Skip to content
Certinuity
How it worksWorkflowsAudit registerPricing
Sign inBook a demoStart free trial→
Free trial
LEGAL

Data processing agreement

Effective date: 26 September 2026

Last updated: 26 September 2026

At a glance

This summary gives you the key points. The full agreement follows in the numbered sections and annexes below.

Question Short answer
What is this? The agreement required by Article 28 GDPR for the personal data you store in Certinuity
Who are the parties? Your organisation (the controller) and Aventruks DOOEL Skopje, which operates Certinuity (the processor)
How is it accepted? It forms part of the Terms of service and applies automatically when you accept them. A signed copy is available on request
What data does it cover? Your users, your supplier contacts, and personal data inside the documents your suppliers upload
What do we do with it? Only what is needed to provide Certinuity, on your instructions
Who else processes it? The sub-processors in Annex 3. We tell you 30 days before adding or replacing one
Breaches? We notify you without undue delay, and within 48 hours at the latest
What happens at the end? You export your data, and we delete it within the periods in section 13
Contact Martin Mihailovski, DPO - martin@aventrux.com - +389 71 333 194

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the Terms of service (the "Principal Agreement") between:

Controller: the organisation that uses Certinuity under the Principal Agreement ("Controller").

Processor: Aventruks DOOEL Skopje, Mateja Matevski 22, Skopje, North Macedonia, operator of Certinuity ("Processor").

Together the "Parties", and each a "Party".

This DPA is entered into under Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Law on Personal Data Protection of the Republic of North Macedonia (Official Gazette no. 42/2020). It sets out the terms on which the Processor processes personal data on behalf of the Controller.

The Controller accepts this DPA by accepting the Principal Agreement, for example by ticking the Terms and DPA box on the trial form. A Controller that wants a signed copy can ask for one at info@certinuity.com.

2. Definitions

2.1. "Applicable Data Protection Law" means the GDPR, the Law on Personal Data Protection of North Macedonia, the UK GDPR where it applies, and any national law implementing or supplementing them.

2.2. "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject") that the Processor processes on behalf of the Controller through the Platform.

2.3. "Processing", "Controller", "Processor" and "Supervisory Authority" have the meanings given in the GDPR.

2.4. "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

2.5. "Platform" means Certinuity, the multi-tenant software service for supplier document compliance at https://platform.certinuity.com, including the public supplier upload pages and the emails it sends.

2.6. "Sub-processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.

2.7. "Technical and Organisational Measures" means the measures in Annex 2.

3. Purpose of processing

3.1. The Processor processes Personal Data only to provide the Platform under the Principal Agreement, namely:

(a) Users and access: creating and managing user accounts, invitations, roles, facility access and signed-in devices within the Controller's organisation.

(b) Supplier records: storing the Controller's suppliers, their contact people and languages, the documents each supplier must hold per facility, and internal notes.

(c) Requests and reminders: sending emails to supplier contacts on the Controller's behalf, in the supplier's language, with a personal upload link, as triggered by the Controller's users and workflows, and recording whether emails were opened or their links used.

(d) Uploads and review: receiving files through the supplier upload page or from users, storing them, and supporting review, approval, rejection and approval by exception.

(e) Audit register and files: producing the audit register, file downloads and ZIP archives, and keeping an audit trail of decisions and changes.

(f) Internal notifications: emailing the Controller's users as configured in workflows.

(g) Import and export: importing supplier spreadsheets, and exporting the Controller's data on request.

(h) Security and support: keeping the Platform secure, investigating problems, and providing support when the Controller asks for it.

3.2. The Processor does not process Personal Data for any other purpose, and in particular not for its own marketing, unless the Controller instructs it in writing or the law requires it. In the latter case the Processor informs the Controller of that requirement before processing, unless the law prohibits this.

4. Types of personal data and categories of data subjects

4.1 Types of personal data

Category Data
User data Name, email address, job title, interface language, role and facility access, access end date, sign-in credentials (hashed) and one-time codes, signed-in devices (device, browser, IP address, last active), last sign-in time
Supplier contact data Contact name, contact email, language, country of the supplier, internal notes
Communication data Emails sent to supplier contacts and users, and whether they were opened or their links used
Upload data Uploaded files and their metadata, expiry text and notes typed by the supplier, page language, IP address and browser on the upload page
Personal data in documents Names, signatures and other details of individuals that appear in uploaded certificates, insurance schedules, declarations and reports, such as auditors, signatories and company officers
Decision and audit data Who approved, rejected, granted an exception or changed a record, when, and with what reason or note

The Controller should not upload special categories of personal data (Article 9 GDPR) or data about criminal convictions (Article 10 GDPR). The Platform is not designed for them.

4.2 Categories of data subjects

Category Description
Controller's users Owners, Admins, Reviewers and Read-only users, including external auditors given read-only access
Supplier contacts People at the Controller's suppliers who receive requests and reminders and upload documents
Other people in documents Individuals named in the documents suppliers or users upload
Other recipients Anyone else the Controller chooses to email through workflows

5. Obligations of the processor

The Processor shall:

5.1. Follow documented instructions. Process Personal Data only on the Controller's documented instructions, including on transfers to third countries. The Principal Agreement, this DPA and the Controller's use of the Platform's features are the Controller's instructions. The Processor tells the Controller straight away if it believes an instruction infringes Applicable Data Protection Law.

5.2. Ensure confidentiality. Ensure that everyone authorised to process Personal Data is bound by confidentiality.

5.3. Keep it secure. Implement the Technical and Organisational Measures in Annex 2, taking into account the state of the art, the cost, and the nature, scope, context and purposes of the processing, as well as the risks to Data Subjects (Article 32 GDPR).

5.4. Use sub-processors only as allowed. Engage Sub-processors only under section 8.

5.5. Help with data subject rights. Assist the Controller in responding to requests from Data Subjects under Chapter III GDPR, as set out in section 10.

5.6. Help with compliance. Assist the Controller with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to the Processor.

5.7. Delete or return data at the end. Delete or return Personal Data at the end of the service, as set out in section 13.

5.8. Demonstrate compliance. Make available the information needed to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, as set out in section 11.

5.9. Keep records. Keep a record of processing activities carried out for the Controller (Article 30(2) GDPR).

6. Obligations of the controller

The Controller shall:

6.1. Process lawfully. Ensure that it has a lawful basis for the processing, including storing supplier contacts and having the Processor email them on its behalf, and that it has given Data Subjects the information required by Articles 13 and 14 GDPR.

6.2. Give lawful instructions. Ensure that its instructions comply with Applicable Data Protection Law.

6.3. Keep data accurate. Ensure that the Personal Data it and its users enter is accurate and up to date, and use only the contact details of people who should receive supplier emails.

6.4. Manage access. Manage its users, roles and facility access, remove access that is no longer needed, and keep supplier upload links from being shared beyond the supplier.

6.5. Handle its own obligations. Respond to Data Subject requests, and carry out impact assessments where required.

6.6. Tell the Processor about issues. Tell the Processor without undue delay about any data protection issue affecting the processing under this DPA.

7. Security

7.1. The Processor implements and maintains the Technical and Organisational Measures in Annex 2 to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage.

7.2. The Processor reviews these measures regularly and updates them to address new risks. Updates will not reduce the overall level of protection.

8. Sub-processors

8.1. The Controller gives the Processor general written authorisation to engage the Sub-processors listed in Annex 3, and new Sub-processors under this section.

8.2. The Processor notifies the Controller at least 30 days before a new or replacement Sub-processor starts processing Personal Data, by email to the Owner or by notice in the Platform, with enough information to assess the change.

8.3. The Controller may object on reasonable data protection grounds, in writing, within 14 days of the notice. The Parties will then discuss the objection in good faith. If they cannot resolve it, the Controller may end the affected service without penalty.

8.4. The Processor imposes on each Sub-processor, by written contract, data protection obligations that offer at least the same protection as this DPA.

8.5. The Processor remains fully liable to the Controller for the performance of each Sub-processor's obligations.

9. Personal data breaches

9.1. The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.

9.2. The notice includes, as far as known at the time:

(a) the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned;

(b) the name and contact details of the Processor's data protection officer;

(c) the likely consequences of the breach;

(d) the measures taken or proposed to address the breach and limit its effects.

9.3. Where not all information is available at once, it may be provided in phases without undue further delay.

9.4. The Processor cooperates with the Controller and takes reasonable steps to investigate, contain and remedy the breach.

9.5. The Processor documents every Personal Data Breach, including its facts, effects and the remedial action taken, and makes this available to the Controller and, on request, to the Supervisory Authority.

9.6. The Processor does not notify third parties, including Data Subjects, of a breach affecting the Controller's data without the Controller's consent, unless the law requires it.

10. Data subject rights

10.1. If the Processor receives a request from a Data Subject about Personal Data it processes for the Controller, it passes the request to the Controller without undue delay and does not respond itself, except to confirm that it has passed the request on, unless the Controller authorises it or the law requires it.

10.2. The Platform lets the Controller respond to requests itself:

(a) Access and portability: users with the right role can view all supplier and user records, and export all data from Settings as a ZIP with a CSV file per record type, every file, and the full audit log.

(b) Rectification: supplier contacts, user details and document dates can be edited in the Platform, and changes to document dates are recorded in the audit trail.

(c) Erasure and restriction: suppliers, users, documents and files can be removed, and chasing can be stopped for a supplier or document.

(d) Tracing: the audit trail shows the actions taken on each supplier and document.

10.3. Where the Controller needs help beyond these features, the Processor assists. The Processor may charge a reasonable fee for assistance that goes beyond ordinary support, after telling the Controller the fee in advance.

11. Audits

11.1. The Processor makes available to the Controller the information needed to demonstrate compliance with this DPA and Article 28 GDPR.

11.2. The Processor first answers the Controller's reasonable written questions about its processing and measures, and provides relevant documentation. The Processor does not currently hold third-party security certifications. It will share summaries of any it obtains in the future.

11.3. If that is not enough to demonstrate compliance, or a Supervisory Authority requires it, the Controller or an independent auditor it appoints may carry out an audit, remote or on site, on these conditions:

(a) at least 30 days' written notice;

(b) during business hours, without unreasonable disruption, and in line with the Processor's security rules;

(c) the auditor is bound by confidentiality, and the audit does not give access to other customers' data;

(d) at most once per calendar year, unless a Personal Data Breach has occurred or a Supervisory Authority requires it;

(e) at the Controller's cost, unless the audit reveals a material breach of this DPA by the Processor.

12. International transfers

12.1. The Processor is established in North Macedonia. Its staff access the Platform from there, and the Platform, its database, uploaded files and backups are hosted on the Processor's own servers in Skopje, which the Processor operates itself. North Macedonia is in Europe but is not in the EU or EEA, and has no adequacy decision of the European Commission. Where the Controller is subject to the GDPR or UK GDPR, making Personal Data available to the Processor is therefore a transfer to a third country.

12.2. For such transfers, the Parties agree that the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference, with the Controller as data exporter and the Processor as data importer. Annexes 1 to 3 of this DPA provide the information required by the annexes of the Clauses. Clause 7 (docking) does not apply; under Clause 9 option 2 (general authorisation) applies with the notice period in section 8.2; the optional wording in Clause 11 does not apply; Clauses 17 and 18 are governed by, and disputes go to the courts of, the EU member state in which the Controller is established or, if none, Ireland. For transfers under the UK GDPR, the UK International Data Transfer Addendum to the Clauses applies in addition. If the Clauses conflict with this DPA, the Clauses prevail.

12.3. The Processor transfers Personal Data onwards to Sub-processors outside North Macedonia and the EEA only where an adequacy decision, the Standard Contractual Clauses or another mechanism under Chapter V GDPR applies. Annex 3 shows the location of each Sub-processor.

12.4. The Processor tells the Controller promptly about any change in law that may affect the lawfulness of these transfers, and cooperates on any additional measures needed.

13. Term, return and deletion

13.1. This DPA applies for as long as the Processor processes Personal Data for the Controller under the Principal Agreement, and ends automatically when that processing ends.

13.2. Return: the Controller can export all its data at any time before deletion, as described in section 10.2(a).

13.3. Deletion: the Processor permanently deletes the Controller's Personal Data:

(a) 60 days after a trial ends without a paid plan;

(b) 60 days after the end of the last paid period, when the subscription was cancelled or ended;

(c) 14 days after the Owner requests deletion of the account, unless the request is cancelled in that time.

Backup copies of the Platform are kept for at most 5 daily, 3 weekly and 2 monthly copies and are then overwritten, so deleted data disappears from backups within that cycle. Backups are used only to restore the Platform.

13.4. On request, the Processor confirms deletion in writing.

13.5. The Processor may keep Personal Data only where the law requires it. It then processes that data only for that legal purpose, keeps it confidential and secure, and deletes it when the obligation ends. Invoices and billing records are data for which the Processor is the controller, and are kept for 7 years under accounting law.

13.6. Sections 5, 7, 9, 11 and 13 survive the end of this DPA for as long as the Processor holds any of the Controller's Personal Data.

14. Liability

14.1. Each Party's liability under this DPA is subject to the limitations in the Principal Agreement, except that those limitations do not apply to liability that cannot be limited by law.

14.2. Each Party is liable to Data Subjects as set out in Article 82 GDPR. The Processor is liable for damage caused by processing that does not comply with this DPA or the obligations of processors under the GDPR, or that goes against the Controller's lawful instructions.

15. General

15.1. Governing law. Except as set out in section 12.2, this DPA is governed by the law of the Republic of North Macedonia.

15.2. Disputes. Disputes are resolved as set out in the Principal Agreement, with the competent courts of Skopje. Either Party may also refer a matter to the competent Supervisory Authority.

15.3. Changes. The Processor may update this DPA and its annexes, for example to reflect new Sub-processors or security measures, by giving notice as in section 8.2. Changes that reduce the protection of Personal Data require the Controller's agreement.

15.4. Severability. If a provision is invalid, the rest remains in force, and the invalid provision is replaced by the closest valid one.

15.5. Precedence. If this DPA conflicts with the Principal Agreement, this DPA prevails on data protection matters.

15.6. Language. This DPA is provided in English. If a translation differs, the English version prevails.

Signatures (optional)

This DPA is binding without signatures. For Controllers that want a signed copy:

Controller

Organisation: _________________________________

Name: _________________________________

Title: _________________________________

Date: _________________________________

Signature: _________________________________

Processor: Aventruks DOOEL Skopje

Name: _________________________________

Title: _________________________________

Date: _________________________________

Signature: _________________________________

Annex 1: Details of processing

Element Description
Data exporter The Controller, as identified in its Certinuity account
Data importer Aventruks DOOEL Skopje, Mateja Matevski 22, Skopje, North Macedonia. Contact: Martin Mihailovski, DPO, martin@aventrux.com
Subject matter Provision of the Certinuity platform for supplier document compliance
Duration For the term of the Principal Agreement, plus the deletion periods in section 13
Frequency Continuous
Nature of processing Collection, storage, organisation, retrieval, consultation, use, transmission by email, restriction, erasure and destruction, by automated means through the Platform
Purpose To let the Controller track the documents its suppliers must hold, request and collect them, review them and produce the audit register (section 3)
Data subjects See section 4.2
Personal data See section 4.1
Special categories None intended
Retention See section 13
Competent supervisory authority The authority of the member state where the Controller is established, or for Controllers in North Macedonia, the Agency for Personal Data Protection (https://azlp.mk)

Annex 2: Technical and organisational measures

A. Access control

Measure Description
Tenant isolation One database with every tenant record tied to an organisation. Every query is limited to the signed-in user's organisation, and membership is checked again on every request. Automated tests try every endpoint across organisations
Facility scope Every supplier, requirement, file, review and register query is limited to the user's facilities. Covered by automated tests per endpoint
Roles Owner, Admin, Reviewer and Read-only, each for all facilities or a list of them. Permissions are enforced by the server, not only hidden in the interface. Read-only access can end on a set date, after which it is refused
Sign-in Users sign in with email address and password; passwords are stored only as one-way hashes. Optional two-step sign-in adds a one-time email code, valid 10 minutes, with 5 attempts. Sign-in rate-limited per email address and IP address
Devices Each sign-in is a revocable token listed under Signed-in devices, with device, IP address and last use. Removing a user revokes their tokens for that organisation
Invitations Single-use, valid 7 days, stored as a hash
Staff access Platform administration is restricted to named Processor staff. Opening a customer account as an organisation admin is time-limited and every action is audited with the staff member's identity

B. Supplier links and files

Measure Description
Upload links One personal link per supplier, a 40-character random token, looked up by its SHA-256 hash, with an encrypted copy so authorised users can copy it. Resettable at any time. Unknown, reset or suspended links all show the same neutral page
Rate limits Upload pages limited per link, sign-in per email and IP address
File validation File type checked on the server and matched to the extension; web page and SVG files refused; size limits per document, with a hard cap of 50 MB
Private storage Files are stored under random names, never on a public address, and served only through authorised requests or signed preview links valid for 5 minutes
Hosting The Platform, its database and files run on the Processor's own servers in Skopje, North Macedonia, operated by the Processor itself. No third party hosts or has access to the servers
Network isolation The production server runs in its own isolated network segment, separated from other networks, behind a firewall that allows only HTTP, HTTPS and administrator SSH
Server hardening SSH by key only; repeated failed sign-in attempts are blocked automatically; security updates are installed automatically
Encryption in transit The Platform is served over HTTPS only
Payment card data Never processed or stored by the Platform. Card payments are handled by cPay

C. Integrity and availability

Measure Description
Audit trail Decisions and changes are written to an append-only audit log. No part of the Platform edits or deletes audit entries
Decision safety Approvals, rejections and exceptions can be undone within 30 seconds; supplier emails about decisions are delayed until then
Backups Automatic daily snapshot backups at 03:00, compressed and stored on a separate disk pool of the same server infrastructure in Skopje. Retention: 5 daily, 3 weekly and 2 monthly copies, then deleted automatically. Failure alerts go to the Processor by email

D. Organisational measures

Measure Description
Confidentiality Everyone with access to Personal Data is bound by confidentiality
Least privilege Production access limited to staff who need it, and reviewed regularly
Secrets Credentials and keys are kept out of source code
Development Code review and automated tests for every change, including tenancy and facility scope tests. Separate development and production environments
Incidents A documented procedure for Personal Data Breaches, with notification as in section 9
Data protection officer Martin Mihailovski, martin@aventrux.com, +389 71 333 194

Annex 3: Authorised sub-processors

The following Sub-processors are authorised as of the effective date:

Sub-processor Purpose Personal data Location
Microsoft Ireland Operations Limited (Microsoft 365, Exchange Online via Microsoft Graph, in the Processor's own Microsoft 365 tenant) Delivery of emails to supplier contacts and users Recipient names and email addresses, email content EU, with possible transfers to the United States under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses

The Platform is hosted on the Processor's own servers in Skopje, North Macedonia, so hosting is not a Sub-processor. No error-tracking or monitoring services are used.

Not a Sub-processor: card payments are handled by cPay (CaSys International, Skopje, North Macedonia). cPay processes billing data for which the Processor is the controller, not the Controller's Personal Data in the Platform. It is listed in the Privacy notice.

The Controller's acceptance of this DPA is its authorisation of the Sub-processors listed above. Changes follow section 8.

CertinuitySupplier certificates, always in date.

PRODUCT

How it worksWorkflowsAudit registerPricing

GET STARTED

Start free trialBook a demoSign in

LEGAL

Privacy noticeTermsData processing agreementCookie policy
© 2026 Certinuity. See Terms for the operating company.