1. Introduction
The Data Processing Agreement (hereinafter the « Agreement ») is intended to govern the use of Personal Data belonging to the clients (hereinafter the « Client ») of Nexway SASU (hereinafter the « Processor » or « Nexway SASU ») when they use its services (hereinafter the « Service »).
2. Definitions
The terms "adequacy decision", "technical and organisational measures", "data subjects", "privacy by design", "privacy by default", "record", "joint controller(s)", "controller", "processor", “processing”, “personal data breach” as used in the Agreement have the meanings set out in Articles 4 et seq. of the GDPR.
The other terms are defined below:
- "Agreement": refers to the annex to the Contract governing the use of the Client’s Personal Data in accordance with the provisions of Article 28 of the GDPR, also known as the "Data Processing Addendum" (« DPA »)
- "DPIA": refers to a Data Protection Impact Assessment that enables the proportionality of the processing of personal data to be verified and helps to prevent risks associated with the processing of personal data
- "Anonymization": refers to a process designed to make it impossible to identify the data subjects affected by the processing carried out within the scope of the Service, and to do so irreversibly
- "Supervisory authority": means the GDPR supervisory authority competent for the Service provided by the Processor
- "Client": means the entity that has subscribed to the Service provided by the Processor
- "Contract": means the contract entered into between the Processor and the Client for the use of the Service to which this Agreement is annexed
- "Data subject requests": refers to the fundamental right(s) established by the GDPR in Articles 15 et seq. (e.g. right of access, right to erasure, etc.).
- "Client’s personal data": means any data relating to an identified or identifiable natural person transmitted to the Processor and processed by the latter on behalf of the Client in connection with the Service, a detailed list of which is set out in the Annex
- "Party(ies)": refers jointly to the Client and the Processor
- "GDPR": refers to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, also known as the "General Data Protection Regulation"
- "Applicable regulations on the protection of personal data": refers collectively to French Law No. 78-17 of 6 January 1978 on information technology, data files and civil liberties and the GDPR
- "Reversibility": refers to the process of enabling the transfer and integration, in a usable and recognised format, of the Service User’s Personal Data from the Processor’s service to an equivalent service provided by another service provider
- "SaaS service": refers to software hosted by the Processor and capable of being used simultaneously by an unlimited number of clients
- "Sub-processor": means the subsequnt processors engaged by the Processor to process the Client’s Personal Data exclusively within the scope of the Service
- "End users": means the individuals whose personal data is processed by the Processor on behalf of the Client
3. Contractual relationship and duration
The Agreement is an integral annex to the Contract signed between the Client and the Processor for the use of the Service.
In the event of any conflict between the Contract entered into for the use of the Service and the Agreement, the obligations set out in the Agreement shall prevail over the Contract with regard to the GDPR as a whole.
The Agreement shall remain in force for the entire duration of the contract entered into in connection with the use of the Service and may continue beyond that period for as long as all obligations set out herein remain applicable.
4. Role of the Parties and scope of application
Under the Agreement, the Client acts as the controller and Nexway SASU acts as the processor within the meaning of Article 28 of the GDPR.
Under no circumstances shall the Parties be considered as joint controllers in connection with the Service. However, the Parties agree that in the event of an error or a change in their status, the Parties shall meet without undue delay to amend the Agreement and take all necessary measures in relation to such a situation to comply with the requirements of the applicable data protection regulations.
The Agreement governs exclusively the processing of the Client’s Personal Data carried out within the scope of the Service as a processor within the meaning of Article 28 of the GDPR, to the exclusion of processing carried out as a controller by Nexway SASU, which is governed by the contract.
5. Instructions and commitments
The Processor undertakes to use the Client’s Personal Data in connection with the use of the Service only in accordance with instructions set out in the annex to the Agreement. The Processor shall immediately inform the Client if it considers that an instruction provided by the Client is unlawful under the applicable data protection regulations. The Processor shall not be held liable in the event that, despite the Processor’s notification regarding the unlawfulness of the instruction, the Client maintains and applies that instruction via the Service.
The Processor undertakes to comply with the provisions of the GDPR and, in particular, to maintain a record of processing activities specific to the Service and to develop its Service in accordance with the principles of ‘privacy by design’ and ‘privacy by default’.
The Processor undertakes never to transfer the Client’s Personal Data for any purpose other than the provision of the Service and undertakes never to use the Client’s Personal Data for its own benefit, in its capacity as controller.
The Processor declares that all internal and external staff involved in processing the Client’s Personal Data are bound by one or more binding legal agreements and receive regular training and awareness-raising.
The Processor undertakes to ensure the security of the Client’s Personal Data and to implement all necessary technical and organisational measures for its Service, the details of which are set out in the annex to the Agreement.
However, the Processor shall never be liable for any breaches by the Client of the applicable data protection regulations when the Client uses the Service as a controller.
6. Assistance with DPIA
Data Protection Impact Assessments (DPIAs) must be carried out by the Client, in accordance with the provisions of the GDPR. Nevertheless, the Processor undertakes to provide, upon written request from the Client, all the information necessary and required to enable the Client to carry out a DPIA.
However, the Processor is not required to carry out the DPIAs on behalf of and for the Client. Any request for information beyond what has already been provided may be refused.
7. Assistance with data subject requests
Data subject requests submitted by end users are forwarded to the Client without undue delay. The Processor is not required to maintain a record of data subject requests on behalf of the Client and is not liable for any failures on the part of the Client in the management of data subject requests.
Upon written request from the Client, the Processor shall carry out the technical measures necessary to enable the Client to fulfil its obligation to respond to requests from data subjects.
The Client accepts and understands that the Processor is not obliged to handle data subject requests made in connection with the Service on behalf of and for the Client. Any additional request seeking to ensure such handling will be refused.
Data subject requests sent to the Processor in its capacity as controller are handled exclusively by the Processor and are not forwarded to the Client.
8. Assistance with security measures
The Processor undertakes to provide all necessary and required information regarding the technical and organisational security measures to be implemented to ensure the security of the Client’s Personal Data in the context of the provision of the Service.
9. Personal data breaches
The Processor undertakes to notify the Client, without undue delay and no later than 48 working hours after becoming aware of it, of any personal data breach in connection with the Service that may affect the Client’s Personal Data, as well as to provide all necessary and required information in its possession to mitigate the effects of the personal data breach. The Client accepts and acknowledges that the 72-hour period applicable to them only begins to run from the time they become aware of the personal data breach and, as such, the 48-working-hour period complies with the GDPR.
The Processor is not authorised to handle data breach notifications to the Supervisory Authority or to inform end users on behalf of the Client. Any request to this effect from the Client will be refused.
10. Subsequent processors
The Client grants the Processor general authorization to engage sub-processors, provided that the Client is informed of any changes regarding such sub-processors without undue delay to allow the Client to raise objections. The Client accepts and acknowledges that a specific authorization for a SaaS tool is not applicable and could result in the Service being blocked.
In the absence of any objections raised by the Client within eight (8) days of notification, the new sub-processor shall be definitively appointed without the Client being able to object, claim damages or request the termination of the contract. If the objection raised within the time limit is deemed admissible by the Processor, the latter may propose one of the following solutions to the Client: i) the withdrawal of the sub-processor, ii) the implementation of additional measures to ensure the security of the Client’s Personal Data, iii) the termination of the Service without the Client being entitled to claim damages.
To be considered admissible by the Processor, objections must be objective and serious and must be duly substantiated. The Parties agree that the following situations shall, by default, be considered admissible: i) the proposed sub-processor is a direct competitor of the Client, ii) the sub-processor is involved in a dispute with the Client, iii) The sub-processor has been subject to a sanction by a Supervisory authority within the 12 months preceding its engagement; and iv) the sub-processor does not comply, where applicable, with the applicable rules governing transfers outside the European Union.
The Processor undertakes to engage only sub-processors who, following verification, provide the necessary and sufficient guarantees to ensure the security and confidentiality of the Client’s Personal Data. The relationship between the Processor and the sub-processor must be governed by an agreement containing obligations similar to those in this Agreement.
The Processor remains liable, within the limits of liability set out in the Contract, for any breaches of the GDPR that may be committed by its sub-processors in the course of providing the Service.
11. Hosting and transfers outside the European Union
a) Data hosting
The Processor undertakes to take all necessary steps to host the Client’s Personal Data exclusively within a Member State of the European Union. The Client grants the Processor authorisation to choose the Member State of the European Union of its choice. In the event that Personal Data is hosted in a country outside the European Union, The Processor undertakes to obtain the Client’s prior authorisation and to implement all necessary measures to regulate such a transfer, such as entering into standard contractual clauses and, where applicable, implementing additional technical measures to enhance the security of the Client’s Personal Data.
b) Data transfers
The Client grants the Processor a general authorization for transfers outside the European Union provided that, cumulatively, i) the transfers are made exclusively to GDPR-compliant sub-processors and that ii) the transfers are made exclusively to a country benefiting from an adequacy decision or are governed by appropriate safeguards such as, in particular, standard contractual clauses. If these conditions are not met, transfers outside the European Union are only permitted with the Client’s prior agreement. Additional technical security measures aimed at strengthening the security of the Client’s Personal Data must be implemented where Personal Data is transferred to a non-democratic country.
12. Retention periods and fate of the Client's Personal Data
The Processor undertakes to retain the Client’s Personal Data only for the duration of the use of the Service, in accordance with the instructions set out in the annex, and to delete it at the end of the Contract. The Processor shall, upon written request, certify the deletion of the Personal Data and all existing copies.
The Client is informed that they must retrieve their Personal Data before the end of the Agreement. Failing this, the Client will no longer be able to retrieve their Personal Data, as the deletion of personal data is irreversible and final. The Processor shall not be held liable for any loss of Personal Data following its deletion, with the Client assuming full responsibility. The Client agrees that the complete, irreversible and definitive anonymization of the Client’s Personal Data may be used as a means of deletion and that the Processor may retain the anonymized data for the purpose of improving the Service, as accepted by the Supervisory authorities.
The Processor informs the Client that the return of Personal Data provided for in the GDPR does not constitute reversibility of data to a new processor and that any request to that effect will always be refused by the Processor.
13. Audits
The Client has the right to conduct an audit in the form of a written questionnaire once a year to verify compliance with this Agreement. The questionnaire shall be deemed a sworn statement binding on the Processor. The questionnaire may be provided to the Processor in any form, and the Processor undertakes to respond to it without undue delay upon receipt.
The Client also has the right to carry out, once a year and at its own expense, an on-site audit, where applicable at the Processor’s premises, in the event of a data breach resulting from a proven and demonstrated failure on the part of the Processor that has caused duly justified harm to the Client. An audit at the Processor’s premises may be conducted either by the Client or by an independent third party appointed by the Client and must be notified in writing to the Processor at least thirty (30) days prior to the audit taking place. The Processor shall have the right to refuse the choice of the independent third party if the latter is (i) a direct or indirect competitor of the Processor, (ii) in a situation of conflict of interest with the Processor (e.g. acting as a consultant to a competitor of the Processor), or (iii) involved in pre-litigation or litigation with the Processor. In such cases, the Client undertakes to select a new independent third party to carry out the audit. The Processor may refuse access to certain areas for reasons of confidentiality or security. In such cases, the Processor shall carry out the audit in those areas and communicate the results to the Client.
In the event of any discrepancies identified during the audit, the Processor undertakes to implement, without delay and at its own expense, the necessary measures to ensure compliance with this Agreement. Discrepancies may relate only to the applicable regulations concerning the Client’s personal data and shall not relate to internal procedures or measures implemented by the Client on a specific basis. Discrepancies must be duly demonstrated, justified and documented.
In the event that the Processor disputes the identified discrepancies, the Processor may, at its discretion and subject to the Client’s prior written consent, propose to: i) meet to find an amicable solution and a compromise; ii) refer the matter to the Supervisory authority to obtain arbitration on the dispute; and iii) refer the matter to an independent expert to arbitrate the dispute.
14. Cooperation with authorities
The Processor undertakes to cooperate with the CNIL (French Data Protection Authority), the competent Supervisory authority, in the event of an inspection concerning the processing carried out within the scope of the Service, and undertakes to notify the Client as soon as possible in the event of requests concerning its Personal Data made by the Supervisory authority or by an administrative, judicial or police authority.
15. Contact
The Client and the Processor shall each appoint a contact person responsible for this Agreement, who shall be the recipient of the various notifications and communications required under the Agreement.
The Processor informs the Client that it has appointed Dipeeo SAS as its data protection officer, who can be contacted at the following contact details:
- Email address: [email protected]
- Postal address: Dipeeo SAS, 95 avenue du Président Wilson, 93100 Montreuil, France
- Telephone number: 01 59 06 81 85
16. Revisions
The Processor reserves the right to amend this Agreement in the event of changes to the applicable rules on the protection of personal data or in the event of changes to the Service that would result in the amendment of any of its provisions.