1. Subject matter and duration
The processor provides hosting, transmission, display, reporting, backup, support and maintenance of LIO for the controller. Processing continues for the contractual term and afterwards only as required for agreed export, return or secure deletion and compliance with legal duties.
2. Purpose and nature
Data is processed for machine monitoring, production results, targets, alarms, maintenance, user accounts, access sharing, reports, support, diagnostics and security. The processor does not use it for its own advertising or for a purpose incompatible with the controller’s documented instructions.
3. Data subjects and data types
Data subjects may include employees, contractors, administrators, service personnel and other authorised users. Data may include name, business email, role, account identifier, technical logs, IP address, assigned modules, production and maintenance data, and notes entered by the controller. Special-category data is not intended and must not be entered without a specific written agreement and valid legal basis.
4. Instructions
The processor acts only on documented instructions, including these terms, service settings, support requests and the main agreement, unless processing is required by law. If an instruction appears to infringe data protection law, the processor will inform the controller and may suspend it.
5. Confidentiality and access
Access is limited to authorised personnel who need it for their work and are bound by confidentiality. Least privilege, customer separation, control of administrative access and protection of authentication and infrastructure secrets are applied.
6. Security
Risk-appropriate measures include encrypted transmission, access controls, secure password and secret storage, backups, availability monitoring, updates, logging of important actions, recovery procedures and regular security review. The controller remains responsible for its users, permissions, network, modules and safe machine integration.
7. Sub-processors
The controller grants general authorisation for vetted hosting, email, push notification and other providers supporting enabled features. Current categories include Hetzner hosting, Firebase push notifications and the configured email provider; an AI provider is used only when an AI feature is enabled. The controller will be informed of material additions or replacements and may raise a reasoned objection.
8. International transfers
If a sub-processor handles data outside the EEA, a valid GDPR Chapter V mechanism will be used, such as an adequacy decision or Standard Contractual Clauses, with supplementary safeguards where required.
9. Assistance
Taking account of the nature of processing, the processor assists with data-subject requests, security, impact assessments, supervisory consultation and demonstrating compliance. Requests concerning controller data are normally forwarded to the controller and not answered substantively without its instructions.
10. Personal data breaches
The processor informs the controller without undue delay after confirming a personal data breach and supplies available information needed to assess risk and meet notification duties.
11. Return, deletion and backups
After termination, the processor returns or deletes personal data at the controller’s choice unless law requires retention. Backups are removed through the normal retention cycle and remain protected from ordinary use until then.
12. Information and audits
The processor makes reasonably necessary compliance information available and permits contractually agreed audits. Audits must protect system security, confidential information and other customers’ data and must not unreasonably disrupt the service.
13. Controller responsibilities
The controller is responsible for lawful collection and instructions, notices to employees and others, valid legal bases, data accuracy, user permissions, and ensuring LIO is not used for disproportionate or covert employee monitoring.
14. Order of precedence
A specifically negotiated provision in a signed main agreement or separate DPA prevails where it addresses the same issue. Otherwise the LIO Terms of Service and Slovenian law apply.