1. Purpose and Status of This Agreement
1.1. This Data Processing Agreement ("DPA") forms part of the contractual relationship between MCTO Advisory d.o.o. ("MCTO" or "Processor") and the customer using a dedicated Cogeto Instance ("Customer" or "Controller") to the extent MCTO processes personal data on behalf of that Customer.
1.2. This DPA is intended to satisfy the requirements of Article 28(3) and Article 28(4) of Regulation (EU) 2016/679 ("GDPR") and any corresponding mandatory data-protection law applicable to the processing.
1.3. The Customer enters into this DPA by accepting it electronically, accepting the Cogeto General Terms where this DPA is incorporated, creating or using a dedicated Instance, or signing another agreement that expressly incorporates this DPA.
1.4. This DPA applies only where and to the extent:
- the Customer is a controller or processor subject to applicable data-protection law; and
- MCTO processes personal data on the Customer's behalf in connection with a Cogeto Instance.
1.5. Personal data processed by MCTO for MCTO's own account administration, security, billing relationship, legal compliance, or other independent purposes as controller is governed by the Cogeto Privacy Policy and is outside the processor relationship described in this DPA.
2. Definitions
2.1. Terms including "controller", "processor", "personal data", "processing", "data subject", "personal data breach", and "supervisory authority" have the meanings assigned to them by the GDPR.
2.2. "Customer Data" means data, files, records, content, messages, configuration, and other information processed within or through the Customer's dedicated Cogeto Instance.
2.3. "Customer Personal Data" means personal data contained in Customer Data that MCTO processes on behalf of the Customer.
2.4. "Instance" means a dedicated, single-tenant Cogeto stack provisioned for the Customer, including its dedicated application containers, database, storage volume, subdomain, and associated technical resources.
2.5. "Subprocessor" means another processor engaged by MCTO to process Customer Personal Data on behalf of the Customer.
3. Roles of the Parties
3.1. The Customer determines the purposes and essential means of processing Customer Personal Data within its Instance and acts as Controller, except where the Customer itself acts as processor for another controller.
3.2. MCTO acts as Processor and processes Customer Personal Data only to provide, host, technically operate, secure, maintain, update, and support the Cogeto Service in accordance with the Customer's documented instructions, this DPA, and applicable law.
3.3. Where the Customer is itself a processor, the term "Controller" in this DPA includes the Customer acting as processor, and the Customer represents that it is authorised by the relevant controller to appoint MCTO as a subprocessor and to give the instructions reflected in this DPA.
3.4. MVT Solutions Group d.o.o. ("MVT") provides implementation, integration, technical operation, maintenance, and related services to MCTO and acts as a Subprocessor for relevant Customer-Instance processing.
3.5. The Customer is responsible for the lawfulness of its instructions, the Customer Personal Data it chooses to process, the notices it provides to data subjects, the legal bases on which it relies, and its compliance with its own controller obligations.
4. Documented Instructions
4.1. MCTO shall process Customer Personal Data only on documented instructions from the Customer, unless processing is required by European Union or Member State law to which MCTO is subject.
4.2. The following constitute documented instructions for purposes of this DPA:
- the Cogeto General Terms;
- this DPA and its Annexes;
- configuration and actions performed by authorised Customer users through the Instance or Platform;
- support requests and written instructions submitted by authorised Customer representatives; and
- any separately signed written agreement or instruction accepted by MCTO.
4.3. If MCTO is required by applicable law to process Customer Personal Data other than on the Customer's instructions, MCTO shall inform the Customer of that legal requirement before processing unless the law prohibits such information on important grounds of public interest.
4.4. MCTO shall inform the Customer without undue delay if, in MCTO's reasonable opinion, an instruction infringes the GDPR or other applicable Union or Member State data-protection law. MCTO may suspend the affected processing until the parties resolve the issue.
4.5. MCTO is not required to follow an instruction that would require MCTO to violate law, compromise the security of Cogeto or another customer, or materially alter the Service outside the agreed scope without a separate written agreement.
5. Nature and Scope of the Processing
5.1. The subject matter, duration, nature, purposes, data-subject categories, and personal-data categories are described in Annex II — Description of Processing.
5.2. Cogeto uses a dedicated single-tenant architecture. Each Customer Instance is provisioned with dedicated application containers, database, storage volume, subdomain, and TLS certificate.
5.3. MCTO does not routinely inspect or monitor the contents of Customer databases and does not maintain the Customer's ordinary in-Instance login credentials.
5.4. Processing by MCTO is principally technical and infrastructure-oriented. Customer Personal Data may nevertheless be technically stored, transmitted, backed up, secured, or otherwise processed as necessary to operate the Instance.
5.5. Exceptional human access to Customer Personal Data may occur only where reasonably necessary and legally permitted, including:
- investigation or containment of a security incident;
- serious technical diagnosis that cannot reasonably be performed without such access;
- response to suspected compromise, malware, abuse, or unlawful activity;
- compliance with a binding legal obligation or lawful request of a competent authority;
- protection of the Service, customers, third parties, or infrastructure from material harm; or
- an express Customer request or authorisation.
5.6. Any exceptional access shall be limited to personnel who need the access, limited to the minimum scope reasonably necessary, and subject to confidentiality and security obligations.
6. Confidentiality and Personnel
6.1. MCTO shall ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, whether contractual or statutory.
6.2. Access shall be limited to personnel and authorised contractors who require it for the relevant technical, security, legal, or support purpose.
6.3. MCTO shall maintain appropriate access-control practices and shall revoke or adjust access when it is no longer reasonably required.
6.4. Confidentiality obligations continue after the relevant person's employment, engagement, or access ends.
7. Security of Processing
7.1. Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the risks to data subjects, MCTO shall implement appropriate technical and organisational measures designed to provide a level of security appropriate to the risk in accordance with Article 32 GDPR.
7.2. The technical and organisational measures currently applicable to Cogeto are described in Annex III — Technical and Organisational Measures.
7.3. MCTO may update security measures over time to reflect changes in technology, architecture, threat conditions, suppliers, or law, provided that the overall level of protection is not materially reduced without a valid reason.
7.4. The Customer acknowledges that security is a shared responsibility. The Customer remains responsible for:
- its in-Instance users and credentials;
- account and role administration under its control;
- lawful configuration of the application;
- the personal data it chooses to process;
- endpoint and device security under its control; and
- maintaining any independent records or exports required by its legal or operational obligations.
8. Special Categories of Data and High-Risk Processing
8.1. Cogeto is a general-purpose service and MCTO does not determine which categories of personal data the Customer chooses to place inside its Instance.
8.2. If the Customer processes special categories of personal data under Article 9 GDPR, personal data relating to criminal convictions and offences under Article 10 GDPR, or other data subject to heightened legal protection, the Customer is responsible for ensuring that:
- the processing is lawful;
- an appropriate legal basis and, where required, an Article 9 condition applies;
- required transparency information has been provided;
- any required data-protection impact assessment or prior consultation has been completed; and
- appropriate access, security, retention, and minimisation controls are implemented.
8.3. The Customer shall not instruct MCTO to process data in a manner that is unlawful or incompatible with the agreed Service.
8.4. Nothing in this Section authorises unlawful content or use prohibited by the Cogeto General Terms.
9. Subprocessors
9.1. General Authorisation
The Customer gives MCTO general written authorisation to engage the Subprocessors listed in Annex IV — Approved Subprocessors and to replace or add Subprocessors in accordance with this Section.
9.2. Subprocessor Obligations
Before a Subprocessor processes Customer Personal Data, MCTO shall enter into a written arrangement imposing data-protection obligations that are no less protective in substance than those required by Article 28 GDPR for the relevant processing.
9.3. Responsibility
MCTO remains responsible to the Customer for the performance of a Subprocessor's data-protection obligations to the extent required by Article 28(4) GDPR.
9.4. Changes to Subprocessors
MCTO shall provide notice of an intended material addition or replacement of a Subprocessor that will process Customer Personal Data, normally at least 15 days before the change takes effect where reasonably practicable.
The Customer may object during that period on reasonable and documented data-protection grounds directly related to the proposed Subprocessor.
9.5. Objections
If the Customer makes a valid objection, the parties shall attempt in good faith to resolve it. MCTO may, at its discretion:
- provide additional information or safeguards;
- use a commercially reasonable alternative where available;
- allow the Customer to discontinue the affected feature; or
- terminate the affected Service if no reasonable alternative is available.
MCTO is not required to continue using a legacy supplier or maintain a technically or commercially unreasonable alternative solely because of a Customer objection.
9.6. Emergency Changes
Where an immediate Subprocessor change is necessary for security, continuity, legal compliance, or another urgent reason, MCTO may implement the change without the ordinary notice period and shall notify the Customer as soon as reasonably practicable.
10. International Transfers
10.1. MCTO shall not transfer Customer Personal Data to a third country or international organisation except:
- on documented instructions from the Customer;
- as necessary to provide the Service using an authorised Subprocessor; or
- where required by applicable law,
and in each case in compliance with Chapter V GDPR where applicable.
10.2. Cogeto's core hosting is operated in European OVHcloud infrastructure.
10.3. Cogeto configures Mailgun/Sinch Email to use its European processing region for Customer-Instance message data. The Customer acknowledges that global service providers may process limited account, support, security, or operational data through group entities or subprocessors in accordance with applicable transfer mechanisms.
10.4. Where a transfer requires safeguards under Article 46 GDPR, MCTO or the relevant Subprocessor may rely on European Commission Standard Contractual Clauses or another valid transfer mechanism, together with supplementary measures where appropriate.
10.5. On reasonable request, MCTO shall provide information available to it concerning the applicable transfer mechanism, subject to confidentiality and supplier restrictions.
11. Data Subject Requests
11.1. Taking into account the nature of processing, MCTO shall assist the Customer by appropriate technical and organisational measures, insofar as reasonably possible, with the Customer's obligation to respond to requests by data subjects exercising rights under Chapter III GDPR.
11.2. If MCTO receives a request directly from a data subject relating to Customer Personal Data for which the Customer is Controller, MCTO shall not substantively respond on the Customer's behalf unless authorised or legally required to do so.
11.3. MCTO shall, where reasonably identifiable, forward the request to the Customer or direct the requester to the Customer.
11.4. Because the Customer administers its dedicated Instance and MCTO does not routinely hold the Customer's in-Instance credentials or inspect the Customer database, assistance may consist of technical guidance, infrastructure-level action, or other measures reasonably available to MCTO rather than direct manipulation of individual records.
11.5. MCTO may charge reasonable fees for substantial assistance that exceeds the ordinary Service scope and is not required because of MCTO's breach, to the extent permitted by law and agreed contractual terms.
12. Assistance With Compliance Obligations
12.1. Taking into account the nature of processing and information available to MCTO, MCTO shall provide reasonable assistance to the Customer with obligations under Articles 32 to 36 GDPR, including where applicable:
- security of processing;
- personal data breach assessment and notification;
- data-protection impact assessments; and
- prior consultation with a supervisory authority.
12.2. MCTO's assistance does not transfer the Customer's controller responsibilities to MCTO.
12.3. Where a request requires extensive custom work, legal analysis specific to the Customer, development, forensic investigation, or resources outside the ordinary Service, the parties may agree reasonable fees and scope, except where MCTO is required to provide the assistance without additional charge because of MCTO's own breach or mandatory law.
13. Personal Data Breaches
13.1. MCTO shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data processed by MCTO.
13.2. To the extent information is available, the notification shall include information reasonably necessary for the Customer to meet applicable obligations under Articles 33 and 34 GDPR, such as:
- the nature of the breach;
- categories of affected data or data subjects where known;
- likely consequences where reasonably assessable;
- measures taken or proposed to address or mitigate the breach; and
- an appropriate contact point for follow-up.
13.3. Where all information cannot be provided at once, MCTO may provide information in phases without undue further delay.
13.4. Notification of a security event does not constitute an admission of fault or liability.
13.5. The Customer is responsible for determining whether it must notify a supervisory authority or affected data subjects, unless applicable law assigns that obligation directly to MCTO.
14. Records and Demonstration of Compliance
14.1. MCTO shall make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR, subject to reasonable confidentiality, security, and trade-secret protections.
14.2. MCTO may satisfy information requests by providing relevant policies, summaries, security documentation, supplier information, questionnaires, certifications, audit reports, or other appropriate evidence available to it.
14.3. The Customer shall not require disclosure of information that would compromise the security or confidentiality of another customer, MCTO, a Subprocessor, or the Cogeto Service.
15. Audits and Inspections
15.1. Subject to Article 28 GDPR, the Customer may audit MCTO's compliance with this DPA at reasonable intervals.
15.2. The parties shall ordinarily use a remote, document-based audit or independent third-party assurance material before requesting an on-site inspection.
15.3. An on-site audit may be requested where:
- reasonably necessary to satisfy a legal obligation that cannot be met through available documentation;
- a competent supervisory authority requires it; or
- there is credible evidence of a material breach of this DPA that cannot reasonably be investigated remotely.
15.4. Unless prohibited by law or inappropriate because of an urgent incident, the Customer shall provide at least 30 days' written notice of an on-site audit.
15.5. Audits shall:
- occur during normal business hours;
- avoid unreasonable interference with MCTO's operations;
- comply with MCTO's reasonable security and confidentiality requirements;
- be limited to systems and information relevant to the Customer's processing; and
- be conducted no more than once in any 12-month period unless required by a supervisory authority or justified by a material suspected breach.
15.6. The Customer bears its own audit costs and shall reimburse MCTO's reasonable costs for extraordinary audit support, except where the audit establishes a material breach of this DPA by MCTO or applicable law requires otherwise.
15.7. An independent auditor must not be a competitor of MCTO and must be bound by appropriate confidentiality obligations.
16. Return and Deletion of Customer Personal Data
16.1. The Customer controls the active content of its Instance and is responsible for exporting or otherwise retaining Customer Data it wishes to keep before deleting an Instance or ending the Service.
16.2. When an Instance is deleted, its active containers, database, storage volume, and active Customer Data are deleted as part of the Instance-deletion process.
16.3. Restricted technical backup copies may remain for up to 30 days after Instance deletion solely for internal technical, resilience, security, or disaster-recovery purposes.
16.4. Backup copies retained under Section 16.3:
- are not available to the Customer for restoration, retrieval, export, or archive access;
- are not treated as an active copy of the Instance;
- remain protected under this DPA while retained; and
- are deleted or overwritten according to the technical retention process after the applicable period.
16.5. MCTO is not required to reconstruct a deleted Instance from technical backups.
16.6. If European Union or Member State law requires MCTO to retain specific Customer Personal Data longer, MCTO may retain only the data and for the period legally required and shall restrict further processing except as required by law.
16.7. Where the Customer requests return of data, the Customer must use available export or application functionality before deletion unless the parties separately agree in writing on another technically feasible method.
17. Unlawful Instructions and Prohibited Use
17.1. The Customer shall not use the Service to process unlawful content or instruct MCTO to process Customer Personal Data unlawfully.
17.2. If MCTO receives credible information indicating that Customer Data or processing may be unlawful, MCTO may take proportionate steps permitted by law and the General Terms, including requesting clarification, preserving relevant evidence where lawfully required, restricting processing, suspending the Instance, or cooperating with competent authorities.
17.3. MCTO is not required to proactively monitor private Customer databases for unlawful content.
18. Liability
18.1. Each party remains responsible for its own compliance with applicable data-protection law.
18.2. Nothing in this DPA restricts rights or remedies of data subjects or supervisory authorities that cannot lawfully be restricted by contract.
18.3. As between MCTO and the Customer, contractual liability relating to this DPA is subject to the applicable limitation-of-liability provisions in the Cogeto General Terms or another separately signed agreement, except to the extent such limitation is prohibited by mandatory law.
18.4. The Customer is responsible for claims, losses, or regulatory consequences caused by the Customer's unlawful instructions, absence of a lawful basis, failure to provide required notices, or Customer-controlled processing, subject to applicable law and any contractual allocation of liability.
19. Term and Termination
19.1. This DPA begins when the Customer first becomes subject to it and remains in force for as long as MCTO processes Customer Personal Data on the Customer's behalf.
19.2. Termination of the Cogeto Service ends this DPA after MCTO completes the deletion or legally required retention of Customer Personal Data under Section 16.
19.3. Confidentiality, deletion, audit, liability, and other provisions intended by their nature to survive continue for as long as relevant Customer Personal Data remains in MCTO's possession or control.
20. Order of Precedence
20.1. If this DPA conflicts with the Cogeto General Terms regarding protection of Customer Personal Data, this DPA prevails for that data-protection issue.
20.2. A separately signed data-processing agreement prevails over this DPA only to the extent it expressly states that it replaces or modifies this DPA.
20.3. A separately signed SLA does not modify this DPA unless the SLA expressly states a data-protection modification and that modification complies with applicable law.
21. Governing Law and Disputes
21.1. This DPA is governed by Croatian law, without prejudice to directly applicable GDPR provisions and mandatory data-protection law.
21.2. For Business Customers, disputes concerning this DPA are subject to the negotiation, mediation, and HGK arbitration provisions in the Cogeto General Terms unless the parties separately agree otherwise in writing.
21.3. Nothing in this Section limits the powers of a competent supervisory authority, rights of data subjects, or mandatory jurisdiction rules that apply by law.
Annex I — Parties
A. Controller
The Customer identified by the Cogeto Account, applicable order, commercial record, or separately signed agreement that uses a dedicated Cogeto Instance and accepts this DPA.
Role: Controller of Customer Personal Data processed within the Customer's Instance, or processor where the Customer acts on behalf of another controller.
Contact: The administrator or other contact designated in the Customer's Cogeto Account or separate agreement.
B. Processor
MCTO Advisory d.o.o.
Bregana Pisarovinska 37
10451 Bregana Pisarovinska
Croatia
Office: Radnička cesta 34, 10000 Zagreb, Croatia
VAT ID / OIB: HR74348605691
Email: legal@cogeto.eu
Role: Processor providing the Cogeto Service.
Annex II — Description of Processing
1. Subject Matter
Hosting, provisioning, technical operation, maintenance, updating, security, backup, email delivery, and related technical processing necessary to provide the Customer's dedicated Cogeto Instance.
2. Duration
For the duration of the Customer's use of the relevant Instance and for the limited deletion/backup period described in this DPA, subject to any legally required retention.
3. Nature of Processing
Depending on Customer use and technical operation, processing may include:
- receiving;
- transmitting;
- hosting;
- storing;
- structuring;
- organising;
- retrieving by the application at the Customer's request;
- making available to authorised Customer users;
- encrypting in transit;
- backing up for technical purposes;
- deleting;
- restricting;
- securing;
- logging technical/security events; and
- exceptional access where permitted under Section 5.5.
4. Purpose
To provide and technically operate the Cogeto Service according to the Customer's instructions and contractual configuration.
5. Categories of Data Subjects
The categories are determined by the Customer and may include, depending on the Customer's use of its Instance:
- Customer personnel;
- workers and contractors;
- customers and prospective customers of the Customer;
- suppliers and business contacts;
- users of the Customer's services;
- individuals communicating with the Customer; and
- any other persons whose data the Customer lawfully chooses to process through its Instance.
6. Categories of Personal Data
The categories are determined by the Customer and may include:
- names and identifiers;
- contact information;
- account and user data;
- business and professional information;
- communications;
- records and documents uploaded by the Customer;
- transactional or operational information;
- technical data;
- email message and delivery information; and
- other personal data lawfully entered or generated by the Customer through the Instance.
7. Special Categories
Special categories under Article 9 GDPR and data under Article 10 GDPR may be processed only where the Customer chooses to process them and has a lawful basis and appropriate safeguards. MCTO does not require such data as part of ordinary Cogeto platform administration.
8. Processing Frequency
Continuous or as initiated by the Customer while the Instance is running, together with automated technical processing necessary to maintain the Service.
Annex III — Technical and Organisational Measures
MCTO maintains measures appropriate to the Cogeto architecture and may evolve those measures over time without materially reducing the overall level of protection.
1. Tenant Isolation
- Dedicated single-tenant stack per Customer Instance.
- Dedicated application containers per Instance.
- Dedicated database per Instance.
- Dedicated storage volume per Instance.
- Dedicated Instance subdomain.
- Separate TLS certificate for each provisioned Instance.
2. Transport Security
- TLS/HTTPS used for supported web access and encrypted transport.
- Certificates are provisioned and maintained for Instance endpoints.
- Administrative network access is restricted according to operational need.
3. Identity and Access Management
- Platform identity is handled through a self-hosted identity-management service.
- Email verification is used for Platform registration.
- Role-based Platform permissions include administrator and user roles.
- Privileged technical access is restricted to authorised personnel and contractors with a need to know.
- MCTO does not ordinarily possess the Customer's in-Instance user credentials.
4. Data Access Minimisation
- MCTO and MVT do not routinely inspect Customer database contents.
- Ordinary Customer activity inside the Instance is not centrally retained as a general platform activity history.
- Exceptional access is limited to the circumstances set out in the DPA and General Terms.
- Personnel with exceptional access are subject to confidentiality obligations.
5. Audit and Security Logging
- Platform audit records are append-only.
- Audit records are hash-chained to support integrity and tamper evidence.
- Audit rows use internal user identifiers rather than names or email addresses.
- IP information written to Cogeto audit records is truncated at write time:
- IPv4 to
/24; - IPv6 to
/48.
- IPv4 to
- Full IP addresses are not intentionally stored in those Cogeto audit rows.
6. Infrastructure Security and Maintenance
- Infrastructure is hosted in European OVHcloud Public Cloud facilities/services.
- Operating components, infrastructure, and application components are maintained and updated as reasonably necessary.
- Security patches and infrastructure updates may be deployed by MCTO and/or authorised MVT technical personnel.
- Technical resource controls and isolation mechanisms are used to protect platform stability and tenant separation.
7. Email Separation
- Cogeto Platform/provisioning email and Customer-Instance outbound email use separate technical configurations.
- Instance email data is associated with the relevant Customer Instance.
- Mailgun/Sinch Email is configured to use its European processing region for message data.
8. Backup and Deletion Controls
- Active Instance deletion destroys the active containers, database, and storage volume associated with that Instance.
- Restricted technical backup copies may persist for up to 30 days following Instance deletion.
- Such backups are retained only for technical, resilience, security, or disaster-recovery purposes.
- Customer restoration or retrieval from post-deletion backups is not offered.
- Backup copies are deleted or overwritten under the technical retention process after the applicable period, unless retention is required by law.
9. Incident Management
- Security events may be investigated by authorised personnel.
- MCTO maintains processes for escalation, containment, remediation, and communication of material personal data breaches.
- Where Customer Personal Data is affected, Controller notification is made without undue delay after MCTO becomes aware of the relevant personal data breach.
10. Confidentiality and Organisational Controls
- Persons authorised to perform relevant technical operations are bound by confidentiality obligations.
- Access is limited according to operational role and necessity.
- MCTO uses contractual data-protection obligations with Subprocessors as required by Article 28 GDPR.
Annex IV — Approved Subprocessors
The Customer gives general authorisation for the following Subprocessors.
| Subprocessor | Location / relevant processing region | Function | Customer Personal Data potentially processed |
|---|---|---|---|
| MVT Solutions Group d.o.o., Podolje 11A, 10000 Zagreb, Croatia, VAT ID / OIB HR85300439344 | Croatia / EU | Implementation, integration, technical operation, maintenance, infrastructure administration | Customer Personal Data only where technically necessary for authorised operations or exceptional access |
| OVH SAS, 2 rue Kellermann, 59100 Roubaix, France | European Union | Cloud hosting, compute, network, block storage | Customer Instance data stored or transmitted through hosted infrastructure |
| Mailgun / Sinch Email — relevant contracting entity identified in MCTO's applicable Service Order | European processing region configured by Cogeto | Outbound transactional/application email | Sender, recipient, message content, routing, delivery, suppression, event and related technical data necessary for email delivery |
Notes on Other Providers
Paddle is not listed as a Customer-Instance Subprocessor because Paddle's Merchant-of-Record role concerns the purchase of Cogeto Credits and payment/buyer data rather than processing of the Customer's in-Instance database on behalf of the Customer. Paddle's processing is described in the Cogeto Privacy Policy and Paddle's own buyer/privacy terms.
Cogeto identity management is self-hosted and is therefore not listed as an external identity-provider Subprocessor.
Processor contact: legal@cogeto.eu
MCTO Advisory d.o.o.
Bregana Pisarovinska 37, 10451 Bregana Pisarovinska, Croatia