Data Processing Addendum
Last updated: 12 August 2026
Parties
This Data Processing Addendum ("Addendum") forms part of the concurrent Master Service Agreement between the business client (controller) and Maquila (data processor):
Controller: Business client
and
Processor: Maquila
Registration No.: 17541881
Sepapaja tn 6, Lasnamäe, Tallinn 15551, Estonia
Email: info@maquila.biz
Together hereby referred to as the "Parties", and where separate as "Processor" and "Controller" respectively.
Controller: Business client
and
Processor: Maquila
Registration No.: 17541881
Sepapaja tn 6, Lasnamäe, Tallinn 15551, Estonia
Email: info@maquila.biz
Together hereby referred to as the "Parties", and where separate as "Processor" and "Controller" respectively.
1. Purpose
This Addendum governs the Processor's processing of personal data on behalf of the Controller in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Subject Matter
The Processor provides intermediary facilitation services such as marketing, customer communication, appointment booking, webpage and social media creation and management, lead generation and related administrative services on behalf of the Controller.
The Processor shall only process personal data necessary to perform the purposes constituted by these services, and as otherwise pursuant to mandatory law.
The Processor shall only process personal data necessary to perform the purposes constituted by these services, and as otherwise pursuant to mandatory law.
3. Categories of Personal Data
Depending on the services provided, the Processor may process:
- Names
- Email addresses
- Telephone numbers
- Customer enquiries and requests
- Appointment information and geodata
- Communication records
- Information relating to requested services
- Other customer information provided by the Controller
- Financial data to fulfill bookkeeping obligations pursuant to mandatory law
4. Categories of Data Subjects
Personal data may relate to:
- Existing customers
- Prospective customers
- Business contacts
- Employees or representatives of the Controller where necessary
5. Duration
The Processor shall process personal data for the duration of the master service agreement and its respective purposes, unless otherwise instructed by the Controller or required by mandatory law.
6. Processor Obligations
The Processor shall:
- process personal data only on documented instructions from the Controller
- ensure that persons authorised to process personal data are subject to appropriate confidentiality obligations
- implement appropriate technical and organisational measures to protect personal data
- assist the Controller, where reasonably possible, in responding to requests from data subjects
- notify the Controller without undue delay after becoming aware of a personal data breach
- assist the Controller in meeting its GDPR obligations where required
- upon termination of the services, delete or return personal data, unless retention is required by mandatory law
7. Controller Obligations
The Controller is responsible for:
- determining the purposes and means of processing
- ensuring a lawful basis for processing
- providing any required privacy information to data subjects
- issuing lawful instructions to the Processor
8. Confidentiality
The Processor shall ensure that all personnel authorised to process personal data are bound by confidentiality obligations.
9. Data Security Measures
The Processor shall implement appropriate technical and organisational security measures, taking into account the nature of the processing, the risks involved, and current technological standards.
Such measures may include:
Such measures may include:
- access controls
- password protection
- encryption where appropriate
- secure storage of information
- regular software updates
- restricted access to personal data
10. Sub-processors
The Processor shall not engage another processor without the prior written authorisation of the Controller.
Where authorised, the Processor shall ensure that the sub-processor is bound by data protection obligations equivalent to those contained in this Addendum.
Where authorised, the Processor shall ensure that the sub-processor is bound by data protection obligations equivalent to those contained in this Addendum.
11. International Transfers of Data
The Processor shall not transfer personal data outside the European Economic Area (EEA) unless explicitly authorized by the Controller and only where appropriate safeguards under the GDPR are in place.
12. Audits
Upon reasonable notice, the Controller may request information reasonably necessary to demonstrate the Processor's compliance with this Addendum.
13. Personal Data Breaches
The Processor shall notify the Controller without undue delay after becoming aware of any personal data breach affecting personal data processed under this Addendum.
The notification shall include available information concerning:
• the nature of the breach;
• categories of affected data;
• likely consequences;
• measures taken or proposed.
The notification shall include available information concerning:
• the nature of the breach;
• categories of affected data;
• likely consequences;
• measures taken or proposed.
14. Return or Deletion of Data
Upon termination of the services, the Processor shall, at the Controller's choice where directed by applicable mandatory law:
• return all personal data; or
• securely delete the personal data,
unless applicable law requires continued storage.
• return all personal data; or
• securely delete the personal data,
unless applicable law requires continued storage.
15. Governing Law
This Addendum shall be governed by the laws of Estonia.
Any disputes shall be subject to the jurisdiction of the ordinary Estonian courts.
Any disputes shall be subject to the jurisdiction of the ordinary Estonian courts.