Data processing agreement

This Data processing agreement (“Agreement”) is concluded by Vercom S.A. with a registered office in Poznań (61-569), Poland, at: Wierzbięcice 1B Street, entered into the Register of Entrepreneurs of the National Court Register (KRS) kept by the District Court Poznań – Nowe Miasto and Wilda in Poznań, 8th Commercial Department of the National Court Register under the KRS No.: 0000535618, PL Tax ID: 7811765125, REGON: 300061423 (“Vercom” or “Processing Entity”) and the Client, as defined in the Main Agreement.

 

The Parties cooperate on basis of the Framework Agreement on the Provision of Services by Electronic Means (“Main Agreement”), on the basis of which Vercom provides to the Client services of automation and sending of electronic communication of a particular kind, selected by the Client (“Services”). The performance of the Main Agreement is related to the processing of personal data which the Client is a controller of, or which the Client processes as a Processing Entity, i.e. acting on behalf of a separate data controller. The intention of the Parties is to guarantee that the processing made in connection with the performance of the Main Agreement is in line with the provisions of the Regulation (EU) 2016/679 of the European Parliament and of the Council dated as of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”).

 

1. General Provisions

  1. On the basis of this Agreement, the Client entrusts Vercom with processing of personal data in relation to which the Client is the data controller – in the meaning of the Article 4 point 7 of the GDPR, exclusively within the scope and for the purpose referred to in Schedule 1 hereof, and Vercom undertakes to process the above personal data in accordance with the instructions and orders of the Client, as well as in accordance with this Agreement, limiting the processing to the scope and purpose, as well as the way of processing referred to in Schedule 1 hereof.
  2. The provisions of this Agreement shall apply accordingly in case, where the Client entrusts Vercom with processing of personal data, as defined in this Agreement, acting as a Processing Entity in the meaning of the Article 4 point 8 of the GDPR, i.e. on behalf of a separate data controller.
  3. Subject to the provisions of the Clause 5 hereof, Vercom shall be processing the entrusted personal data for the period of the performance of the Main Agreement.

 

2. Commitments of the Processing Entity

The Processing Entity undertakes to and warrants that it shall:

  1. Process the personal data entrusted under this Agreement upon the Client’s order, as well as in accordance with the instructions of the Client, unless the obligation to process the data results from the European law or domestic regulations of the member state to which the Processing Entity is subject – in such case, however, the Processing Entity shall inform the Client of such a legal requirement to process the data before the processing, unless the law prohibits providing such information due to important grounds of public interest,
  2. process the entrusted personal data exclusively within the scope and for the purpose in line with this Agreement,
  3. Has implemented and shall keep implemented for the whole period of this Agreement the adequate technical and organizational measures in order to protect the personal data, especially from the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to data transmitted, stored or otherwise processed, as well as from other unlawful forms of the processing. Taking into account the newest technical achievements and costs of their implementation, the Processing Entity warrants that the security measures will guarantee a security level adequate to the risks related to the processing, as well as the character of processed personal data,
  4. Shall keep the entrusted personal data confidential and shall assure that: (i) all employees and other persons authorized to process the data will be informed of the confidential character of the data, as well as obliged to keep them confidential, and (ii) are aware of the obligations of the Processing Entity deriving from this Agreement and shall obey them as their own.
  5. Shall inform, immediately, the Client of: (i) every breach of personal data entrusted under this Agreement, including (but not limited to) unauthorized access, loss, alteration or another security threat to such data (“Data Breach”), (ii) every complaint, correspondence or request received by the Processing Entity or its sub-processing contractor directly from the data subject, without responding to such a request. The Processing Entity shall not be obliged to assess the compatibility of Client’s instructions and requests relating to the processing of personal data, with binding provisions of law – in this regard, the liability relies exclusively on the Client.
  6. After the Data Breach is detected: (i) the Processing Entity is obliged to take immediate actions in order to protect the data from further consequences of the breach, and (ii) immediately, no later than within 36 hours since the breach was detected, the Processing Entity shall provide the Client with necessary information, as well as provide necessary help and cooperation in connection with the Client’s or controller’s obligation to notify the supervisory authority of the Data
  7. Where possible, shall assist the Client with every complaint, correspondence or request received by the Client from the data subject, including: (i) providing the Client with justified and available to Vercom details regarding the complaint, correspondence or request, (ii) sharing with the Client all personal data of such data subject – if applicable, in a commonly used, structured, electronic and machine readable format; (iii) providing the Client with justified information regarding the processing made by the Processing Entity under this Agreement, required by the Client; (iv) correct, erase or limit the processing, as well as (v) implement adequate technical and organizational measures, which enable the Processing Entity to comply with this point 7.
  1. Where possible and if reasonable, the Processing Entity shall do its best efforts to help and assist the Client with the data processing impact assessment or consultations with the supervisory authority, which the Client or a data controller is obliged to perform in relation to the personal data processed under this Agreement.
  2. If possible and to a reasonable scope, the Processing Entity shall make available to the Client, on demand, all information and evidence which is necessary to demonstrate by the Client that the Client or a data controller fulfills all obligations and legal requirements resulting from binding regulations, especially from the GDPR.
  3. On the Client’s demand and at the Client’s own cost, the Processing Entity shall enable the Client to inspect or audit the processing of data subject to this Agreement, including inspections and audits of the Processing Entity’s premises where the processing takes place; the audits and inspections shall be conducted by the Client or independent auditors or inspectors toward whom the Processing Entity will not raise a justified objection. The inspections and audits may be carried out only once a year, and exclusively upon prior notice delivered to the Processing Entity at least 21 days before the date of an intended audit/ inspection.
  4. The Processing Entity shall not entrust the processing of personal data entrusted on the basis of this Agreement with the sub-processing contractor, unless: (i) the Processing Entity obtained the Client’s prior, written consent for such sub-processing, and (ii) the sub-processing contractor will be subject to a written agreement imposing the same obligations and requirements on such entity as imposed on the Processing Entity under this The provisions of the preceding sentence shall not apply to the processing contractors listed in Schedule 1 hereof – these entities have been accepted by the Client under this Agreement. Any change of the sub-processing contractors, i.e. their addition or deletion, shall not require an amendment of this Agreement, but shall be subject only to the Processing Entity’s requirement of a prior, at least 30 days’ before the effective date of an intended change, notice made by the Processing Entity to the Client. Within 21 days since the notification mentioned in the preceding sentence has been sent out by the Processing Entity, the Client has the right to raise a justified objection to addition/discontinuation of a sub-processing contractor – in such a case, if provision of the Service to the Client will no longer be possible, or becomes much complicated due to the objection of the Client, the Parties may decide on terminating the Main Agreement immediately, i.e., with no termination notice.

 

3. Liability of the Processing Entity

  1. The Processing Entity shall be liable for the processing of data entrusted under this Agreement and responsible for the processing to be compliant with this Agreement, data controller’s instructions and binding law.
  2. In the event where the performance of this Agreement shall require the Processing Entity to engage the sub-processing contractor, the Processing Entity shall be responsible for all such entity’s actions and omissions as if they were the Processing Entity’s own actions and omissions.

 

4. Data transfer to the third country

 The processing entity shall not transfer the personal data processed under this Agreement to any third country in the meaning of the GDPR, as well as shall not allow the sub-processing contractor to transfer these data or process them to/ in the third country, unless the Client consented to such processing prior to the transfer.

 

5. Term of the Agreement

  1. This Agreement is concluded for a definite period, i.e. for the period of the processing carried out in relation to the performance of the Main Agreement and shall remain in full force until all personal data are deleted by the Processing Entity in accordance with section 2 below.
  2. After the termination of the Main Agreement, the Client shall be obliged to download all personal data being processed by the Processing Entity on the basis of this Agreement, on its own, or request that the Processing Entity delete the data. If the Client does not download the data within 3 business days since the termination of the Main Agreement, nor requests that the Processing Entity delete the data, the data shall be subject to automatic deletion without prior notification made by the Processing Entity to the Client. The provisions of this section 2 do not apply to personal data processed by the Processing Entity within the framework of a back-up copy – the back-ups are made, in particular, for purposes related to securing the personal data and assure their accessibility during the term of the Main The back-ups are kept for the period of 2 years since their creation and are subject to automatic deletion afterwards. Personal data processed within the framework of the back-ups, are processed in an encrypted form and may be accessed exclusively by authorized persons acting on behalf of the Processing Entity. This Agreement shall expire as of the date of a deletion of data processed as part of the back-up copy.

 

6. Final provisions

  1. This Agreement was executed in two identical counterparts, one for each
  2. All amendments to this Agreement shall be made in accordance with the provisions stipulating amendments to the Main
  3. All schedules to this Agreement constitute an integral part of
  4. The Agreement constitutes an integral part of the Main

 

 

Schedule 1:

  1. Scope, character and purpose of data processing
    The processing shall be carried out for purposes related to the proper performance of the Main Agreement, as well as for purposes related to the proper performance of Vercom’s commitments deriving from this data processing agreement relating to, in particular, making the data secure especially by ensuring their integrity and accessibility.
  2. Period of the processing
    The period during which the personal data are processed shall be the same as the period of the performance of services rendered on basis of the Main Agreement, subject to the provision that the data processing agreement shall remain in full force until all data are deleted in line with the provisions hereof.
  3. Categories of Data Subjects
    The processing shall be related to the following categories of data subjects: End – users – natural persons being addressees of electronic communication sent by the Client o basis of the Main Agreement.
  4. Special category personal data
    The processing involves also processing of special category personal data, i.e.: Not applicable.
  1. Approved sub-processing contractors
    Categories of processors:

    1. Server rooms and Data Center (hosting, collocation services, backup),
    2. Providers of solutions that increase the security of the services provided and the confidentiality of the transmitted communication (in particular the WAF tool);

Detailed list of the sub-processing contractors:

Beyond.pl sp. z o.o.
Adama Kręglewskiego 11 Str., 61-248 Poznań, Poland
Servers’ location and Data Center (collocation, backup)Processing area: EEA
NTT Global Data Centers EMEA GmbH
Voltastraße 15, 65795 Hattersheim, Germany
Servers’ location and Data Center (collocation, backup)Processing area: EEA
Cyber Folks S.A.
Wierzbięcice 1B Str., 61-569 Poznań, Poland
HostingProcessing area: EEA
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy, LU-1855 Luxemburg, R.C.S., Luxemburg: B186284
BackupProcessing area: EEA
Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, USA
Security tools’ service provider (WAF)Processing area: EEA

RSS