This Annex sets out the mutual rights and obligations of the Customer (as "Controller") and Claritalk (as "Processor") regarding the Processing of Personal Data by Claritalk, in accordance with Data Protection Legislation. The Dutch version is the legally binding text; this translation is provided for convenience.
Article 1 Definitions
The terms used in this Data Processing Agreement have the following meaning:
- 1.1 GDPR: Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC;
- 1.2 Data Subject: the natural person to whom Personal Data relates;
- 1.3 End Customers: the customers of the Customer;
- 1.4 Agreement: the Claritalk Agreement under which the Controller has instructed the Processor to carry out Processing;
- 1.5 DPA or Data Processing Agreement: this Annex 2;
- 1.6 Personal Data: any information relating to an identified or identifiable natural person that the Processor receives from the Controller under the Agreement and must Process;
- 1.7 Process/Processing: any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- 1.8 Controller: the Customer that has entered into a Claritalk Agreement with Claritalk;
- 1.9 Processor: SalesNote BV (Claritalk), registered with the Crossroads Bank for Enterprises under number 0765.323.961, with registered office at Staatsbaan 305, 9870 Zulte, Belgium.
Article 2 Applicability
2.1 Unless the Parties have agreed otherwise in writing, this Data Processing Agreement applies to all Processing of Personal Data by the Processor under the Agreement. In the event of any conflict or inconsistency between this Data Processing Agreement and the Agreement, this Data Processing Agreement prevails.
Article 3 Basic information on the Processing
3.1 In performing the Agreement, the Processor has access to certain Personal Data of specific categories of Data Subjects (see article 3.3). This Processing serves solely to perform the Agreement.
3.2 The Processor may Process the Personal Data provided by the Controller for as long as necessary to carry out the assignment defined in the Agreement. Once the assignment has been completed, the Processor immediately ceases any use of the Personal Data other than what is necessary to allow the Controller to recover the data entrusted to the Processor and to use the data resulting from the processing entrusted to the Processor.
3.3 The types of Personal Data processed per category of Data Subject can be described as follows:
The End User
- Name (initials, first name, surname, title, company name)
- Billing address
- Mobile number, email, website
- IBAN, payment method
- Customer number
- Contracts
- Invoices
- Payments
The Customer
- Company name
- VAT number
- Address details
- Bank account number
- Telephone number
- System user information: first name and surname, email address (also used as login), one-way encrypted password, telephone number
3.4 The rights and obligations of the Controller are set out in this Data Processing Agreement.
Article 4 Processing by the Processor
4.1 The Processor only Processes the Personal Data on the basis of written instructions from the Controller, save for deviating legal obligations and deviating requests from Data Subjects; in that case the Processor informs the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
4.2 The Processor Processes Personal Data on behalf of the Controller, in accordance with its instructions, under its responsibility and in the manner set out in the Agreement.
4.3 The Processor has no control over the purpose and means of the Processing of Personal Data. If the Processor, in breach of this Data Processing Agreement and the GDPR, determines the purposes and means of a processing operation, the Processor shall be considered a controller in respect of that Processing.
4.4 The Processor ensures compliance with the conditions imposed by the GDPR and other regulations on the Processing of Personal Data.
4.5 The Processor only grants access to the Personal Data to its employees who are bound by a duty of confidentiality, and only to the extent necessary to provide the services under the Agreement.
4.6 The Processor informs the Controller of requests concerning the exercise of rights regarding Personal Data received directly from a Data Subject. The Processor also provides the Controller with all reasonably required assistance, taking into account the nature of the Processing and the information available to it, in fulfilling its obligation to respond to requests from data subjects exercising their rights.
4.7 The Controller gives the Processor general written authorisation to engage a sub-processor in performing this Data Processing Agreement, provided that the protection of the Personal Data remains guaranteed.
The Processor informs the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes in writing within 7 calendar days.
Before the Processor engages a sub-processor to carry out specific processing activities on behalf of the Controller, the Processor imposes on that sub-processor, by contract, at least the same data protection obligations as those set out in this Data Processing Agreement. This includes in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures so that the Processing meets the requirements of the GDPR and ensures the protection of the Data Subject's rights. The agreement with the sub-processor must designate the Controller as a direct beneficiary, so that it can also exercise contractual rights directly against the sub-processor.
4.8 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations in this Data Processing Agreement. To this end, the Controller, or an auditor mandated by the Controller, has the right to carry out audits and inspections at the Processor. The Processor allows for and contributes to such audits and inspections. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
4.9 The Processor may not Process the Personal Data outside the EEA without the prior written consent of the Controller, to which the Controller may attach conditions. Where a provision of Union or Member State law requires the Processor to Process in a third country, the Processor informs the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
Article 5 Data breach notification
5.1 The Processor notifies the Controller without undue delay (and in any event no later than 24 hours after discovery) of a security breach relating to the Processing of Personal Data and, as far as possible, provides information on: (i) the nature of the breach; (ii) the (possibly) affected Personal Data; (iii) the established and expected consequences of the breach for the Processing of the Personal Data and the persons concerned; and (iv) the measures the Processor has taken and will take to limit the negative consequences of the breach.
5.2 The Processor acknowledges that the Controller may be legally obliged to report a security breach that concerns or may concern the Personal Data Processed by the Processor to the supervisory authority and possibly to the Data Subjects. Before making such a report, the Controller consults and informs the Processor about the intended notification.
5.3 The Processor takes all measures necessary to limit the (possible) damage and supports the Controller in notifying the supervisory authority and the Data Subjects. The Processor keeps the Controller informed of new developments regarding the breach and of the measures taken to limit and end the breach and to prevent a similar incident in the future.
Article 6 Security measures
6.1 The Processor takes all appropriate technical and organisational measures required under article 32 GDPR to secure Personal Data against loss or any form of unlawful Processing.
6.2 The Controller acknowledges that the security measures taken by the Processor are appropriate in view of all relevant aspects of the Processing, including the state of the art and the context of the Agreement.
Article 7 Obligations of the Controller
7.1 With regard to the Processing of Personal Data under this Data Processing Agreement, the Controller is the "controller", as it alone or jointly with others determines the purposes and means of the Processing of personal data.
7.2 The Controller agrees and warrants that the Processing of the Personal Data in accordance with the Data Processing Agreement complies with the GDPR.
7.3 Taking into account the nature of the Processing and the information available to it, the Processor provides the Controller with all reasonably required assistance in meeting the obligations under articles 32 to 36 GDPR.
Article 8 Termination
8.1 The Data Processing Agreement starts on the day the Agreement is signed and ends when the Agreement ends, provided that article 8.2 remains in force after termination until the Processor has fully complied with the obligation under article 8.2.
8.2 At the first request of the Controller, upon termination of the Data Processing Agreement, the Processor returns all Personal Data made available to it to the Controller and destroys all digital copies of Personal Data, unless the Processor is required by Union or Member State law to store the Personal Data.
If the Controller considers that destruction may not take place, it informs the Processor in writing. In that case the Processor guarantees the confidentiality of the Personal Data towards the Controller and will not Process the Personal Data except to comply with its legal obligation or on the written instruction of the Controller.