Data Processing Agreement - AwiFin

Effective as of: 01.05.2025

This Data Processing Agreement ("DPA") forms part of the agreement between eRapid Studio and the customer using AwiFin where eRapid Studio processes personal data on behalf of the customer.

This DPA applies where the customer is the controller of personal data contained in Customer Content and eRapid Studio processes such personal data as processor.

1. Parties

Processor: eRapid Studio, Machowa 25a, 39-220 Pilzno, Poland, NIP: 8722318796, REGON: 362035564. Email: contact@awifin.com. Operating the AwiFin service available at AwiFin.com.

Controller: The company, team, organisation, sole trader, or other legal entity that uses AwiFin and determines the purposes and means of processing personal data contained in Customer Content. The controller is referred to as the "Customer."

Together, eRapid Studio and the Customer are referred to as the "Parties."

2. Relationship with the Terms of Service

This DPA supplements the AwiFin Terms of Service, Privacy Policy, and any applicable order, subscription, or service agreement between the Parties.

If there is a conflict between this DPA and the Terms of Service concerning processing of personal data on behalf of the Customer, this DPA prevails.

3. Definitions

For the purposes of this DPA:

  • "GDPR" means Regulation (EU) 2016/679.
  • "Personal Data" means personal data processed by eRapid Studio on behalf of the Customer through AwiFin.
  • "Customer Content" means content, data, text, updates, reports, stakeholder profiles, imported Jira data, Slack-related data, prompts, AI inputs, AI outputs, shared reports, and other materials submitted to or generated through AwiFin by the Customer or its authorised users.
  • "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach," and "Subprocessor" have the meanings given in the GDPR.
  • "Services" means the AwiFin software-as-a-service product.

4. Roles of the Parties

The Customer is the controller of Personal Data contained in Customer Content.

eRapid Studio is the processor of such Personal Data and processes it on behalf of the Customer.

For data relating to account administration, billing, subscription management, security, support, analytics, marketing, and legal compliance, eRapid Studio may act as an independent controller, as described in the AwiFin Privacy Policy.

5. Subject matter of processing

The subject matter of processing is the provision of AwiFin, including project update management, stakeholder report generation, AI-assisted summaries, shared reports, Slack integration, Jira integration, account access, workspace management, support, security, and related SaaS functionality.

6. Duration of processing

Processing continues for the duration of the Customer's use of AwiFin and until Personal Data is deleted or returned in accordance with this DPA, the Terms of Service, the Privacy Policy, or applicable law.

Backup copies may remain for a limited period until overwritten according to the applicable backup cycle.

7. Nature and purpose of processing

eRapid Studio processes Personal Data to provide AwiFin functionality, including hosting Customer Content, creating and storing project updates, generating reports, generating AI-assisted summaries and outputs, managing stakeholder profiles, enabling shared reports, supporting Slack and Jira integrations, managing workspace access and permissions, providing support, troubleshooting errors, securing the service, maintaining backups, and complying with applicable law.

Processing operations may include collection, recording, organisation, structuring, storage, hosting, retrieval, consultation, use, transmission, disclosure by transmission, alignment, combination, restriction, erasure, and destruction.

8. Categories of Personal Data

Depending on the Customer's use of AwiFin, Personal Data may include:

  • names;
  • email addresses;
  • role or job title;
  • company/team/workspace affiliation;
  • user identifiers;
  • project-related information;
  • task or issue information imported from Jira;
  • Slack-related identifiers or message metadata;
  • stakeholder profile information;
  • project updates;
  • report content;
  • blockers, risks, decisions, action items;
  • AI prompts and AI-generated outputs;
  • shared report content;
  • technical metadata;
  • access and usage logs.

The Customer controls what Personal Data is submitted to AwiFin.

9. Categories of Data Subjects

Personal Data may concern:

  • Customer employees;
  • Customer contractors;
  • Customer team members;
  • Customer users;
  • project stakeholders;
  • client contacts;
  • vendor contacts;
  • business partners;
  • Jira users referenced in imported data;
  • Slack users referenced through integrations;
  • other individuals whose data is included in Customer Content by the Customer or its authorised users.

10. Special categories of data

AwiFin is not designed for processing special categories of Personal Data under Article 9 GDPR, including health data, biometric data, political opinions, religious beliefs, trade union membership, or data concerning sex life or sexual orientation.

The Customer must not submit special-category data to AwiFin unless the Customer has a valid legal basis and has assessed that AwiFin is appropriate for such processing.

The Customer is responsible for ensuring that Customer Content does not contain unnecessary sensitive personal data.

11. Customer instructions

eRapid Studio will process Personal Data only on documented instructions from the Customer, including instructions given through use of AwiFin, account configuration, workspace settings, integration settings, support requests, written communication, this DPA, and the Terms of Service.

If eRapid Studio believes that an instruction infringes GDPR or other applicable data protection law, it will inform the Customer, unless prohibited by law.

12. Customer obligations

The Customer is responsible for:

  • ensuring that it has a lawful basis for processing Personal Data;
  • providing required notices to Data Subjects;
  • obtaining required consents, where applicable;
  • ensuring that users are authorised to submit Customer Content;
  • ensuring that Customer Content is accurate, lawful, and appropriate;
  • responding to Data Subject requests where the Customer is controller;
  • configuring integrations lawfully;
  • deciding whether shared reports may be disclosed to recipients;
  • avoiding unnecessary special-category or sensitive data;
  • complying with applicable data protection laws.

13. Processor obligations

eRapid Studio will:

  • process Personal Data only on documented Customer instructions;
  • ensure that persons authorised to process Personal Data are bound by confidentiality;
  • implement appropriate technical and organisational measures;
  • assist the Customer with Data Subject requests, where reasonably possible;
  • assist the Customer with security, breach notification, DPIAs, and supervisory authority consultation, where required and reasonably possible;
  • use subprocessors only in accordance with this DPA;
  • delete or return Personal Data after the end of services, unless storage is required by law;
  • make available information reasonably necessary to demonstrate compliance with this DPA;
  • notify the Customer if it becomes aware of a Personal Data Breach affecting Customer Personal Data.

14. Security measures

eRapid Studio will implement appropriate technical and organisational measures considering the nature, scope, context, and purposes of processing, as well as the risks to Data Subjects. Such measures may include:

  • TLS encryption for data in transit;
  • access controls and role-based access restrictions;
  • authentication mechanisms;
  • secure password storage;
  • infrastructure security controls;
  • limited access to production systems;
  • confidentiality obligations;
  • backup procedures;
  • logging and monitoring;
  • vulnerability and risk management practices;
  • incident response procedures;
  • data minimisation where possible;
  • separation of customer workspaces where technically applicable;
  • regular review of security measures.

The Customer acknowledges that security measures may evolve over time, provided they do not materially reduce the overall level of protection.

15. Subprocessors

The Customer gives eRapid Studio general authorisation to use subprocessors to provide AwiFin. Current subprocessors include:

  • Fly.io - Hosting and infrastructure;
  • OpenAI - AI-assisted generation and summarisation;
  • Stripe - Payment and subscription processing;
  • Google Analytics - Website/app analytics, where consent applies;
  • Mailgun - Transactional or product email delivery;
  • MailerLite - Marketing/product email delivery;
  • Slack - Integration functionality, if enabled;
  • Jira / Atlassian - Integration functionality, if enabled.

eRapid Studio will ensure that subprocessors are bound by data protection obligations that provide an appropriate level of protection for Personal Data.

eRapid Studio may add or replace subprocessors where necessary to provide the service. If required by applicable law or a separate written agreement, eRapid Studio will provide notice of material subprocessor changes and give the Customer an opportunity to object on reasonable data protection grounds.

If the Customer objects to a new subprocessor and the Parties cannot resolve the objection, the Customer may stop using the affected functionality or terminate the affected service, unless otherwise agreed.

16. International transfers

Some subprocessors may process Personal Data outside the European Economic Area. Where Personal Data is transferred outside the EEA, eRapid Studio will use appropriate safeguards required by GDPR, such as:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses adopted by the European Commission;
  • additional safeguards where required;
  • another lawful transfer mechanism under GDPR.

The Customer authorises such transfers where necessary to provide AwiFin, subject to the safeguards described above.

17. Assistance with Data Subject requests

Taking into account the nature of processing, eRapid Studio will reasonably assist the Customer in responding to Data Subject requests, including requests for access, rectification, erasure, restriction, objection, and portability.

Where possible, AwiFin may provide functionality allowing the Customer to access, correct, export, or delete relevant Customer Content directly.

If eRapid Studio receives a Data Subject request concerning Customer-controlled Personal Data, it will, where reasonably possible, direct the request to the Customer or notify the Customer, unless prohibited by law.

18. Personal Data Breach

If eRapid Studio becomes aware of a Personal Data Breach affecting Personal Data processed on behalf of the Customer, eRapid Studio will notify the Customer without undue delay.

The notification will include, where reasonably available: nature of the breach; affected categories of Personal Data; affected categories of Data Subjects; likely consequences; measures taken or proposed to address the breach; contact point for further information.

eRapid Studio will reasonably assist the Customer in meeting any breach notification obligations. A notification under this section does not constitute an admission of fault or liability.

19. DPIA and supervisory authority assistance

Taking into account the nature of processing and information available to eRapid Studio, eRapid Studio will reasonably assist the Customer with data protection impact assessments and prior consultation with supervisory authorities where required by GDPR.

Such assistance may be subject to reasonable fees if it requires substantial additional work and is not caused by eRapid Studio's breach of this DPA.

20. Deletion or return of Personal Data

Upon termination of the services, eRapid Studio will delete or return Personal Data processed on behalf of the Customer, unless applicable law requires continued storage.

The Customer may delete certain Customer Content directly through AwiFin functionality where available. Backup copies may remain for a limited period until overwritten according to the applicable backup cycle.

eRapid Studio may retain data where necessary to comply with legal obligations, resolve disputes, enforce agreements, or maintain security records.

21. Audits and compliance information

eRapid Studio will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer may request information about security measures, subprocessors, and processing practices.

Any audit must be limited to what is necessary to verify compliance, conducted with reasonable prior notice, subject to confidentiality, conducted during normal business hours, and designed to avoid disruption to AwiFin operations or compromise the security or confidentiality of other customers.

Where possible, audits should be satisfied through documentation, security summaries, questionnaires, or third-party reports. On-site audits require separate written agreement.

22. Confidentiality

Each Party must keep confidential any non-public information received from the other Party in connection with this DPA, including security information, technical information, business information, Customer Content, and Personal Data.

Confidentiality obligations do not apply to information that is public, independently developed, lawfully received from a third party, or required to be disclosed by law.

23. Liability

Liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service or other agreement between the Parties, unless prohibited by applicable law.

Nothing in this DPA limits liability where such limitation is not permitted under applicable data protection law.

24. Termination

This DPA remains in effect for as long as eRapid Studio processes Personal Data on behalf of the Customer.

Termination of the Terms of Service or the applicable service agreement also terminates this DPA, except for provisions that must survive termination, including confidentiality, deletion/return, liability, and audit-related obligations.

25. Governing law

This DPA is governed by the laws of Poland, unless mandatory data protection law provides otherwise.

Annex 1 - Processing Details

Subject matter: Provision of AwiFin SaaS, including project updates, stakeholder reporting, AI-assisted summaries, integrations, shared reports, support, hosting, and security.

Duration: For the duration of the Customer's use of AwiFin and until Personal Data is deleted or returned according to the DPA, Terms of Service, Privacy Policy, or applicable law.

Nature of processing: Collection, recording, organisation, structuring, storage, hosting, retrieval, consultation, use, transmission, disclosure by transmission, alignment, combination, restriction, erasure, and destruction.

Purpose of processing: To provide, maintain, secure, support, and improve AwiFin, and to process Customer Content according to Customer instructions.

Categories of Personal Data: names; email addresses; user identifiers; company/team information; job titles or roles; project updates; stakeholder information; task and issue data; Jira data; Slack metadata; blockers; risks; decisions; action items; reports; AI prompts; AI outputs; shared report content; technical metadata.

Categories of Data Subjects: Customer employees; contractors; team members; users; project stakeholders; client contacts; vendor contacts; business partners; individuals referenced in Customer Content.

Special categories: Not intended. Customer must not submit special-category data unless it has a valid legal basis and has assessed that AwiFin is appropriate for such processing.

Annex 2 - Technical and Organisational Measures

Access control: restricted access to production systems; role-based permissions where applicable; account authentication; least-privilege access principles.

Transmission security: TLS encryption for data in transit; secure communication channels for service access.

Storage and infrastructure: hosting through Fly.io; database and infrastructure access restrictions; backup procedures.

Application security: authentication and authorisation mechanisms; input validation where applicable; monitoring of errors and unusual behaviour; security review of critical changes where feasible.

Confidentiality: access to Personal Data limited to authorised persons; confidentiality expectations for persons with access.

Availability and resilience: backup procedures; infrastructure monitoring where available; recovery procedures proportionate to the stage and scale of the service.

Incident management: investigation of suspected incidents; mitigation of identified risks; notification process for Personal Data Breaches affecting Customer Personal Data.

Data minimisation: processing limited to what is necessary to provide the service; users advised not to submit unnecessary personal or sensitive data.

Annex 3 - Approved Subprocessors

The following subprocessors are approved. Subprocessors may be updated from time to time where necessary to provide the service.

  • Fly.io - Hosting and infrastructure - EEA and/or third countries depending on configuration;
  • OpenAI - AI-assisted generation and summarisation - EEA and/or third countries;
  • Stripe - Payment and subscription processing - EEA and/or third countries;
  • Google Analytics - Analytics, where consent applies - EEA and/or third countries;
  • Mailgun - Transactional/product email delivery - EEA and/or third countries;
  • MailerLite - Marketing/product email delivery - EEA and/or third countries;
  • Slack - Integration functionality, if enabled - EEA and/or third countries;
  • Jira / Atlassian - Integration functionality, if enabled - EEA and/or third countries.
AwiFin: Client follow-up software for founders who handle their own salesAwiFin - Project Updates Stakeholders Actually Understand | Product Hunt