Data Processing Agreement

Data Processing Agreement

(the "DPA")

This DPA sets out the rules for entrusting the processing of personal data of which you are the Controller, by us as the Processor.

1. Definitions

  • Regulation – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
  • Personal Data – data within the meaning of Article 4(1) of the Regulation, i.e. any information relating to an identified or identifiable natural person.
  • Processing of Personal Data – any operations performed on Personal Data, such as collection, recording, storage, adaptation, alteration, disclosure, reading, and erasure of the data, within the meaning of Article 4(2) of the Regulation.

2. General provisions

  • In order to perform the agreement concluded between the Controller and the Processor (the "Main Agreement"), the Controller entrusts the Processor with Personal Data for processing under Article 28 of the Regulation, on the terms set out in this DPA.
  • The Controller declares that it remains the Controller of the Personal Data within the meaning of Article 4(7) of the Regulation, processed in the entrusted set of Personal Data.
  • The Processor undertakes to process the entrusted Personal Data in accordance with this DPA, the Regulation, and other generally applicable laws protecting the rights of the persons to whom the data relate.
  • The Processor declares that it satisfies all requirements and obligations arising from Article 28 of the Regulation.

3. Subject matter

  • The Processor will process the Personal Data entrusted under this DPA of persons whose data the Controller provides or makes available in connection with the use of the Platform (in particular research respondents and persons whose data may be contained in the materials provided by the Controller), in particular in the form of:
    • identification and contact data – to the extent provided by the Controller;
    • data relating to activity and interactions within the Mockups – to the extent it constitutes Personal Data;
    • other Personal Data provided or made available by the Controller in connection with the use of the Service.
  • The Processor will in particular perform the following operations on the entrusted Personal Data: collection, recording, organisation, storage, use (for the purpose indicated in section 2(1) of this DPA), disclosure to other entities in accordance with the law, the provisions of the Agreement, or the Controller's instructions, and erasure. The Personal Data will be processed by the Processor in electronic form in IT systems.
  • The Processor will collect the Personal Data from the Controller in electronic form.

4. Obligations of the Processor

  • When processing the entrusted Personal Data, the Processor undertakes to secure it by applying appropriate technical and organisational measures ensuring an adequate level of security corresponding to the risk associated with the processing of Personal Data, as referred to in Article 32 of the Regulation.
  • The Processor undertakes to maintain a register of authorisations to process Personal Data, covering the persons who will process the entrusted data in order to perform this DPA.
  • The Processor undertakes to ensure that persons whom it authorises to process Personal Data in order to perform this DPA keep the processed data confidential (as referred to in Article 28(3)(b) of the Regulation), both during their engagement with the Processor and after it ends.
  • After the end of the provision of the processing-related services, the Processor erases all Personal Data and all existing copies thereof within 30 (thirty) days of termination of this DPA, unless Union law or the law of a Member State requires storage of the Personal Data. Personal Data contained in routine backups is deleted in the ordinary course of the Processor’s backup cycle and remains subject to the security and confidentiality obligations of this DPA until deleted.
  • As far as possible, the Processor assists the Controller, to the extent necessary, in fulfilling its obligation to respond to requests from a data subject exercising their rights set out in Chapter III of the Regulation.
  • Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in fulfilling the obligations set out in Articles 32–36 of the Regulation.

5. Right of audit

  • The Controller, in accordance with Article 28(3)(h) of the Regulation, has the right to verify whether the measures applied by the Processor in processing and securing the entrusted Personal Data meet the provisions of the Agreement.
  • The Controller may audit the Processor’s compliance with this DPA during the Processor’s working hours, with at least 30 (thirty) days’ prior written notice, not more than once in any 12-month period (except where required by a supervisory authority or following a confirmed personal data breach), at its own cost, and subject to the confidentiality obligations of this DPA. The Parties will agree the scope in advance so as to avoid unreasonable disruption to the Processor’s operations.
  • The Processor undertakes to remedy any material deficiencies identified during the audit within a reasonable period agreed by the Parties, taking into account the nature of the deficiency.
  • The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 of the Regulation and allows for, and contributes to, audits, including inspections, conducted by the Controller or an auditor authorised by the Controller.

6. Further entrustment of data for processing

  • The Processor may entrust the Personal Data covered by this DPA to sub-contractors for further processing only for the purpose of performing the Agreement. The Controller grants the Processor a general authorisation for this purpose. The Processor will inform the Controller of any intended changes concerning the addition or replacement of sub-contractors, giving the Controller the opportunity to object to such changes on reasonable grounds.
  • The sub-contractor will meet the same guarantees and obligations as those imposed on the Processor under this DPA.
  • The Processor bears full responsibility towards the Controller for any failure by the sub-contractor to fulfil its data protection obligations.
  • Transfer of the entrusted data to a third country (outside the European Economic Area) takes place only where an adequate level of protection is ensured by an appropriate safeguard provided for in the Regulation, in particular the Standard Contractual Clauses (SCC), or on the Controller's documented instruction, unless the Processor is required to make the transfer by Union or Member State law to which it is subject (in which case the Processor informs the Controller of that legal obligation before processing, unless that law prohibits the provision of such information).

7. Liability

  • The Controller is responsible for compliance with the law in respect of the processing and protection of Personal Data under the Regulation.
  • The above does not exclude the Processor's liability for processing the entrusted Data contrary to this DPA.
  • The Processor is liable for damage caused by processing where it has not complied with the obligations imposed by this DPA, or where it acted outside or contrary to the Controller's lawful instructions.
  • The Processor is liable for disclosing or using Personal Data contrary to this DPA, and in particular for disclosing the entrusted Personal Data to unauthorised persons.
  • The Processor undertakes to inform the Controller of any proceedings, in particular administrative or judicial, concerning the processing of the entrusted Personal Data, and of any administrative decisions or rulings issued in connection therewith. This paragraph applies only to Personal Data entrusted by the Controller.
  • The Processor undertakes to inform the Controller of any suspected or confirmed breach of Personal Data protection without undue delay - no later than within 48 (forty-eight) hours of becoming aware of the suspected or confirmed breach of Personal Data protection.

8. Confidentiality

  • The Processor undertakes to keep confidential all information, data, materials, documents, and Personal Data received from the Controller and from persons cooperating with it, in connection with the performance of the Agreement.
  • The Processor declares that confidential data will not be used, disclosed, or made available without the Controller's consent for any purpose other than performing the order, unless the need to disclose the information held arises from applicable law.

9. Duration

  • This DPA applies for the duration of the Agreement.
  • The Controller may terminate this DPA with immediate effect where the Processor:
    • despite being required to remedy deficiencies identified during an audit, fails to remedy them within the period set by the Controller;
    • processes Personal Data in a manner inconsistent with this DPA;
    • has entrusted the processing of Personal Data to another entity in breach of section 6 of this DPA (in particular without informing the Controller of the change or despite the Controller's reasonable objection).
  • Notwithstanding the above, termination of the Agreement is equivalent to termination of this DPA with immediate effect.
  • Any arrangements concerning the protection of Personal Data contained in the Agreement cease to apply on the date this DPA enters into force.

10. Final provisions

  • This DPA supplements the Main Agreement and is to be read together with it. The provisions of the Main Agreement concerning limitation of liability, governing law and jurisdiction, and duration and termination apply to this DPA as if set out in it. In the event of a conflict between this DPA and the Main Agreement, this DPA prevails in respect of the processing of personal data.
  • In matters not regulated herein, the provisions of the Civil Code, the Regulation, and the Act of 10 May 2018 on the protection of personal data apply.
contact form

Reach out — we’re always here

Got a question or looking for more details?Feel free to reach out by filling out the form below — we’re here to help.

By clicking the button, you consent to the processing of your personal data and agree to the Privacy Policy