closetforge
← Back to Closetforge

Data Processing Addendum

Version 1.1 · Effective 2026-09-02

This Data Processing Addendum ("DPA") is entered into between Smartilabs razvoj in svetovanje d.o.o. ("Processor", "Closetforge") and the Customer that has accepted Closetforge's Master Subscription Agreement ("MSA") ("Controller", "you"). It forms part of the MSA and applies whenever Closetforge processes Personal Data on Controller's behalf in connection with the Service.

This DPA is structured to satisfy Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR for transfers to/from the United Kingdom, and equivalent provisions of Slovenian law.

In case of conflict between this DPA and the MSA, this DPA prevails on data-protection matters.


1. Definitions

Terms not defined here have the meanings given in the MSA or the GDPR. In particular:

  • "Personal Data" has the meaning in GDPR Article 4(1).
  • "Processing" has the meaning in GDPR Article 4(2).
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
  • "End User" means a natural person who uses the Configurator on Controller's website (typically a homeowner).
  • "Sub-processor" means a third party engaged by Closetforge to process Personal Data on Controller's behalf.
  • "SCCs" means the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.

2. Roles and scope

2.1 For Personal Data Closetforge processes about End Users in the course of providing the Service, Controller is the data controller and Closetforge is the data processor.

2.2 Closetforge will process Personal Data only:

  • (a) to provide the Service to Controller in accordance with the MSA,
  • (b) on Controller's documented instructions (the MSA, this DPA, and any further instructions given through the admin interface or in writing constitute documented instructions), and
  • (c) as required by EU or member-state law, in which case Closetforge will inform Controller before processing unless prohibited from doing so on important grounds of public interest.

2.3 Closetforge will inform Controller without undue delay if, in Closetforge's opinion, an instruction infringes the GDPR or other applicable data-protection law.

2.4 This DPA does not cover Personal Data of Controller's own personnel that Controller submits during account administration. Closetforge processes that data as a separate controller under its Privacy Policy at closetforge.com/privacy.


3. Subject matter, duration, nature and purpose

ItemDetails
Subject matterProvision of the Closetforge wardrobe-configurator Service
DurationFor the term of the MSA, plus any post-termination period in which Closetforge retains data per the MSA
Nature of processingCollection, storage, structuring, retrieval, transmission, and deletion of Personal Data submitted to or generated by the Service
PurposeEnabling End Users to design wardrobes, enabling Controller to receive leads and quotes, enabling Closetforge to deliver Service features (3D rendering, AI chat, real-time co-design, lead management)
Categories of Data SubjectsEnd Users (homeowners and other persons who interact with Controller's embedded Configurator); Controller's personnel listed as users
Categories of Personal DataIdentifiers (name, email, phone), location/postcode, design selections, free-text chat messages, IP address, device data, communications metadata, quote-engagement metadata (when a quote link was opened, how often, and which revision was shown), photos uploaded to the Configurator (if Controller enables this feature)
Special categoriesNone expected. Controller must not submit special-category data (GDPR Art. 9) or data relating to criminal convictions through the Service.
FrequencyContinuous during the Service term

4. Controller obligations

4.1 Controller warrants that it has a valid legal basis for the processing instructed and that all required notices have been given to Data Subjects.

4.2 Controller is responsible for:

  • Publishing its own privacy notice covering the processing, with a clear description of the role of Closetforge as processor
  • Obtaining any required consents from End Users (for example, marketing consent before contacting them)
  • Honouring Data Subject rights requests directed to Controller
  • Configuring the Service appropriately for the categories of data processed
  • Not submitting special-category Personal Data, criminal-conviction data, or data of children under 16 unless explicitly permitted by Closetforge in writing

4.3 Controller indemnifies Closetforge against claims arising from Controller's breach of its obligations as data controller, on the indemnity terms in the MSA.


5. Confidentiality and personnel

5.1 Closetforge ensures that personnel authorised to process Personal Data are bound by confidentiality (contractual or statutory) and trained in data protection.

5.2 Access to Personal Data is restricted to personnel with a need to know.


6. Security measures

Closetforge implements technical and organisational measures appropriate to the risk, as described in Annex II. Closetforge reviews these measures regularly and updates Annex II as the Service evolves; updates may not materially reduce the level of protection.


7. Personal Data breaches

7.1 Closetforge will notify Controller without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data breach affecting Personal Data processed under this DPA.

7.2 The notification will include, to the extent known and as it becomes available:

  • (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned,
  • (b) the likely consequences,
  • (c) the measures taken or proposed to address the breach and mitigate its effects, and
  • (d) the contact details of the Closetforge incident-response coordinator.

7.3 Closetforge will provide reasonable assistance to Controller in fulfilling Controller's notification obligations to authorities and Data Subjects, including providing factual information about the breach. Closetforge's communications about a breach are not an admission of fault.

7.4 Closetforge will document all breaches and corrective actions in a register available to Controller on reasonable request.


8. Sub-processors

8.1 General authorisation. Controller authorises Closetforge to engage Sub-processors. The current list is at closetforge.com/subprocessors.

8.2 Notice of changes. Closetforge will provide at least thirty (30) days' prior notice (by email and through the admin dashboard) before adding or replacing a Sub-processor.

8.3 Objection. Controller may object on reasonable data-protection grounds within thirty (30) days of the notice. The parties will work together in good faith to resolve the objection. If they cannot, Controller may terminate the affected portion of the Service for convenience and receive a pro-rata refund of prepaid unused fees.

8.4 Sub-processor terms. Closetforge imposes on each Sub-processor data-protection obligations that are no less protective than those in this DPA, including the SCCs where required.

8.5 Liability. Closetforge remains liable to Controller for the performance of each Sub-processor's obligations.


9. International transfers

9.1 Where Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is governed by the SCCs (with the UK Addendum or Swiss FDPIC modifications as applicable), incorporated by reference, with the following parameters:

  • Module: Module Two (Controller-to-Processor) for transfers from Controller to Closetforge; Module Three (Processor-to-Processor) for onward transfers to Sub-processors.
  • Clause 7 (docking): Optional clause is included.
  • Clause 9(a) (sub-processors): Option 2 (general written authorisation) with thirty (30) days' notice.
  • Clause 11 (independent dispute resolution): Optional clause is not included.
  • Clause 17 (governing law): Slovenian law.
  • Clause 18 (forum): Courts of Ljubljana, Slovenia.
  • Annex I.A (parties): Controller is the data exporter; Closetforge is the data importer.
  • Annex I.B (transfer description): as set out in Section 3 of this DPA.
  • Annex I.C (competent supervisory authority): Slovenian Information Commissioner (IP-RS).
  • Annex II (technical and organisational measures): as set out in Annex II to this DPA.

9.2 The parties have completed and will keep updated a transfer impact assessment for the SCCs.


10. Assistance to Controller

10.1 Data Subject rights. Closetforge will, taking into account the nature of the processing, assist Controller through appropriate technical and organisational measures, insofar as possible, in fulfilling Controller's obligations to respond to Data Subject requests under GDPR Articles 15–22. The admin interface includes self-service tools for export and deletion.

10.2 Compliance support. Closetforge will assist Controller, taking into account the nature of processing and information available, in ensuring compliance with GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation), to the extent that compliance requires Closetforge's involvement.

10.3 Costs. Closetforge's assistance under this Section 10 is included in the subscription fees for reasonable, non-excessive requests. For requests requiring substantial engineering effort, Closetforge may charge time and materials at its then-current rates with prior written notice.


11. Audits

11.1 Closetforge will, at Controller's reasonable written request and no more than once per twelve (12) month period (except after a confirmed Personal Data breach), make available information necessary to demonstrate compliance with this DPA, including:

  • (a) the most recent third-party security audit reports (for example, ISO 27001 or SOC 2 reports), where available, or
  • (b) Closetforge's responses to a security questionnaire reasonably required by Controller.

11.2 If the information in 11.1 does not sufficiently demonstrate compliance and Controller has reasonable grounds, Controller may request an on-site audit at Closetforge's facilities. The audit will be conducted by an independent third-party auditor agreed by both parties, on at least thirty (30) days' written notice, during business hours, in a manner that does not unreasonably interfere with Closetforge's operations, and subject to confidentiality. Costs are borne by Controller, except where the audit reveals material non-compliance.

11.3 Audits are not permitted to disclose data of other Closetforge customers.


12. Return and deletion of Personal Data

12.1 On termination of the MSA, Closetforge will, at Controller's choice, return or delete all Personal Data processed under this DPA, except to the extent EU or member-state law requires retention.

12.2 Controller's choice must be communicated in writing within thirty (30) days after termination. If Controller does not respond, Closetforge will delete after ninety (90) days.

12.3 Backups containing Personal Data are deleted as each backup copy expires on its retention schedule: 14 days for the database copies held on the primary server, and 90 days for the off-site database copies. Stored files generated by the Service (documents and images) are additionally retained in the off-site archive until removed manually. During these periods the data is not actively accessed except as required for disaster recovery, and deletion from live systems is not deferred by them.

12.4 Closetforge will provide a written confirmation of deletion on request.


13. Liability

The liability provisions of the MSA apply to this DPA. For clarity, regulatory fines imposed on a party arising from the other party's breach of this DPA are not subject to the cap on liability in MSA Section 10, to the extent permitted by law.


14. General

14.1 This DPA is governed by the laws of the Republic of Slovenia, except where the GDPR or applicable member-state law provides otherwise.

14.2 If any provision is held unenforceable, the remainder remains in effect, and the parties will replace the unenforceable provision with one that achieves the same data-protection effect to the maximum extent legally possible.

14.3 The parties may update this DPA to reflect changes in law, regulator guidance, or supervisory-authority decisions, with thirty (30) days' notice.


Annex I — Parties and Description of Processing

A. Parties

  • Data exporter / Controller: Customer as identified on the Order Form
  • Data importer / Processor: Smartilabs razvoj in svetovanje d.o.o., Prvomajska ulica 11, 4226 Žiri, Slovenia, legal@closetforge.com

B. Description of transfer See Section 3 of this DPA.

C. Competent supervisory authority Slovenian Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, Slovenia. www.ip-rs.si.


Annex II — Technical and Organisational Measures

Closetforge implements the following measures, regularly reviewed and updated:

Pseudonymisation and encryption

  • TLS 1.2 or higher for all data in transit
  • AES-256 encryption at rest for databases and object storage
  • Pseudonymisation of identifiers in analytics datasets

Confidentiality, integrity, availability, and resilience of processing systems

  • Role-based access control with least privilege
  • Multi-factor authentication for production-system access
  • Hardened cloud infrastructure with managed firewalls
  • Daily backups with periodic restore tests
  • Documented disaster-recovery plan with RTO 24h, RPO 24h

Ability to restore availability and access in a timely manner after an incident

  • Redundant infrastructure across availability zones
  • Documented incident-response procedure with on-call rotation
  • Regular tabletop exercises

Process for regularly testing, assessing, and evaluating effectiveness

  • Annual penetration test by an independent firm
  • Continuous dependency-vulnerability scanning
  • Quarterly internal security review

Identification and authorisation

  • Unique user accounts; no shared credentials
  • Just-in-time access for sensitive operations
  • Audit logs of administrative actions, retained for 12 months

Data minimisation and purpose limitation

  • The Service collects only the data necessary for its purpose
  • Configurable retention controls in the admin interface
  • Self-service deletion of End-User records

Sub-processor management

  • Written contracts with all Sub-processors imposing equivalent data-protection obligations
  • Initial and periodic vendor security review

Personnel

  • Background checks for personnel with production access
  • Mandatory annual data-protection and security training
  • Confidentiality undertakings as part of employment contracts

Physical security

  • Production infrastructure hosted in tier-3+ data centres with 24/7 staffed access control, biometric entry, and CCTV (provided by hosting providers — see Sub-processor List)

This Annex is updated as the Service evolves. The current version is the one in this document, published at closetforge.com/legal/dpa.