DEK
Features Pricing Log in Start for free

Data Processing Agreement

Last updated: 2026-07-19 · Version: Beta 1.0

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service and applies automatically when a User processes its clients' personal data through the DEK Service. It sets out the processing terms under Article 28 GDPR.

1. Parties and roles

  • Controller: the User (a business) using the Service.
  • Processor: Majevski, MB, legal entity code 304720404, Smalinės g. 21-3, LT-06225, Vilnius, Lietuva.

The Controller determines the purposes and means of processing. The Processor processes data only on the Controller's documented instructions (including use of the Service and this DPA).

2. Subject matter and description

  • Subject matter and purpose: providing client-booking, calendar and notification services to the Controller.
  • Duration: for as long as the Terms of Service are in force.
  • Nature of processing: collection, storage, use, transmission for notifications, deletion.
  • Data subjects: the Controller's clients and its staff.
  • Data categories: names, contacts (email, phone), visit history, notes, Controller-chosen custom fields and consents.

3. Processor obligations

The Processor shall:

  • process data only on the Controller's documented instructions, unless required to do so by Union or Member State law to which the Processor is subject; in that case the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes the law;
  • ensure persons with access to the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures under Art. 32 GDPR, taking into account the state of the art and risk, including encryption of data in transit, access control, backups and restoration, and resilience of systems;
  • taking into account the nature of processing and insofar as possible, assist the Controller by appropriate technical and organisational measures to respond to data subjects' requests regarding their rights (Arts. 12-23 GDPR);
  • assist the Controller in ensuring its obligations on security, breach notification and data protection impact assessments (Arts. 32-36 GDPR), taking into account the nature of processing and the information available to the Processor;
  • delete or return the data when the services end (see section 8);
  • make available to the Controller the information necessary to demonstrate compliance and allow for audits (see section 7).

4. Sub-processors

The Controller gives general authorisation to engage sub-processors. The Processor ensures they are subject to no-less-onerous obligations. Where a sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor's obligations. Currently engaged:

  • UAB "Interneto vizija": server hosting (Lithuania, Vilnius).
  • Stripe: payment processing (card data handled directly by Stripe).
  • 1e.lt (Mailwizz): sending emails.
  • asms.lt: sending SMS via the Controller's connected account.

The Processor will give prior notice of any intended change to sub-processors, giving the Controller the opportunity to reasonably object.

5. Transfers

Primary data is stored in the European Union (Lithuania). Where a sub-processor transfers data outside the European Economic Area, it is done under appropriate safeguards (e.g. Standard Contractual Clauses).

6. Personal data breach notification

On becoming aware of a personal data breach, the Processor shall notify the Controller without undue delay and provide available information so the Controller can meet its obligations to the supervisory authority and data subjects.

7. Audit

At the Controller's reasonable request, the Processor provides the information necessary to demonstrate compliance with this DPA and allows for and contributes to audits and inspections conducted by the Controller or an auditor mandated by the Controller, carried out in a manner and at a time agreed in advance, without compromising the confidentiality of other clients' data.

8. Return and deletion of data

When the services end, at the Controller's choice the Processor returns or deletes the processed data and existing copies, unless retention is required by law. The Controller may export data at any time through the Service.

9. Liability and term

The parties' liability to each other (contractual) is determined under the Terms of Service, including the limitation of liability set out there; statutory liability to data subjects and supervisory authorities is governed by the GDPR and is not subject to that limitation. The Beta status (see the Terms of Service) does not reduce the data protection obligations set out in this DPA. This DPA remains in force for as long as the Processor processes personal data on the Controller's behalf.

10. Contact

For data processing questions, contact pagalba@majevski.com.

DEK

A booking and salon management system for service businesses.

Product

Features Pricing FAQ

Legal

Terms Privacy Data Processing Agreement Client privacy notice Cookie policy Cookie settings

© 2026 Majevski, MB. All rights reserved.
Company code 304720404

LT EN RU PL

We respect your privacy

Necessary cookies keep the site working. We will only use analytics and marketing cookies if you agree. Decline and everything still works exactly as before.

Cookie policy Privacy