Personal Data Processing Rules for the WebDisk VM Service
Allocation of roles between the parties
Version: 1.0 · Effective from: 2026-07-25
The Polish version is the legally binding version. This English translation is provided for convenience only.
This document sets out the allocation of roles and obligations of the parties as regards the protection of personal data in connection with the use of the WebDisk VM service (hereinafter: "Service"), provided on the terms set out in the VM Terms.
Provider: Mazura sp. z o.o. with its registered office in Ząbki, ul. Baśniowa 1C/2, 05-091 Ząbki, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under number KRS 0000971559, NIP 1251732787, owner of the WebDisk brand.
Customer:
- Name: [Customer name]
- Address: [Address], [Postal code] [City]
- NIP: [VAT ID]
- Email address: [Email]
§1. The nature of the service and personal data protection
1.1. WebDisk VM is an infrastructure as a service (IaaS) offering. The Provider makes available to the Customer compute resources, disk space and network connectivity in the form of a virtual server.
1.2. Exclusive administrative access to the virtual server belongs to the Customer. The Customer independently installs and configures the operating system and the software, decides what data is processed on the server and for what purpose, and independently selects the measures for its protection.
1.3. In the course of ongoing operations the Provider does not obtain access to the data processed inside the virtual server, does not review it, does not index it, does not analyse it and does not use it for its own purposes. The Provider has no knowledge of what categories of data the Customer processes on the server or which persons that data concerns.
§2. Allocation of roles
2.1. The Provider is the controller of personal data in relation to the data connected with the conclusion and performance of the contract for the provision of the Service — account data, billing data and technical operational data of the server. The rules for their processing are set out in the WebDisk VM Privacy Policy.
2.2. The Customer is the controller of personal data processed by it inside the virtual server. Where the Customer processes that data on behalf of third parties, it acts towards them as a processor — on the basis of separate agreements concluded in its own name, to which the Provider is not a party.
2.3. Position of the parties. Given the nature of the Service described in §1, the parties accept that, in relation to the personal data processed by the Customer inside the virtual server, the Provider makes available solely a technical resource and does not process that data on behalf of the Customer within the meaning of Article 28 GDPR. For that reason, the provision of the Service in its basic scope does not require the conclusion of a data processing agreement.
2.4. Conclusion of a data processing agreement at the Customer's request. If the assessment carried out by the Customer — in particular in the course of fulfilling its obligations arising from Articles 24, 28 or 32 GDPR — leads to the conclusion that, in relation to the data stored on the virtual server, it is necessary to conclude a data processing agreement, the Provider shall conclude such an agreement with the Customer at the Customer's request. The request should be submitted to iod@webdisk.io. This provision applies in particular to Customers subject to specific sectoral or audit requirements.
§3. Obligations of the Customer
The Customer undertakes to:
3.1. Process personal data on the virtual server in accordance with the GDPR and other personal data protection provisions, in particular to have a legal basis for the processing.
3.2. Independently fulfil the information obligations towards data subjects and give effect to the rights vested in them (Articles 12–22 GDPR). The Provider has no access to that data and is not able to fulfil such requests.
3.3. Secure the virtual server — in particular to update the operating system and the software, to configure the firewall, to manage accounts and permissions, and also to select and implement technical and organisational measures corresponding to the risk connected with the data processed (Article 32 GDPR).
3.4. Apply data encryption on its own if the data processed requires encryption at rest. The data carriers of the virtual servers and the snapshots are not currently encrypted on the Provider's side (VM Terms, clause 3.4).
3.5. Independently detect, assess and report personal data breaches occurring inside the virtual server — to the supervisory authority and to the data subjects, to the extent that these obligations rest upon it.
3.6. Maintain its own backups of the data processed on the server (VM Terms, clause 4.3).
3.7. Not process on the server data subject to special regulatory regimes without prior written arrangements with the Provider (VM Terms, clause 7.1 letter g).
§4. Security measures applied by the Provider
The Provider applies at the infrastructure layer in particular:
4.1. Access control:
- named accounts of personnel with multi-factor authentication for critical operations,
- administrative access to the production infrastructure solely through a dedicated jump host, with cryptographic key authentication, with session logging,
- no access by the Provider's personnel to the operating system of the Customer's server in the course of ongoing operations,
- separation of the production, test and development environments.
4.2. Isolation: each Customer's server is launched as a separate virtual machine, isolated at the level of the virtualisation layer.
4.3. Logging and monitoring: logging of infrastructure operations (launch and decommissioning of the server, taking and restoring a snapshot, migration, access to the low-level layer) with a retention of 12 months, and security monitoring of the infrastructure on a continuous basis.
4.4. Business continuity: hardware redundancy of the power supply layer, of network connectivity and of the storage for the disks of the virtual servers; rotating snapshots in accordance with the parameters of the plan.
4.5. Location: infrastructure located in the territory of the Republic of Poland; the Provider does not transfer the disks or snapshots of the servers outside the European Economic Area.
4.6. Maintaining the level of security: regular security updates of the infrastructure, periodic security testing and a periodic review of the measures applied, no less frequently than once a year.
§5. Disk images, snapshots and requests from authorities
5.1. Snapshots of the server are taken automatically at the level of the storage layer, without the Provider reading or interpreting their content.
5.2. At the Customer's request, the Provider may make a disk image or a snapshot of the server available to the Customer — insofar as this is technically possible.
5.3. The Provider complies with lawful requests from public authorities which, to the extent technically possible and required by law, may cover the release of a disk image or a snapshot. We inform the Customer about a request if the law permits it.
§6. Deletion of data after the completion of the provision of the Service
6.1. Following the termination or expiry of the contract for the provision of the Service, the Customer independently downloads its data from the server during the grace period set out in the VM Terms (30 days). The Provider does not export the data on the Customer's behalf.
6.2. After the expiry of the grace period or immediately upon the written request of the Customer, the Provider permanently deletes the virtual server together with all its snapshots.
6.3. The Provider retains solely the infrastructure operations log stripped of data from inside the server (for 12 months) and the accounting documentation (for the period required by accounting and tax regulations).
6.4. At the Customer's request, the Provider issues a written confirmation of the deletion of the server and the snapshots.
§7. Personal data breaches
7.1. In the event of a security breach at the infrastructure layer which may affect the Customer's data, the Provider notifies the Customer without undue delay, no later than within 48 hours of becoming aware of the breach, providing information on the nature of the breach, its possible consequences and the remedial measures applied.
7.2. Breaches occurring inside the virtual server — resulting from the operating system, the software, the configuration or the data of the Customer — remain outside the scope of the Provider's knowledge. Their detection, assessment and reporting to the supervisory authority and to the data subjects rest with the Customer.
7.3. Should the Provider obtain information about a breach concerning the Customer's server — in particular on the basis of an abuse report — the Provider shall immediately notify the Customer.
§8. Final provisions
8.1. Amendments. Amendments to this document require documentary form. Notification of the Customer by email together with a requirement of renewed acceptance in the Customer panel is deemed to satisfy that form. We inform about amendments 30 days in advance.
8.2. Precedence. In matters of personal data protection, the provisions of this document take precedence over the VM Terms and the IaaS Terms. Where a data processing agreement is concluded on the basis of §2.4, that agreement takes precedence.
8.3. Language versions. In the event of discrepancies between the Polish and the English version of the document, the Polish version is binding.
8.4. Governing law and jurisdiction of the court. The governing law is Polish law. Disputes are settled by the common court having jurisdiction over the Provider's registered office, subject to the provisions on the jurisdiction of the court in cases involving consumers.
8.5. Acceptance. The document is accepted at the moment of its acceptance in the Customer panel, recorded together with an indication of the version of the document and the moment of acceptance.
8.6. Contact. Personal data protection matters, including a request to conclude a data processing agreement on the basis of §2.4: iod@webdisk.io.
Mazura sp. z o.o. · WebDisk VM · Personal Data Processing Rules — allocation of roles between the parties · version 1.0 · effective from 2026-07-25
Version 1.0 · EN