This agreement is entered into under Art. 28 GDPR and forms an integral part of the Terms and Conditions. It applies automatically to every Customer from the moment the account is created, without the need for a separate signature.
Purpose of this agreement. By uploading a drawing or inviting a client into a project, the Customer determines what data enters the Platform and for what purpose. In respect of that data the Customer is the controller and the Provider is the processor. Art. 28(3) GDPR requires the relationship between controller and processor to be set out in a written contract. This agreement satisfies that requirement.
1. The parties
1.1The processor — the company operating the platform:
Layro S.R.L.
Registered office: Str. Pitar Moș nr. 27, et. 5, ap. 17, Sector 1, București, România
VAT no.: RO44254027
Trade Register: J2021008343401
Email: contact@layro.ro
1.2The controller — the Customer, as defined in the Terms: the sole trader, company, or architecture or interior design practice that creates an account on app.layro.ro and uploads data into its projects. Its identity is established by the details given on account creation and in the billing section.
2. The roles
2.1The roles differ depending on which data is at issue, and the distinction is central to this agreement:
| Category of data | Controller | Processor |
|---|---|---|
| The Customer's account data: name, email, password, plan, billing, sign-in logs | Layro | — |
| The Customer's project data: the files it uploads, project names, the names and email addresses of the Invited Clients, and their markups, comments, minutes and approvals | The Customer | Layro |
2.2For the first category, the processing is described in the Privacy Policy and this agreement does not apply.
2.3For the second category, this agreement applies. The Customer determines which files are uploaded, whom to invite and how long a project is retained; the Provider processes them solely in order to supply the Service.
2.4The Provider does not process the Customer's project data for its own purposes. It does not use it for marketing, does not sell it, does not make it available to other Customers, and does not train models on it.
2.5By way of exception to clause 2.4, the Provider remains the controller for the technical data strictly necessary to operate and secure the Platform — access logs, IP addresses, performance metrics — and for the transactional emails it sends to Invited Clients on the Customer’s behalf, to the extent that it determines their content and form.
3. Subject matter, duration, nature and purpose
3.1Subject matter — processing the personal data contained in the Customer’s projects, in order to provide the Platform under the Terms.
3.2Nature — storage, organisation, structuring, consultation, transmission to the Invited Clients, backup and deletion.
3.3Purpose — hosting project files, sending invitations and notifications, collecting markups and approvals, keeping the phase activity history.
3.4Duration — for as long as the contract between the Parties subsists, together with the retention periods in section 9.
3.5Categories of data subjects — the Clients invited into projects by the Customer, and any identifiable person appearing in the content it uploads.
3.6Types of personal data — names, email addresses, preferred language, the content of markups, comments and minutes, the author and date of approvals, and any personal data contained in the files uploaded by the Customer.
3.7The Platform is not intended for special categories of data under Art. 9 GDPR. The Customer undertakes not to upload such data.
4. The controller’s instructions
4.1The Provider processes the data only on the controller’s documented instructions. Documented instructions comprise: this agreement, the Terms, and the operations carried out by the Customer in the Platform — uploading a file, inviting a Client, deleting a project.
4.2Where a legal obligation requires processing beyond the controller’s instructions, the Provider shall inform it prior to processing, unless the law prohibits such notice on important grounds of public interest.
4.3The Provider shall inform the controller without delay if it considers that an instruction infringes the GDPR or other data protection provisions.
5. Confidentiality of personnel
5.1Access to the Customer’s project data is limited to those persons to whom it is necessary in order to provide or maintain the Service.
5.2Those people are bound by a duty of confidentiality, contractual or statutory, which survives the end of their relationship with the Provider.
6. Security measures
6.1The Provider implements the appropriate technical and organisational measures required by Art. 32 GDPR, set out in Annex 2.
6.2The measures may be updated during the contract, provided the level of security does not fall below that described in Annex 2.
7. Sub-processors
7.1The controller grants general authorisation for the use of sub-processors. The list in force is set out in Annex 3.
7.2The Provider shall notify the controller by email at least 30 days before adding or replacing a sub-processor. Within that period the controller may object on reasoned grounds. If the objection cannot be resolved, the controller may terminate the contract without penalty, with a refund of any paid and unused period.
7.3The Provider imposes on each sub-processor, by contract, data protection obligations at least equivalent to those in this agreement, and remains fully liable to the controller for their performance.
8. Assistance
8.1Data subject rights. The Platform provides the controller with the means to resolve most requests itself: viewing, amending and deleting Invited Clients’ details and project content. Where a request cannot be resolved from the Platform, the Provider shall assist so far as reasonably possible.
8.2Where a data subject approaches the Provider directly regarding data in the controller’s projects, the Provider shall not answer on the merits but shall pass the request to the controller without delay.
8.3Security incidents. The Provider shall inform the controller without undue delay after becoming aware of a breach affecting its project data, with the information available at that time, and shall provide the support needed for the notifications under Arts. 33 and 34 GDPR. The duty to notify the supervisory authority rests with the controller.
8.4Impact assessments. On request, the Provider shall furnish the information within its possession that the controller requires for a data protection impact assessment or for prior consultation with the authority.
9. Deletion and return of data
9.1The controller may export or delete its project data at any time during the contract.
9.2On termination, the data remains available for retrieval for a period of 30 days, after which it is deleted.
9.3Backups rotate automatically and disappear within 5 days of deletion from the live system. Until then they are encrypted and not accessible in day-to-day operation.
9.4The Provider may retain data beyond these periods only to the extent required by a legal obligation, in which case it retains the data solely for that purpose.
10. Audit and demonstrating compliance
10.1On the controller’s written request, the Provider shall make available the information needed to demonstrate compliance with its obligations under Art. 28 GDPR.
10.2The controller may request an audit at most once per calendar year, on 30 days’ notice, during normal working hours and without disrupting the operation of the Service. The audit may be carried out by the controller or by an independent auditor accepted by both Parties and bound by confidentiality. A further audit may be carried out where a supervisory authority requires it, or following a security incident affecting the controller’s data.
11. International transfers
11.1The controller’s project data is stored in the European Union, on Amazon Web Services infrastructure in Frankfurt, Germany.
11.2The Provider does not transfer that data outside the European Economic Area. Should a transfer become necessary, it shall take place only under an adequacy decision or the standard contractual clauses adopted by the European Commission, following an assessment of the safeguards, the controller being informed in accordance with clause 7.2.
12. Liability and duration
12.1Liability is governed by the Terms and by Art. 82 GDPR.
12.2This agreement takes effect when the account is created and ends with the Terms. The obligations in sections 5, 9 and 10 survive termination for as long as the Provider still holds data belonging to the controller.
12.3In case of conflict between this agreement and the Terms, this agreement prevails as regards the processing of the controller’s project data.
Annex 1 — Details of the processing
| Item | Description |
|---|---|
| Subject matter | Providing the Layro platform under the Terms. |
| Duration | The term of the contract, plus the periods in section 9. |
| Nature | Storage, organisation, consultation, transmission, backup, deletion. |
| Purpose | Hosting projects, inviting clients, collecting markups and approvals, keeping the phase history. |
| Categories of data subjects | Clients invited into projects; identifiable people appearing in uploaded content. |
| Types of personal data | Names, emails, language, the content of markups and comments, approvals with author and date, personal data inside uploaded files. |
| Special categories | None. The platform is not intended for Art. 9 GDPR data. |
Annex 2 — Technical and organisational measures
The measures below are those actually in place as at the date this document was last updated:
- Encryption in transit — all traffic to the platform and the API travels over HTTPS only.
- Encryption at rest — the database is encrypted; project files are encrypted in storage with keys managed through AWS KMS.
- Access control — token-based authentication with a limited lifetime; invited clients reach only the project they were invited to and never see the rest of the Customer’s portfolio.
- Data isolation — each account holder's data is logically separated; one account holder cannot reach another's projects.
- Backups — automatic, encrypted, kept for 5 days.
- Logs — application logs are kept for 14 days and used only for diagnostics and security.
- Tamper-evident history — each phase's activity history is cryptographically chained, so a retroactive change to an entry becomes detectable.
- Perimeter protection — web application traffic filtering and request rate limiting.
- Protection against accidental deletion — the database is protected against deletion; replaced file versions are removed automatically after 30 days.
- Minimisation — no behavioural analytics are used inside the application, and no session or screen recording takes place.
Annex 3 — Sub-processors
The providers below process the controller’s project data on the Provider’s behalf:
| Sub-processor | Role | Processing location |
|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg) | Hosting the application, the database and project files. | Frankfurt, Germany (EU). |
| Hostinger International Ltd. (Lithuania) | Delivering transactional email: invitations, notifications, the daily digest. These carry the project name and the recipient’s name. | European Union. |
Providers that handle only the Customer’s account data — the payment processor and the accounting service — are not sub-processors for the purposes of this agreement, as they have no access to project data. They are listed in the Privacy Policy.
Contact
For anything concerning this agreement, including audit requests or data subject rights matters, write to contact@layro.ro.