Section 1
Introduction
Incentivai Inc. (operating as StarlixAI) acts as the Processor, while the customer is the Controller. The agreement governs transfer and processing of personal data per GDPR requirements.
Section 2
Purpose
The Controller entrusts the Processor with personal data handling on terms set out in this Agreement and applicable regulations pertaining to the processing of personal data — in particular Regulation (EU) 2016/679. Details appear in Schedule 1.
Section 3
Representations of the Processor
The Processor confirms it has implemented technical and organisational measures ensuring the processing of the Personal Data in accordance with applicable regulations and possesses the necessary expertise.
Section 4
Processing Personal Data
Subsections cover general rules, authorization requirements, and sub-processor engagement. The Processor must process data per Controller instructions, maintain processing records, assist with data subject rights requests, and ensure staff confidentiality.
Section 5
Personal Data Security
Requirements include technical and organisational measures which are appropriate to the threats and nature, scope, context and purposes of processing. Notification of breaches must occur not later than within 48 (forty eight) hours of detection.
Section 6
Right of Control
Controllers may conduct — directly or via an auditor — audits, including inspections, with 14 days' notice, once annually.
Section 7
Termination
Upon termination, the Processor must delete all Personal Data or return carriers containing it.
Section 8
Notices
Correspondence occurs via email or registered mail in English.
Section 9
Final Provisions
Governed by Polish law; disputes resolved through negotiation then court proceedings.
Schedule 1 — Personal Data
Specifies data types (names, emails, IP addresses), subject categories (business partners, users), processing scope, and purpose (service provision).