Data Processing Addendum

    Last Updated: December 21, 2025

    Note: This DPA applies if you are a Business User processing personal data of third parties via our Service.

    1. Parties

    This DPA is between inithouse.com s.r.o. ("Processor") and the Business Customer ("Controller").

    2. Scope

    This DPA applies to the processing of personal data solely for the purpose of providing the Service. This includes any conflict descriptions, participant names, or responses submitted through MagicalSong for business or organizational use.

    3. Security

    Processor shall implement appropriate technical and organizational measures to protect data, including:

    • Encryption of data in transit and at rest
    • Access control and authentication
    • Regular security assessments
    • Incident response procedures

    4. Subprocessors

    Controller authorizes Processor to use subprocessors (hosting, AI APIs) as listed in the Privacy Policy. Processor shall ensure subprocessors are bound by equivalent data protection obligations.

    5. Assistance

    Processor shall assist Controller with GDPR compliance obligations where possible, including:

    • Responding to data subject access requests
    • Breach notification procedures
    • Data protection impact assessments

    6. Audits

    Processor shall provide security documentation or audit reports upon reasonable request to demonstrate compliance with this DPA and applicable data protection laws.

    7. International Transfers

    Any transfers of personal data outside the European Economic Area (EEA) are safeguarded by Standard Contractual Clauses (SCCs) or other approved transfer mechanisms under GDPR.

    8. Data Retention & Deletion

    Upon termination of the business relationship or upon request, Processor shall delete or return all personal data processed on behalf of the Controller, unless retention is required by law.

    9. Contact

    For DPA-related inquiries:
    Inithouse inithouse.com s.r.o.
    Email: info@inithouse.com