Data Processing Agreement
Version 14 September 2026 · English only
This Data Processing Agreement ("DPA") forms part of the TeamMatch Terms of Service between the business customer ("Customer") and Tesla Solution d.o.o., Pavlovec Zabočki 19A, Pavlovec Zabočki, Republic of Croatia, OIB 77355791759 ("Tesla Solution").
It applies where Tesla Solution processes personal data on behalf of the Customer, in particular personal data that the Customer enters or uploads into TeamMatch Office. For such data the Customer acts as Controller and Tesla Solution acts as Processor within the meaning of Regulation (EU) 2016/679 (GDPR).
Where Tesla Solution processes personal data for its own purposes (for example account administration, billing, platform security and service improvement), Tesla Solution acts as Controller and the Privacy Policy applies instead of this DPA.
1. Subject matter, duration and nature of processing
Tesla Solution processes Customer personal data to provide the TeamMatch platform and the TeamMatch Office functionality: hosting, storage, display, retrieval, structuring, backup, support and deletion, as instructed by the Customer through the use of the service.
Processing lasts for the duration of the Customer's use of the service and the subsequent retention period described below.
2. Categories of data subjects and personal data
- Data subjects: the Customer's employees, workers, subcontractors, contact persons and other individuals whose data the Customer chooses to enter.
- Personal data: identification and contact data; employment-related data; worker documents such as identity documents, passports, A1 certificates, work permits, driving licences, certificates and qualifications, and their expiry dates; timesheets and working-time records; project assignments; internal compensation and hourly-rate information; accommodation allocation information.
- Special categories of data are not required by the service. The Customer must not upload special-category data unless it has a valid legal basis under Article 9 GDPR and has taken appropriate safeguards.
3. Customer obligations
- The Customer determines the purposes and means of the processing it carries out in TeamMatch Office.
- The Customer warrants it has a lawful basis for uploading each category of data, has informed the data subjects, and applies data minimisation.
- The Customer is responsible for the accuracy of the data and for responding to data subject requests relating to it.
4. Tesla Solution obligations
- process personal data only on documented instructions from the Customer, including the instructions inherent in the Customer's use of the service, unless required otherwise by Union or Member State law;
- ensure that persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures, taking into account the state of the art, the costs of implementation and the risks to data subjects;
- assist the Customer, taking into account the nature of the processing, with data subject requests and with obligations under Articles 32 to 36 GDPR;
- notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data;
- at the Customer's choice, delete or return the personal data at the end of the service, unless storage is required by law;
- make available the information reasonably necessary to demonstrate compliance with this DPA and allow for audits, which may be satisfied by written information where an on-site audit would be disproportionate.
5. Restricted administrative access to Customer documents
Documents uploaded by the Customer into TeamMatch Office, including identity documents, passports, A1 certificates, work permits and other worker documents, are stored in private storage and are not treated as documents routinely accessible to TeamMatch personnel.
Administrative access is restricted to specifically authorised personnel, applying the principle of least privilege, and only where reasonably necessary for one of the following purposes:
- support requested by the Customer;
- resolving a technical problem affecting the service;
- investigating a security incident;
- preventing fraud or abuse;
- fulfilling documented instructions of the Customer;
- complying with a binding legal obligation.
6. Honest statement about technical access
Tesla Solution does not claim that it is technically impossible for it to access Customer documents. Administrative and infrastructure-level access is technically possible and is controlled by organisational restrictions and access limitation as described above. Tesla Solution does not claim that privileged-access audit logging is in place beyond the logging actually provided by the underlying infrastructure.
7. Sub-processors
The Customer grants a general authorisation for the use of sub-processors. Tesla Solution remains fully liable for the performance of its sub-processors and imposes data protection obligations on them that are no less protective than those in this DPA. Tesla Solution will inform the Customer of intended changes to sub-processors and give the Customer the opportunity to object on reasonable data protection grounds.
The service providers currently used to operate TeamMatch are listed in the separate section below. Where a provider is a hosting or infrastructure provider, the processing locations are determined by that provider's configuration for this project.
8. Service providers currently used (verified from the production configuration)
Corporate entity details, processing locations and international transfer mechanisms of these providers must be confirmed with each provider before production launch and will then be documented here.
- Lovable Cloud (managed Supabase infrastructure) – application hosting, database, authentication and private file storage.
- Stripe – subscription payments, invoicing and tax calculation.
- Lovable AI Gateway (Google Gemini models) – AI-assisted parsing of request text and AI-assisted extraction of data from uploaded documents, when the Customer uses that functionality.
- Mailgun – processing of inbound email sent to TeamMatch email addresses.
- European Commission VIES service – verification of VAT identification numbers (company data, not worker data).
9. International transfers
Where a sub-processor processes personal data outside the European Economic Area, such transfer takes place only on the basis of a valid transfer mechanism under Chapter V GDPR, such as an adequacy decision or Standard Contractual Clauses concluded with that provider.
10. Retention and deletion
Customer personal data is retained while the Customer's account exists. After termination it is deleted or returned upon the Customer's request, except where retention is required by law. Backups are overwritten in the ordinary cycle of the infrastructure provider.
11. Liability and order of precedence
Liability under this DPA follows the liability provisions of the Terms of Service, subject to mandatory GDPR liability rules. In the event of conflict between this DPA and the Terms of Service regarding the processing of Customer personal data, this DPA prevails.
12. Contact
Data protection contact: requests@teammatch.eu — Tesla Solution d.o.o., Pavlovec Zabočki 19A, Pavlovec Zabočki, Republic of Croatia.
See also the Privacy Policy and the Terms of Service.
