Data Processing Agreement (DPA)
concluded between:
The entity defined as the “Client”, which has decided to purchase and use the services offered by the Agency RYS SP. Z O.O.,
hereinafter referred to in this Agreement as the “Controller”
a
RYS spółka z ograniczoną odpowiedzialnością with its registered office in Bielsko-Biała (43-300) at ul. Podwale nr 47, entered into the register of entrepreneurs kept by the District Court in Bielsko-Biała, 8th Commercial Division of the National Court Register under KRS number: 0001006923, NIP: 5472234742, REGON: 523865502, with a share capital in the amount of 5,000.00 PLN,
hereinafter referred to in this Agreement as the “Processor”
who shall hereinafter be jointly referred to as the “Parties”, and each of them separately as a “Party”
Whereas:
- The Parties have concluded a service agreement of (hereinafter: the Main Agreement), in connection with the performance of which the Controller shall entrust the Processor with the processing of personal data, to the extent specified in this Agreement,
- The Parties, in concluding this Agreement, seek to regulate the principles of the processing of personal data in such a way that they fully correspond to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the GDPR)
The Parties have decided to conclude the Agreement with the following content:
§ 1. General provisions
- On the terms specified in this Agreement and in the Main Agreement, the Controller entrusts the Processor with the personal data of natural persons (hereinafter: the Personal Data).
- The Controller declares that it processes all the Personal Data as the controller of such personal data, and that the processing is carried out lawfully.
- The Controller entrusts the Processor with the Personal Data of natural persons of the following categories:
a) the Controller's employees,
b) the Controller's associates,
c) the Controller's clients, - The entrustment of the Personal Data takes place for the purpose of the Processor providing to the Controller services connected with the performance of the Main Agreement, including in particular the services of comprehensive handling and management of sales on marketplace platforms, after-sales customer service (complaints and returns), and running and optimising advertising campaigns.
- The processing of the Personal Data by the Processor, as regards the nature of the processing, shall:
a) take place at the Processor's registered office,
b) be carried out on a continuous basis, until the agreement ceases to be in force. - The processing of personal data by the Processor shall take place solely on the basis of a documented instruction of the Controller. In order for the Parties to consider a particular instruction to be documented, it should follow directly from this Agreement or from the Main Agreement, or it should be sent by e-mail, in accordance with the rules of communication set out in § 8(2) of the Agreement.
- Under this Agreement, the Processor will process, in particular, the following types of Personal Data:
CATEGORIES OF DATA SUBJECTS | TYPE OF ENTRUSTED PERSONAL DATA | PURPOSE OF THE PROCESSING OF PERSONAL DATA |
|---|---|---|
The Controller's employees | first name, surname, job title, e-mail, telephone number, and in the case of verification on a marketplace: PESEL number, bank statement, ID card number. | performance of the Main Agreement |
The Controller's collaborators | first name, surname, job title, e-mail, telephone number, and in the case of verification on a marketplace: PESEL number, bank statement, ID card number. | performance of the Main Agreement |
The Controller's clients who are legal persons | company name, e-mail, telephone number, NIP, registered office address, data of the persons representing the Clients, such as: first name, surname, e-mail address, telephone number, order number | performance of the Main Agreement |
The Controller's clients who are persons conducting sole proprietorship business activity | first name, surname, company name, address, e-mail address, telephone number, NIP, order number | performance of the Main Agreement |
The Controller's clients who are natural persons | first name, surname, address, telephone number, e-mail address, order number | performance of the Main Agreement |
- The Controller may also entrust the Processor with other Personal Data not listed in § 1(7) of the Agreement, as well as with Personal Data of categories of persons other than those listed in § 1(3) of the Agreement, including unstructured data, that is data resulting from content with a potential and probable personal data content (entries, text documents, recordings, images, videos). The entrustment of such Personal Data requires it to be sent in accordance with the rule of communication set out in § 8(2) of the Agreement and shall not be treated as an amendment to this Agreement requiring a written annex.
- This Agreement enters into force on the date of its signing by both Parties (hereinafter referred to as the “Effective Date”).
- In cases where this is applicable, in particular where the Controller also acts as a processor with respect to the personal data which it entrusts to the Processor, this Data Processing Agreement shall also be treated as an Agreement for the sub-entrustment of processing of personal data.
§ 2. Duration of the processing of Personal Data
- The Processor will process the Personal Data for the duration of the Main Agreement.
- The term of this Agreement is the same as the term of the Main Agreement, and this Agreement shall expire automatically upon termination of the Main Agreement.
§ 3. Sub-entrustment
- The Processor may sub-entrust specific operations of processing Personal Data to other processors, provided that the Controller has given its prior approval of the entity to which the Personal Data is to be sub-entrusted.
- The sub-entrustment of the processing of Personal Data referred to in § 3(1) of the Agreement requires that this fact be notified to the Controller in order to enable it to raise an objection. The notification of the sub-entrustment should be made in accordance with the rules for contact between the Parties indicated in § 8(2) of the Agreement. The Controller may, for justified reasons, raise an objection to the sub-entrustment of the data to a particular processor within 7 days of receiving the notification referred to in the preceding sentence. If an objection is raised, the Processor shall have no right to entrust the Personal Data to the processor covered by the objection. Where the Controller does not respond in any way to the Processor's e-mail concerning the planned sub-entrustment, the Parties shall treat such silence as the Controller's consent to carrying out the sub-entrustment. The Processor shall notify the Controller of any doubts as to the merits of the objection and its possible negative consequences in time to allow the continuity of the processing of Personal Data to be ensured.
- The Controller hereby consents to the sub-entrustment of the Personal Data by the Processor to the following entities:
- providers of hosting and server and cloud infrastructure services,
- providers of IT and telecommunications systems used for customer relationship management (CRM), business process automation and marketing analytics,
- providers of cybersecurity tools, including systems for the encrypted management of credentials and passwords (password managers).
- providers of advanced analytical, reporting and SEO systems as well as tools used for the aggregation, integration and processing of marketing data,
- providers of services and software for the electronic signing of documents and for handling the digital circulation of agreements.
- When making a sub-entrustment, the Processor is obliged to oblige the entity to which it sub-entrusts the processing of Personal Data to apply appropriate measures for the protection of such Data.
- The Processor shall have no right to transfer the performance of this Agreement in its entirety to the sub-entrusted entity.
§ 4. Representations and obligations of the Processor
- The Processor hereby represents that:
1) it has implemented procedures ensuring the compliance of the processing of personal data as regulated by the GDPR,
2) it has the expert knowledge and the resources guaranteeing the due performance of personal data protection procedures, in accordance with the GDPR,
3) it applies organisational and technical measures serving the processing of personal data in accordance with the GDPR, described in the content of Appendix No. 1 to this Agreement, - Under this Agreement, the Processor is obliged to:
1) process the entrusted Personal Data solely in accordance with the documented instructions or directions of the Controller,
2) cooperate in the exercise of the rights of the individual, taking into account that the Controller is the party solely responsible for examining the requests of natural persons, and that the Processor should inform the Controller of all requests received, and that the Parties should also inform each other of any disputes or claims in order to settle them amicably as quickly as possible,
3) cooperating with the Controller in the performance of personal data protection obligations referred to in Articles 32-36 GDPR,
4) informing the Controller, without undue delay, of any doubts as to the lawfulness of the orders or instructions issued by the Controller, failing which it shall lose the possibility of pursuing claims against the Controller on that account, - The Controller is obliged to cooperate with the Processor in the performance of this Agreement. It is furthermore obliged to provide the Processor with the necessary explanations, in particular in the event of doubts as to the lawfulness of the Controller's orders, as well as to fulfil its obligations.
§ 5. Security of Personal Data
- The Processor has carried out a risk analysis of the processing of the entrusted Personal Data and complies with its results as regards the organisational and technical measures for the protection of Personal Data.
- The Processor shall notify the Controller of every suspected Personal Data breach no later than within 24 hours of the first report, enabling the Controller to participate in the investigation activities and informing it of the findings as soon as they are made, in particular of the confirmation of a breach or of the absence thereof.
- The Processor is obliged to send the Controller a notification of the confirmed breach together with all necessary documentation concerning the breach, in order to enable the Controller to fulfil its obligation to notify the supervisory authority.
§ 6. Supervision of the Processing of Personal Data
- The Controller is entitled to carry out an inspection of the manner in which personal data is processed by the Processor solely to the extent necessary to verify the compliance of the processing with this Agreement and with Article 28 GDPR.
- A planned inspection shall be carried out after prior notification of the Processor at least 7 days in advance, in documentary form, specifying the scope of the inspection, its anticipated duration and the composition of the inspection team.
- A planned inspection may be carried out no more frequently than once in a calendar year and shall take place during the Processor's working hours, in a manner that does not unjustifiably disrupt the continuity of its operational activities.
- The limitations referred to in paragraphs 2–3 shall not apply in the event of:
1) confirmation of a personal data breach
2) a justified suspicion of a breach of the provisions of this Agreement,
3) a request or recommendations of the supervisory authority. - The inspection may be carried out by the Controller or by a third party acting on its instructions, provided that such entity has first been bound to confidentiality at least at the level resulting from this Agreement and that there is no conflict of interest with the Processor.
- The scope of the inspection does not include:
1) information constituting the Processor's business secret, to the extent not directly connected with the processing of the Controller's personal data,
2) personal data or information of the Processor's other clients.
The protection referred to above is implemented in particular through anonymisation, pseudonymisation or supervised access to documentation. - The Processor shall provide the Controller with access to the information necessary to demonstrate compliance with the obligations arising from Article 28 GDPR, primarily by:
1) making available up-to-date documentation concerning the protection of personal data,
2) reports from internal audits or certifications,
3) responses to the Controller's written enquiries.
Carrying out an on-site audit constitutes a measure of last resort, applied solely where verification in the manner referred to above is not possible. - A standard documentary or remote inspection is carried out free of charge. In the case of an on-site inspection or an inspection going beyond the standard scope, requiring a significant commitment of the Processor's resources, the Controller shall cover the reasonable and actual organisational costs of such inspection, agreed in advance between the Parties.
- The Parties jointly confirm that inspections are carried out with respect for the principles of proportionality, minimisation and accountability referred to in Article 5(1) and (2) GDPR.
§ 7. Liability
- The liability of the Parties for non-performance or improper performance of this Agreement is subject to the limitations, exclusions and liability caps set out in the Main Agreement, subject to mandatory provisions of law, including Article 82 GDPR.
- Subject to paragraphs 4–6, the Processor's total liability towards the Controller, regardless of the legal basis of the claim, is limited to an amount corresponding to the total net remuneration due to the Processor from the Controller in the 12-month period preceding the event giving rise to liability.
- The Processor shall be liable solely for damage caused by wilful misconduct or gross negligence, whereby liability for damage caused as a result of ordinary negligence is excluded to the fullest extent permitted by law.
- The limitations of liability set out in this Agreement do not apply to the Processor's liability towards data subjects arising from Article 82(1)–(2) GDPR.
- The Processor shall not be liable for administrative fines or other public-law sanctions imposed on the Controller, unless they have been imposed as a result of a breach of personal data protection provisions for which the Processor is at fault.
- The Processor's liability for lost profits and indirect damage in the contractual relationship with the Controller is excluded, to the fullest extent permitted by law.
- Upon expiry of the Agreement, the Processor shall return or delete the personal data, in accordance with Article 28(3)(g) GDPR, subject to retention obligations arising from provisions of law or the need to secure claims.
- In the event of receiving an unlawful order, the Processor is entitled to withhold its performance until the matter has been clarified and shall not be liable for the consequences of such withholding, within the limits permitted by law.
- The Controller's claims against the Processor arising from this Agreement shall expire if they are not notified within 12 months from the date of obtaining information about the event, excluding claims arising from Article 82 GDPR.
§ 8. Final Provisions
- Each Party undertakes to notify the other Party without delay of any breaches of confidentiality known to it relating to this Agreement. The Processor undertakes to take due action in order to recover and secure the Personal Data or Confidential Information and to prevent further unauthorised actions or breaches of this Agreement.
a) In order to perform this Agreement, the Parties shall communicate via the e-mail addresses of the persons designated for contact and for the coordination of cooperation, indicated in the Main Agreement or provided to the other Party during the implementation of the service (onboarding). - In the event of a dispute arising between the Parties out of this Agreement, the court competent to hear the case shall be the court determined by the principal place of business of the Processor.
- In matters not regulated by this Agreement, the provisions of the GDPR and other generally applicable provisions of Polish law shall apply.
Appendix No. 1 Description of the technical and organisational personal data security measures
1. Organisational measures
- Personal data are processed solely by persons holding written authorisations to process them.
- Authorised persons are obliged to maintain the confidentiality of personal data and of the means of securing them.
- The Processor maintains a register of persons authorised to process personal data.
- Employees and co-workers are trained in the protection of personal data and the GDPR.
- Personal data are processed solely to the extent necessary to achieve the specified purposes (the minimisation principle).
- The Processor has implemented procedures for responding to personal data breaches, including the rules for reporting and documenting them.
2. Technical measures
- Access to IT systems is secured by means of:
- individual logins and passwords,
- strong passwords,
- two-factor authentication,
- permission management (the principle of least privilege is applied – employees/co-workers have access only to those tools and client data which are necessary for the performance of their tasks)
- IT systems have access control mechanisms, restricting access to data solely to authorised users.
- Named accounts are used, with no shared accounts, where the platform allows this.
- Personal data processed in IT systems are protected by:
- encryption of data transmission (SSL/TLS),
- network firewalls (firewall),
- up-to-date antivirus and anti-malware software,
- MFA/2FA (in particular for remote access and privileged accounts),
- automatic account lockouts after failed login attempts.
- encryption and pseudonymisation- encryption of data at rest (AES-256) and in transmission (TLS 1.2+), pseudonymisation of data in test and analytical environments,
- Regularly performed are backups (backup) data, stored in a secure environment.
- Devices used for data processing (computers, laptops) are:
- password-protected,
- protected against access by third parties,
- locked in the event of user inactivity.
3. Measures ensuring the continuity and integrity of data
- The Processor applies procedures ensuring the continuity of operation of IT systems.
- Data are protected against:
- accidental or unauthorised destruction,
- loss,
- modification,
- unauthorised disclosure.
- Backups and business continuity:
- regular backups (the 3-2-1 rule),
- data restoration tests,
4. Periodic verification of security measures
- The Processor carries out periodic verification and updating of the technical and organisational measures applied.
- The security measures are adapted to:
- the nature of the data processed,
- the scale of the processing,
- the risk of infringement of the rights or freedoms of data subjects.