Data Processing Addendum (Draft)

Last updated: September 5, 2026

Draft for counsel review. This is not a signed contract until countersigned by both parties. It describes how Digitermin processes personal data on behalf of business customers under the Law on Personal Data Protection of North Macedonia (LPDP / ЗЗЛП), aligned with GDPR Art. 28 concepts.

1. Parties and roles

Customer (salon, clinic, or other company using Digitermin) is the controller of client/patient and booking data it enters. РЕТРОСПЕКТИВА ДОО trading as Digitermin (ЕДБ 4023025514526, 8-МИ СЕПТЕМВРИ бр.22, Радовиш, Republic of North Macedonia) is the processor for that Customer Content. Digitermin remains controller of account, billing, security, and marketing data as described in the Privacy Policy.

2. Subject matter and duration

Digitermin processes Customer Content to provide the SaaS booking/CRM platform (hosting, display, SMS/email reminders when enabled, backups, support). Processing lasts for the term of the service and the retention periods in the Privacy Policy (including 30-day deletion after an account is marked expired).

3. Nature and purpose

Storage, retrieval, transmission (e.g. SMS via LINK Mobility), organization, and deletion of Customer Content solely to provide the contracted service and related support/security.

4. Types of personal data and data subjects

May include names, phone numbers, emails, appointment details, notes, and—if clinic modules are used—special-category health-related data (allergies, medical history, dental/optician records). Data subjects are typically the Customer’s clients/patients and staff.

5. Customer instructions and lawful basis

Digitermin processes Customer Content only on documented instructions from the Customer (use of the product features and support requests), unless required by law. The Customer warrants it has a lawful basis to collect and instruct processing of the data, including special categories under LPDP Art. 13 where applicable, and will inform data subjects.

6. Confidentiality and security

Digitermin ensures persons authorized to process Customer Content are bound to confidentiality and implements appropriate technical and organizational measures (TLS, Hostinger VPS with local MongoDB and backups, role-based access). Details are in the Privacy Policy.

7. Sub-processors

Customer authorizes Digitermin to use sub-processors needed to deliver the service, including currently: Hostinger (hosting/backups/DB), LINK Mobility Bulgaria (SMS), Vercel (marketing site), Resend (transactional email), Anthropic (optional help chatbot), Google (SSO/Maps/ads where used), Firebase/APNs (mobile push where used), and other providers listed in the Privacy Policy. Digitermin will impose data-protection obligations on sub-processors. Material changes to the list will be reflected in the Privacy Policy; continued use after notice constitutes acceptance for standard SaaS changes.

8. International transfers

Primary Customer Content is stored on Digitermin’s Hostinger VPS. Some sub-processors may process data in the EU/EEA or other countries. Digitermin will use safeguards required under the LPDP (including SCCs / provider terms where applicable) and AZLP procedures as required.

9. Assistance with data-subject rights and compliance

Taking into account the nature of processing, Digitermin will assist the Customer, via appropriate technical and organizational measures, to respond to data-subject requests and to meet security, breach, and DPIA obligations under the LPDP, insofar as possible through the product and support at info@digitermin.com.

10. Personal data breaches

Digitermin will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, with information reasonably available to help the Customer meet its LPDP notification duties.

11. Return or deletion

Upon termination, Digitermin will delete operational Customer Content according to the Privacy Policy (including the 30-day post-expired purge), unless retention is required by law (e.g. Digitermin’s own accounting records). Export assistance may be provided on request before deletion where reasonably feasible.

12. Audits

Digitermin will make available information necessary to demonstrate compliance with this Addendum and allow audits by the Customer or an agreed auditor, limited to once per year (unless a breach or authority request requires more), with reasonable notice, during business hours, and without disrupting operations or revealing other customers’ confidential data.

13. Governing law

This Addendum is governed by the laws of the Republic of North Macedonia. The Macedonian text prevails if translations conflict. Courts competent for Radoviš apply unless mandatory law requires otherwise.