Version 1.0, in force from 10.10.2026 · SHA-256 c81a26619aa068b3deb180bc852a1ef73811f37bf0f9515d15ab209af851e7a1 · text for checking the checksum
postaX — DPA

ADDENDUM NO. ___

to the Service Agreement No. ______ dated «___» ___________ 20___

(Data Processing Addendum — DPA)

Chișinău, Republic of Moldova «___» ___________ 20___

The company _______________, a legal entity registered under the laws of the Republic of Moldova, under state identification number (IDNO) ________________, represented by _____________________, acting on the basis of _____________________, hereinafter referred to as the "Controller" (or "Client"), on the one part,

and

SRL «APB COPR», a legal entity established and operating under the laws of the Republic of Moldova, registered under state identification number (IDNO) 1020600014501, represented by its Administrator acting on the basis of the Articles of Association, hereinafter referred to as the "Processor" (or "Service Provider" / "postaX Provider"), on the other part,

collectively referred to as the "Parties," and individually as a "Party," guided by the provisions of Law of the Republic of Moldova No. 195/2024 "On the Protection of Personal Data" (in particular, Article 28), for the purpose of complying with data protection legislation in connection with the performance of principal obligations under Service Agreement No. ______ dated «___» ___________ 20___ (hereinafter the "Principal Agreement"), have entered into this Data Processing Addendum (hereinafter the "Addendum" or "DPA") as follows.

1. Subject matter and roles of the parties

1.1. This Addendum sets out the terms, procedures, and technical and organisational security measures for the processing of personal data by the Processor on behalf of, upon the instruction of, and in accordance with the documented instructions of the Controller, in connection with the provision of cloud email hosting services under the postaX platform under the Controller's domain names pursuant to the Principal Agreement.

1.2. The Parties acknowledge and agree that, for the purposes of this Addendum and the laws of the Republic of Moldova (including Law No. 195/2024 and CNPDCP letter No. 02/2-05/2819 dated 30.07.2026):

a) The Client acts as the Controller (Operator / Controlor de date), determining the purposes and means of processing personal data of its employees, representatives, and correspondents;

b) The Service Provider (SRL «APB COPR») acts as the Processor (Persoană împuternicită de operator), performing technical processing of personal data (reception, routing, storage of messages, and security) exclusively on behalf of and upon instruction from the Controller.

1.3. This Addendum forms an integral part of the Principal Agreement. In the event of a conflict between the provisions of the Principal Agreement and this Addendum with respect to personal data protection and confidentiality, the terms of this DPA shall prevail.

2. Categories of data and data subjects. Nature of processing

2.1. The nature, purposes, list of personal data, and categories of data subjects processed under this Addendum are determined by the Parties in the Processing Specification (Annex No. 1 to this Addendum), which forms an integral part hereof.

2.2. The Processor undertakes to perform only those operations (actions) with the Controller's personal data that are directly necessary for the performance of its obligations under the Principal Agreement, including collection, recording, systematisation, storage, transmission via encrypted communication channels, structuring, blocking or destruction, and only within the scope of instructions provided by the Controller.

3. Obligations of the Processor

3.1. The Processor, when processing personal data, undertakes to:

  1. process personal data solely on the basis of the Controller's documented instructions, including with regard to the cross-border transfer of personal data. If the Processor is required by the laws of the Republic of Moldova to process data on other grounds, it shall immediately notify the Controller prior to commencing such processing, unless the law prohibits such notification on important grounds of public interest;
  2. ensure that persons authorised by it to process personal data (including permanent and engaged employees) have committed to confidentiality or are subject to an appropriate statutory obligation of non-disclosure regarding confidential information and personal data (execution of NDA, compliance with job descriptions);
  3. implement all necessary organisational, legal, and technical measures required by Article 32 of Law No. 195/2024 to ensure an adequate level of security for personal data commensurate with the risks of processing, including protection against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data;
  4. not engage other processors (subcontractors / sub-processors) in the processing of personal data without the prior written consent of the Controller (specific or general). In the event of general consent, the Processor undertakes to inform the Controller of any planned changes concerning the addition or replacement of other processors at least 10 (ten) calendar days in advance, giving the Controller the right to object to such changes and to block the engagement of a new subcontractor;
  5. where a subcontractor (sub-processor) is engaged with the Controller's consent, impose upon such subcontractor the same data protection obligations as are imposed on the Processor under this Addendum, by means of a written contract or addendum (DPA). The Processor shall bear full liability to the Controller for the failure of engaged subcontractors to fulfil their personal data protection obligations;
  6. assist the Controller, to the extent possible, by appropriate technical and organisational measures, in fulfilling the Controller's obligations to respond to requests by data subjects for the exercise of their rights under Articles 12–22 of Law No. 195/2024 (including the right of access, rectification, erasure of data, restriction of processing, and data portability);
  7. assist the Controller in ensuring compliance with the obligations set out in Articles 32–36 of Law No. 195/2024 (including ensuring the security of processing, conducting data protection impact assessments (DPIA), and prior consultations with the National Centre for Personal Data Protection — CNPDCP), taking into account the nature of processing and the information available to the Processor;
  8. notify the Controller immediately, but in any event no later than 24 (twenty-four) hours from the moment of discovery, by email, of any security incidents (data breaches, unauthorised access, loss or corruption of data), providing the Controller with all information necessary for the Controller to fulfil its obligation to notify the CNPDCP and data subjects pursuant to Article 33 of Law No. 195/2024;
  9. at the Controller's choice, irreversibly delete or return to the Controller all personal data upon termination of services under the Principal Agreement, and delete all existing copies of personal data, unless applicable legislation of the Republic of Moldova requires mandatory long-term storage of such data (e.g., tax legislation, archival records, or employment records);
  10. provide the Controller, upon request, with all information necessary to demonstrate compliance with the obligations set out in Article 28 of Law No. 195/2024 and this Addendum, and to permit and assist with audits, including inspections conducted by the Controller or an independent auditor authorised by the Controller. The costs of such audits shall be borne by the Controller, unless an audit reveals a material breach of the Addendum by the Processor.

4. Obligations of the Controller

The Controller undertakes to:

  1. guarantee that the collection and transfer of personal data to the Processor is carried out on lawful grounds (in accordance with Article 6 of Law No. 195/2024) and does not infringe the rights of data subjects or the rights of third parties;
  2. provide the Processor with clear, feasible, and documented instructions regarding the processing of personal data. If, in the Processor's opinion, the Controller's instructions infringe the requirements of Law No. 195/2024 or other regulatory acts of the Republic of Moldova on data protection, the Processor shall immediately inform the Controller accordingly;
  3. respond in a timely manner to the Processor's requests relating to the engagement of subcontractors, amendments to instructions, or responses to security incidents.

5. Security of data processing

5.1. The Processor warrants the implementation of technical and organisational security measures, including:

6. Cross-border transfer of data

6.1. The Processor shall not carry out cross-border transfers of personal data received from the Controller without the Controller's prior written consent.

6.2. The Parties agree that the transfer of personal data to countries ensuring an adequate level of personal data protection (including countries of the European Economic Area (EEA)) is carried out freely in accordance with Article 44(2) of Law No. 195/2024. The transfer of data to other countries (including the USA, the Russian Federation, and China) is only permissible with CNPDCP authorisation or upon execution of Standard Contractual Clauses (SCCs) under the Controller's supervision.

7. Term of the addendum and liability

7.1. This Addendum enters into force upon signing and remains in effect for the entire duration of the Principal Agreement or until the final deletion or return of the Controller's personal data by the Processor.

7.2. The Processor bears full material and legal liability for direct actual damage caused to the Controller as a result of unlawful actions by the Processor or its employees in breach of this Addendum, as well as for fines imposed on the Controller by the CNPDCP due to the Processor's fault. The aggregate liability of the Parties under this Addendum is limited to the amount equivalent to the value of services under the Principal Agreement for the preceding 12 (twelve) months.

8. Legal addresses, details and signatures of the parties

CONTROLLER (CLIENT)
SRL «APB COPR»
IDNO: 1020600014501
Address: Republic of Moldova, mun. Chișinău, MD-2052, sec. Ciocana, str. Ciocana 12, of. 16
Email: legal@postax.md / dpo@postax.md
__________________ / [Name Surname]
Administrator, SRL «APB COPR»
PROCESSOR (SERVICE PROVIDER)
[Name of the Service Provider / Contractor]
IDNO: [Contractor IDNO]
Address: Republic of Moldova, [Contractor Address]
Email: [Contractor Email]
__________________ / [Name of Director]
[Title of Director]

Annex No. 1 — Personal Data Processing Specification

(to Addendum No. ___ dated «___» ___________ 20___)

Processing Parameter Description and Details of Controller's Instructions
1. Nature and Subject Matter of Processing
(Характер обработки)
Technical and administrative processing of personal data in connection with the provision of email hosting services under the Principal Agreement, including server storage, system administration, and billing operations.
2. Purposes of Processing
(Цели обработки)
Ensuring proper delivery of services under the Principal Agreement, including maintaining the Controller's records, HR administration, payroll processing, IT support, storage and processing of backups.
3. Categories of Data Subjects
(Категории субъектов)
– The Controller's employees (both current and former);
– Counterparties, clients and partners of the Controller (natural persons);
– Representatives and contact persons of the Controller.
4. Categories of Personal Data
(Категории данных)
– Full name, date of birth, passport details, IDNP;
– Contact details: addresses, phone numbers, email;
– Financial data: bank details, salaries, taxes, transactions;
– HR information: length of service, positions, order data, CPAS, AOAM health insurance policies.
5. Retention Period
(Срок обработки)
Processing is carried out for the entire duration of the Principal Agreement. Upon termination of the Agreement, data shall be subject to complete deletion or return within 30 calendar days, except for archival documents subject to mandatory retention under applicable law.