DATA PROCESSING AGREEMENT

The Controller and the Processor have entered into an Agreement. In the performance of the Agreement, the Processor shall process personal data on behalf of the Controller. The Parties, also in view of Article 28(3) of the General Data Protection Regulation (GDPR), wish to record in this Data Processing Agreement their mutual rights and obligations under the GDPR and other Applicable Laws and Regulations regarding the Processing of Personal Data. This Data Processing Agreement forms an integral and inseparable part of the Agreement and the General Terms and Conditions.

Article 2. Definitions

In this Data Processing Agreement, the following terms shall have the meaning assigned to them below:

  • Data Subject, Processor, Third Party, Personal Data, Processing, and Controller: the terms as defined in the GDPR.
  • Data Processing Agreement: this agreement, including the Annexes, between Controller and Processor, in which their mutual rights and obligations with regard to the Processing of Personal Data are set out.
  • Annex: an annex to this Data Processing Agreement, which forms an integral part thereof.
  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data, as referred to in Article 4(12) GDPR.
  • Sub-processor: the party engaged by the Processor as a processor for the (further) Processing of Personal Data in the context of this Data Processing Agreement.
  • GDPR: the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC) (OJ EU 2016, L 119).
  • Applicable Laws and Regulations regarding the Processing of Personal Data: the GDPR and other applicable (Union and national) laws and regulations and/or (further) treaties, regulations, directives, decisions, policies, instructions, and/or recommendations of a competent authority regarding the Processing of Personal Data, including national implementing laws of the GDPR and the Dutch Telecommunications Act.
  • In Writing: in written form or electronically, as referred to in Article 6:227a of the Dutch Civil Code.

3. DATA PROCESSING AGREEMENT

3.1 This data processing agreement applies to the processing of personal data in the context of the performance of the agreement. 3.2 The controller issues the processor with instructions to process personal data on behalf of the controller for the performance of the agreement. The instructions of the controller are further described in this data processing agreement and in the agreement. 3.3 The provisions of the data processing agreement apply to all processing carried out in the performance of the agreement. The processor shall immediately inform the controller if the processor has reason to believe that it can no longer comply with the data processing agreement.

4. ROLES

4.1 With regard to the Processing of Personal Data carried out on its instructions, the Controller shall be regarded as the Controller within the meaning of the GDPR. The Processor shall be regarded as the Processor within the meaning of the GDPR. The Controller shall retain independent authority over the determination of the purposes and means of the Processing of Personal Data. 4.2 The Processor shall ensure that the Controller is adequately informed in advance of entering into this Data Processing Agreement regarding the service(s) provided by the Processor and the Processing to be carried out. 4.3 The information provided shall enable the Controller to understand which Processing activities are associated with a proposed service. 4.4 The Processor shall inform the Controller in Annex 1 of the services referred to in paragraph 2 of this Article and of the Processing carried out in that context. 4.5 The Controller shall record the Processing of Personal Data referred to in paragraph 2 of this Article in a register of processing activities carried out under its responsibility. 4.6 To the extent required by Article 30(5) GDPR, the Processor shall keep a register of all categories of Processing activities carried out on behalf of the Controller in accordance with Article 30(2) GDPR. 4.7 The Controller and Processor shall provide each other with all necessary information in order to ensure proper compliance with the Applicable Laws and Regulations regarding the Processing of Personal Data.

5. USE OF PERSONAL DATA

5.1 The Processor undertakes not to process the Personal Data received from the Controller for purposes and/or by means other than those necessary for the performance of the Agreement. 5.2 The Processor shall therefore not carry out any Processing other than those instructed by the Controller in the context of the Agreement, unless a provision of Union or Member State law applicable to the Processor requires the Processor to process Personal Data. In that case, the Processor shall inform the Controller in writing prior to the Processing of that provision, unless such legislation prohibits such notification on important grounds of public interest. 5.3 An overview of, among other things, the categories of Personal Data and the purposes for which the Personal Data are processed is set out in our information sheet (Annex 1). 5.4 The Processor shall refrain from providing Personal Data to any Third Party, unless such provision takes place on the instructions of the Controller or is necessary to comply with a legal obligation incumbent on the Processor.

6. CONFIDENTIALITY

6.1 The Processor shall ensure that all persons (including its employees, representatives, and/or Sub-processors) involved in the Processing of Personal Data treat such Personal Data as confidential. 6.2 The Processor shall ensure that persons authorized by it to process the Personal Data are bound by a confidentiality agreement or clause, or are otherwise bound by a statutory duty of confidentiality. 6.3 The duty of confidentiality referred to in this Article shall not apply to the extent that: the Controller has given express written consent to disclose the Personal Data to a Third Party; disclosure of the Personal Data to a Third Party is necessary in view of the nature of the services to be provided by the Processor to the Controller; or a mandatory legal provision or court order requires the Parties to disclose such Personal Data.

7. SECURITY AND SUPERVISION

7.1 The Processor guarantees that it will take appropriate technical and organizational measures as referred to in Article 32 GDPR to secure and protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. 7.2 The measures referred to in Article 7.1 shall, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing as well as the varying likelihood and severity of the risks to the rights and freedoms of natural persons, ensure a level of security appropriate to the risk. 7.3 The Processor shall periodically evaluate the information security measures it has taken and shall tighten, supplement, or improve them where requirements or (technological) developments so warrant. 7.4 The Processor shall enable the Controller to comply with its legal obligation to supervise the Processor’s compliance with this Data Processing Agreement, particularly the technical and organizational security measures and the obligations concerning Personal Data Breaches referred to in Article 8 of this Agreement. 7.5 The Controller shall have the right, in consultation with the Processor and subject to reasonable notice, to verify compliance with the Applicable Laws and Regulations on the Processing of Personal Data, the Agreement, and this Data Processing Agreement, by means of an audit conducted by an independent certified external expert.

8. PERSONAL DATA BREACHES

8.1 The Processor and the Controller shall maintain an appropriate policy for dealing with Personal Data Breaches. 8.2 If the Processor detects a Personal Data Breach, it shall notify the Controller thereof without undue delay after becoming aware of it. 8.3 The Processor shall immediately inform the Controller if the security breach is likely to result in a high risk to the rights and freedoms of natural persons as referred to in Article 34(1) GDPR. 8.4 In the event of a Personal Data Breach, the Processor shall enable the Controller to take appropriate follow-up steps regarding the breach. 8.5 In the event of a Personal Data Breach, the Controller shall comply with any statutory notification obligations to the Dutch Data Protection Authority and Data Subjects.

9. ASSISTANCE

The Processor shall assist the Controller in fulfilling its obligations under the GDPR and other Applicable Laws and Regulations regarding the Processing of Personal Data, including but not limited to:

  • responding in a timely manner to requests by Data Subjects to exercise their rights under Chapter III of the GDPR;
  • carrying out inspections and audits as referred to in Article 7 of this Data Processing Agreement;
  • carrying out a data protection impact assessment (DPIA);
  • complying with requests from the Data Protection Authority or any other government body;
  • reporting Personal Data Breaches as referred to in Article 8 of this Data Processing Agreement.

10. TRANSFER TO A THIRD COUNTRY OR INTERNATIONAL ORGANIZATION

10.1 The Processor shall only be permitted to transfer Personal Data to a third country (countries outside the European Economic Area) or international organization if the Controller has given specific written consent. 10.2 If Personal Data are transferred to third countries or an international organization, this shall be indicated in Annex 1 to this Data Processing Agreement.

11. USE OF SUB-PROCESSORS

11.1 The Controller grants the Processor permission to engage Sub-processors, whose identity and registered details are listed in Annex 1. 11.2 Upon the Controller’s first request, the Processor shall provide the Controller with an overview of the Sub-processors engaged by the Processor. 11.3 The Processor shall be obliged to impose at least the same data protection obligations on each Sub-processor through a contract or other legal act as are imposed on the Processor under this Data Processing Agreement. 11.4 The Controller may withdraw its written consent for the engagement of a Sub-processor if the Processor does not comply with the obligations of this Data Processing Agreement.

12. RETENTION AND DELETION OF PERSONAL DATA

12.1 The Controller shall adequately inform the Processor of statutory retention periods applicable to the Processing of Personal Data by the Processor. 12.2 The Controller shall require the Processor to delete the Personal Data processed on behalf of the Controller upon termination of this Data Processing Agreement.

13. CONFLICTS AND AMENDMENTS

13.1 This Data Processing Agreement supplements the Agreement and replaces any previous arrangements between the Parties regarding the Processing of Personal Data. 13.2 Amendments and additions to this Data Processing Agreement shall only be valid if they are made in writing and both Parties have expressly agreed in writing to the amendments or additions.

14. LIABILITY

14.1 The Processor shall only be liable for direct damage suffered by the Controller as a result of an attributable failure to comply with this Data Processing Agreement or a violation of the GDPR or other Applicable Laws and Regulations. 14.2 The liability of the Processor shall be limited to the amount paid out in the relevant case under the Processor’s liability insurance.

15. TERM AND TERMINATION

15.1 The term of this Data Processing Agreement shall be equal to the term of the Agreement entered into between the Parties. 15.2 This Data Processing Agreement shall terminate automatically upon termination of the Agreement.

16. JURISDICTION AND APPLICABLE LAW

This Data Processing Agreement shall be governed exclusively by Dutch law.

17. GOVERNING LAW AND LANGUAGE

This English version of the Data Processing Agreement is provided for convenience only. In case of any discrepancies or interpretation issues, the original Dutch version shall prevail.

ANNEX 1: PRIVACY INFORMATION SHEET COMMUNICATION PLATFORM

The Controller provides a service whereby agents can interactively maintain contact with customers via various communication channels.

Data processing

  • Company names, numbers, VAT numbers, address details, telephone numbers.
  • Email addresses, usernames, (encrypted) passwords, IP addresses, balances, expenditures, messages, visitor interaction logs, call recordings (optional) of Visitors.

Categories of Personal Data

  • Authentication personal data: login names, passwords.
  • Confidential communication customer data: messages, emails, call recordings.
  • Confidential specific customer data: company names, numbers, address, IBAN, VAT number, identity documents, etc.

Retention periods

Systematix Solutions does not retain confidential data longer than strictly necessary to achieve the purposes of optimal service provision, conforming to legal requirements.

Sub-processors

  • Equinix AM5: hosting, storage, registrations
  • Pay: online payments
  • Global Premium Telecom: implementation of service numbers and telephony
  • PayPal (Europe): online payments

ANNEX 2: SECURITY ANNEX

The Processor is obliged under the GDPR and Articles 6 and 7 of this Data Processing Agreement to take appropriate technical and organizational measures to secure the Processing of Personal Data.