Personal Data Processing Agreement

between the Partner (Controller) and STILIO DIGITAL SRL (Processor) — in accordance with Law No. 195/2024

Preliminary Article. Parties to the Agreement

This Personal Data Processing Agreement (hereinafter referred to as the "Agreement" or "DPA") is concluded between:
(1) The Partner, the natural or legal person whose identification details (name, legal form, IDNO/tax code, registered office/address, contact details) are those provided when creating an account on the STILIO platform, hereinafter referred to as the "Controller" or the "Partner";
(2) STILIO DIGITAL LIMITED LIABILITY COMPANY, IDNO 1022600029811, with its registered office at MD-2044, Chișinău municipality, 17 Mihail Sadoveanu St., office 249A, legally represented by its administrator, hereinafter referred to as "STILIO" or the "Processor", together referred to as the "Parties" and each individually as a "Party".
WHEREAS the Partner uses the STILIO platform to manage appointments and its relationship with its own clients;
WHEREAS in the course of this use STILIO processes personal data of the Partner's clients on behalf of and for the account of the Partner;
WHEREAS the Parties wish to establish their rights and obligations in accordance with Law No. 195/2024 on the protection of personal data and, where applicable, Regulation (EU) 2016/679 (GDPR),
The Parties have agreed as follows:

Article 1. Definitions and interpretation

1.1. Throughout the Agreement, the terms below have the following meaning:
a) "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" have the meaning set out in Law No. 195/2024 and, where applicable, in the GDPR;
b) "Applicable Law" means Law No. 195/2024 and any other data protection legislation applicable to the processing, including the GDPR where it applies;
c) "Data" means the personal data of the Partner's clients, processed by STILIO under this Agreement, as described in Annex 1;
d) "Main Contract" means the contract and/or terms of use of the STILIO platform accepted by the Partner, of which this Agreement forms an integral part;
e) "Documented instructions" means the Controller's instructions regarding the processing of the Data, including the Partner's use of the platform's features in accordance with their intended purpose, as well as any subsequent written instructions;
f) "Supervisory Authority" means the National Center for Personal Data Protection (CNPDCP) or another competent authority.
1.2. Article headings are for guidance only and do not affect interpretation. The Annexes form an integral part of the Agreement.

Article 2. Subject matter and precedence of the Agreement

2.1. The Agreement governs the conditions under which STILIO processes the Data on behalf of the Controller, setting out the Parties' obligations in accordance with Art. 28 of the GDPR and the corresponding provisions of Law No. 195/2024.
2.2. The Agreement forms an integral part of the Main Contract. In the event of a conflict between this Agreement and the Main Contract with respect to the processing of personal data, the provisions of this Agreement shall prevail.
2.3. This Agreement applies to all Partners using the STILIO platform, regardless of the plan chosen (free or paid), for as long as STILIO processes Data on behalf of the Partner.
2.4. In the event of a conflict between the Agreement and the Applicable Law, the Applicable Law shall prevail.

Article 3. Roles of the Parties

3.1. The Partner acts as controller: it determines the purposes and means of processing its clients' Data and is responsible for the lawfulness of the legal basis for processing.
3.2. STILIO acts as processor: it processes the Data solely on behalf of the Controller and on the basis of the Controller's Documented instructions.
3.3. Each Party is individually responsible for complying with its own obligations under the Applicable Law, according to its role.
3.4. This Agreement does not create a joint-controller relationship. If, in a particular activity, STILIO determines its own processing purposes, that activity is governed by STILIO's privacy policy, as a separate controller, and not by this Agreement.

Article 4. Description of the processing

4.1. The subject matter, duration, nature and purpose of the processing, as well as the categories of data and data subjects, are detailed in Annex 1.
4.2. The duration of the processing corresponds to the duration of the Main Contract, subject to the retention and deletion obligations set out in Art. 15.

Article 5. Obligations of the Controller (the Partner)

5.1. The Controller undertakes:
a) to have a valid legal basis for collecting and processing its clients' Data and to be responsible for it;
b) to inform data subjects and, where necessary, to obtain their consent, in accordance with the Applicable Law;
c) to transmit to STILIO only data that is accurate, relevant, and limited to what is necessary for the stated purposes;
d) not to enter special categories of data into the platform unless it has a specific legal basis provided for by the Applicable Law, in which case it bears full responsibility for doing so;
e) to issue instructions that comply with the Applicable Law and to be responsible for their compliance.

Article 6. Processing based on instructions

6.1. STILIO processes the Data only on the basis of the Controller's Documented instructions, including with respect to transfers, unless a legal obligation requires otherwise; in that case, STILIO informs the Controller before processing, unless the law prohibits this for reasons of public interest.
6.2. STILIO promptly informs the Controller if, in its opinion, an instruction infringes the Applicable Law. STILIO is not obliged to carry out a legal assessment of the Controller's instructions.

Article 7. Confidentiality

7.1. STILIO ensures that persons authorized to process the Data have committed to confidentiality or are under a statutory obligation of confidentiality.
7.2. Access to the Data is limited to staff who need it to perform the Main Contract, on a need-to-know basis.

Article 8. Security of processing

8.1. STILIO implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 of the GDPR and Law No. 195/2024. The measures are detailed in Annex 2.
8.2. STILIO may update the security measures, provided that the level of protection does not fall below that set out in Annex 2.

Article 9. Sub-processors

9.1. The Controller grants STILIO general authorization to engage sub-processors for the provision of the service (e.g. hosting, communications, notifications, technical analysis).
9.2. The updated list of sub-processors is available at https://stilio.ro/en/subprocessor and in Annex 3.
9.3. STILIO informs the Controller of any intention to add or replace sub-processors, through appropriate means (e.g. e-mail or notification within the platform). The Controller may raise justified objections within 30 (thirty) days of notification. In the event of a justified objection, the Parties shall make reasonable efforts to find a solution; in the absence of an objection within this period, the change is deemed accepted.
9.4. STILIO imposes on sub-processors, by contract, data protection obligations at least equivalent to those set out in this Agreement, and remains fully liable to the Controller for the performance of these obligations by such sub-processors.

Article 10. International transfers

10.1. STILIO's main hosting infrastructure is located in the European Union.
10.2. To the extent that a sub-processor processes Data outside the Republic of Moldova or the European Economic Area, STILIO ensures that the transfer is carried out with adequate safeguards, such as standard contractual clauses, an adequacy mechanism (e.g. the EU-U.S. Data Privacy Framework), or another basis provided for by the Applicable Law.

Article 11. Assistance regarding data subjects' rights

11.1. STILIO provides the Controller with the platform's features through which the Controller can respond to its clients' requests regarding access, rectification, erasure, restriction, portability and objection.
11.2. Taking into account the nature of the processing, STILIO assists the Controller, through appropriate technical and organizational measures and insofar as possible, in fulfilling its obligation to respond to requests from data subjects.
11.3. If a data subject contacts STILIO directly regarding Data processed on behalf of the Controller, STILIO does not respond on the merits but forwards the request to the Controller without undue delay.

Article 12. Assistance regarding security, impact assessment and prior consultation

12.1. STILIO assists the Controller, taking into account the nature of the processing and the information available, in fulfilling its obligations regarding the security of processing, breach notification, data protection impact assessments (DPIA), and prior consultation with the Supervisory Authority.

Article 13. Notification of personal data breaches

13.1. STILIO notifies the Controller without undue delay after becoming aware of a breach of the security of Data processed on behalf of the Controller.
13.2. The notification includes, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
13.3. The Controller, as controller, is responsible for notifying the breach to the Supervisory Authority (usually within 72 hours) and, where applicable, to the data subjects.

Article 14. Audit and demonstration of compliance

14.1. STILIO provides the Controller with the information necessary to demonstrate compliance with the obligations set out in this Agreement.
14.2. STILIO allows and contributes to audits, including inspections, carried out by the Controller or an auditor mandated by the Controller, upon reasonable prior notice, during working hours, without affecting the confidentiality of other clients' data or the security of its systems. STILIO may also demonstrate compliance by providing relevant reports or certifications.

Article 15. Retention, deletion and return of the Data

15.1. Termination of a paid subscription does not result in deletion of the account. Upon termination of a subscription, the Partner switches to the free plan and remains an active user of the platform; the account and associated Data are retained, since the Partner continues to use the service, and there remains an ongoing basis for processing.
15.2. The Data is deleted or anonymized:
a) at the Controller's express request;
b) after an extended period of total account inactivity of 5 (five) years from the last use, following prior notice to the Partner;
c) except for Data whose retention is required by law (e.g. data with tax/accounting relevance), which is retained for the period required by law.
15.3. Upon deletion of the account, the Data remains available for export for a period of 30 (thirty) days, after which it is deleted from production environments and, in accordance with the backup retention policy, from backups as well.
15.4. Upon termination of the Main Contract, at the Controller's choice, STILIO deletes or returns the Data, unless the law requires it to be retained.

Article 16. Liability

16.1. Each Party is liable for damages caused by the breach of its own obligations under the Applicable Law and this Agreement, according to its role.
16.2. The Controller is responsible for the lawfulness of the legal basis for processing, for informing data subjects, and for the instructions it issues. STILIO is responsible for the obligations specific to a processor, in accordance with the Applicable Law.
16.3. Nothing in this Agreement limits any liability that, under the Applicable Law, cannot be limited or excluded. Any limitation of liability agreed by the Parties in the Main Contract shall apply correspondingly to this Agreement as well, to the extent permitted by law.

Article 17. Term and termination

17.1. The Agreement enters into force on the date of electronic acceptance and remains valid for the duration of the Main Contract and for as long as STILIO processes Data on behalf of the Controller.
17.2. Obligations which, by their nature, must continue after termination (confidentiality, deletion, statutory retention) remain in force.

Article 18. Governing law and dispute resolution

18.1. This Agreement is governed by the laws of the Republic of Moldova, in particular Law No. 195/2024.
18.2. Disputes arising from this Agreement shall be settled amicably, and failing an amicable solution, by the competent courts in Chișinău municipality, Republic of Moldova.

Article 19. Final provisions

19.1. Amendments to the Agreement are communicated to the Controller and take effect in accordance with the platform's terms of use.
19.2. If a clause is declared void or unenforceable, the remaining clauses remain in force.
19.3. This Agreement, together with its annexes and the Main Contract, constitutes the entire agreement between the Parties regarding the processing of the Data.
19.4. Annexes: Annex 1 (Description of the processing), Annex 2 (Technical and organizational measures), Annex 3 (List of sub-processors).
Effective date: the date of the Agreement's electronic acceptance by the Partner (Art. 17.1).

Electronic acceptance of the Agreement

This Agreement is not signed individually with each Partner. The Agreement is published on the platform and is accepted electronically by the Partner when creating an account, by checking a dedicated box, separately from acceptance of the other terms.
Electronic acceptance has the same legal effect as a signature. STILIO retains proof of acceptance, including the Partner's identity, the date and time of acceptance, and the version of the Agreement accepted.
The applicable version is the one published on the platform at the time of acceptance. Subsequent amendments are communicated to the Partner and are subject to acceptance in accordance with the platform's terms of use.
The Partner's identification (name, IDNO/tax code, contact details) results from the data provided when creating the account. Processor: STILIO DIGITAL LIMITED LIABILITY COMPANY, IDNO 1022600029811, MD-2044, Chișinău municipality, 17 Mihail Sadoveanu St., office 249A.

Annex 1 — Description of the processing

ElementDescription
Subject matter of the processingProvision of the STILIO platform for managing appointments and the relationship with the Partner's clients.
Nature of the processingCollection, storage, organization, consultation, use, transmission of service notifications, deletion.
Purpose of the processingManaging appointments, client records, and service communications, on behalf of the Controller.
Duration of the processingFor the duration of the Main Contract, subject to Art. 15.
Categories of data subjectsThe Partner's clients.
Categories of dataIdentification and contact data (first name, last name, phone, e-mail); appointment history; other data entered by the Partner at its own discretion (e.g. notes about services).
Special categories of data (e.g. health, allergies)The platform does not request such data. The Partner may enter such information into its own client records; in this case the Partner, as controller, determines the purpose and legal basis and is responsible for it, while STILIO processes it solely on the basis of the Partner's instructions, as processor.

Annex 2 — Technical and organizational security measures

STILIO applies, at a minimum, the following measures (detailed in internal security documentation, available upon request):
ElementDescription
EncryptionEncryption of data in transit (TLS/HTTPS); encryption at rest at the hosting infrastructure level.
Access controlIndividual accounts per user, need-to-know principle, revocation of access upon termination of the working relationship.
AuthenticationTwo-factor authentication (2FA) for access to critical systems.
LoggingLogging of access and relevant operations on the systems.
BackupsPeriodic backups and a restoration mechanism.
LocationHosting of the main infrastructure in the European Union.
Separation of environmentsSeparation of production environments from testing environments; avoiding the use of real data in testing environments.
Staff confidentialityConfidentiality commitments for persons with access to the data.

Annex 3 — List of sub-processors

The updated list is published at https://stilio.ro/en/subprocessor (last updated: September 1, 2026). Sub-processors process data solely on behalf of STILIO, on the basis of its instructions and under data processing agreements.

Infrastructure and hosting

ProviderPurposeData Location
DigitalOceanHosting for servers, databases, and filesEuropean Union (Frankfurt)
CloudflareContent delivery network (CDN), security, and DNSGlobal network

User Communication

ProviderPurposeData Location
TwilioSending SMS notificationsUnited States
SMS.mdSending SMS notifications (markets of the Republic of Moldova, Romania, and Italy)Republic of Moldova
Twilio SendGridSending transactional emails (confirmations, codes)United States
Meta PlatformsCommunication via Instagram and Facebook, advertisingUnited States

Management and Analytics Tools

ProviderPurposeData Location
PipedrivePartner relationship management (CRM), marketingEuropean Union (Estonia)
Google/FirebasePush notifications, usage analytics, statisticsUnited States
SentryMonitoring technical errors in the applicationUnited States
PostHogProduct usage analyticsUnited States
New RelicMonitoring technical errors in the applicationUnited States

Payments and Subscriptions

ProviderPurposeData Location
RevenueCatManaging in-app subscriptionsUnited States

International Data Transfers

For providers that process data outside the European Union or the Republic of Moldova, transfers are carried out on the basis of appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission and, where applicable, certification under the EU-U.S. Data Privacy Framework.

Independent payment processors

The following entities act as independent controllers, under their own responsibility, and not as sub-processors of STILIO: MAIB (BC Moldova-Agroindbank) for card payments, and Apple / Google for payments made through their app stores. Full card details are entered directly on their infrastructure and are not accessible to STILIO.