Strimeta - smlouva o zpracování osobních údajů (DPA)
Product: Strimeta
Operator / Provider: Jakub Marcinka, trading under jmarcinka.cz
IČO: 21474672
Business address: Na Kopci 1210/10, 460 14 Liberec XIV-Ruprechtice, Czech Republic
Contact: jmarcinka@email.cz
Website: https://jmarcinka.cz
Version: 1.0
Effective date: 9 September 2026
Status. This is Strimeta's operational legal documentation prepared for launch. Mandatory law prevails over contractual text. Because international privacy, tax, consumer and platform rules change, the regional launch gates and vendor list must be re-checked before entering a new market or materially changing the product.
Tato DPA je součástí smlouvy se zákazníkem všude, kde Strimeta zpracovává osobní údaje jménem zákazníka.
1. Role a pokyny
Zákazník je zpravidla správce a Strimeta zpracovatel; je-li zákazník zpracovatelem, Strimeta je dalším zpracovatelem. Strimeta zpracovává data jen podle zdokumentovaných pokynů zákazníka, není-li k jinému zpracování povinen zákonem.
2. Důvěrnost a bezpečnost
Přístup mají jen oprávněné osoby v nezbytném rozsahu a jsou vázány důvěrností. Strimeta udržuje opatření popsaná v dokumentu Security/TOMs včetně řízení přístupů, MFA privilegovaných účtů, TLS, šifrovaných záloh, logování, správy tajemství, zranitelností a incidentů.
3. Další zpracovatelé
Zákazník uděluje obecné oprávnění k použití zpracovatelů uvedených v aktuálním registru. O materiální změně bude informován v přiměřeném předstihu a může vznést odůvodněnou námitku z hlediska ochrany dat.
4. Práva subjektů
Strimeta s ohledem na povahu zpracování pomůže zákazníkovi vyřídit přístup, opravu, výmaz, omezení, přenositelnost, námitku a obdobná práva.
5. Incidenty
Strimeta oznámí zákazníkovi potvrzené porušení zabezpečení osobních údajů bez zbytečného odkladu a poskytne dostupné informace o povaze, rozsahu, dopadech a nápravě.
6. DPIA a dozorové orgány
Strimeta poskytne přiměřeně dostupné informace potřebné pro DPIA, posouzení přenosů, předchozí konzultaci a dotazy regulátora týkající se služby.
7. Ukončení
Po ukončení Strimeta umožní podporovaný export a následně smaže osobní údaje zákazníka z aktivních systémů, pokud zákon nevyžaduje uchování. Zbytkové kopie v šifrovaných zálohách dožijí v řízené rotaci a nejsou používány pro běžný provoz.
8. Přenosy
Pro přenosy mimo EHP se podle potřeby použijí aktuální oficiální SCC EU a posouzení přenosu. Pro Spojené království se použije aktuální UK IDTA/Addendum a britský data protection test. Další regiony se řídí příslušným regionálním dodatkem.
9. Rozsah
Subjekty, kategorie dat, účely a technická opatření jsou podrobně uvedeny v úplné anglické DPA, která je součástí tohoto balíku. Tato česká verze má sloužit jako české smluvní znění pro běžný rozsah; při mezinárodním transferu se vždy připojí povinný oficiální transferový nástroj.
Strimeta Data Processing Agreement (DPA)
Product: Strimeta
Operator / Provider: Jakub Marcinka, trading under jmarcinka.cz
IČO: 21474672
Business address: Na Kopci 1210/10, 460 14 Liberec XIV-Ruprechtice, Czech Republic
Contact: jmarcinka@email.cz
Website: https://jmarcinka.cz
Version: 1.0
Effective date: 9 September 2026
Status. This is Strimeta's operational legal documentation prepared for launch. Mandatory law prevails over contractual text. Because international privacy, tax, consumer and platform rules change, the regional launch gates and vendor list must be re-checked before entering a new market or materially changing the product.
This DPA forms part of the agreement between the Customer and Strimeta where Strimeta processes Personal Data on behalf of the Customer.
1. Roles
1.1 For Customer/community Personal Data, Customer is normally the controller/business and Strimeta is the processor/service provider/data intermediary. If Customer is itself a processor, Strimeta acts as subprocessor.
1.2 Strimeta is an independent controller for its own account administration, billing, security, legal compliance and business records as described in the Privacy Notice.
1.3 The parties will interpret role labels under local law by function rather than title.
2. Subject matter, duration, nature and purpose
Strimeta processes Customer Personal Data to connect authorised communities, ingest permitted metadata, calculate Customer-requested community analytics, provide dashboards/exports/alerts, operate integrations, troubleshoot, secure and support the Service. Processing lasts for the subscription and controlled deletion/backup period.
3. Documented instructions
Strimeta will process Customer Personal Data only on Customer's documented instructions, including configuration choices and authorised API/integration actions, unless binding law requires otherwise. Strimeta will inform Customer where legally permitted if law requires processing beyond those instructions. Strimeta may suspend an instruction that appears unlawful or would violate binding platform rules while the parties resolve it.
4. Confidentiality and personnel
Strimeta limits access to persons who require it for authorised duties and who are bound by confidentiality. Privileged access is logged where technically feasible and removed when no longer necessary.
5. Security
Strimeta will maintain appropriate technical and organisational measures proportionate to risk, including the measures in Annex B. Strimeta may update controls as technology changes provided the overall level of protection is not materially reduced.
6. Subprocessors
6.1 Customer gives general written authorisation to use the subprocessors in the live Subprocessor Register.
6.2 Strimeta will impose appropriate confidentiality, security, processing and deletion obligations on subprocessors where the law requires a processor contract.
6.3 Strimeta will give reasonable advance notice of a new subprocessor materially involved in Customer Personal Data. Customer may object on documented data-protection grounds. The parties will attempt a reasonable alternative; if none exists, either party may terminate the affected Service without penalty for the unused prepaid affected period.
6.4 Strimeta remains responsible for its processor obligations to the extent required by applicable law.
7. Assistance with individual rights
Taking into account the nature of processing, Strimeta will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection, opt-out, appeal and equivalent statutory requests. Requests received directly for Customer-controlled data may be forwarded to Customer unless law requires Strimeta to respond itself.
8. Security incidents and Personal Data Breaches
Strimeta will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Available notice will describe the nature of the breach, likely affected categories/approximate scale, likely consequences, containment/remediation measures and a contact point. Information may be delivered in phases. Customer remains responsible for controller notifications unless law allocates the duty differently.
9. DPIA, risk assessment and regulator assistance
Strimeta will provide information reasonably available to assist Customer with DPIAs, privacy impact assessments, transfer assessments, prior consultations and regulator inquiries specifically concerning Strimeta processing. Additional bespoke assistance beyond standard documentation may be charged at reasonable cost unless caused by Strimeta's breach.
10. Return, export and deletion
On termination or valid instruction, Strimeta will make available an export of Customer Data supported by the Service and delete Customer Personal Data from active systems after the exit window, unless law requires retention. Residual copies in encrypted backups are isolated from ordinary use and expire through controlled rotation. If a disaster recovery restore reintroduces data scheduled for deletion, deletion instructions are re-applied.
11. Audit and evidence
Strimeta will make available information reasonably necessary to demonstrate compliance, including the Security/TOMs document, subprocessor information and relevant assessment results. Audits should use existing documentation and remote evidence first. On-site inspection is limited to cases required by law or where remote evidence is inadequate after a material incident, subject to reasonable notice, confidentiality, security and non-disruption requirements.
12. International transfers
12.1 The default production deployment covered by this DPA uses an EU/EEA Contabo data centre. The exact country must be published before production launch.
12.2 For EEA restricted transfers, the parties will use an adequacy decision or the European Commission's current SCCs for international transfers with the module matching the roles, plus a documented transfer assessment and supplementary measures where necessary.
12.3 For UK restricted transfers, the parties will use the current ICO IDTA or UK Addendum to the EU SCCs, together with the UK data protection test/transfer assessment. EU SCCs alone are not sufficient for a UK restricted transfer.
12.4 For Australia, New Zealand, Japan, South Korea and Singapore, Strimeta will use comparable-protection contractual and technical safeguards, notices/consents or other mechanisms required by the applicable local law.
12.5 Mandatory approved transfer clauses override inconsistent terms in this DPA.
13. US state privacy processor/service-provider terms
Where a US state privacy law applies and Strimeta is a processor/service provider/contractor, Strimeta will:
- process only for the documented business purposes and instructions;
- not sell Customer Personal Data or share it for cross-context behavioural advertising;
- not retain, use or disclose it outside the direct business relationship except as legally permitted;
- not combine it with unrelated personal data except as legally permitted;
- apply appropriate security and confidentiality;
- assist Customer with required rights and assessments; and
- permit reasonable monitoring/evidence of compliance as required by law.
14. Canada, Australia/NZ, Japan/Korea/Singapore processor obligations
Where local law uses different terminology (for example service provider, agent, outsourcing recipient or data intermediary), Strimeta accepts the functionally equivalent obligations required for processing only on Customer's behalf, including confidentiality, security, retention limits, rights assistance and cross-border safeguards.
15. Platform restrictions
Customer instructions may not require Strimeta to violate Discord Developer Terms/Policy or binding rules of another integration. Discord-derived data may not be used through Strimeta for prohibited individual profiling, identity/relationship profiling, advertising, resale, unauthorised scraping or prohibited AI training.
Annex A - Processing details
Data subjects: Customer users; community owners/admins/moderators; community members; persons represented in permitted moderation/activity metadata.
Categories: account-linked community IDs, platform user/member IDs, usernames/display names if technically necessary, roles/channels, timestamps, event/activity counters, reactions, moderation-event metadata, integration configuration, audit/security metadata and derived aggregates.
Excluded by default: persistent message content, account passwords in plaintext, payment-card data, biometric data, health data and deliberate collection of special-category/sensitive data or children's data.
Frequency: continuous/event-driven or scheduled, depending on connector.
Purpose: community-level analytics, operational health, retention/cohort analytics, response/moderation workload metrics, connector operation and Customer-requested reporting.
Retention: according to the published Retention Policy and Customer configuration; backups expire by controlled rotation.
Annex B - Technical and organisational measures
- Least-privilege and role-based access; MFA for privileged administrative access.
- TLS for data in transit; encrypted backup archives before transfer/storage.
- Secrets outside source code; secret rotation and redaction from logs.
- Environment separation and prohibition on using production personal data in development unless specifically controlled and necessary.
- Data minimisation and discard-by-default for message content.
- Structured security/audit logging with access controls and retention limits.
- Dependency/vulnerability management and security patching.
- Input validation, rate limiting, abuse controls and authentication monitoring.
- Three-location encrypted backup design: Contabo recovery copy, Provider-controlled encrypted workstation copy, Provider-controlled encrypted NAS copy; regular restore verification.
- Incident classification, evidence preservation and regional notification workflow.
- Privileged access review/offboarding.
- Vendor/subprocessor due diligence and written data-processing protections.
- Machine-readable export and deletion workflows.
- Monitoring of health, authentication failures, anomalies, backlog, storage and security events.
- Data segregation by logical customer/community identifiers and access authorisation.
Annex C - Documented instructions
The Agreement, authorised configuration, connected integrations, API actions and authenticated support requests constitute Customer instructions. Additional instructions must be lawful, technically feasible and consistent with the purchased Service.
Annex D - Transfer execution
If SCCs, UK IDTA/Addendum or another official transfer instrument is required, the parties must execute or incorporate the current official form without impermissible modification. The Regional Transfer Schedules in this pack provide the factual fields but do not replace mandatory official clause text.