Zer.lv Data Processing Agreement
This Data Processing Agreement forms part of the Zer.lv Terms and governs SIA FIXLAB's processing of workspace personal data on behalf of the customer.
Version 2026-09-04 · Terms · Privacy Terms · DPA
1. Status, parties and precedence
This DPA is concluded electronically between the Zer.lv customer identified in the account and SIA FIXLAB, registration No. 40203523267, legal address Liepu aleja 38, Babīte, Babītes pag., Mārupes nov., LV-2101, Latvia. Acceptance of the Zer.lv Terms includes acceptance of this DPA.
For workspace personal data the customer is the controller and SIA FIXLAB is the processor. If the customer itself acts as a processor, it confirms that the relevant controller has authorised the instructions and the appointment of SIA FIXLAB and its subprocessors. This DPA prevails over the Terms only to the extent of a conflict concerning processing on behalf of the customer.
2. Subject matter and duration
SIA FIXLAB processes workspace personal data for the subscription term and the subsequent return and deletion period solely to provide, secure, maintain, support, back up and recover Zer.lv. This DPA remains effective until SIA FIXLAB has deleted or returned all workspace personal data in accordance with section 16 of this DPA, ‘Return and deletion’.
3. Documented instructions
The Terms, this DPA, the customer's configured settings, authorised use of Zer.lv and written requests accepted by SIA FIXLAB constitute documented instructions. SIA FIXLAB processes and transfers workspace personal data only on those instructions, unless EU or Latvian law requires otherwise. In that case SIA FIXLAB informs the customer before processing unless the law prohibits notification.
An instruction outside the ordinary Zer.lv service requires prior written agreement and may be subject to reasonable technical limits, implementation time and cost. SIA FIXLAB promptly informs the customer if an instruction appears to infringe applicable data-protection law and may suspend that instruction while the parties clarify it.
4. Purpose, nature and processing operations
Purposes include operating the CRM workspace; authentication and access control; managing clients, devices, orders, services, inventory, sales, finance, employees and reports; generating documents; storing comments and attachments; delivering optional notifications; providing support; maintaining security logs; and backup and recovery.
Operations may include receiving, collecting, recording, organising, structuring, storing, retrieving, consulting, updating, transmitting, restricting, backing up, restoring, exporting at the customer's request and deleting data. SIA FIXLAB does not sell workspace personal data or use it for third-party advertising.
5. Categories of data subjects
Data subjects may include the customer's clients and prospective clients; the customer's owners, employees and contractors; suppliers and their representatives; payers, contact persons and any other individual whose data the customer lawfully enters into the workspace.
6. Categories of personal data
The data may include names, roles, company details, addresses, telephone numbers and email addresses; client history; device type, brand, model, IMEI and serial number; orders, reported defects, diagnostics, repair results, services, products, comments, attachments and communications; employee assignments, permissions and remuneration calculations; sales, transaction amounts and payment method without payment-card credentials; IP address, session, device, application, security and audit records; and other free-text or files deliberately uploaded by the customer.
7. Restricted data
Zer.lv is not designed for payment-card credentials, account passwords, authentication secrets, extensive government-identification records, criminal-offence data or special categories of personal data. The customer must not enter such data unless it is strictly necessary, lawful, proportionate and protected by appropriate safeguards agreed with SIA FIXLAB. The customer remains responsible for avoiding unnecessary confidential data in free-text fields and attachments.
8. Customer obligations
The customer ensures a lawful basis and transparent notices, responds to data-subject requests, applies data minimisation and retention limits, keeps data reasonably accurate, gives access only to authorised personnel, configures roles appropriately, protects user credentials and devices, and ensures that its instructions and exports comply with applicable law. The customer must notify SIA FIXLAB without undue delay of suspected unauthorised access affecting the workspace.
9. Processor obligations and confidentiality
SIA FIXLAB processes workspace personal data only as described in this DPA and limits access to authorised persons who require it for support, security, recovery, maintenance, abuse investigation or legal compliance. Such persons are bound by contractual or statutory confidentiality duties. Access by platform administration or support is restricted and logged.
10. Technical and organisational security measures
Taking account of the state of the art, implementation costs, processing context and risk, SIA FIXLAB maintains measures including logical isolation of company workspaces; role-based access and least privilege; password, authentication and protected-session controls; request-rate and request-origin protections; encryption in transit and protection of attachments and backups at rest; private file storage with access, size, type and malware controls; audit and login logging; restricted server and secret access; security maintenance and dependency review; encrypted rolling backups and recovery checks; and incident identification, containment, recovery and review.
Measures may be updated to reflect technical progress, provided the overall protection is not materially reduced. Security information that would create a meaningful risk to Zer.lv or other customers may be supplied under confidentiality rather than published.
11. Data-subject requests and compliance assistance
If SIA FIXLAB receives a request concerning workspace data directly from a data subject, it promptly forwards the request to the customer and does not respond on the substance unless authorised by the customer or required by law. Taking account of the nature of processing and available information, SIA FIXLAB reasonably assists the customer with access, correction, deletion, restriction, portability and objection requests, and with obligations under Articles 32–36 GDPR, including data-protection impact assessments and supervisory-authority consultations.
12. Personal-data breaches
After becoming aware of a confirmed personal-data breach affecting workspace data, SIA FIXLAB notifies the customer without undue delay and takes reasonable steps to contain, investigate and remediate it. As information becomes available, the notice describes the nature of the breach, affected data and approximate categories or numbers where reasonably ascertainable, a contact point, likely consequences and measures taken or proposed. Information may be provided in stages. Notification is not an admission of fault or liability.
13. Public-authority requests
SIA FIXLAB informs the customer of a legally binding request, inquiry or investigation concerning workspace data unless law prohibits notification. SIA FIXLAB reviews the legal basis, limits disclosure to what is required and, where appropriate and legally available, challenges an unlawful or disproportionate request.
14. Subprocessors
The customer gives general written authorisation for the subprocessors listed below. SIA FIXLAB imposes data-protection obligations substantially equivalent to this DPA and remains responsible for the performance of their processing obligations.
Hetzner Online GmbH, Germany/EEA — infrastructure hosting, network, workspace database, private file storage and protected backups. Google Cloud EMEA Limited, Ireland — Firebase Cloud Messaging, only when Android push notifications are enabled; processing is limited to a device push token and the notification or order-event metadata needed for delivery.
SIA FIXLAB gives at least 14 days' advance notice to the account email before a new material workspace subprocessor begins processing, where reasonably possible, and provides its name, location and activity. The customer may object during that period on reasonable data-protection grounds. The parties will seek a practical solution; if none is available, SIA FIXLAB may disable the affected optional function or the customer may terminate the affected service before the change takes effect.
15. International transfers
Primary Zer.lv workspace hosting is in the EEA. If a subprocessor or its approved subprocessor transfers workspace personal data outside the EEA, SIA FIXLAB ensures that the transfer complies with Chapter V GDPR through an applicable adequacy decision, approved Standard Contractual Clauses and supplementary measures where required, or another lawful mechanism. The customer may request information about the applicable mechanism at fixlablv@gmail.com.
16. Return and deletion
During an active subscription the owner can use the available export functions. At the end of processing SIA FIXLAB, at the customer's choice, returns available workspace data in the supported export format or deletes it, unless EU or Latvian law requires retention. Active workspace data is normally deleted within 30 days after a verified deletion request or the end of processing; encrypted backup remnants expire through the rolling backup cycle within 30 days. Data lawfully retained for accounting, security, fraud prevention, dispute or legal-claim purposes is isolated and used only for that purpose.
17. Evidence and audits
SIA FIXLAB provides information reasonably necessary to demonstrate compliance with Article 28 GDPR. Documentation and remote evidence are used first. Subject to confidentiality and security, the customer may conduct a proportionate audit no more than once in any 12-month period with at least 30 days' written notice, during normal business hours and without disrupting other customers. A qualified independent auditor must not be a competitor and must be bound by confidentiality. The customer bears reasonable audit costs, unless the audit identifies a material breach by SIA FIXLAB. Frequency and notice limits do not apply after a material incident, credible indication of non-compliance or a competent authority's request.
18. Termination and contact
If SIA FIXLAB cannot comply with this DPA, it informs the customer and may suspend the affected processing until compliance is restored. The liability and governing-law provisions of the Zer.lv Terms apply without limiting rights or duties that cannot lawfully be limited. Privacy and DPA notices must be sent to fixlablv@gmail.com.