Data Processing Agreement
Last updated 21 September 2026
Between the organisation that uses one of our products for its people (the Customer, the controller) and Human Hygiene Kft., 1163 Budapest, Datolya utca 40., Hungary (company registration number 01-09-464537, Company Registry Court of Budapest (Fővárosi Törvényszék Cégbírósága); EU VAT number HU12087783), which runs mixtape.works (we, the processor). Version 1.0, in force from 21 September 2026. It forms part of the Terms.
It covers Voks and Dayrule: the personal data the Customer puts into them about its people (Customer Personal Data). For data where we are the controller ourselves — your mixtape account, and visitors to our sites — the privacy page applies instead. On data protection, this agreement prevails over the Terms.
The Customer accepts it when a person creates a workplace (Voks) or a company account (Dayrule) on its behalf; that person confirms they may. A Customer that wants a signed copy can ask at [email protected].
1. Roles
1.1 For Customer Personal Data the Customer is the controller and we are the processor, under Article 28 of Regulation (EU) 2016/679 (the GDPR). Words defined in the GDPR have the same meaning here.
1.2 The Customer decides whom it invites or adds, what it records, and who holds which role, and sets the retention period where the product has one. It is responsible for having a lawful basis for the processing — including a condition under Article 9 where it records special categories of data (in Dayrule: a child’s disability, and sick leave) — and for informing its people.
2. Instructions
2.1 We process Customer Personal Data only on the Customer’s documented instructions: this agreement, the Terms, the Customer’s settings and use of the product, and written requests to [email protected]. If EU or Member State law requires otherwise, we tell the Customer first, unless that law forbids it.
2.2 We tell the Customer without delay if, in our opinion, an instruction infringes data protection law.
3. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality, by contract or by law. Access to it is limited to the founders of mixtape.works who run the service.
4. Security
4.1 We apply the technical and organisational measures in Annex 2, which are designed to give a level of security appropriate to the risk (GDPR Article 32).
4.2 We may change them, provided the level of security is not reduced.
5. Sub-processors
5.1 The Customer authorises the sub-processors listed in Annex 3.
5.2 We tell the Customer at least 30 days before adding or replacing one, on this page and by email to the address its workplace or company account was created with. The Customer may object on reasonable data protection grounds within that time; if we cannot resolve the objection, the Customer may stop using the product without penalty.
5.3 We impose on each sub-processor, by contract, data protection obligations that are the same in substance as these, and remain liable to the Customer for their performance.
6. Transfers outside the EEA
We transfer Customer Personal Data outside the European Economic Area only to the sub-processors in Annex 3, and only on the basis of an adequacy decision (including the EU–US Data Privacy Framework, where the sub-processor is certified under it) or of the European Commission’s standard contractual clauses (GDPR Article 46).
7. Helping the Customer
7.1 People’s rights. Taking into account the nature of the processing, we help the Customer answer requests from its people to exercise their rights. In Voks, anonymous posts on the idea wall are by design not linked to any person: they cannot be found, exported or deleted “for” a named person, by the Customer or by us. What is linked to a person — their name, address, role, votes and reports — can be.
7.2 Other obligations. We help the Customer with its obligations under GDPR Articles 32 to 36 (security, breach notification, impact assessments, prior consultation), taking into account the nature of the processing and the information available to us.
8. Personal data breaches
8.1 We notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notice describes, as far as then known, the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. What is not yet known follows as soon as it is.
9. When the Customer stops
When the Customer stops using a product, we delete its Customer Personal Data in that product within 30 days, and from our backups as they expire (they are kept for at most 14 days), unless EU or Member State law requires us to keep it. Before deletion, and at the Customer’s request, we provide an export: the walls in CSV (Voks), or the people and their absences in CSV (Dayrule).
10. Information and audits
We make available the information needed to show compliance with GDPR Article 28, and allow for and contribute to audits, including inspections, by the Customer or an auditor it mandates, on reasonable notice and at the Customer’s cost. A product’s database schema and the automated tests that enforce what Annex 2 promises are available on request.
11. Liability
Each party’s liability under this agreement is subject to the limitations in the Terms, except where data protection law does not allow them. Nothing here affects a person’s statutory rights or a supervisory authority’s powers.
12. Term, law and language
This agreement applies for as long as we process Customer Personal Data. Hungarian law governs it, and the Hungarian courts competent for our registered seat have jurisdiction. It is written in English, which is the version that binds; the Hungarian text is a translation.
Annex 1 — The processing
Subject matter and duration. Providing the product to the Customer, for as long as it uses it and the 30 days in clause 9.
Voks
Nature and purpose. Two walls for the Customer’s staff, reached through a QR code on an office wall: an idea wall where problems are posted anonymously as a problem and its fix and ranked with a monthly allowance of points, and a managers’ board where managers post under their own names; and running the Customer’s workplace — inviting staff, assigning roles, moderating posts — which the Customer’s owner does from their own console, and we do on the Customer’s request.
People concerned. The Customer’s employees and other staff it invites, including managers and moderators, and the Customer’s owner.
| Data | Comes from | Kept |
|---|---|---|
| Name and work email address of each invited person | The Customer | Until the person is removed or the Customer stops |
| The owner's email address and name, as their mixtape account confirms them | The owner, on signing up | Until the Customer stops |
| Role (owner, colleague, moderator, manager) | The Customer | As above |
| When a person's sign-in link was used | The product | As above |
| Session cookie, a random token | The product | 90 days, or until sign-out |
| Votes: who gave how many points to which idea, per month | The person voting | Until the idea is deleted |
| Reports: who reported which post | The person reporting | Until the post is kept, hidden and restored, or deleted |
| Managers' board posts, with their author's name | The manager | Until the retention period ends or the post is deleted |
| Idea wall posts — not linked to any person | Anonymous | Until the retention period ends or the post is deleted |
| A moderator's reason for hiding a post | The moderator | With the post |
Not collected. No IP address, no browser or device identifier, no location, no request log, and nothing that links an idea wall post to the person who wrote it: an anonymous post is held with a random per-device token that is itself linked to nobody.
Free text. A person may write anything in a post — including, against the product’s purpose, health, beliefs or other special categories of data, or things about named people. The Customer’s owner and moderators can hide such a post; the owner can delete it, and we delete it on the Customer’s request.
Retention. Posts are deleted automatically when they are older than the retention period the Customer sets (12 months unless changed), with their votes and reports.
Dayrule
Nature and purpose. Keeping the Customer’s leave records: people ask for time off, a manager or owner decides, and balances are counted against the leave rules and public holidays of the country each person works in; a monthly export for payroll.
People concerned. The Customer’s employees and other staff it adds, their managers, the Customer’s owners, and — where the entitlement depends on them — the children of employees.
| Data | Comes from | Kept |
|---|---|---|
| Each person: name, email address, country, start date and last day, full or part time, manager | The Customer | As long as the company account exists |
| Date of birth, where the country's rules use age | The Customer | As above |
| A child’s date of birth, and whether the child has a disability (health data) | The Customer | As above |
| Payroll id, if the Customer adds one | The Customer | As above |
| Leave requests: dates, half days, type (annual, sick — health data — or unpaid), notes, who decided, when and why | The person asking; the person deciding | As above |
| Login: email address (as the person's mixtape account confirms it) and role (owner, manager, employee) | The Customer; the person | As above; it stops working the day after the last day |
| Sign-in links, stored only as a hash | The product | 14 days, or until used |
| Session cookie, a random token stored only as a hash | The product | 30 days, or until log-out |
Not collected. No IP address, no device identifier, no request log, no analytics.
Retention. People are not deleted when they leave, so that past balances and payroll exports keep adding up. We delete a person, or the Customer’s whole account, on the Customer’s request.
Annex 2 — Technical and organisational measures
In every product
- Encryption in transit. All traffic is served over HTTPS (TLS).
- Sign-in. Through the mixtape account (OpenID Connect with PKCE; tokens verified cryptographically). The products keep no passwords. Staff come in through a single-use link.
- Minimisation. No IP addresses, device identifiers or request logs are stored or read; automated tests fail the build if code reads them.
- Isolation. Each product runs in its own container, with a read-only file system, no added privileges, all Linux capabilities dropped, and memory and process limits.
- No third-party code in the browser. No analytics, advertising or third-party scripts.
- Backups. A consistent snapshot of each product’s database every night, kept for 14 days on the same server.
- Access. Limited to the founders who run the service.
- Incidents. Handled by the founders; breaches notified under clause 8.
Voks
- Anonymity by construction. The database cannot store an idea wall post with a person attached: two database constraints require an anonymous token and forbid a member, and automated tests check this against the live schema.
- Moderation. The owner and moderators can hide a post, with a reason that stays visible in its place; only the owner, or we on request, delete one.
- Retention. Enforced automatically, several times a day.
Dayrule
- Company scoping. Every query is scoped to one company, and a session is honoured only for the company it was issued in.
- Roles. A manager sees only the people who report to them; only an owner changes roles and settings.
- Links and sessions. A sign-in link works once, expires after 14 days, and only for the address it was made for. Links and sessions are stored only as hashes.
Annex 3 — Sub-processors
| Sub-processor | Where | What it does |
|---|---|---|
| Hetzner Online GmbH | Germany (EU); our servers are in Helsinki, Finland (EU) | Hosts the servers and databases the products run on |
| Cloudflare, Inc. | United States | Carries traffic to and from the internet: network, TLS, protection against attacks |
Questions about this agreement: [email protected].