Last updated: October 5, 2026
Version 1.0 · Effective from: November 1, 2026
Annex No. 1 to the Terms of Service of the Portali.Space portal
1. Parties and Subject Matter
1.1. Processor: TTN, s.r.o., registered office Sadová 2719/3A, 905 01 Senica, Slovak Republic, Company ID (IČO): 52330443, Tax ID (DIČ): 2120984085, VAT ID: SK2120984085, registered in the Commercial Register of the District Court Trnava, Section Sro, Insert No. 44230/T, e-mail: privacy@ttn.sk (“TTN”).
1.2. Controller: the organisation (legal entity or self-employed person/sole trader) that created an account in the Portal, identified by the details provided at registration and in the Portal’s billing profile (the “Organisation”).
1.3. This Data Processing Agreement (the “DPA”) is concluded under Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”) and Slovak Act No. 18/2018 Coll. on the Protection of Personal Data. It governs the processing of personal data that TTN carries out on behalf of the Organisation when providing the Portali.Space portal, operated as the HelpDesk and MaintenanceDesk products (the “Portal”), under the Terms of Service (the “Terms”).
1.4. The DPA applies to content that the Organisation and its users enter into the Portal (tickets and their attachments, devices, contacts, knowledge base, AI Assistant data created within the Organisation). It does not apply to data whose purposes and means TTN determines itself (user accounts and sign-in, communication, invoicing, Portal security, visitor analytics, web inquiries); TTN processes such data as a controller under the Privacy Policy.
1.5. The DPA forms Annex No. 1 to the Terms. The Organisation accepts it on registration (creation of its account) in the Portal; an Organisation whose account was created before the DPA took effect accepts it by accepting the Terms in version 1.1 or later. The Organisation’s administrator may request a signed copy of the DPA at any time at privacy@ttn.sk.
2. Scope of Processing
2.1. Subject matter: operation of the Portal and provision of its Services to the Organisation — in particular ticket management (HelpDesk), maintenance and device planning and records (MaintenanceDesk), knowledge base, notifications, reports and the AI Assistant, if the Organisation has enabled it.
2.2. Duration: for the lifetime of the Organisation’s account in the Portal and thereafter for the periods under Article 12.5 of the Terms (data export and subsequent deletion) and Article 10 of this DPA.
2.3. Nature and purpose: storage, organisation, retrieval, display, transmission (e.g. e-mail notifications), alteration and erasure of personal data solely for the purpose of providing the Portal’s Services to the Organisation under the Terms.
2.4. Types of personal data:
- identification data (first name, surname, job title, organisation),
- contact data (e-mail address, phone number),
- content of tickets and their attachments, comments and internal notes,
- data on devices, their location, maintenance and responsible persons,
- AI Assistant conversations created within the Organisation,
- records of activities in the Portal (audit log) relating to the above data.
2.5. Categories of data subjects: employees and associates of the Organisation, the Organisation’s customers and suppliers and their representatives, end users of the Portal (e.g. persons reporting a request or a fault).
3. Instructions of the Organisation
3.1. TTN processes personal data only on documented instructions from the Organisation, including with regard to transfers to third countries (Article 7). The instructions are these Terms and this DPA, the Portal settings and functions used by the Organisation and its administrators, and further written instructions sent to privacy@ttn.sk.
3.2. Where processing is required by Union or Member State law to which TTN is subject, TTN will inform the Organisation of that legal requirement before processing, unless that law prohibits such information.
3.3. TTN will immediately inform the Organisation if, in its opinion, an instruction infringes the GDPR or other data protection provisions. TTN is not obliged to carry out such an instruction until it is confirmed or amended.
4. Confidentiality
4.1. TTN ensures that persons authorised to process the Organisation’s personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The obligation continues after their employment or contractual relationship with TTN ends and after the DPA ends.
4.2. Only persons who need access to fulfil obligations under the Terms and the DPA (e.g. operations, support, troubleshooting) have access to the Organisation’s personal data.
5. Security of Processing
5.1. TTN implements appropriate technical and organisational measures under Article 32 GDPR, taking into account the nature, scope, context and purposes of processing and the risks to the rights and freedoms of natural persons. An overview of the measures is set out in Article 9 of the Privacy Policy.
5.2. TTN operates an information security management system certified to ISO/IEC 27001:2022 — Certificate no. 2025312 (ELBACERT, SNAS accreditation), valid until 06/2028.
5.3. TTN may adapt the measures in line with technical progress, provided that the level of personal data protection is not reduced.
6. Sub-processors
6.1. The Organisation grants TTN general written authorisation to engage other processors (sub-processors). TTN concludes a contract with each sub-processor imposing essentially the same data protection obligations as this DPA and remains liable to the Organisation for the performance of the sub-processor’s obligations.
6.2. Current list of sub-processors:
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Anthropic Ireland, Limited (Ireland) | Processing AI Assistant questions — only if the Organisation has enabled the AI Assistant | USA; for some requests also other countries in which the provider operates computing infrastructure | DPA + Standard Contractual Clauses (SCC) |
| Mailgun (Sinch) | Delivery of e-mail notifications and receipt of e-mails into tickets | EU | DPA + SCC |
| Hosting infrastructure provider (VPS) | Operation of the Portal’s virtual servers — infrastructure layer only (hardware, virtualisation, network) without logical access to data; the servers are managed exclusively by TTN, disks are encrypted | EU | DPA, ISO 27001; we will provide the provider’s identity and safeguards to the Organisation’s administrator on request (Article 6.4) |
| Cloudflare, Inc. | Network infrastructure (proxy) in front of the services on the portali.space domain and Cloudflare Turnstile verification — mainly processes the IP address and technical browser data | EU/USA | DPA + EU-US Data Privacy Framework; alternatively SCC included in the DPA |
| Google Ireland Limited (Google Analytics 4) | Visitor analytics — only if the user consents in the cookie banner | EU/USA | DPA + EU-US Data Privacy Framework; alternatively SCC included in the DPA |
6.3. TTN will notify the Organisation’s administrator by e-mail of any intended change to the list (addition or replacement of a sub-processor) at least 30 days in advance. Within that period the Organisation may object to the change in writing at privacy@ttn.sk. If TTN does not accommodate the objection, the Organisation may terminate the contractual relationship (by cancelling its account) as of the date the change takes effect.
6.4. For business-confidentiality reasons TTN does not publicly name its hosting infrastructure provider. The Organisation’s administrator may at any time request, at privacy@ttn.sk, its identification, a copy of its data processing agreement and its certificates; TTN will provide them within 5 working days. The right to object under Article 6.3 also applies to this sub-processor and to any change of it.
7. Transfers to Third Countries
7.1. Personal data may be transferred to third countries (USA) only through the sub-processors under Article 6 and only with safeguards under Chapter V GDPR as described in Article 4.2 of the Privacy Policy:
- for companies certified under the EU-US Data Privacy Framework (Google, Cloudflare), the European Commission adequacy decision of 10 July 2023; alternatively the standard contractual clauses (SCC) under Decision 2021/914 included in their DPAs, should the adequacy decision cease to apply,
- for other recipients (Anthropic Ireland, Limited), standard contractual clauses (SCC) under Decision 2021/914 and supplementary measures (encryption, data minimisation).
8. Assistance
8.1. Data subject requests: TTN provides the Organisation with Portal functions enabling it to fulfil its obligations towards data subjects (access, rectification, erasure, export). If TTN receives a data subject request concerning the Organisation’s data, it forwards it to the Organisation without undue delay and no later than 5 working days after receipt, and does not respond to it on the merits itself unless instructed to do so by the Organisation.
8.2. Further assistance: taking into account the nature of processing and the information available to it, TTN provides the Organisation with reasonable assistance in fulfilling its obligations under Articles 32 to 36 GDPR, in particular with data protection impact assessments (DPIA) and prior consultation with the competent supervisory authority.
9. Security Incidents
9.1. TTN notifies the Organisation of a personal data breach affecting the Organisation’s data without undue delay and no later than 48 hours after becoming aware of it, by e-mail to the Organisation’s administrator.
9.2. The notification contains the information under Article 33(3) GDPR to the extent known to TTN: a description of the nature of the breach including the categories and approximate number of data subjects and records concerned, a contact point, the likely consequences, and the measures taken or proposed. Where it is not possible to provide all information at the same time, TTN provides it in phases without further undue delay.
9.3. TTN takes reasonable measures to mitigate the consequences of the breach and assists the Organisation in notifying the supervisory authority and the data subjects.
10. End of Processing
10.1. After the provision of the Services ends, the Organisation may export its data and TTN subsequently deletes it in accordance with Article 12.5 of the Terms, unless Union or Member State law requires further storage.
10.2. At the Organisation’s request, TTN confirms the deletion by e-mail.
10.3. Data in backups is deleted in the regular backup rotation cycle, no later than 6 months after deletion from the Portal. Until then, backups are protected under Article 5 and are used for no purpose other than disaster recovery.
11. Audit
11.1. TTN makes available to the Organisation the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and this DPA.
11.2. The Organisation may carry out an audit, including an on-site inspection, at most once per calendar year, with at least 30 days’ prior written notice, at its own cost, itself or through an auditor bound by confidentiality, in a manner that does not disrupt the operation of the Portal or the protection of data of TTN’s other customers.
11.3. TTN may also fulfil the obligation under Article 11.2 by providing a valid ISO/IEC 27001:2022 certificate or a report from an independent audit, where these contain the required information.
11.4. The powers of the supervisory authority remain unaffected.
12. Liability
12.1. The parties’ liability for damage caused by an infringement of the GDPR is governed by Article 82 GDPR.
12.2. The limitations of liability under Article 9 of the Terms also apply to this DPA to the extent permitted by law.
13. Final Provisions
13.1. In matters of personal data protection, the DPA takes precedence over the Terms.
13.2. The DPA is governed by the laws of the Slovak Republic.
13.3. The DPA is effective from November 1, 2026 and remains in force for as long as TTN processes personal data on behalf of the Organisation.
13.4. Changes to the DPA are announced and take effect in the same way as changes to the Terms (Article 11 of the Terms).
13.5. The Slovak version of the DPA is binding; the other language versions are translations.
Contact Information
TTN, s.r.o. Sadová 2719/3A, 905 01 Senica, Slovak Republic Registered in the Commercial Register of the District Court Trnava, Section Sro, Insert No. 44230/T E-mail: privacy@ttn.sk