Data Processing Addendum (Controller → Processor)

This Data Processing Addendum (“DPA”) forms part of the agreement between the applicable business customer identified in an order or master agreement (“Customer” or Controller) and TIMONIX DOO, Carkovacka 30v, 34206 Donja Sabanta, Serbia, operating AdCast Digital Signage (“TIMONIX DOO” or Processor).
Effective date: 2026-09-11
Last updated:

1. Definitions

  • Applicable Data Protection Law: laws on privacy/data protection, including EU GDPR and UK GDPR.
  • EU GDPR: Regulation (EU) 2016/679.

    EU/EEA Representative (Art. 27)

    Aleksandar Milenkovic
    Piazza Giuditta Tavani Arquati 119
    00153 Rome, Italy
    gdpr@timonix.com

    TIMONIX DOO has appointed Aleksandar Milenkovic as its representative in the European Union pursuant to Article 27 GDPR. EU/EEA data subjects and supervisory authorities may also use the GDPR request form.

  • UK GDPR: EU GDPR as retained in UK law.
  • Personal Data: information relating to an identified or identifiable natural person processed under the Agreement.
  • Process/Processing: as defined by GDPR. • Sub-processor: any processor engaged by TIMONIX DOO.
  • Customer Personal Data: Personal Data for which Customer is Controller and which TIMONIX DOO Processes on Customer’s behalf.
  • Services: AdCast services under the Agreement (e.g., AdCast Player, dashboards, APIs, support).

2. Scope and Roles

(a) For Processing of Customer Personal Data, Customer is Controller and TIMONIX DOO is Processor.

(b) This DPA does not apply where TIMONIX DOO acts as an independent controller, including for its website, account administration, billing, support, security, marketing, and product analytics/telemetry. That processing is covered in the Privacy Policy.

3. Customer Instructions

(a) TIMONIX DOO shall Process Customer Personal Data only on documented instructions from Customer, including regarding international transfers, unless required by law (in which case TIMONIX DOO will inform Customer unless prohibited).

(b) Customer instructs TIMONIX DOO to Process Customer Personal Data as needed to provide the Services, manage security, provide support/maintenance, and comply with law, as described in Annex I(B).

(c) Customer is responsible for the lawfulness of its instructions and will not instruct TIMONIX DOO to act unlawfully.

4. Confidentiality

TIMONIX DOO ensures persons authorized to Process Customer Personal Data are under appropriate confidentiality obligations (contractual/statutory).

5. Security

(a) TIMONIX DOO implements and maintains appropriate technical and organizational measures (TOMs) considering the state of the art, costs, nature and purposes of Processing, and risk to data subjects; see Annex II.

(b) Customer is responsible for measures under its control (e.g., user access, secure configuration, optional customer-side encryption).

6. Sub-processors

(a) Authorization: Customer gives general authorization for TIMONIX DOO to engage Sub-processors. Current Sub-processors: Annex III.

(b) New Sub-processors & Notice: TIMONIX DOO will provide prior notice of intended changes to Sub-processors, allowing Customer to object on reasonable data-protection grounds. If unresolved, Customer may terminate the affected Services as sole remedy.

(c) Flow-down: TIMONIX DOO imposes obligations on Sub-processors no less protective than this DPA.

(d) Liability: TIMONIX DOO remains responsible for Sub-processors’ performance of their data-protection obligations.

7. Assistance; DPIAs; Audits

(a) Data Subject Requests: Taking account of Processing, TIMONIX DOO assists Customer by appropriate measures to fulfil requests under law; if TIMONIX DOO receives a request directly, it will forward it to Customer unless legally prohibited.

(b) DPIAs & Prior Consultation: TIMONIX DOO provides reasonable cooperation for Customer’s DPIAs/prior consultations given the nature of Processing and information available to TIMONIX DOO.

(c) Audits: TIMONIX DOO makes available information to demonstrate compliance and allows reasonable audits once per 12 months (except after a Security Incident or as required by a regulator). Audits require 30-day notice, normal business hours, minimal disruption, confidentiality, and first rely on third-party reports or certifications before any on-site visit. Customer bears costs unless a material breach is found.

8. Personal Data Breach Notification

TIMONIX DOO will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, including known details, likely consequences, measures taken or proposed, and a contact point, followed by updates as information emerges.

9. Return and Deletion

Upon termination or expiry of the Services, and at Customer’s choice, TIMONIX DOO will return or delete Customer Personal Data, unless applicable law requires retention. The timing and treatment of residual copies and backups are subject to the applicable agreement, documented operational procedures, and applicable law.

10. International Data Transfers

(a) TIMONIX DOO may transfer and Process Customer Personal Data outside the EEA/UK as necessary to provide the Services, subject to Chapter V safeguards.

(b) For EEA→third country transfers without adequacy, the parties rely on the EU SCCs (2021/914) Module 2 (Controller→Processor) as set out in Annex I. For UK transfers, the UK International Data Transfer Addendum applies.

(c) Where applicable, TIMONIX DOO may rely on another valid transfer mechanism in addition to SCCs.

11. Liability and Conflict

(a) Each party’s aggregate liability under this DPA is limited by the Agreement’s liability terms.

(b) In case of conflict: this DPA prevails over the Agreement for data-protection matters; the SCCs/UK Addendum prevail over this DPA where applicable.

12. Miscellaneous

This DPA is governed by the Agreement’s law, except the SCCs/UK Addendum require their own governing law/jurisdiction as selected therein. If any provision is invalid, the remainder remains effective. Electronic execution is permitted.

Annex I - SCC Appendix (Art. 28(3) Details)

A. List of Parties

  • Data Exporter (Controller): Customer (per Agreement). Contact: as provided in Order/Agreement.
  • Data Importer (Processor): TIMONIX DOO, Serbia, operating AdCast Digital Signage. Contact: privacy@adcast.app.

B. Description of Processing/Transfer

  • Subject matter: Provision of AdCast Digital Signage services, including AdCast Player, dashboards, APIs, support, hosting, and service operation.
  • Duration: Term of the Agreement and any period necessary for return or deletion, subject to applicable law and the parties’ documented arrangements.
  • Nature & purpose: Processing necessary to provide, secure, support, and maintain the Services.
  • Data subjects: Customer-authorized users, Customer personnel, and display/device operators, to the extent their Personal Data is processed through the Services.
  • Categories of data: Customer Personal Data submitted to or generated through use of the Services, including authorized-user account and support information and device or display information where processed. Customer must not submit special categories of data unless expressly agreed and subject to appropriate safeguards.
  • Sensitive data: Not intended. If special categories are expressly agreed, appropriate safeguards apply.
  • Frequency: Continuous/as needed.
  • Retention: Per Section 9 and Annex II.
  • Supervisory authority: Authority of the exporter’s main establishment (or representative’s Member State).

C. SCC Clause Selections (Module 2)

  • Clause 7 (Docking): Enabled.
  • Clause 9 (Sub-processors): General authorization with notice/objection per Section 6.
  • Clause 11 (Redress): Not applicable.
  • Clause 17 (Governing law): Ireland.
  • Clause 18 (Forum/jurisdiction): The courts of Ireland.

The full text of the EU SCCs (2021/914) Module 2 and the UK Addendum are incorporated by reference. A countersigned copy can be provided on request.

Annex II - Technical & Organizational Measures (TOMs)

  1. Organizational measures: access to Customer Personal Data is limited to personnel authorized to provide and support the Services and subject to confidentiality obligations.
  2. Access and security measures: TIMONIX DOO applies measures appropriate to the risks of the Processing, including measures designed to protect the confidentiality, integrity, availability, and resilience of systems used for the Services.
  3. Operational measures: TIMONIX DOO maintains procedures appropriate to the operation, support, security, and incident handling of the Services.
  4. Sub-processor management: TIMONIX DOO applies the requirements in Section 6 when engaging Sub-processors.

Annex III - Authorized Sub-processors

TIMONIX DOO maintains its current list of authorized Sub-processors and will provide it to Customer on request and notify changes as required by Section 6.

VendorPurposeTypical DataLocation/RegionSafeguard
The current authorized Sub-processor list is available from TIMONIX DOO on request and is updated through the notice process in Section 6.

Annex IV - UK Addendum (Summary)

For transfers from the UK to third countries without adequacy, the parties adopt the ICO International Data Transfer Addendum to the EU SCCs (Addendum B.1.0), incorporated by reference with the following selections:

  • Table 1 (Parties): As in Annex I(A).
  • Table 2 (Selected SCCs): EU 2021/914 Module 2.
  • Table 3 (Appendix Information): As in Annex I and Annex II of this DPA.
  • Table 4: The Addendum updates to the latest version unless otherwise agreed.
AdCast support

Skontaktuj się z nami

Masz pytania lub chcesz dowiedzieć się więcej? Napisz do nas.

We usually reply within one business dayContact support