Data Processing Agreement (DPA)
Effective from January 1, 2026
This Data Processing Agreement (“DPA”) is an integral appendix to the agreement for use of the TOT Sites platform between TOT STUDIO LABS SRL (“Processor”, “TOT”) and the client company using the platform (“Controller”, “Client”). This DPA sets out the terms under which TOT processes the personal data of the Controller's end customers on its behalf and in accordance with its instructions, pursuant to Moldovan Law No. 195/2024 (replacing Law No. 133/2011, effective from August 23, 2026) and, where applicable, the GDPR.
1. Roles of the Parties
With respect to the personal data the Client collects through its website on the TOT Sites platform (data of its own end customers, visitors and clients who make bookings), the Client acts as the Data Controller: it determines the purposes and means of processing. TOT acts as the Processor: it processes data solely on the Client's documented instructions and for the purpose of providing and technically supporting the platform.
2. Subject and Duration of Processing
The subject of the processing is the storage, display and technical maintenance of data entered by the Client or its end users through the platform's features (business-card website, online booking, order acceptance, customer account, loyalty program). Processing continues for the term of the platform subscription agreement and ends as set out in Section 13.
3. Categories of Data and Data Subjects
- Data subjects: end customers, visitors and users interacting with the Client's website (booking a service, placing an order, registering a personal account, loyalty program).
- Categories of data: name, phone number, email, order and booking history, bonus points history, content of messages submitted through website forms, technical device and visit data.
- Special categories of data (health, biometric data, etc.) are not processed through the platform unless separately agreed in writing.
4. Instructions from the Controller
TOT processes data only to the extent necessary for the operation of the platform features the Client has enabled in its account, and in accordance with instructions given through the dashboard settings or in writing. If TOT believes a Client instruction violates applicable data protection law, TOT will promptly inform the Client.
5. TOT's Obligations as Processor
- Process data only on the Client's instructions and for the purposes set out in the agreement.
- Ensure confidentiality: only TOT employees and contractors who need access for their work, and who are bound by confidentiality obligations, may access the data.
- Not use the Controller's end-customer data for TOT's own marketing purposes.
- Assist the Client in fulfilling its obligations as Data Controller (Sections 8–9).
6. Sub-processors
TOT may engage sub-processors to operate the platform (hosting providers, the MAIB Business payment provider, email delivery and SMS/Telegram notification services). TOT enters into agreements with sub-processors imposing data protection obligations no lower than the level set out in this DPA.
An up-to-date list of sub-processors is provided to the Client upon request. TOT notifies the Client in advance of any change of sub-processor that could affect the nature of the processing.
7. Technical and Organizational Security Measures
- Encrypted connection (HTTPS/TLS) for all platform pages.
- Role-based access control in the dashboard and logging of user actions.
- Regular data backups and infrastructure protection against DDoS attacks.
- Isolation of different Clients' data from each other at the platform level.Isolation of different Clients' data from one another at the platform level.
- Bank card data is not stored on TOT's servers — it is processed directly by the payment provider.
8. Assistance with Data Subject Requests
If an end customer of the Controller contacts TOT directly with a request to access, correct or delete their data, TOT forwards the request to the Controller as the party responsible for the decision. TOT provides the Controller with technical tools (in the dashboard) and reasonable assistance to fulfill such requests within the statutory deadlines.
9. Security Incident Notification
In the event of a breach, unauthorized access or other security incident affecting data processed on the Controller's behalf, TOT will notify the Controller without undue delay, no later than 72 hours after becoming aware of the incident, describing the nature of the incident, the categories of data affected, and the measures taken.
10. Audit and Compliance Verification
Upon a reasonable written request, no more than once a year, TOT will provide the Controller with the information needed to verify compliance with this DPA, including a description of the security measures applied.
11. International Data Transfers
Data is stored on servers located in Moldova and EU countries. If a sub-processor outside this area is used for certain functions (e.g., email delivery), TOT ensures the application of contractual data protection safeguards equivalent to the requirements of Law No. 195/2024 (replacing Law No. 133/2011) and the GDPR.
12. Liability
Each party is liable for damages caused by a breach of its obligations under this DPA, in the manner and within the limits set out in the main platform subscription agreement and applicable law.
13. Term and Return/Deletion of Data
This DPA remains in effect for the term of the platform subscription agreement. Upon its termination, TOT provides the Controller with at least 14 days to export its data, after which the Controller's end-customer data is deleted from active systems, except where longer retention is required by law (e.g., for accounting purposes).
14. Contacts
TOT STUDIO LABS SRL
Republic of Moldova, mun. Chișinău, sec. Centru, str. Drumul Viilor
Phone: +373 7999 6927
Email: [email protected]
This DPA is concluded automatically upon activation of the TOT Sites platform and forms an integral part of the agreement between TOT and the Client. See also Privacy Policy and Terms of Use.