Data Processing Addendum

Last updated: 12 August 2026

Parties

This Data Processing Addendum ("Addendum") forms part of the concurrent Master Service Agreement between the business client (controller) and Maquila (data processor):

Controller: Business client

and

Processor: Maquila
Registration No.: 17541881
Sepapaja tn 6, Lasnamäe, Tallinn 15551, Estonia
Email: info@maquila.biz

Together hereby referred to as the "Parties", and where separate as "Processor" and "Controller" respectively.

1. Purpose

This Addendum governs the Processor's processing of personal data on behalf of the Controller in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

2. Subject Matter

The Processor provides intermediary facilitation services such as marketing, customer communication, appointment booking, webpage and social media creation and management, lead generation and related administrative services on behalf of the Controller.

The Processor shall only process personal data necessary to perform the purposes constituted by these services, and as otherwise pursuant to mandatory law.

3. Categories of Personal Data

Depending on the services provided, the Processor may process:
  • Names
  • Email addresses
  • Telephone numbers
  • Customer enquiries and requests
  • Appointment information and geodata
  • Communication records
  • Information relating to requested services
  • Other customer information provided by the Controller
  • Financial data to fulfill bookkeeping obligations pursuant to mandatory law

4. Categories of Data Subjects

Personal data may relate to:
  • Existing customers
  • Prospective customers
  • Business contacts
  • Employees or representatives of the Controller where necessary

5. Duration

The Processor shall process personal data for the duration of the master service agreement and its respective purposes, unless otherwise instructed by the Controller or required by mandatory law.

6. Processor Obligations

The Processor shall:
  • process personal data only on documented instructions from the Controller
  • ensure that persons authorised to process personal data are subject to appropriate confidentiality obligations
  • implement appropriate technical and organisational measures to protect personal data
  • assist the Controller, where reasonably possible, in responding to requests from data subjects
  • notify the Controller without undue delay after becoming aware of a personal data breach
  • assist the Controller in meeting its GDPR obligations where required
  • upon termination of the services, delete or return personal data, unless retention is required by mandatory law

7. Controller Obligations

The Controller is responsible for:
  • determining the purposes and means of processing
  • ensuring a lawful basis for processing
  • providing any required privacy information to data subjects
  • issuing lawful instructions to the Processor

8. Confidentiality

The Processor shall ensure that all personnel authorised to process personal data are bound by confidentiality obligations.

9. Data Security Measures

The Processor shall implement appropriate technical and organisational security measures, taking into account the nature of the processing, the risks involved, and current technological standards.

Such measures may include:
  • access controls
  • password protection
  • encryption where appropriate
  • secure storage of information
  • regular software updates
  • restricted access to personal data

10. Sub-processors

The Processor shall not engage another processor without the prior written authorisation of the Controller.

Where authorised, the Processor shall ensure that the sub-processor is bound by data protection obligations equivalent to those contained in this Addendum.

11. International Transfers of Data

The Processor shall not transfer personal data outside the European Economic Area (EEA) unless explicitly authorized by the Controller and only where appropriate safeguards under the GDPR are in place.

12. Audits

Upon reasonable notice, the Controller may request information reasonably necessary to demonstrate the Processor's compliance with this Addendum.

13. Personal Data Breaches

The Processor shall notify the Controller without undue delay after becoming aware of any personal data breach affecting personal data processed under this Addendum.

The notification shall include available information concerning:

• the nature of the breach;
• categories of affected data;
• likely consequences;
• measures taken or proposed.

14. Return or Deletion of Data

Upon termination of the services, the Processor shall, at the Controller's choice where directed by applicable mandatory law:

• return all personal data; or
• securely delete the personal data,

unless applicable law requires continued storage.

15. Governing Law

This Addendum shall be governed by the laws of Estonia.

Any disputes shall be subject to the jurisdiction of the ordinary Estonian courts.