Data Processing Agreement
Last updated: 2026-02-18
This Data Processing Agreement ("Agreement") is entered into pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, hereinafter "GDPR") and governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of the Garazh® platform available at garazh.eu.
1. Parties
Data Controller ("Controller"):
MORWA TRADE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office at Gen. Władysława Sikorskiego 20, 42-202 Częstochowa, Poland, NIP: 9492260466, KRS: 0001030216, the operator of the Garazh® platform (hereinafter referred to as "Garazh").
Data Processor ("Processor"):
The Service Station (STO) that has registered an account on the Garazh® platform and accesses personal data of Customers in connection with providing vehicle servicing through the platform (hereinafter referred to as "Service Station" or "Processor").
By activating an account on the Garazh® platform and accessing Customer personal data, the Service Station accepts the terms of this Agreement.
2. Subject Matter and Duration
This Agreement governs the processing of personal data of Customers by the Service Station in connection with the provision of vehicle servicing, appointment management, and related services through the Garazh® platform.
This Agreement enters into force upon the Service Station's registration on the platform and remains in effect for the entire duration of the Service Station's active account. Upon termination of the account, the provisions regarding data return and deletion (Section 13) shall apply.
3. Nature and Purpose of Processing
The Processor processes personal data on behalf of the Controller for the following purposes:
- Managing appointment bookings made by Customers at the Service Station
- Performing vehicle diagnostics, repairs, and maintenance services
- Recording repair history, parts used, and labor performed
- Generating and managing invoices for services rendered (via the Fakturowo.pl integration)
- Communicating with Customers regarding scheduled or completed services
- Fulfilling legal obligations related to the provision of vehicle services
The processing is carried out by automated means within the Garazh® platform and may include collection, recording, storage, retrieval, consultation, use, and erasure of personal data.
4. Types of Personal Data
The following categories of personal data are processed under this Agreement:
4.1. Customer Identification Data
- First name and last name
- Email address
- Phone number
4.2. Vehicle Data
- VIN (Vehicle Identification Number)
- License plate number
- Brand, model, and year of manufacture
- Engine type and displacement
- Current mileage
4.3. Appointment and Repair Data
- Appointment dates and times
- Types of work ordered and performed
- Comments and notes from Customers and Service Station staff
- Diagnostic results
- Labor cost and hours
- Parts used with quantities and prices
- Mileage at the time of service
4.4. Invoice Data
- Buyer details (name, address, NIP)
- Invoice amounts, items, and payment status
5. Categories of Data Subjects
The personal data processed under this Agreement relates to Customers — natural persons who have booked appointments or received vehicle services at the Service Station through the Garazh® platform.
6. Obligations of the Processor (Service Station)
The Processor undertakes to:
- Process data only on documented instructions from the Controller. The Processor shall not process personal data for any purpose other than those specified in this Agreement, unless required to do so by Union or Member State law, in which case the Processor shall inform the Controller of that legal requirement before processing (Article 28(3)(a) GDPR).
- Ensure confidentiality. The Processor shall ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b) GDPR).
- Implement appropriate security measures in accordance with Article 32 GDPR, including as appropriate:
- Encryption of personal data
- The ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
- The ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident
- A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures
- Not engage sub-processors without prior specific or general written authorization of the Controller. The Processor shall not transfer or disclose Customer personal data to any third party without the Controller's prior written consent (Article 28(2) GDPR).
- Assist the Controller in fulfilling obligations to respond to requests from data subjects exercising their rights under Chapter III of the GDPR, including access, rectification, erasure, restriction, portability, and objection (Article 28(3)(e) GDPR).
- Assist the Controller in ensuring compliance with obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor (Article 28(3)(f) GDPR).
- Notify data breaches. The Processor shall notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach (see Section 9).
- Delete or return data on termination. At the choice of the Controller, the Processor shall delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage of the personal data (Article 28(3)(g) GDPR).
- Make available all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (Article 28(3)(h) GDPR).
7. Obligations of the Controller (Garazh)
The Controller undertakes to:
- Ensure a lawful basis for the processing of personal data that is entrusted to the Processor, in accordance with Article 6 GDPR.
- Provide documented instructions for the processing of personal data. The Controller shall ensure that its instructions to the Processor comply with applicable data protection laws.
- Respond to data subject requests. The Controller shall handle and respond to all requests from data subjects exercising their rights under the GDPR, with the assistance of the Processor where necessary.
- Inform the Processor of any changes to data protection legislation or supervisory authority guidance that may affect the Processor's obligations under this Agreement.
- Conduct data protection impact assessments where required by Article 35 GDPR for processing operations carried out through the platform.
8. Sub-processors
The Controller engages the following sub-processors for the operation of the Garazh® platform. By entering into this Agreement, the Processor grants general authorization for the use of the sub-processors listed below:
- Google LLC (Firebase Auth, Analytics, Maps, Calendar, Drive) — EU/US, certified under the EU-US Data Privacy Framework
- Amazon Web Services, Inc. (S3 file storage) — EU, Frankfurt (eu-central-1)
- Vercel Inc. (platform hosting) — EU edge servers
- Fakturowo.pl (invoice management) — Poland
- InterCars S.A. (auto parts catalog and ordering) — Poland
- Functional Software, Inc. (Sentry) (error and performance monitoring) — US, Standard Contractual Clauses (SCCs)
- Telegram FZ-LLC (notification delivery) — UAE/EU
The Controller shall inform the Processor of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Processor the opportunity to object to such changes. If the Processor does not object within 14 days of being notified, the Processor shall be deemed to have consented to the change.
The Controller shall ensure that each sub-processor is bound by data protection obligations no less protective than those set out in this Agreement, in accordance with Article 28(4) GDPR.
9. Data Breach Notification
In the event of a personal data breach, the following notification procedure shall apply:
- The Processor shall notify the Controller of any personal data breach without undue delay, and in any event within 24 hours of becoming aware of the breach. The notification shall include:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned
- The name and contact details of the person from whom more information can be obtained
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach and mitigate its effects
- The Controller shall, where required by Article 33 GDPR, notify the supervisory authority (Urząd Ochrony Danych Osobowych — UODO) within 72 hours of becoming aware of the breach.
- Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall communicate the breach to the affected data subjects without undue delay (Article 34 GDPR).
10. Audit Rights
The Controller has the right to conduct audits and inspections to verify the Processor's compliance with this Agreement and applicable data protection legislation (Article 28(3)(h) GDPR).
- The Controller shall provide the Processor with reasonable prior notice (at least 14 days) before conducting an audit, unless the audit is necessitated by a data breach or a request from a supervisory authority.
- Audits shall be conducted during normal business hours and in a manner that minimizes disruption to the Processor's operations.
- The Processor shall make available all information necessary to demonstrate compliance and shall cooperate fully with the audit process.
- The Controller may engage a qualified, independent third-party auditor to conduct the audit on its behalf. Such auditor shall be bound by confidentiality obligations.
11. International Data Transfers
Where the processing of personal data involves transfer to third countries (outside the European Economic Area), such transfers shall be carried out in compliance with Chapter V of the GDPR. The Controller ensures that appropriate safeguards are in place, including:
- EU-US Data Privacy Framework: For transfers to Google LLC, which is a certified participant under the EU-US Data Privacy Framework.
- Standard Contractual Clauses (SCCs): For transfers to Functional Software, Inc. (Sentry), approved by the European Commission pursuant to Article 46(2)(c) GDPR.
- EU-based processing: Amazon Web Services processes data in Frankfurt (eu-central-1); Vercel uses EU edge servers.
The Processor shall not transfer personal data to any third country or international organization without the prior written consent of the Controller and without ensuring appropriate safeguards under Chapter V of the GDPR.
12. Liability
Liability for damages caused by processing that infringes the GDPR shall be governed by Article 82 GDPR:
- The Controller shall be liable for damage caused by processing which infringes the GDPR.
- The Processor shall be liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the lawful instructions of the Controller.
- A controller or processor shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.
13. Termination and Data Return
Upon termination of this Agreement (including closure or deactivation of the Service Station's account on the Garazh® platform):
- The Processor shall cease all processing of personal data carried out on behalf of the Controller.
- At the Controller's choice, the Processor shall either return all personal data to the Controller or delete all personal data and existing copies, unless Union or Member State law requires continued storage.
- The deletion of personal data shall be completed within 30 days of the date of account closure.
- The Processor shall provide the Controller with written confirmation that all personal data has been deleted, upon request.
- Obligations of confidentiality and provisions regarding liability shall survive the termination of this Agreement.
14. Contact
For any questions or concerns regarding this Data Processing Agreement or the processing of personal data, please contact the Controller at:
MORWA TRADE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Gen. Władysława Sikorskiego 20, 42-202 Częstochowa, Poland
NIP: 9492260466, KRS: 0001030216
Email: support@garazh.eu
Supervisory authority:
Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa
https://uodo.gov.pl
