the legal entity and registry code unchanged, is an update of particulars and does not require renewed DPA acceptance. The Processor publishes its current registered address and contact details in the Privacy Policy.
“Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings in Regulation (EU) 2016/679 (GDPR).
“Controller Data” means personal data entered into VirtualGarage or received through its features by the Customer or its Users, including through public pages, forms and embedded widgets, which TopSoft OÜ processes on the Customer’s behalf. TopSoft OÜ’s processing for its own purposes, including billing and access administration, is described in the Privacy Policy.
2. Subject matter, purpose and duration
The Processor processes data only to host, operate, protect, maintain and support VirtualGarage, send communications instructed by the Controller and perform related obligations. Processing continues for the service term and the return/deletion period under Section 11.
3. Description of processing
Data may be entered by the Customer or its Users or received from persons seeking the Customer’s services through VirtualGarage public pages, forms and widgets, including those embedded on the Customer’s websites. Data may be received through price requests, responses to quotations, orders created from quotations or online bookings. These actions do not require registration or account access.
| Subject matter and nature | Collection, storage, organisation, retrieval, display, transmission, backup, support access, correction, export and deletion within a cloud service for managing business operations. |
|---|---|
| Purposes | Work orders, quotations, scheduling, customer communication, vehicles/equipment, files, invoices, payments, stock, suppliers, employees, transferring selected data to Customer-enabled accounting and other systems, and other configured operations. |
| Data subjects | The Controller’s customers and persons seeking its services, their representatives and contacts, employees and contractors, suppliers and partners, vehicle/equipment owners and users, and other individuals whose data is lawfully entered. |
| Data categories | Identification and contact details; vehicle and equipment data including registration number and VIN; service history; orders and bookings; incoming and outgoing email, SMS and other messages; attachments, documents, files and images; invoices, payments and transactions; employee, supplier and partner data; work assignments; integration settings; encrypted credentials, tokens and other information needed to connect Customer-selected third-party accounts; audit and technical data. |
| Special categories | Not intentionally required. The Controller must not enter special-category or criminal-offence data unless lawful, necessary and expressly supported by the Service. |
4. Instructions and Controller obligations
The Processor acts only on documented instructions, including feature settings and authorised users’ actions, unless processing is required by EU or Member State law. In that case, it informs the Controller before processing unless law prohibits such notice.
The Controller is responsible for lawful collection and instructions, transparency, legal bases, accuracy and minimisation, responding to data subjects and user permissions. If the Processor considers an instruction to infringe data protection law, it informs the Controller immediately.
5. Confidentiality and access
Only authorised TopSoft OÜ personnel bound by confidentiality may access Controller Data. Access is limited to what is necessary to respond to a Customer or authorised User enquiry, diagnose, reproduce and fix errors, verify operation after updates, respond to security incidents or comply with law. Where possible, test, demonstration or anonymised data is used before accessing Controller Data. Access must not be used for purposes unrelated to provision, support or security of the Service.
6. Security
The Processor maintains the risk-proportionate technical and organisational measures in Annex 2. The Controller is responsible for protecting its credentials, devices, networks, users, roles and exports.
7. Subprocessors
The Controller gives general written authorisation for the subprocessors in Annex 1. The Processor imposes substantially equivalent obligations on them and remains responsible under GDPR. At least 30 days before a new or replacement subprocessor accesses Controller Data, the Processor notifies the Controller through the application or by email, identifying the provider, function and processing location. The Controller may reasonably object on data protection grounds; the parties seek a solution and, if none is found, the Controller may terminate the affected feature or agreement.
8. Data subject requests
Taking account of the nature of processing, the Processor reasonably assists through product features and support in fulfilling GDPR Chapter III rights. Requests received directly concerning Controller Data are forwarded to the Controller unless law requires otherwise.
9. Incidents, DPIAs and authorities
The Processor notifies the Controller without undue delay after becoming aware of a breach affecting Controller Data and supplies available information needed for compliance. It reasonably assists with security, impact assessments and prior consultations, taking account of the nature of processing and available information. Additional assistance beyond standard features may be charged by prior agreement.
10. Information and audits
The Processor provides reasonably necessary information to demonstrate GDPR Article 28 compliance. The Controller may audit once a year, following a material breach, at an authority’s request or where an additional audit is reasonably necessary to verify Article 28 compliance, on reasonable notice, during business hours, without access to other customers’ data or compromising security. Current reports and documents may be used first. The Controller bears costs unless the audit identifies a material Processor breach.
11. Return and deletion
During the subscription, the Controller may use available export features or contact support to prepare return of data. After termination, at the Controller’s choice, data is returned and remaining Processor copies deleted, or deleted without return. Active-system deletion takes place within 90 days of termination unless retention is required by law. For switching, the specific rules in Terms Section 11.1 apply, including retrieval periods and mandatory full-erasure deadlines; data is not deleted before the guaranteed retrieval period ends.
If further processing time is needed to complete export or transfer, the parties may separately agree in writing its purpose, necessary data scope and precise end date. All DPA requirements remain applicable and use is limited to the agreed purpose. Technical work alone does not permit unilateral extension of retention or mandatory switching deadlines.
After deletion from active systems, residual data may remain in shared backups of several Customers until scheduled rotation, normally for no more than 30 days and, where technically justified, no more than 60 days from active-system deletion. Access is restricted to authorised persons; the data is not used for ordinary operation or other purposes except necessary recovery. Upon restoration, previously deleted data is deleted again before ordinary processing resumes. Shorter mandatory legal deletion periods prevail.
The Controller is responsible for retention periods for its accounting and other records and timely retrieval of necessary copies. The Processor does not undertake long-term accounting archiving after termination unless separately agreed.
12. Transfers
Primary processing is expected to take place in the EEA. Transfers outside the EEA require a lawful GDPR Chapter V mechanism and necessary supplementary measures. A message to a recipient outside the EEA may necessarily be transmitted there on the Controller’s instructions.
13. Liability and precedence
Each party is responsible for its data protection obligations. Contractual claims between the parties are subject to Terms Section 12 liability limits to the extent permitted by law. These do not limit data subjects’ rights, supervisory authorities’ powers or mandatory GDPR liability. This DPA prevails over conflicting general Terms concerning data processing.
14. Termination and changes
This DPA remains effective until return and deletion of Controller Data, including residual backups, are completed; data protection obligations continue while the Processor retains such data. Updates display a new version and date. Material changes are notified through the application or by email at least 30 calendar days in advance, stating the changes and effective date. The Controller may terminate the affected feature or agreement before materially adverse changes apply. If law requires earlier changes, an explanation and notice are provided without undue delay.
Changes requiring new agreement on instructions or other obligations apply after separate confirmation by the Controller’s authorised representative. New subprocessors follow Section 7. Activating an integration within the described purposes and data categories is a separate documented instruction and does not itself require renewed acceptance of the entire DPA.
15. Electronic acceptance and law
The DPA is accepted electronically with the Terms. TopSoft OÜ retains evidence: document version and hash, acceptance date and time, and Customer and accepting representative details. Estonian law applies and disputes follow the Terms. Where translations differ, the language version of the relevant document accepted by the Customer prevails unless otherwise separately agreed in writing. Changing interface language does not change the accepted document’s language.
Annex 1 — Authorised subprocessors
| Subprocessor | Service | Location |
|---|---|---|
| OVH HOSTING LIMITED (OVHcloud, Ireland) | Hosting and data storage | Frankfurt, Germany |
| Zone Media OÜ (zone.ee) | VirtualGarage email infrastructure: service correspondence, notifications and support enquiries | Estonia / European Union |
| Think Intermedia SIA (Sendberry) | SMS transmission | Latvia; delivery routing depends on the recipient’s location and telecommunications operators involved |
These providers are subprocessors to the extent they process Controller Data on TopSoft OÜ’s behalf. VirtualGarage email infrastructure processes Controller Data, in particular where included in support enquiries, service correspondence or notifications.
Zone Media OÜ operates VirtualGarage’s email infrastructure. This does not mean it hosts Customer email accounts. Customer-selected email providers are determined by the Customer’s settings and contracts.
New or replacement subprocessors are notified under Section 7. This list is aligned with Section 5 of the Privacy Policy. Providers used solely for TopSoft OÜ’s own purposes do not become subprocessors under this DPA merely by being mentioned in the Policy.
Annex 2 — Technical and organisational measures
- TLS encryption for supported network connections;
- encryption of stored credentials, tokens and other secrets used to connect third-party accounts;
- authentication, role-based access and least-privilege administration;
- logical separation of account data and checks of account and location access rights;
- logging and monitoring of significant operational and security events;
- controlled support access and confidentiality commitments;
- security updates, vulnerability remediation and incident response;
- regular local backups and recovery procedures;
- minimisation, retention periods and secure deletion;
- supplier checks and contractual data protection obligations.
