DPA& TOM
This DataProcessing Agreement("Agreement") forms part of the Contract forServices under the MakeMarket.ioby Makeitfuture SRL Terms and Conditions (the"Principal Agreement").This Agreement is an amendment to thePrincipal Agreement and is effective uponits incorporation to the PrincipalAgreement, which incorporation may bespecified in the Principal Agreement oran executed amendment to the PrincipalAgreement. Upon its incorporation intothe Principal Agreement, this Agreementwill form a part of the PrincipalAgreement.
Weperiodically update this Agreement. If you havean active MakeMarket.io byMakeitfuture SRL account, you will be informed of anymodification by email.At the bottom of this page you can find archived versionsof our DPA.
The term ofthis Agreement shall follow the term ofthe Principal Agreement. Terms notdefined herein shall have the meaning as setforth in the Principal Agreement.
WHEREAS
(A) Yourcompany act as a Data Controller (the"Controller").
(B) Yourcompany wishes to subcontract certainServices (as defined below), which implythe processing of personal data, to MakeitfutureSRL, acting as a DataProcessor (the "Processor").
(C) TheParties seek to implement a data processingagreement that complies with therequirements of the current legal framework inrelation to data processing andwith the Regulation (EU) 2016/679 of theEuropean Parliament and of the Councilof 27 April 2016 on the protection ofnatural persons with regard to theprocessing of personal data and on the freemovement of such data, andrepealing Directive 95/46/EC (General Data ProtectionRegulation).
(D) TheParties wish to lay down their rights andobligations.
IT ISAGREED AS FOLLOWS:
1. Definitions and Interpretation
1.1 Unless otherwise defined herein, capitalized terms and expressions used in this DPA shall have the following meaning:
1.1.2 "Company Personal Data" means any Personal Data Processed by a Contracted Processor on Controller's behalf pursuant to or in connection with the Principal Agreement;
1.1.3 "Contracted Processor" means a Subprocessor;
1.1.4 "Data Protection Laws" means EU Data Protection Laws and, to the extent applicable, the data protection or privacy laws of any other country;
1.1.5 "EEA" means the European Economic Area;
1.1.6 EU Data Protection Laws" means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR;
1.1.7 "GDPR" means EU General Data Protection Regulation 2016/679;
1.1.8 "Data Transfer" means:
1.1.8.1 a transfer of Company Personal Data from Controller to a Contracted Processor; or
1.1.8.2 an onward transfer of Company Personal Data from a Contracted Processor to a Subcontracted Processor, or between two establishments of a Contracted Processor,
in each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);
1.1.9 "Services" means end-to-end encrypted email services. The Service is described more in detail in Schedule 1.
1.1.10 "Subprocessor" means any person appointed by or on behalf of Processor to process Personal Data on behalf of Controller in connection with the Agreement.
2. Processing of Company Personal Data
2.1 Processor shall: comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and not process Company Personal Data other than on Controller's documented instructions.
2.2 Controller instructs Processor to process Company Personal Data to provide the Services and related technical support.
3. Processor Personnel
Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Company Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with Applicable Laws in the context of that individual's duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
4. Security
4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.
5. Subprocessing
5.1 Processor shall not appoint (or disclose any Company Personal Data to) any Subprocessor unless required or authorized by Controller.
6. Data Subject Rights
6.1 Taking into account the nature of the Processing, Processor shall assist Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Controller obligations, as reasonably understood by Controller, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
7. Personal Data Breach
7.1 Processor shall notify Controller without undue delay upon Processor becoming aware of a Personal Data Breach affecting Company Personal Data, providing Controller with sufficient information to allow Controller to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws.
This Agreement is governed by German Law.