Data processings terms

ANNEX NO. 1 TO THE TERMS AND CONDITIONS OF PRACOŠ.SK

DATA PROCESSING TERMS PURSUANT TO ARTICLE 28 GDPR

Last updated: 6 October 2026


I. INTRODUCTORY PROVISIONS

  1. These Data Processing Terms (the “Data Processing Terms”) govern the processing of personal data by:

Webian s.r.o.
Dubová 426/5A
080 05 Teriakovce
Slovak Republic

Company ID No.: 52 975 380

registered in the Commercial Register of the District Court Prešov, Section Sro, Insert No. 53615/P,

hereinafter referred to as the “Processor”,

on behalf of an Employer using the services of Pracoš.sk,

hereinafter referred to as the “Controller”.

  1. These Data Processing Terms form an integral part of the Terms and Conditions of Pracoš.sk and of the contractual relationship between the Processor and the Controller where Webian s.r.o. processes personal data on behalf of the Employer through Pracoš.sk.
  2. These Data Processing Terms constitute a data processing agreement pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”).
  3. By entering into a contractual relationship with Pracoš.sk, using a Service enabling receipt of Applicant Applications or otherwise accepting the Terms and Conditions, the Employer instructs Webian s.r.o. to process personal data under these Data Processing Terms.
  4. Where Webian s.r.o. processes certain personal data for its own purposes and independently determines the purposes and means of processing, Webian s.r.o. acts as an independent controller. These Data Processing Terms do not apply to such processing.

II. SUBJECT MATTER OF PROCESSING

  1. The processing concerns personal data of Applicants who respond through Pracoš.sk to a specific Job Offer published by the Controller.
  2. The Processor provides technical services enabling in particular:

a) receipt of an Application,

b) recording of an Application,

c) storage of an Application,

d) storage of CVs and attachments,

e) assignment of an Application to a specific Job Offer,

f) management of Applications,

g) making an Application available to the Controller,

h) transmission of information to the Controller,

i) technical protection of data,

j) deletion of data after expiry of the applicable retention period,

k) creation of anonymous statistical information following removal of personal data where the relevant natural person can no longer be identified.

  1. The Processor may not use personal data processed under these Terms for its own incompatible purposes.

III. PURPOSE AND NATURE OF PROCESSING

  1. The purpose of processing is to enable the Controller to conduct recruitment for a position published through Pracoš.sk.
  2. Processing includes in particular collection, recording, organisation, storage, retrieval, consultation, disclosure, transmission and subsequent deletion of Applicant personal data.
  3. The Controller determines the purpose of processing.
  4. The Controller is responsible for ensuring that the purpose of processing is lawful and that Applicant personal data are used only in a manner compatible with that purpose and applicable law.

IV. CATEGORIES OF DATA SUBJECTS

The data subjects are primarily:

Applicants for employment or other employment opportunities who respond to the Controller’s Job Offers through Pracoš.sk.


V. CATEGORIES OF PERSONAL DATA

  1. The Processor may process on behalf of the Controller in particular:

a) first name,

b) surname,

c) email address,

d) telephone number,

e) cover message,

f) CV,

g) documents and attachments submitted by the Applicant,

h) information identifying the Job Offer to which the Applicant responded,

i) date and time of the Application,

j) other information voluntarily included by the Applicant in a CV, attachment or message.

  1. CVs or attachments may contain information concerning, for example:

a) education,

b) work experience,

c) professional qualifications,

d) language skills,

e) abilities and skills,

f) employment history,

g) other information provided by the Applicant.

  1. Pracoš.sk does not require Applicants to provide special categories of personal data within the meaning of Article 9 GDPR in their CVs or attachments.
  2. Applicants may nevertheless voluntarily include information in free-text fields, CVs or attachments that constitutes special-category personal data.
  3. The Controller is responsible for assessing the lawfulness of any further processing of such information and must not require special-category data unless a lawful basis exists.

VI. DURATION OF PROCESSING

  1. Personal data contained in an Application may be processed through Pracoš.sk for a maximum period of 24 months from submission of the relevant Application, unless deleted earlier.
  2. Earlier deletion may occur in particular:

a) following a lawful instruction from the Controller,

b) following a justified request from a data subject,

c) following termination of the Service where further storage is unnecessary,

d) where further processing is unlawful,

e) for another reason arising under the GDPR or applicable law.

  1. After expiry of the retention period, the Processor will remove personal data enabling identification of the Applicant.
  2. CVs and attachments will be deleted from the system following expiry of the relevant retention period in accordance with the Processor’s technical procedures.
  3. After removal of personal data, the Processor may retain only information that has been irreversibly anonymised so that the data subject can no longer reasonably be identified.
  4. Such anonymous information may include, for example:

a) number of Applications to a Job Offer,

b) date or period of an Application,

c) Job Offer category,

d) region,

e) type of employment,

f) other aggregated statistical information that does not permit identification of an Applicant.

  1. The GDPR does not apply to genuinely anonymous information.

VII. INSTRUCTIONS OF THE CONTROLLER

  1. The Processor shall process personal data only on documented instructions from the Controller unless processing is required by European Union or Slovak law.
  2. Documented instructions include in particular:

a) these Data Processing Terms,

b) the Terms and Conditions of Pracoš.sk,

c) Service settings configured by the Controller through its User Account,

d) legitimate requests submitted by the Controller to the Processor,

e) other agreed conditions applicable to the relevant Service.

  1. Where the Processor is required by law to process personal data beyond the Controller’s instructions, it shall inform the Controller before such processing unless prohibited by law from doing so.
  2. Where the Processor considers that an instruction infringes the GDPR or other applicable data protection legislation, it shall inform the Controller without undue delay.
  3. The Processor is not required to carry out an instruction that would result in a breach of applicable law.

VIII. OBLIGATIONS OF THE CONTROLLER

  1. The Controller is responsible for the lawfulness of processing Applicant personal data.
  2. The Controller must in particular:

a) establish an appropriate legal basis for processing,

b) provide Applicants with information required under Articles 13 or 14 GDPR to the extent for which the Controller is responsible,

c) process only information adequate and necessary for recruitment,

d) comply with the principle of data minimisation,

e) ensure data accuracy to the extent for which it is responsible,

f) determine an appropriate retention period,

g) ensure the lawfulness of further processing after obtaining data from Pracoš.sk,

h) protect data downloaded from Pracoš.sk,

i) ensure proper handling of data subject rights,

j) use personal data solely for lawful purposes.

  1. The Controller must not use Applicant Applications for:

a) unsolicited marketing,

b) sale of databases,

c) unauthorised profiling,

d) disclosure to unauthorised third parties,

e) purposes incompatible with the original recruitment purpose without an appropriate legal basis.


IX. CONFIDENTIALITY AND AUTHORISED PERSONNEL

  1. The Processor shall ensure that persons authorised to process personal data are subject to an appropriate obligation of confidentiality.
  2. Access to personal data shall be granted only to persons who require such access to perform their duties.
  3. The Processor applies the principle of least privilege.
  4. Confidentiality obligations continue after a person’s authority to access personal data ends.

X. SECURITY OF PROCESSING

  1. The Processor shall implement appropriate technical and organisational measures corresponding to the risk of processing in accordance with Article 32 GDPR.
  2. In determining the appropriate level of security, the Processor shall take into account in particular:

a) the state of the art,

b) implementation costs,

c) the nature of processing,

d) the scope of processing,

e) the context and purposes of processing,

f) the likelihood and severity of risks to the rights and freedoms of natural persons.

  1. Measures may include, as appropriate:

a) encrypted transmission using HTTPS/TLS,

b) access control,

c) User authentication,

d) protection of server infrastructure,

e) regular system updates,

f) backups,

g) protection against unauthorised access,

h) logging of relevant security events,

i) procedures for restoring data availability,

j) appropriate testing and evaluation of security measures.

  1. The Processor may continuously modify and improve technical and organisational measures provided that the overall appropriate level of personal data protection is not reduced.

XI. SUB-PROCESSORS

  1. The Controller grants the Processor general written authorisation to engage sub-processors necessary for providing Pracoš.sk Services.
  2. Sub-processors may provide in particular:

a) hosting and server infrastructure,

b) electronic communications,

c) backups,

d) security services,

e) technical operation,

f) SMS services,

g) other necessary technical services.

  1. Providers used in connection with Pracoš.sk may, depending on the Services currently used, include Contabo for server and email infrastructure and BudgetSMS for SMS services.
  2. The Processor shall ensure that a sub-processor is contractually bound by data protection obligations providing an appropriate level of protection corresponding to the requirements of Article 28 GDPR.
  3. Where a sub-processor fails to fulfil its data protection obligations, the Processor remains liable to the Controller for the performance of that sub-processor’s obligations to the extent provided by the GDPR.
  4. The Processor shall maintain current information concerning material sub-processors or otherwise make such information available to the Controller.
  5. The Processor shall provide the Controller with a reasonable opportunity to object on legitimate data protection grounds to the intended addition or replacement of a sub-processor.
  6. Where a legitimate objection cannot reasonably be resolved, the parties shall agree on further steps; where no technically and reasonably feasible solution exists, the affected Service may be terminated.

XII. INTERNATIONAL DATA TRANSFERS

  1. The Processor shall ensure that any transfer of personal data outside the European Economic Area takes place only in accordance with Chapter V GDPR.
  2. Where a Service involves an entity located in a third country or permitting access from a third country, an appropriate transfer mechanism under the GDPR shall be implemented.
  3. Such mechanism may include in particular:

a) an adequacy decision of the European Commission,

b) a valid framework recognised by the European Commission,

c) Standard Contractual Clauses,

d) another mechanism permitted under Chapter V GDPR.

  1. Where required by the GDPR, appropriate supplementary technical or organisational measures shall also be implemented.

XIII. DATA SUBJECT RIGHTS

  1. The Processor shall provide reasonable assistance to the Controller in handling requests by Applicants to exercise their rights under the GDPR.
  2. Such rights include in particular:

a) right of access,

b) right to rectification,

c) right to erasure,

d) right to restriction of processing,

e) right to data portability where applicable,

f) right to object where applicable.

  1. Where an Applicant submits a request directly to the Processor concerning processing carried out exclusively on behalf of a specific Controller, the Processor may forward the request to that Controller.
  2. The Processor shall not respond on behalf of the Controller without its instructions unless required to do so by law.
  3. The Processor shall provide technical assistance necessary to locate, rectify, export, restrict or delete information where such operation is technically relevant within the Service.

XIV. PERSONAL DATA BREACHES

  1. Where the Processor becomes aware of a personal data breach concerning personal data processed on behalf of the Controller, it shall notify the Controller without undue delay.
  2. The notification shall, to the extent information is available, contain in particular:

a) a description of the nature of the breach,

b) categories of affected data subjects,

c) approximate number of affected data subjects where known,

d) categories and approximate number of affected records where known,

e) likely consequences of the breach,

f) measures taken or proposed to address the breach.

  1. Where all information cannot be provided at the same time, it may be provided in phases without further undue delay.
  2. The Processor shall provide reasonable assistance to the Controller in fulfilling obligations under Articles 33 and 34 GDPR.
  3. The Controller is responsible for determining whether the breach must be notified to a supervisory authority or affected data subjects to the extent it acts as controller of the relevant personal data.

XV. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION

  1. The Processor shall provide reasonable assistance to the Controller with obligations under Articles 35 and 36 GDPR where such obligations apply in light of the nature of processing.
  2. Such assistance may include available information concerning:

a) processing methods,

b) technical and organisational measures,

c) systems used,

d) sub-processors,

e) security measures relevant to risk assessment.


XVI. AUDITS AND DEMONSTRATION OF COMPLIANCE

  1. The Processor shall provide the Controller with information necessary to demonstrate compliance with Article 28 GDPR.
  2. The Controller may verify compliance with these Data Processing Terms to a reasonable extent.
  3. The Processor shall allow audits, including inspections, conducted by the Controller or an auditor appointed by the Controller under reasonable conditions.
  4. An audit must not:

a) unreasonably disrupt the Processor’s operations,

b) compromise system security,

c) provide access to data belonging to other customers,

d) result in breach of confidentiality obligations owed to third parties.

  1. The Controller shall provide reasonable advance notice of an intended audit except where an immediate audit is justified by a serious security incident or a request from a supervisory authority.
  2. The parties may reasonably use security documentation, independent audit results, certifications or other reliable evidence to demonstrate compliance where available.

XVII. TERMINATION OF PROCESSING AND DELETION OF DATA

  1. Upon termination of Services involving processing on behalf of the Controller, the Processor shall, at the Controller’s choice, delete the personal data or, to the extent technically available, enable their return, unless applicable law requires further storage.
  2. This is without prejudice to the agreed maximum 24-month processing period for Applications during the provision of the Service.
  3. The Controller may download information accessible through the Portal before its deletion where the Portal provides such functionality.
  4. Where the Controller downloads or otherwise stores information in its own systems, the Processor is not responsible for further storage or processing of that copy by the Controller.
  5. Following expiry of the applicable retention period, the Processor shall remove in particular:

a) first name and surname,

b) telephone number,

c) email address,

d) cover messages containing personal data,

e) CVs,

f) attachments,

g) other identifiers enabling a record to be associated with a particular natural person, unless further storage has a separate lawful basis.

  1. Only genuinely anonymous statistical information may remain.
  2. Personal data contained in technical backups may be deleted according to the ordinary backup rotation cycle provided that such data are not used for ordinary operational purposes after expiry of the retention period and remain appropriately secured until overwritten or deleted.

XVIII. INDEPENDENT PROCESSING BY WEBIAN

  1. These Data Processing Terms do not mean that Webian s.r.o. acts as a Processor for every processing operation related to the Portal.
  2. Webian s.r.o. may act as an independent Controller in particular when processing information necessary for:

a) creation and administration of User Accounts,

b) Portal security,

c) fraud and abuse prevention,

d) technical logs,

e) billing and accounting,

f) customer support,

g) compliance with legal obligations,

h) establishment, exercise or defence of legal claims,

i) marketing where the relevant legal requirements are met.

  1. Details of such processing are set out in the Pracoš.sk Privacy Policy.

XIX. LIABILITY

  1. Each party is responsible for complying with the obligations imposed on it by the GDPR and these Data Processing Terms.
  2. The Controller is responsible in particular for the lawfulness of the purpose and legal basis of processing and for the instructions it provides to the Processor.
  3. The Processor is responsible for obligations expressly imposed on processors by the GDPR and for complying with lawful instructions from the Controller.
  4. Liability of the parties towards data subjects shall be determined in accordance with Article 82 GDPR and other applicable law.

XX. PRECEDENCE

  1. In the event of a conflict between these Data Processing Terms and the Terms and Conditions of Pracoš.sk concerning processing carried out on behalf of the Controller, these Data Processing Terms shall prevail.
  2. Where an individual written agreement between the Controller and Processor contains specific data processing provisions differing from these Terms, the individually agreed provisions shall prevail to the extent of the conflict.
  3. Nothing in these Data Processing Terms may be interpreted as reducing the level of protection required by the GDPR.

XXI. AMENDMENTS

  1. The Processor may update these Data Processing Terms in particular due to:

a) changes in applicable law,

b) changes to the Service,

c) changes in technologies used,

d) changes in sub-processors,

e) improvements to personal data protection.

  1. Where an amendment materially affects the processing of personal data on behalf of the Controller, the Processor shall inform the Controller in an appropriate manner.
  2. The current version shall be available through Pracoš.sk.

XXII. DURATION

  1. These Data Processing Terms apply for as long as the Processor processes personal data on behalf of the Controller.
  2. Provisions concerning confidentiality, security, deletion, audits and liability shall continue to apply after termination to the extent necessary to comply with the parties’ legal obligations.

XXIII. FINAL PROVISIONS

  1. These Data Processing Terms are governed by the laws of the Slovak Republic and directly applicable European Union law.
  2. The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and other data protection terms have the meanings assigned to them by the GDPR.
  3. If any provision becomes invalid or unenforceable, the remaining provisions shall remain unaffected.
  4. These Data Processing Terms constitute Annex No. 1 to the Terms and Conditions of Pracoš.sk.
  5. They become effective together with the Terms and Conditions to which they are attached or on a later date specified upon publication.

SUMMARY OF PROCESSING

Controller:
The Employer whose Job Offer the Applicant responds to.

Processor:
Webian s.r.o., Dubová 426/5A, 080 05 Teriakovce, Slovak Republic, Company ID No. 52 975 380.

Data subjects:
Applicants responding to Job Offers.

Purpose:
Technical receipt, storage, management and availability of an Applicant’s Application to the Employer.

Typical personal data:
First name, surname, telephone number, email address, CV, attachments, cover message and Application information.

Maximum storage period within Pracoš.sk:
24 months from submission of the Application.

After expiry:
Identifying information is deleted; CVs and attachments are deleted; only irreversibly anonymised statistical information may be retained.

Sub-processors:
Providers of technical infrastructure and related services may be engaged in accordance with Article 28 GDPR.


PROCESSOR

Webian s.r.o.
Dubová 426/5A
080 05 Teriakovce
Slovak Republic

Company ID No.: 52 975 380
Commercial Register of the District Court Prešov
Section: Sro
Insert No.: 53615/P

Email: [ADD CONTACT EMAIL]

Last updated: 6 October 2026