Personal Data Processing Agreement
Preamble
Ofelia may act as a Processor for the Processing of data carried out on behalf of the Client, who acts as the Controller within the meaning of Regulation (EU) 2016/679 (the "Regulation"), as set out in the "Personal Data" article of the General Terms and Conditions.
Ofelia has taken note of the Regulation, and in particular of Article 28 thereof concerning the obligations imposed on any Processor acting on behalf of a controller of personal data.
This document sets out Ofelia's commitments to the Client regarding data protection in connection with the provision of the Services.
Definitions
The terms used herein have the meaning set out in the Regulation, including:
Adequacy Decision
A decision adopted by the European Commission establishing that a Third Country ensures an adequate level of protection of Personal Data by reason of its domestic legislation or the international commitments it has entered into.
Data / Personal Data
Any information relating to an identified or identifiable natural person (hereinafter referred to as a "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, Location Data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
EEA
The European Economic Area.
Third Country
A country that is not a member of the EU or the EEA.
Controller
The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing; where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its designation may be provided for by Union or Member State law.
Processor
The natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller.
Sub-processor
The sub-processor engaged by the Processor which processes Personal Data on behalf of the Processor.
Transfer outside the EU
Also referred to as "Processing outside the EU" or "Transfer": the transmission of Data from a Member State of the EU or the EEA to a Third Country, or access to Data located within an EU or EEA Member State from a Third Country (e.g., remote access to a database located in Europe).
Processing of Personal Data
Also referred to as "Processing" or "Process": any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
EU
The European Union.
Data Breach
Also referred to as "Breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
Description of the Data Processing
The Data Processing carried out by Ofelia as Processor is performed for the purposes set out in Annex A.
Implementation of the Processing
Ofelia undertakes to comply with the Client's written instructions regarding the use that may be made of the Data. The list of Processing operations that Ofelia may carry out on behalf of the Client is attached as Annex A hereto – Register of Processing Activities Carried Out as Processor (Article 30 of the GDPR).
Ofelia will immediately inform the Client if one of its instructions appears likely to constitute a breach of the Regulation.
In the event that the Client considers that a new data processing operation entrusted to Ofelia requires a data protection impact assessment within the meaning of Article 35 of the Regulation, Ofelia will assist the Client in carrying out that impact assessment. This assistance may be subject to billing.
Information of Data Subjects
The Controller informs data subjects of the personal data processing carried out in connection with the Services.
Security Measures
Ofelia undertakes to implement all organizational and technical measures to ensure the physical and logical security of the Data in accordance with the state of the art and the recommendations published by Data Protection Authorities or the competent administrative authorities in matters of information security.
The security and confidentiality measures taken by Ofelia must take into account the most recent technical possibilities and the cost of their implementation, the characteristics of the processing (nature, scope, purpose, etc.), and the risks posed to the rights of data subjects.
The security measures guarantee the integrity, traceability of access, confidentiality, and availability of the Data at all times, and include in particular:
Identification and securing of premises (e.g., locked access, restricted access requiring authorization and authentication);
Logical security (e.g., firewalls, authentication and logging of access to Data, incident simulations);
Securing of Personal Data exchange flows so that they cannot be exploited by an unauthorized third party;
Logging of activity on the IT system;
Protection of IT environments through up-to-date antivirus software (programs and virus signatures);
Implementation of control procedures to ensure the level of security.
Ofelia ensures that only secure means of communication are used to process Personal Data.
Ofelia undertakes to limit access to the Data to only those authorized persons who need to know it.
Ofelia also ensures that persons authorized to process Personal Data for the purposes hereof, including its staff and the staff of any Sub-processors, are bound by an appropriate confidentiality obligation.
Ofelia's Cooperation
Ofelia undertakes to cooperate with the Client by providing it, upon written request, with all information necessary to demonstrate compliance with its obligations, and by allowing it, to that end, to carry out any verification it deems useful, the practical arrangements for which will be agreed upon.
Subsequent Sub-processing
The Client hereby authorizes the subcontracting of all or part of the processing entrusted to Ofelia, and Ofelia undertakes to engage only Sub-processors that comply with the provisions of the GDPR.
The list of Ofelia's current Sub-processors appears in Annex B. An updated version may be provided to the Client at any time upon simple request.
Ofelia guarantees compliance by its Sub-processors with the commitments it itself has made, particularly with regard to any commitments it may have made in terms of security or within standard contractual clauses or any other appropriate safeguard.
Data Transfers
Ofelia does not voluntarily transfer Personal Data outside the territory of the EU or the EEA.
In the event that, for the purposes of providing the Services, Ofelia is required to carry out a Transfer of Data outside the EU or the EEA, such Processing meets the requirements of the Regulation regarding Transfers of Data outside the EU, namely:
The Processing is carried out within a Third Country benefiting from an Adequacy Decision;
The Processing is governed by standard contractual clauses published by the European Commission. In this case, Ofelia and the importing Sub-processor incorporate such standard clauses into the General Terms and Conditions and undertake to ratify them prior to the implementation of the Processing concerned;
The Processing is governed by Binding Corporate Rules (BCRs).
If the exception(s) used for the Transfer were to lapse, Ofelia undertakes to modify the chosen mechanism to replace it with a mechanism capable of governing the intended Transfer.
When Ofelia uses Sub-processors, it ensures that they have implemented appropriate technical and organizational measures to guarantee a level of protection for the transferred Data at least equivalent to that provided herein in the event of a Data Transfer (standard contractual clauses, BCRs, etc.).
Data Protection Officer
Ofelia has appointed a Data Protection Officer: the company Virtual DPO – contact@virtual-dpo.fr.
The Client provides Ofelia, upon signature of the Commercial Proposal, with the identity and contact details of its DPO.
Where the Client has not appointed a DPO, it provides Ofelia with the name and detailed contact information of a relevant contact from whom information about the Processing of Data may be obtained.
Notification in the Event of a Personal Data Breach
In the event of an incident likely to affect the security of Personal Data, of a probable or confirmed breach of the integrity of Personal Data, or of a probable or confirmed violation of the confidentiality rules applied to Personal Data, Ofelia will inform the Client as soon as possible. This information is provided to enable the Client to comply with its notification obligations to the CNIL and to data subjects, pursuant to Article 33 of the GDPR.
Ofelia will carry out the investigations necessary to provide the Client, as they progress, with all useful information on the nature and extent of the potential Data Breach and the corrective measures implemented.
Ofelia will describe the security breach and, if possible, the categories and number of data subjects affected by the breach, as well as the Data concerned.
Ofelia further undertakes to cooperate with the Client and to implement the means necessary to resolve the incident.
Notification of Third-Party Requests for Disclosure
Ofelia undertakes to notify the Client as soon as possible of any request for the transmission or consultation of Data issued by a judicial or administrative authority, before responding to it, unless the applicable law prohibits such notification for reasons of public interest.
Exercise of Rights by Data Subjects
Any natural person whose Data is collected by Ofelia on behalf of the Client has a right of access, restriction, rectification, erasure, and, where applicable, objection to processing or portability of the Personal Data concerning them, in accordance with the applicable regulations.
The rights set out in the preceding paragraph are exercised directly with the Controller.
Accordingly, Ofelia notifies the Client as soon as possible of any request to exercise the aforementioned rights and complies with the Client's instructions, provided they comply with applicable regulations and are communicated to Ofelia in advance.
Data Retention Period / Termination of Subscription
Ofelia retains the Data processed for the duration of the Subscription, unless otherwise requested by the Client or required by a legal obligation imposing a different retention period.
In any event, Ofelia undertakes to delete all Data upon the Client's first request.
Ofelia will provide the Client, upon request, with a certificate attesting to the destruction of the Data.
The Data may be subject to interim archiving for a maximum period corresponding to the applicable statutory limitation period.
Annex A – Register of Processing Activities Carried Out on Behalf of the Client
For all of these processing activities: Legal basis defined by the Client, as Controller.