Data Processing Agreement
Last updated: 24 July 2026
Data Processing Agreement:
1. Scope
This Data Processing Agreement (“DPA”) forms part of the agreement between TopLeader s.r.o. (“TopLeader” or “Processor”) and the organisation using the TopLeader Services (“Customer” or “Controller”).
It applies where TopLeader processes personal data on behalf of the Customer in connection with the TopLeader leadership development platform and related services.
In case of conflict concerning the processing of personal data, this DPA takes precedence over the general Terms & Conditions. A specifically negotiated data processing agreement signed by the parties takes precedence over this public DPA.
2. Roles of the parties
The Customer acts as Controller and determines the purposes and lawful basis of the processing.
TopLeader acts as Processor and processes Customer Personal Data only:
-
on documented instructions from the Customer;
-
as necessary to provide the Services;
-
as required by applicable law.
TopLeader will inform the Customer if it reasonably believes that an instruction infringes applicable data protection law.
3. Customer obligations
The Customer is responsible for:
-
the lawfulness, accuracy and quality of Customer Personal Data;
-
providing required information to data subjects;
-
establishing an appropriate legal basis for processing;
-
ensuring that instructions to TopLeader comply with law;
-
determining which data may be processed through the Services;
-
avoiding the submission of unnecessary special-category personal data;
-
communicating the reporting and confidentiality boundary to participants.
4. Confidentiality
TopLeader ensures that persons authorised to process Customer Personal Data:
-
are subject to confidentiality obligations;
-
process data only on a need-to-know basis;
-
receive appropriate instructions concerning privacy and security.
Experts receive access only to the information reasonably required to provide the relevant expert service.
5. Security
TopLeader maintains appropriate technical and organisational measures having regard to:
-
the state of the art;
-
implementation costs;
-
the nature, scope, context and purposes of processing;
-
the likelihood and severity of risks to individuals.
Measures include, as appropriate:
-
role-based access control;
-
authentication and account-security measures;
-
encryption in transit and at rest;
-
logical separation of customer data;
-
logging and monitoring;
-
backup and recovery procedures;
-
vulnerability and dependency management;
-
confidentiality controls;
-
incident-response procedures;
-
secure development and change-management practices.
TopLeader may update its security measures provided that the overall level of protection is not materially reduced.
6. Sub-processors
The Customer grants TopLeader general authorisation to engage sub-processors necessary to provide the Services.
TopLeader will:
-
impose data protection obligations on sub-processors that are no less protective than the relevant obligations in this DPA;
-
remain responsible for the performance of its sub-processors to the extent required by applicable law;
-
provide information about current sub-processors on request;
-
notify the Customer of material intended changes to sub-processors where required by the applicable Agreement.
The Customer may object to a new sub-processor on reasonable data-protection grounds. The parties will work in good faith to resolve the objection.
7. International transfers
TopLeader will not transfer Customer Personal Data outside the EEA unless an appropriate legal mechanism applies.
Such mechanisms may include:
-
an adequacy decision;
-
the European Commission’s Standard Contractual Clauses;
-
another mechanism permitted by applicable data protection law.
Where required, the parties agree that the appropriate module of the Standard Contractual Clauses is incorporated into this DPA.
8. Data-subject requests
Where TopLeader receives a request from a data subject concerning Customer Personal Data, TopLeader will:
-
notify the Customer where legally permitted;
-
not respond substantively unless instructed by the Customer or required by law;
-
provide reasonable assistance to enable the Customer to respond.
The Customer remains responsible for responding to the request.
9. Personal data breaches
TopLeader will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The notification will include available information reasonably required to help the Customer fulfil its legal obligations, including where known:
-
the nature of the breach;
-
affected categories of data and data subjects;
-
likely consequences;
-
measures taken or proposed;
-
a contact point for further information.
Notification does not constitute an admission of fault or liability.
10. Compliance assistance
Taking into account the nature of the processing and information available to TopLeader, TopLeader will provide reasonable assistance with:
-
data-subject rights;
-
security obligations;
-
breach notification;
-
data protection impact assessments;
-
consultation with supervisory authorities.
Additional assistance outside the normal Services may be subject to reasonable fees.
11. Return and deletion
During the Agreement, the Customer may request an export of Customer Personal Data reasonably available through the Services.
After termination, TopLeader will delete or return Customer Personal Data in accordance with the Customer’s instructions.
Unless otherwise agreed or required by law, TopLeader will complete deletion within six months after termination.
Personal data may remain temporarily in secured backups until overwritten under the normal backup cycle.
TopLeader may retain data where required by law, provided that it remains protected and is processed only for the legally required purpose.
12. Audits and information
TopLeader will provide information reasonably necessary to demonstrate compliance with this DPA.
The Customer should first use available documentation, questionnaires, security materials and remote review.
Where this is insufficient and the Customer has reasonable grounds to suspect material non-compliance, the Customer may request an audit:
-
no more than once per year, unless required following a serious incident or by a supervisory authority;
-
with reasonable advance notice;
-
during normal business hours;
-
in a manner that protects other customers and confidential systems;
-
by an independent auditor subject to confidentiality.
The Customer bears its audit costs unless the audit identifies a material breach by TopLeader.
13. Liability
Liability arising under this DPA is subject to the limitations and exclusions in the applicable Agreement, except where such limitation is prohibited by mandatory law.
14. Duration
This DPA remains in effect for as long as TopLeader processes Customer Personal Data on behalf of the Customer.
Annex 1 — Details of processing
Subject matter
Provision of the TopLeader leadership development platform, configured Programs, expert services and related support.
Duration
For the duration of the applicable Agreement and the subsequent deletion period.
Nature and purposes
Processing may include collection, recording, organisation, storage, consultation, use, transmission, restriction, export and deletion as necessary to provide the Services.
Purposes include:
-
account creation and administration;
-
delivery of leadership and talent Programs;
-
weekly practice, learning and reflection;
-
diagnostics and feedback;
-
management of coaching or mentoring sessions;
-
communication and support;
-
program-level progress and participation reporting;
-
security, troubleshooting and service operation.
Categories of data subjects
-
Program participants;
-
Customer administrators and program sponsors;
-
employees or contractors of the Customer;
-
Experts;
-
support and business contacts.
Categories of personal data
-
name and professional contact information;
-
employer, role, language and time zone;
-
account and profile information;
-
authentication and technical data;
-
Program membership and participation;
-
goals, milestones and weekly activity status;
-
assessments and feedback;
-
session allocation, booking and attendance metadata;
-
messages and support communications;
-
security and audit logs.
Special-category data
The Services are not intended for systematic processing of special-category personal data.
The Customer must not instruct Users to provide such data unless:
-
it is necessary for a specifically agreed purpose;
-
a valid legal basis and Article 9 condition apply;
-
appropriate safeguards have been agreed.
Annex 2 — Security measures
TopLeader’s measures include, as appropriate:
-
role-based and least-privilege access;
-
secure authentication;
-
encrypted communications;
-
encryption of stored production data;
-
customer-data separation;
-
controlled production access;
-
system and security logging;
-
backups and recovery processes;
-
dependency and vulnerability management;
-
secure development practices;
-
confidentiality agreements;
-
incident detection and response;
-
access revocation during offboarding;
-
periodic review of security and privacy measures.