Agreement on the Protection of Personal Data Processed by a Processor
ealing Directive 95/46/EC (General Data Protection Regulation), and Act No. 18/2018 Coll. on Personal Data Protection and on Amendments and Supplements to Certain Acts, as amended
(hereinafter referred to as the “DPA”)
Contracting Parties
This DPA is concluded between:
the Customer within the meaning of the General Terms and Conditions of ITACON, s. r. o. (hereinafter referred to as the “GTC”), available on the Tazilla website (hereinafter referred to as the “Controller”)
and
ITACON, s. r. o., with its registered office at Kominárska 2, 831 04 Bratislava – Nové Mesto, Company ID No.: 50838563, represented by Terézia Rybárová, Managing Director (hereinafter referred to as the “Processor”).
(The Controller and the Processor are hereinafter individually also referred to as a “Contracting Party” and jointly as the “Contracting Parties”.)
Preamble
Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the “GDPR”) requires the relationship between the Controller and the Processor in connection with the processing of personal data to be governed by a contract in written or electronic form. For this reason, the Contracting Parties conclude this DPA pursuant to Article 28 of the GDPR.
Article 1 – Introductory Provisions
- The purpose of this DPA is to ensure the secure processing of the Controller’s personal data by the Processor in connection with the use of the Tazilla application.
- In fulfilling their obligations under this DPA in connection with the protection of personal data, the Contracting Parties undertake to comply with the provisions and requirements of the GDPR and Act No. 18/2018 Coll. on Personal Data Protection and on Amendments and Supplements to Certain Acts, as amended (hereinafter referred to as the “Personal Data Protection Act”). On the basis of this DPA, the Controller authorises the Processor to process personal data to the extent necessary to fulfil the subject matter and purpose of this DPA.
- The Contracting Parties declare that, when processing personal data through Tazilla and within the scope of their competences arising from this DPA, they shall at all times ensure the highest possible level of security and protection of the processed data against unauthorised access, leakage, loss, destruction, misuse, modification or deterioration.
- The Processor declares that it ensures the administration and operation of Tazilla in accordance with the requirements arising from Act No. 69/2018 Coll. on Cybersecurity and on Amendments and Supplements to Certain Acts, the Act on ITVS and related implementing regulations.
Article 2 – Subject Matter, Purpose and Duration of Processing and Term of this DPA
- The subject matter of this DPA is to regulate the rights and obligations of the Contracting Parties in ensuring the protection of the Controller’s personal data when processed through Tazilla.
- The Controller hereby authorises the Processor to process personal data exclusively for the purpose of providing the Service under the GTC, in particular to enable the use of the individual modules of the Tazilla application. Processing shall take place only for the duration of the provision of the Service. The Processor shall process personal data exclusively on the instructions of the Controller.
- The Processor is entitled to use aggregated or properly anonymised data that no longer constitutes personal data within the meaning of the GDPR for the purpose of improving and optimising the Service by the Provider.
- The scope of personal data processed on behalf of the Controller for the purposes of this DPA is specified, pursuant to Article 28 of the GDPR, in the Privacy Policy available on the Tazilla website.
- The Controller determines the content of the personal data entered into the application and is responsible for ensuring that personal data exceeding the scope necessary to fulfil the purpose of processing is not entered into the system.
- The Processor does not process special categories of personal data pursuant to Article 9 of the GDPR unless such data is entered into the system by the Controller, in which case the Controller is responsible for the lawfulness of its processing.
- The duration of the processing of personal data under this DPA is determined by the duration of the contractual relationship established by acceptance of the GTC, i.e. for the period during which the Customer has active access to the Service. This DPA is concluded for the same period as the aforementioned contractual relationship and terminates upon its termination in the manner provided for in Article 7 of the GTC.
Article 3 – Rights and Obligations of the Contracting Parties
- The Controller is responsible for the lawfulness of the processing of personal data within its organisation, including processing carried out by its users, employees, partners or other contracting parties through Tazilla.
- The Processor undertakes to process the Controller’s personal data to the extent agreed in Article 2 of this DPA. It shall process such data only for the purpose, by the means and in the manner agreed in this DPA. It shall ensure that the confidentiality, integrity and availability of the processed personal data are not compromised. The Processor shall not use personal data of which it becomes aware for its own purposes and shall maintain confidentiality with respect to such data even after the expiry and termination of this DPA. Without the Controller’s consent, the Processor shall not disclose the processed data, make it available to any unauthorised person, carry out any cross-border transfer thereof or provide it to any third party, with the exception of sub-processors necessary for the operation of the cloud service (hereinafter collectively referred to for the purposes of this Article as “sub-processors”). The list of sub-processors is set out in Annex No. 1 to this DPA. Sub-processors may process personal data only under the conditions agreed in paragraph 10 of this Article and are required to comply with the same security standards and GDPR requirements as the Processor. The Processor shall not process personal data in any other manner, in particular by arranging, structuring, storing, altering, retrieving, consulting, using, disclosing, realigning, combining, restricting or erasing such data, unless this is related to the purpose of processing personal data defined in this DPA. Upon termination of the processing, the Processor shall, within 30 calendar days and on the basis of the Controller’s written instruction, depending on the nature of the processing operations, return the personal data to the Controller or erase it and shall likewise erase all copies and backups containing personal data, where possible according to the current configuration (functionality) of Tazilla and in accordance with the applicable generally binding legal regulations.
- The Processor shall also, without undue delay, inform the Controller and provide relevant reasons if it believes that an instruction of the Controller infringes the GDPR, the Personal Data Protection Act or other generally binding legislation relating to the protection of personal data.
- The Processor shall, without undue delay, provide the Controller with the information necessary to demonstrate compliance with the Processor’s obligations and shall provide cooperation in connection with a personal data protection audit and an inspection by the Controller or an auditor authorised by the Controller, as well as in taking measures in response to a request from a data subject, ensuring compliance with obligations relating to the security of personal data protection and demonstrating compliance with obligations in the context of a personal data protection audit. For this purpose, the Processor shall allow persons carrying out such an audit or inspection access to the data and relevant documentation, including where the Controller demonstrably cannot carry out such activities or prepare such documentation itself. If the Controller requests the Processor’s cooperation in connection with a personal data protection audit, the Processor undertakes not to refuse such cooperation where it demonstrably has the relevant information available and shall provide such cooperation without undue delay. A report shall be drawn up on the results of the personal data protection audit or inspection, recording all facts material to the protection of personal data, including measures mutually approved to remedy identified non-compliance and the deadlines for their implementation.
- The Processor undertakes, to the greatest extent possible and without undue delay, to assist the Controller by appropriate technical and organisational measures in fulfilling its obligations relating to the exercise of the rights of data subjects concerned by the processing under this DPA.
- The Processor further undertakes to provide, without undue delay, the necessary assistance to the Controller in handling a request or complaint from a data subject.
- In accordance with the rights of data subjects whose personal data the Processor processes on behalf of the Controller, the Processor shall act and provide the Controller with the necessary assistance on the basis of written requests in which the Controller shall provide the Processor with a reasonable period of time, which shall not be shorter than 5 business days. If the Processor receives a request from a data subject relating to the exercise of that data subject’s rights against the Controller, the Processor shall forward the request to the Controller.
- The Processor declares that it has implemented the necessary technical measures for the secure processing of the Controller’s personal data under this DPA. The Processor further declares that it has implemented the necessary personnel and organisational measures for the secure processing of personal data, including ensuring that persons authorised to process personal data have undertaken to maintain confidentiality regarding information of which they become aware in the course of processing.
- The Controller is responsible for adopting organisational and technical security measures in connection with the processing of personal data on the Controller’s side, as well as for preparing the relevant security documentation.
- The Controller agrees that the Processor may engage its sub-processors to process personal data for the purpose, to the extent and in the manner agreed in this DPA. The Processor shall notify the Controller of the identification details of all sub-processors that participate or will participate in the performance under this DPA (where, in the performance of their contractual activities, they may process or otherwise become acquainted with the Controller’s personal data) before engaging the relevant sub-processor in the processing of personal data under this DPA. In the event of a planned addition or replacement of a sub-processor, the Processor shall notify the Controller electronically of the relevant identification details 14 days before the planned change, at the address of the responsible person specified in this DPA. Sub-processors may process the Controller’s personal data only for the agreed purpose and within the scope of the authorisation granted by the Controller to the Processor and only on the basis of written instructions from the Processor pursuant to Article 28(4) of the GDPR. The Processor shall remain fully liable for the activities of its sub-processors.
- The Controller is entitled, within 10 business days of receipt of notification of a change of sub-processor, to raise a written and reasoned objection on grounds relating to the protection of personal data by sending it to support@tazilla.com. The objection must be based on a demonstrable risk of infringement of personal data protection legislation. If an objection is raised, the Contracting Parties undertake to negotiate in order to resolve it. If they fail to reach an agreement and the Processor insists on using the new sub-processor, the Controller is entitled to terminate the Agreement in relation to the affected Service without the Customer being entitled to compensation for damages.
- The Processor undertakes, without undue delay, to provide the Controller with all requested assistance and cooperation necessary for the Controller to fulfil its obligations towards the supervisory authority, in particular in connection with prior consultation with the supervisory authority, compliance with all instructions and advice concerning the processing of personal data provided by the supervisory authority and the exercise of the supervisory authority’s powers.
- In the event of notification of a personal data breach pursuant to Articles 33 and 34 of the GDPR and Sections 40 and 41 of the Personal Data Protection Act and/or the occurrence of a security incident constituting a personal data breach, where such security incident is identified on the Processor’s side and concerns personal data processed under this DPA, the Processor shall notify the Controller of the security incident in the manner specified in Article 9 of the GTC, without undue delay and no later than 24 hours after becoming aware of the personal data breach. The Processor shall provide all relevant information, in particular the nature of the breach, the categories and approximate number of data subjects concerned, the number of personal data records concerned, the likely consequences of the breach and the measures taken to address and mitigate the personal data breach. The scope of the information provided shall be sufficient to carry out an analysis of the impact on the rights and freedoms of natural persons and to assess whether the security incident poses a risk to the rights of data subjects and the level of such risk.
Article 4 – Liability for Damage and Compensation
- The Processor shall be liable for damage suffered by the Controller, as well as damage suffered by data subjects as a result of its activities in processing personal data, where it has breached its obligations relating to the processing of personal data laid down in this DPA, the GDPR, the Personal Data Protection Act, specific legislation or an international treaty by which the Slovak Republic is bound, or where the Processor has acted beyond or contrary to the relevant instructions of the Controller that complied with the GDPR, the Personal Data Protection Act, specific legislation or an international treaty by which the Slovak Republic is bound.
- The maximum amount of compensation for damage under this DPA is limited to the amount actually paid by the Customer to the Provider for the provision of the Service during the 12-month period immediately preceding the event giving rise to the damage. If, as of the date on which the damage occurred, the Service had been provided for less than 12 months, the amount actually paid for that shorter period shall be taken into account, but in any event not less than EUR 1,500. This limitation shall not apply in cases of intentional misconduct.
- Pursuant to paragraph 1 of this Article, the Processor shall be required to compensate the Controller and the data subjects for damage in the proven amount only if it is established that the Processor was at fault for the damage.
- Damage shall also include any fine that the Controller is required to pay to the supervisory authority as a result of the Processor’s breach of its obligations under the Personal Data Protection Act.
- The Processor may be fully exempted from liability under this Article of this DPA if it proves that it is in no way responsible for the event giving rise to the damage, as well as if it proves that it was not at fault for the occurrence of the damage. The Processor may be partially exempted from liability if it proves that the Controller’s activities also contributed to the occurrence of the damage.
- If it is not possible to determine the respective shares of responsibility of the Controller and the Processor for damage arising in connection with the processing of personal data, but it is established that the damage arose as a result of the activities of both the Controller and the Processor, the Controller and the Processor shall be jointly and severally liable for the damage.
- If the respective share of responsibility can be determined and one Contracting Party compensates data subjects for the damage caused or pays a fine imposed by the supervisory authority in full, that Contracting Party shall be entitled to recover from the other Contracting Party the portion of the compensation or fine corresponding to the latter’s share of responsibility.
Article 5 – Rules for Communication between the Contracting Parties
- The Contracting Parties agree that any written communications relating to the subject matter of this DPA that have or may have an impact on the mutual rights and obligations of the Contracting Parties governed by this DPA shall be delivered in the manner specified in Article 9 of the GTC.
Article 6 – Final Provisions
- This DPA forms an integral part of the contractual relationship established by acceptance of the General Terms and Conditions and is also an integral part of the GTC themselves pursuant to Section 1.4 of the GTC. The DPA becomes valid and effective at the moment when the relevant Customer expresses its consent to the GTC in the manner specified in Section 3.1 of the GTC.
- The Contracting Parties declare that they enter into this DPA freely and seriously and that their freedom of contract is not restricted.
- The Contracting Parties declare that this DPA has not been concluded under disadvantageous conditions or under duress, that they have duly read it, understood its contents and, as evidence of their agreement with its contents, the authorised representatives of both Contracting Parties affix their handwritten signatures.
- Should any provision of this DPA be or become invalid or ineffective, whether in whole or in part, the remaining provisions of this DPA that are not directly affected by such invalidity or ineffectiveness shall remain unaffected and continue to be valid and effective. In such a case, the Contracting Parties undertake, without undue delay, to replace the invalid or ineffective provision of this DPA with a valid and effective provision that corresponds, to the greatest extent possible, to the will and intention of the Contracting Parties expressed in the invalid or ineffective provision. If this is not legally possible, the relationship between the Contracting Parties shall be governed by valid legal provisions that, by their nature, most closely correspond to the purpose and content of this DPA.
- In the event of a dispute arising out of or in connection with this DPA, the Contracting Parties undertake to use their best efforts to resolve such dispute primarily by mutual agreement and amicable settlement. If such efforts are unsuccessful, the courts of the Slovak Republic shall have jurisdiction to hear and decide the dispute.
- The Processor is entitled to update this DPA unilaterally in the same manner and under the same conditions as those governing updates under Article 4 of the GTC, including notification of changes and the Customer’s right to object or terminate the contractual relationship if it disagrees with the change. Any update must not result in a reduction in the level of personal data protection or the security measures agreed in this DPA.
- The following annex forms an integral part of this DPA:
Annex No. 1 – List of Sub-processors
Consortium partner redByte, s.r.o., Fialová 4036/10, 851 07 Bratislava – Petržalka, Company ID No.: 46557270, to the extent specified in the Privacy Policy.