• Home
  • Services
  • Portfolio
  • About
  • Contact
SQ EN DE
Home Services Portfolio About Contact

Data Processing Agreement

Last updated: 12 September 2026 Vargu Digital L.L.C. · Pristina, Kosovo

On this page

  1. Parties and precedence
  2. Subject matter, duration, nature and purpose
  3. Our obligations as processor
  4. Your obligations as controller
  5. Sub-processors
  6. Personal data breach
  7. International transfers
  8. Audits
  9. Return and deletion of data
  10. Liability and term
  11. Annex I — Description of the processing
  12. Annex II — Technical and organisational measures
  13. Annex III — Authorised sub-processors
  14. Signing this agreement

What this is. Whenever we handle personal data on your behalf — a CRM we built, a site we host, a database we maintain — GDPR Article 28(3) requires a written contract between us before that processing begins. This is that contract. It is drafted to be signed as it stands; you do not need to send us your own.

It applies only where you are the controller and we are the processor. How we handle personal data in our own right is covered by our Privacy Policy.

Parties and precedence

This Data Processing Agreement ("DPA") is entered into between:

  • the client named in the applicable quote, statement of work or master agreement (the "Controller", "you"); and
  • Vargu Digital L.L.C., Pristina, Kosovo (the "Processor", "we").

This DPA forms part of, and is subject to, our Terms & Conditions. Where this DPA and those Terms conflict on a matter of data protection, this DPA prevails. Where this DPA conflicts with a signed master agreement or DPA between us, that signed document prevails.

Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" carry the meanings given in GDPR Article 4. "Data Protection Law" means the GDPR (Regulation (EU) 2016/679), Kosovo's Law No. 06/L-082 on the Protection of Personal Data, and any other law applicable to the processing.

Subject matter, duration, nature and purpose

Article 28(3) requires this contract to set out the subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subject. Those are specified in Annex I, which forms part of this DPA and is completed for each engagement.

In short: we process personal data only to deliver the services you have engaged us for, for as long as we are delivering them, and for no purpose of our own.

We are never a joint controller with you in respect of this processing, and nothing in this DPA makes us one.

Our obligations as processor

These are the obligations Article 28(3)(a)–(h) requires us to accept. We accept them in full.

(a) Documented instructions

We process personal data only on your documented instructions, including on transfers to a third country, unless a law we are subject to requires otherwise — in which case we will tell you before processing, unless that law prohibits it on important grounds of public interest. This DPA, the statement of work, and your ordinary use of the systems we provide constitute your documented instructions.

If we believe an instruction infringes Data Protection Law, we will tell you and may pause that processing until it is resolved.

(b) Confidentiality

Everyone we authorise to process your personal data is bound by an appropriate duty of confidentiality, whether contractual or statutory, and has access only to what their work requires.

(c) Security

We implement the technical and organisational measures required by Article 32, described in Annex II.

(d) Sub-processors

We engage sub-processors only on the conditions in section 5, which reflect Article 28(2) and 28(4).

(e) Helping you answer data subjects

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures — insofar as this is possible — in fulfilling your obligation to respond to requests to exercise rights under GDPR Chapter III (access, rectification, erasure, restriction, portability and objection).

If a data subject contacts us directly about data we process for you, we will not respond substantively. We will forward the request to you without undue delay.

(f) Helping you meet Articles 32 to 36

We will assist you, taking into account the nature of processing and the information available to us, with security of processing, personal data breach notification to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation with a supervisory authority.

(g) Deletion or return

At your choice, we delete or return all personal data at the end of the provision of services, and delete existing copies — unless a law we are subject to requires us to keep it. See section 8.

(h) Demonstrating compliance and audits

We make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. See section 7.

Your obligations as controller

You warrant and undertake that:

  • you have a lawful basis under Article 6 — and, for special categories, Article 9 — for all personal data you ask us to process;
  • you have given data subjects the information required by Articles 13 and 14, including that a processor is involved;
  • your instructions to us comply with Data Protection Law;
  • you will not send us special categories of personal data (Article 9) or criminal-offence data (Article 10) unless we have agreed it in writing in advance and recorded it in Annex I, because those require additional safeguards on both sides;
  • where you upload production data into a test or staging environment, you accept responsibility for that decision — we will recommend against it.

Sub-processors

You give us general written authorisation to engage sub-processors, on these conditions:

  • the sub-processors authorised at the date of this DPA are listed in Annex III;
  • we will give you at least 30 days' written notice before adding or replacing one;
  • you may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected service without penalty and without further liability for it;
  • we impose on every sub-processor, by written contract, the same data protection obligations set out in this DPA, as Article 28(4) requires; and
  • we remain fully liable to you for a sub-processor's performance of those obligations.

Personal data breach

We notify you of a personal data breach affecting your personal data without undue delay after becoming aware of it, and in any event within 48 hours. That window exists so you can meet your own 72-hour deadline to the supervisory authority under Article 33(1).

Our notification will describe, so far as we know it at the time:

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned;
  • the likely consequences;
  • the measures we have taken or propose to take, including to mitigate harm; and
  • a contact point for further information.

Where we cannot provide all of it at once, we provide it in phases without further undue delay. We will not make a public statement about a breach affecting your data without consulting you first, unless we are legally required to.

You are responsible for notifying the supervisory authority and affected data subjects where required — it is your decision to make as controller, and we will give you what you need to make it.

International transfers

Where your personal data is processed determines what safeguard applies. The three locations in Annex III are treated as follows.

  • Frankfurt, Germany (Hostinger). Inside the European Union. No third-country transfer arises.
  • Zurich, Switzerland (Cloudflare). Switzerland is covered by a European Commission adequacy decision, so personal data may be transferred there under Article 45 without any additional safeguard.
  • Pristina, Kosovo (our own server, and our own operations). Kosovo is not an EU or EEA member state and the European Commission has not adopted an adequacy decision for it. Transfers here are made on the basis of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 under Article 46(2)(c), controller-to-processor module, which are incorporated into this DPA by reference and which we will execute on request.

We will not transfer your personal data to a location other than those listed in Annex III without your prior written authorisation and an appropriate Article 45 or 46 basis in place.

Audits

On reasonable written notice of at least 30 days, and no more than once in any 12-month period unless a supervisory authority requires otherwise or we have suffered a breach affecting your data, you or an independent auditor you mandate may audit our compliance with this DPA.

Audits take place during business hours, cause as little disruption as reasonably possible, and are subject to confidentiality. We may require an auditor who is a competitor of ours to be replaced. You bear your own costs; we bear ours, unless the audit reveals a material breach by us, in which case we bear the reasonable cost of the audit.

Where a written response, a completed security questionnaire or existing documentation would reasonably satisfy your request, we will offer that first — it is usually faster for both of us.

Return and deletion of data

On termination or expiry of the services, and at your written choice, we will return your personal data in a commonly used, machine-readable format, or delete it, and delete existing copies.

  • Tell us which you want within 30 days of termination.
  • If you tell us nothing, we will hold the data for 60 days and then delete it. We will remind you before we do.
  • Data held in routine encrypted backups is deleted on the normal backup rotation rather than individually, and remains subject to this DPA until it is.
  • We may retain personal data where a law we are subject to requires it, and only for as long as that law requires.

We will confirm deletion in writing on request.

Liability and term

This DPA takes effect when the services begin, or on signature if earlier, and continues for as long as we process personal data on your behalf. Sections concerning confidentiality, deletion and liability survive it.

Each party's liability under this DPA is subject to the limitations and exclusions in our Terms & Conditions. Nothing in this DPA limits a data subject's rights, or either party's liability to a supervisory authority or to a data subject under Data Protection Law — those cannot be contracted away, and we are not attempting to.

This DPA is governed by the laws of the Republic of Kosovo, without prejudice to any mandatory provision of Data Protection Law applicable to you.

Annex I — Description of the processing

Completed per engagement. Unless the statement of work says otherwise, the following applies to a typical project.

Subject matter Provision of design, development, hosting and maintenance services as described in the applicable statement of work.
Duration The term of the services, plus the return/deletion period in section 8.
Nature and purpose Storage, hosting, retrieval, structuring, display, backup, migration, support and deletion of personal data, solely to deliver the services.
Categories of data subject Determined by you. Typically: your customers and prospects, your employees and contractors who use the system, and visitors to your website.
Types of personal data Determined by you. Typically: names, email addresses, phone numbers, postal addresses, job titles, account credentials, order and transaction records, correspondence, and technical data such as IP addresses and log entries.
Special category data None. Where a system we build offers biometric sign-in, it uses device-based authentication (passkeys / WebAuthn, Face ID, Touch ID): the biometric is matched on the user's own device and never reaches any system we operate. We receive only a public key or cryptographic assertion, which is not biometric data within the meaning of Article 4(14). No special-category data under Article 9, and no criminal-offence data under Article 10, is processed unless expressly agreed in writing in advance and recorded here.
Frequency Continuous for hosted systems; occasional for project and support work.

Annex II — Technical and organisational measures

The measures below are those we apply under Article 32. Measures provided by our infrastructure sub-processors are identified as such, and their own documentation governs the detail.

  • Encryption in transit. All services are served over HTTPS/TLS, with plain HTTP redirected.
  • Encryption at rest. Provided by our infrastructure sub-processors at the storage layer — see their documentation in Annex III.
  • Access control. Individual named accounts, no shared logins, and access limited to personnel who need it for the work in hand. Administrative interfaces are not open to public registration.
  • Database-level authorisation. Row-level security rules are enforced in the database rather than relying on application logic alone.
  • Data minimisation. We hold the smallest amount of personal data the service requires, which limits the impact of any incident.
  • Backups. Regular automated backups of hosted systems, retained on a defined rotation: daily, retained for 30 days
  • Segregation. Client environments are logically separated; we do not commingle one client's data with another's.
  • Personnel. Confidentiality obligations apply to everyone with access.
  • Incident response. Breach assessment and the notification process in section 6.
  • Deletion. Documented return and deletion process per section 8.

We keep this annex honest rather than impressive. If a measure is not listed here, do not assume it is in place — ask us, and we will tell you plainly.

Annex III — Authorised sub-processors

These are the sub-processors authorised at the date of this DPA. We will give at least 30 days' notice before adding or replacing one, per section 5.

Sub-processorPurposeProcessing location
Hostinger Web hosting, backups and VPS infrastructure Frankfurt, Germany — European Union
Cloudflare Domain registration, DNS, content delivery and security Zurich, Switzerland
Vargu Digital — own infrastructure Application hosting and storage on a server we operate ourselves Pristina, Kosovo

Where a project uses additional services at your request — a payment provider, a transactional email service, an analytics tool — those are added to this annex for that engagement before they are used.

Our internal AI assistant does not process client personal data and is therefore not listed as a sub-processor. If that ever changes, this annex is updated and you are notified under section 5 before it does.

Signing this agreement

This DPA can be executed in three ways, whichever suits you:

  • By reference. Where your statement of work states that this DPA applies, it is incorporated and binding without a separate signature.
  • Counter-signed copy. Email legal@vargu.digital with "DPA" in the subject line and we will send a PDF for signature, with Annex I completed for your project.
  • Your paper. If your organisation requires its own DPA, send it over. We will review it and, in most cases, sign it.

This DPA was last updated on 12 September 2026. Where it is incorporated by reference, the version in force on the date your statement of work was signed is the one that applies.

Site

  • Home
  • Services
  • Portfolio
  • About
  • Contact

Legal

  • Privacy Policy
  • Terms & Conditions
  • Acceptable Use
  • DPA
  • Security

Contact

  • contact@vargu.digital
  • +383 49 481 641
© Vargu Digital. All rights reserved.