Data Processing Agreement — WebDisk Next
Version: 1.0 · Effective from: 2026-07-25
The Polish version is the legally binding version. This English translation is provided for convenience only.
Data Processing Agreement (hereinafter: "Data Processing Agreement") concluded between:
The controller of the data (the Customer):
- Name: [Customer name]
- Address: [Address], [Postal code] [City]
- NIP: [VAT ID]
- Email address: [Email]
- represented by the account administrator in the WebDisk Next service
and
The processor (the Processor):
- Mazura sp. z o.o. with its registered office in Ząbki, ul. Baśniowa 1C/2, 05-091 Ząbki, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under number KRS 0000971559, NIP 1251732787, owner of the WebDisk brand.
The Data Processing Agreement governs the processing of personal data in connection with the Customer's use of the WebDisk Next service (hereinafter: "Service"), on the terms set out in the Next Terms.
§1. Definitions
The terms used in the Data Processing Agreement have the meaning given to them in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR"), in particular:
- Personal data — information about an identified or identifiable natural person, processed in connection with the Service,
- Data subjects — the Customer's end users and other natural persons whose data the Customer has placed in the Nextcloud instance,
- Personal data breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Personal data.
§2. Subject matter, nature and purpose of the processing
2.1. Subject matter of the entrustment. The Customer entrusts the Processor with the processing of Personal data contained in the Customer's Nextcloud instance — in files, user accounts and profiles, contacts, calendars and in other data entered by the Customer into the instance.
2.2. Nature of the processing. The processing consists in:
- maintaining a virtual machine with the Nextcloud software and storing the instance's data,
- taking and storing snapshots of the instance and restoring them at the Customer's request,
- performing automated updates of the software and of the operating system.
The Processor does not review, index or analyse the content stored in the Customer's instance and does not use it for its own purposes. In the course of ongoing operations, the Processor's personnel do not obtain access to the instance's operating system or to the content of the Customer's data; maintenance activities are carried out in an automated manner at the infrastructure level.
2.3. Purpose of the processing. Providing the Customer with the Service in accordance with the Next Terms and the chosen plan.
2.4. Categories of Personal data. The scope of the data depends on the content entered by the Customer into the instance and may include in particular: identification data (first name, surname, email address), contact data, data concerning employment or the position held, and also other categories of data resulting from the Customer's decisions.
2.5. Categories of data subjects. The Customer's end users (employees, associates, contractors) and natural persons whose data the Customer stores in the instance.
2.6. Duration of the processing. For the duration of the contract for the provision of the Service, until its termination and the deletion of the data in accordance with §9.
§3. Obligations of the Processor
The Processor undertakes to:
3.1. Process Personal data solely on the documented instruction of the Customer. The Next Terms, this Data Processing Agreement, the configuration of the instance carried out by the Customer, and the maintenance activities necessary to provide the Service are deemed to constitute such an instruction. This also applies to transfers of data to a third country, unless such an obligation is imposed on the Processor by Union law or the law of a Member State — in such a case the Processor informs the Customer of that obligation before the processing begins, unless that law prohibits such information.
3.2. Ensure that persons authorised to process Personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3. Apply the technical and organisational measures set out in §5, ensuring a level of security appropriate to the risk (Article 32 GDPR).
3.4. Assist the Customer — insofar as this is possible and taking into account the nature of the processing — in fulfilling the obligation to respond to requests from data subjects (Articles 12–22 GDPR). Given that the Customer has direct access to the data in the instance and to the Nextcloud administration tools, these requests are fulfilled by the Customer independently; the Processor provides support on the terms set out in §8.
3.5. Assist the Customer in fulfilling the obligations set out in Articles 32–36 GDPR, including as regards the security of processing, the notification of breaches and data protection impact assessments — by making available information on the manner of processing that is at the Processor's disposal.
3.6. Upon the completion of the provision of the Service, delete the Personal data on the terms set out in §9.
3.7. Make available to the Customer the information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and allow for audits on the terms set out in §10.
3.8. Immediately inform the Customer if, in the Processor's opinion, an instruction issued to it infringes the GDPR or other personal data protection provisions.
§4. Obligations of the Customer
The Customer undertakes to:
4.1. Process Personal data in accordance with the GDPR, in particular to have a legal basis for the processing of each category of data entered into the instance.
4.2. Fulfil the information obligations towards data subjects, including informing them about the entrustment of the processing of the data to the Processor.
4.3. Administer its own Nextcloud instance in a manner compliant with the GDPR — in particular to manage user accounts and permissions, the sharing configuration and the installed applications, and also to select and implement security measures adequate to the categories of data processed. The Customer acknowledges that the Nextcloud software makes available a server-side data encryption function which the Customer may enable itself.
4.4. Not enter into the instance special categories of data (Article 9 GDPR), nor data relating to criminal convictions and offences (Article 10 GDPR), nor data subject to special regulatory regimes, without prior written arrangements with the Processor and without implementing adequate security measures on its own side.
4.5. Cooperate with the Processor in fulfilling the requests of data subjects and in handling personal data breaches.
§5. Technical and organisational measures
5.1. Access control:
- named accounts of the Processor's personnel with multi-factor authentication for critical operations,
- administrative access to the production infrastructure solely through a dedicated jump host, with cryptographic key authentication, with session logging,
- no access by the Processor's personnel to the operating system of the Customer's instance or to the content of its data in the course of ongoing operations,
- separation of the production, test and development environments.
5.2. Isolation:
- each Customer's instance is launched on a separate virtual machine, which ensures the isolation of individual Customers' data at the operating system level,
- separate access credentials for each instance.
5.3. Encryption:
- encryption of connections with the TLS protocol in version 1.2 or higher — for the Customer panel and for access to the Nextcloud instance,
- storage of account passwords in the form of cryptographic hashes using a function resistant to dictionary attacks,
- encryption of configuration secrets in the Processor's database.
The Processor informs that the data carriers of the virtual machines and the snapshots are not currently encrypted at rest. A Customer that processes data requiring encryption at rest should apply application-side encryption, including the encryption function available in the Nextcloud software (clause 4.3).
5.4. Logging and monitoring:
- logging of administrative operations (launch and decommissioning of the instance, plan change, taking and restoring a snapshot, migration) with a retention of 12 months,
- security monitoring of the infrastructure with anomaly detection and alerting on a continuous basis.
5.5. Business continuity:
- hardware redundancy of the power supply layer, of network connectivity and of the storage for the disks of the virtual machines,
- rotating snapshots of the instance in accordance with the parameters of the plan, enabling the instance to be restored after a failure.
5.6. Location: Personal data is processed on infrastructure located in the territory of the Republic of Poland. The Processor does not transfer the entrusted data outside the European Economic Area.
5.7. Maintaining the level of security: regular security updates of the software and systems, periodic security testing and a periodic review of the technical and organisational measures applied, no less frequently than once a year.
§6. Sub-processing
6.1. The Customer gives its general authorisation for the Processor to use the services of sub-processors (Article 28(2) GDPR).
6.2. The list of categories of sub-processors is contained in section 10 of the Next Terms. The Processor makes the current list available to the Customer upon request.
6.3. The Processor informs the Customer by email 30 days in advance of intended changes to the list — the addition or replacement of a sub-processor.
6.4. The Customer has the right to raise a reasoned objection to a change, submitted within 14 days of receiving the information. In the event of an objection, the parties shall, within 30 days, attempt to agree an alternative solution; should this prove unsuccessful, the Customer has the right to terminate the contract for the provision of the Service with immediate effect, retaining the possibility of downloading the data.
6.5. The Processor imposes on sub-processors data protection obligations corresponding to the obligations arising from this Data Processing Agreement and is liable to the Customer for the fulfilment of those obligations (Article 28(4) GDPR).
§7. Notification of personal data breaches
7.1. Where a breach of the protection of Personal data covered by the Data Processing Agreement is identified, the Processor:
a) notifies the Customer without undue delay, no later than within 48 hours of becoming aware of the breach — by email and through the Customer panel,
b) provides the information necessary for the Customer to fulfil the obligations under Article 33(3) GDPR, including: the nature of the breach, the categories and approximate number of data subjects and records concerned, the possible consequences of the breach, the remedial measures applied or proposed, and the Processor's contact point,
c) cooperates with the Customer in notifying the supervisory authority and the data subjects.
7.2. The Customer notifies the supervisory authority of the breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights or freedoms of natural persons.
7.3. The parties acknowledge that breaches occurring solely in the application layer of the Customer's instance — resulting from the configuration, permissions or applications introduced by the Customer — may remain outside the scope of the Processor's knowledge; their detection and assessment then rest with the Customer as controller. Should it obtain information about such a breach, the Processor shall immediately notify the Customer.
§8. Support in fulfilling the rights of data subjects
| Right of the data subject | Manner of fulfilment |
|---|---|
| Access to data (Article 15 GDPR) | The Customer fulfils it independently using the Nextcloud administration tools |
| Rectification (Article 16 GDPR) | The Customer fulfils it independently in the instance; billing data — in the Customer panel |
| Erasure of data (Article 17 GDPR) | The Customer fulfils it independently in the instance; decommissioning of the entire instance — in the Customer panel, with a 30-day grace period, after which the permanent deletion of the instance and the snapshots follows |
| Restriction of processing (Article 18 GDPR) | The Customer fulfils it independently; at the Customer's request the Processor suspends the taking of snapshots |
| Data portability (Article 20 GDPR) | The Customer fulfils it independently using the export function and the Nextcloud client applications |
| Objection (Article 21 GDPR) | The Customer examines it as controller; support from the Processor upon a request submitted to iod@webdisk.io |
The Processor does not carry out automated decision-making or profiling in relation to the entrusted data.
§9. Deletion of data after the completion of the provision of the Service
9.1. Following the termination or expiry of the contract for the provision of the Service — irrespective of the reason — the Processor:
a) provides the Customer with the possibility of downloading the data from the instance independently during the grace period set out in the Next Terms (30 days),
b) after the expiry of the grace period or immediately upon the written request of the Customer, permanently deletes the Customer's virtual machine together with all its snapshots.
9.2. The Processor retains solely:
- the infrastructure operations log stripped of data originating from inside the instance — for 12 months, on the basis of Article 17(3)(b) and (e) GDPR,
- accounting documentation — for the period required by accounting and tax regulations.
9.3. At the Customer's request, the Processor issues a written confirmation of the deletion of the data.
§10. Audits
10.1. The Customer has the right to conduct an audit of the Processor's compliance with this Data Processing Agreement, in particular of the measures indicated in §5, no more frequently than once per calendar year, and in addition on each occasion following a personal data breach concerning the Customer.
10.2. The audit is announced in written or documentary form at least 30 days in advance and is conducted during the Processor's working hours, in a manner that does not hinder its ongoing activity.
10.3. The Customer may entrust the conduct of the audit to an independent auditor bound by an obligation of confidentiality. The auditor may not be an entity competing with the Processor.
10.4. The audit may not cover the data of the Processor's other customers or information constituting the Processor's business secret unrelated to the subject matter of the Data Processing Agreement.
10.5. The costs of the audit are borne by the Customer. Where material breaches of the Data Processing Agreement are identified, the reasonable costs of the audit are borne by the Processor.
10.6. The Processor may also demonstrate compliance with its obligations by presenting current reports of an independent auditor or reports from security testing — provided that the Customer considers them sufficient.
§11. Liability
11.1. The Processor is liable for damage caused by processing where it has not complied with the obligations imposed by the GDPR directly on processors or where it has acted outside or contrary to the lawful instructions of the Customer (Article 82(2) GDPR).
11.2. The Processor's liability in damages for the non-performance or improper performance of the Data Processing Agreement is limited to the amount of the fees paid by the Customer in the 12-month period preceding the event giving rise to the damage. The limitation does not apply to damage caused intentionally, nor to cases in which mandatory provisions of law exclude the possibility of limiting liability.
11.3. The rules of liability towards data subjects are set out in Article 82 GDPR, including the rules of joint and several liability and of recourse claims between the controller and the processor.
§12. Final provisions
12.1. Duration. The Data Processing Agreement applies for the duration of the contract for the provision of the Service and expires upon the fulfilment of the obligations set out in §9.
12.2. Amendments. Amendments to the Data Processing Agreement require documentary form. Notification of the Customer by email together with a requirement of renewed acceptance in the Customer panel is deemed to satisfy that form.
12.3. Precedence. In matters of personal data protection, the provisions of the Data Processing Agreement take precedence over the Next Terms and the SaaS Terms.
12.4. Language versions. In the event of discrepancies between the Polish and the English version of the Data Processing Agreement, the Polish version is binding.
12.5. Governing law and jurisdiction of the court. The governing law is Polish law. Disputes are settled by the common court having jurisdiction over the Processor's registered office, subject to the provisions on the jurisdiction of the court in cases involving consumers.
12.6. Conclusion of the Data Processing Agreement. The Data Processing Agreement is concluded at the moment of its acceptance in the Customer panel, recorded together with an indication of the version of the document and the moment of acceptance, or at the moment of signing the document with a qualified signature.
Mazura sp. z o.o. · WebDisk Next · Data Processing Agreement · version 1.0 · effective from 2026-07-25