Document status: This is a public standard framework for processing Customer Content. It becomes contractually binding when incorporated by reference in an accepted proposal, order form or signed agreement, or when accepted electronically by an authorised representative. A separately signed DPA takes precedence.
1. Roles and subject matter
The Customer is the controller of personal data contained in its Butiga workspace, and Temelj za rast is the processor. The subject matter of processing is provision of the Butiga CRM service: storing and organising leads, contacts, email, quotes, tasks, attachments, reports, activities and work handoff, together with support, security, backups and agreed integrations.
Processing continues during the contract and the limited period needed for export, return, deletion and the regular backup cycle.
2. Documented instructions
Temelj za rast processes data only according to the Customer's documented instructions contained in the contract, settings and lawful requests of authorised administrators. If we believe an instruction infringes applicable regulations, we will notify the Customer unless notification is prohibited by law, and may suspend the disputed action pending clarification.
If the law requires processing beyond those instructions, we will notify the Customer in advance where permitted.
3. Confidentiality and access
Access is limited to authorised persons who need it for service delivery, maintenance, support or security and who are contractually or legally bound by confidentiality. Access is limited according to role and business need and revoked when no longer needed.
4. Security measures
Measures are adapted to risk and service development. The standard framework includes:
- separate workspace and tenant boundaries, memberships, roles and backend permission checks;
- PostgreSQL Row-Level Security as an additional data-scope control;
- protection of email credentials and OAuth tokens in storage and secure transmission where applicable;
- controlled handling of HTML email, remote content and attachments;
- auditing of sensitive actions, security records, rate limiting and service monitoring;
- change management, tested backup procedures and the ability to perform a controlled version rollback;
- an incident management process, access restrictions and staff confidentiality obligations.
These measures are not a guarantee of absolute security. The Customer is responsible for correct user and role settings, protecting its devices and accounts, lawful imports and integrations, and timely removal of access.
5. Subprocessors
The Customer gives general written authorisation to engage subprocessors needed for infrastructure, storage, email functions, reliability monitoring, support and other agreed functions. Temelj za rast:
- maintains current information on the identity, location and role of relevant subprocessors and provides it to the Customer on request;
- contractually imposes substantially equivalent data protection obligations;
- remains responsible to the Customer for subprocessors' performance to the extent required by the contract and law;
- announces planned replacements or additions of relevant subprocessors and provides a reasonable period for a substantiated data protection objection.
If the parties cannot resolve a justified objection through a reasonable alternative, the Customer may terminate only the affected part of the Service under the contract.
6. Assistance to the Customer
Taking into account the nature of processing and available information, we reasonably assist the Customer in responding to data subject requests, assessing security, reporting breaches, conducting impact assessments and consulting the supervisory authority. If we receive a data subject request directly concerning Customer Content, we will not decide on it independently except where legally required; we will refer the person to the Customer or forward the request.
Additional work outside standard support may be charged by prior agreement, unless assistance is needed because of our breach of obligation.
7. Incidents
After confirming a personal data breach affecting Customer Content, we notify the Customer without undue delay. To the extent information is available, the notification describes the incident's nature, affected categories, likely consequences, measures taken or proposed and a follow-up contact. We may provide information in stages while the investigation continues.
Notification is not an admission of fault. The Customer decides on reporting to the supervisory authority and individuals, unless the law directly obliges Temelj za rast.
8. Data transfers
We do not transfer Customer Content to another country without a contractual or other lawful mechanism where required. For transfers subject to the GDPR, an adequacy decision, standard contractual clauses and additional risk-based measures may be used. The Customer authorises transfers it directly initiates by choosing an integration, while remaining responsible for assessing their lawfulness.
9. Return and deletion
Upon termination, according to the Customer's choice and technical capabilities, we provide the agreed export or delete the Content. After the export period expires, active copies are removed, and backup copies expire through the regular cycle while remaining isolated from ordinary use. Data may be retained only where required by law, with restricted access and processing solely for that purpose.
10. Evidence of compliance and audits
Upon reasonable request, we provide information needed for the Customer to assess fulfilment of these obligations. Existing documentation, reports and questionnaire responses take precedence. If insufficient, the Customer may conduct a proportionate audit no more than once a year, with reasonable notice and confidentiality, without disrupting other customers or revealing their data, either itself or through an independent expert who is not a competitor.
The Customer bears reasonable audit costs unless the audit reveals a material breach by Temelj za rast. An urgent review following a confirmed serious incident is not limited by the once-a-year rule.
11. Description of processing
| Subject matter and purpose | Providing, maintaining, protecting and supporting the Butiga CRM service under the contract. |
|---|---|
| Nature of operations | Collection on instruction, receipt, organisation, structuring, storage, search, display, synchronisation, transfer to authorised recipients, backup, export and deletion. |
| Data subjects | The Customer's employees and associates; leads, contacts, buyers, suppliers and other business contacts designated by the Customer. |
| Data | Identity and business contact details, company and position, communication and attachments, activities, tasks and deadlines, quotes, notes, technical and audit data. |
| Special categories | Not intended for routine processing. The Customer should not enter them without a specific need, legal basis and agreed measures. |
| Duration | Contract duration, the agreed export period and the regular cycle of removal from backup systems. |
12. Order of precedence and liability
For data protection, this document takes precedence over conflicting general provisions of the Terms. A signed DPA or special clauses take precedence over this public framework. Liability is governed by the accepted contract and applicable law, without limitations prohibited by law.