← Back to home
Effective from: 1 January 2026 · Version 1.0

This is a translation of the Czech original, provided for convenience. In case of any discrepancy, the Czech version prevails.

Data Processing Agreement (DPA)

This agreement (the “DPA”) governs the processing of personal data that the Client (controller) uploads to the HRko service, the provider of which is the operator of the HRko service, whose identification details are stated on the Operator page (processor). The DPA forms an integral part of the Terms and conditions and is concluded pursuant to Article 28 GDPR.

1. Subject matter of processing

The processor processes personal data solely for the purpose of performing the service — operating an HR system in which the controller records its employees, candidates and other persons.

2. Duration of processing

For the duration of the main agreement + a 30-day grace period for data export + backup retention (max. 7 days).

3. Nature and purpose of processing

4. Categories of personal data

5. Data subjects

6. Obligations of the processor

7. Sub-processors

The processor uses other processors (sub-processors) listed publicly on the page /en/subprocessors. The controller gives general authorisation for their use; the processor will notify changes by e-mail at least 30 days in advance. If the controller does not agree with a new sub-processor, it has the right to terminate the agreement.

8. Security measures (Article 32 GDPR)

Detailed description: /en/security.

9. International transfers

Data is stored exclusively in the EU (Oracle Cloud Frankfurt). Should a transfer outside the EU occur in the future, we will notify the controller in advance and ensure an appropriate legal basis (standard contractual clauses, adequacy decision).

10. Audit and accountability

The controller has the right to audit compliance with the DPA in writing — by sending a security questionnaire (e.g. SIG, VSA or its own template) to privacy@hrko.eu. The processor will usually return the completed questionnaire within 5 business days. For enterprise clients with their own information security team, the processor may provide logs of administrative actions, a list of sub-processors and other supporting documentation.

11. Liability

The parties are liable for damage caused by a breach of this DPA. The limit of liability is identical to the limit in the Terms and conditions, unless the parties agree otherwise.

12. Effectiveness and changes

The DPA becomes effective upon conclusion of the main agreement and remains in force for its duration. The current version can always be found on this page. We announce material changes 30 days in advance.


If you need to sign this DPA in written form (for your compliance), send a request to privacy@hrko.eu. We will issue a PDF for signature.