Data protection
DATA PROCESSING POLICY
of Prodactive Solutions VCC
Whereas: Customer had accepted the General Terms and Conditions of Prodactive Solutions VCC and/or Customer and Prodactive Solutions VCC had executed a Master Service Agreement and therefore Customer and Prodactive Solutions VCC had entered into contractual relation (hereinafter referred to as the Agreement);
Whereas: Prodactive Solutions VCC, a variable capital company, established and existing under the laws of Republic of Bulgaria registered in the Commercial Register and the Register of NPLE with the Registry Agency with UIC 208373964, with seat and registered address at: Sofia 1756, Vitosha District, 78 Bistrishko Shose Street, contact e-mail marin@manifutura.ai (hereinafter referred to as “Prodactive”) administrates and/or processes information relating to an identified or identifiable natural persons provided by or on behalf of Customer as part of the provision of the Prodactive Product(s) (hereinafter referred to as Personal Data);
Whereas: both parties are intending to sets out their obligations with regards to the processing of the Personal Data, including such obligations as are required in order to comply with the EU Regulation (EU) 2016/679 of 27 April 2016 as amended from time to time (General Data Protection Regulation, GDPR) on a mutually beneficial basis;
the following Data Processing Policy (DPP) shall apply:
1. Roles of the parties
1.1 The parties acknowledge and agree that:
Prodactive shall process Personal Data in connection with the access of Customer’s employees – members of Customer’s staff, solely on behalf of Customer and in accordance with Customer’s instructions.
Accordingly, in the circumstances as per a) hereinabove, Prodactive acts as a Processor in respect of these data processing services (as such term is defined in the GDPR) and Customer acts as Controller to this personal data;
2. Subject-matter of the processing, nature and purpose of the processing, types of personal data and categories of data subjects
2.1 Where Prodactive acts as a Processor, the purpose of the processing of Personal Data (pursuant to Art. 28(3) GDPR) by Prodactive is the provision of the Prodactive Products pursuant to the Agreement. The types of Personal Data and categories of Data Subjects Processed by Havelock, when acting as a Processor, under this DPP are further specified in Annex 1 (Data Processing Details Annex) to this DPP.
2.2. Customer shall be obliged to create technical and legal prerequisites, so that before commencing any interaction with Prodactive Product (s), the individuals as per clause 1.1., letter “a” above provide their clear and unequivocal consent that their Personal Data is processed, as described in Annex 1 below by a third party – data processor, different from the Customer.
3. Compliance with Data Protection Law
3.1. In respect of the Personal Data for which Customer and Prodactive each act as Controllers, Customer and Prodactive shall comply with their respective obligations under the GDPR and all other mandatory laws and regulations of the European Union (Data Protection Laws). The parties acknowledge that this DPP may allocate responsibility for compliance with a particular requirement under Data Protection Law to one party, but that such contractual allocation of responsibility shall not relieve either party from its obligations under Data Protection Law.
3.2 Whenever Prodactive processes Personal Data as Processor, it shall comply with Data Protection Laws as they apply to Prodactiveas a Processor.
4. Processing of Personal Data and Customer’s instructions
4.1 Prodactive shall only process Personal Data that it processes as a Processor in accordance with Customer’s instructions (pursuant to Art. 28 clause (3)(a) GDPR) or as required by law. Customer instructs Prodactiveto process Personal Data to provide the Prodactive Products (s) as described in the DPP and the Agreement.
4.2 Customer shall (a) ensure that any instructions it issues to Prodactive pursuant to clause 4.1 shall comply with Data Protection Laws; (b) have sole responsibility for the accuracy, quality, and legality of Personal Data, and the means by which Customer acquired Personal Data; (c) notify Prodactive upon becoming aware that Personal Data has become inaccurate or out of date; and (d) establish the legal basis for processing under Data Protection Laws, including by providing all notices and obtaining all consents as may be required under Data Protection Laws in order for Prodactive to lawfully and fairly process Personal Data in order to provide the Prodactive Products (s) and as otherwise contemplated by this DPP and the remainder of the Agreement.
4.3 Customer warrants that (a) the disclosure of Personal Data to Prodactive is limited to what is necessary in order for Prodactive to perform the Services; and (b) such Personal Data is accurate and up to date at the time that it is provided to Havelock.
4.4 Without prejudice to Customer’s obligations under clause 4.2., Prodactive shall inform Customer if, in its reasonable opinion, an instruction issued by Customer infringes Data Protection Laws and shall, without liability, be entitled to stop processing Personal Data in accordance with such infringing instruction. The parties acknowledge and agree that a failure or delay by Prodactive to identify that an instruction infringes Data Protection Laws shall not cause Prodactive to be in breach of neither DPP nor Agreement.
4.5 Customer agrees that during and after the term of the Agreement Prodactivemay use any information it collects and uses in connection with the provision of the Service, together with information from its other services, for data analytics purposes, including to create insights, reports and other analytics to improve the quality of and market Prodactiveadvice, products and services.
5. Confidentiality and security of processing, Breach Management and Notification
5.1 Prodactive shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (pursuant to Art. 28(3)(b) GDPR). Prodactive shall not disclose Personal Data to any third parties without Customer’s prior consent, except as required by law or permitted by the Agreement.
5.2 Prodactive shall take the technical and organisational measures set out in Annex 2 (Security Measures) to protect the confidentiality, integrity, availability and resilience of Prodactive systems which are involved in processing Personal Data. Customer has assessed the level of security appropriate to the processing in the context of its obligations under Data Protection Laws and agrees that the security measures set out in Addendum 2 are consistent with such assessment.
5.3 Customer shall take appropriate technical and organisational measures to protect the security of the Personal Data, including ensuring that Personal Data is securely transferred to Havelock.
5.4 Prodactive shall promptly notify Customer upon becoming aware of the occurrence of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, transmitted, stored or otherwise processed (Personal Data Breach) and provide Customer with the following information as it becomes available:
5.4.1 a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects concerned;
5.4.2 the name and contact details of the Prodactive contact from whom more information can be obtained; and
5.4.3 a description of the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
5.5 Customer shall promptly notify Prodactive upon becoming aware of the occurrence of a Personal Data Breach.
5.6 The parties agree to coordinate in good faith on developing the content of any related public statements and any required notices to the affected data subjects and/or the relevant supervisory authority with authority under Data Protection Laws over the processing of Personal Data (Data Protection Regulator) in connection with a Personal Data Breach.
6. Data Subject Rights; Other Complaints and Requests
6.1 If Prodactive receives a request from a data subject to access, correct, amend, transfer or delete that person's Personal Data consistent with that person’s rights under Data Protection Laws (Data Subject Request), then to the extent permitted by law or unless otherwise agreed by the parties:
6.1.1 Prodactive shall promptly notify Customer upon receipt of the Data Subject Request. Following receipt of a Data Subject Request, Prodactive may contact the relevant data subject to acknowledge receipt of the Data Subject Request and to notify the data subject that it has referred the Data Subject Request to Customer, but Prodactiveshall otherwise not respond to any Data Subject Request without Customer’s prior written instructions;
6.1.2 Customer shall handle the Data Subject request in accordance with Data Protection Law; and
6.1.3 Prodactive shall provide such commercially reasonable assistance as Customer may reasonably request to help Customer fulfil its obligations under Data Protection Laws to respond to Data Subject Requests. Customer shall be responsible for any reasonable costs arising from Prodactive provision of such assistance.
6.2 To the extent permitted by law, Prodactive shall promptly notify Customer upon receipt of any complaint or request (other than Data Subject Requests or enquiries of Data Protection Regulators described in clause 7) relating to: (a) Customer’s obligations under data protection laws; or (b) Personal Data.
Unless otherwise agreed between the parties, Customer shall handle the relevant complaint or request in accordance with Data Protection Law and Prodactive shall provide such commercially reasonable assistance as Customer may reasonably request in relation to such complaint or request. Customer shall be responsible for any reasonable costs arising from Prodactive provision of such assistance.
7. Cooperation with Data Protection Regulators and Conduct of Claims
7.1 Prodactive shall notify Customer of all enquiries from a Data Protection Regulator that Prodactive receives which relate to the processing of Personal Data, unless prohibited from doing so at law or by the Data Protection Regulator.
7.2 In respect of Personal Data that Prodactive processes in relation to Services that it provides as a Processor, unless a Data Protection Regulator requests in writing to engage directly with Prodactive or the parties (acting reasonably and taking into account the subject matter of the request) agree that Prodactive shall handle a Data Protection Regulator request itself, Customer shall: (a) be responsible for all communications or correspondence with the Data Protection Regulator in relation to the processing of Personal Data and the provision or receipt of the Services; and (b) keep Prodactive informed of such communications or correspondence to the extent permitted by law.
8. Return and Deletion of Personal Data
8.1 On termination of the Agreement for any reason, or upon written request from Customer at any time, Prodactive shall cease processing any Personal Data, and (at Customer’s direction) return to Customer or delete (in accordance with Prodactive document retention and deletion policies), any Personal Data in Prodactive possession or control, except as required by law or as required in order to defend any actual or possible legal claims and except as retained pursuant to clause 4.5.
8.2 Customer acknowledges and agrees that Prodactive shall have no liability for any losses incurred by Customer arising from or in connection with Prodactive’s inability to perform the Services as a result of Prodactive complying with a request to delete or return Personal Data made by Customer.
9. Conflict with the Agreement, term of this DPP and Miscellaneous
9.1 In the event of a conflict between the terms of the Agreement and the terms of this DPP, the terms of this DPP shall prevail.
9.2 The binding effect of this DPP to the relations between Prodactive and the Customer will be terminated when Prodactive ceases to process Personal Data, unless otherwise agreed in writing between the parties.
9.3 Unless expressly stated otherwise in this DPP, the parties agree that all liabilities between them under this DPP will be subject to the limitations and exclusions of liability and other terms of the Agreement.
9.4 To the extent required by applicable Data Protection Laws, this DPP shall be governed by the laws of the European Union. In all other cases, this DPP shall be governed by the laws of the jurisdiction specified in the Agreement.
ANNEX 1
Data Processing Details Annex
I. Controller
Customer and the Customer affiliates that process Personal Data for their own business purposes.
II. Processor
The processor is Havelock.
III. Data subjects
The Personal Data processed concern the following categories of data subjects:
employees of the Customer - members of Customer’s staff, like, but not limited to, individuals, directly involved in Customer’s operations and using Prodactive Product (s) as End Users as defined in the Terms;
individuals that interact with the Customer in relation with Customer’s business operations as commercial counterparts, suppliers and other external service providers of the Customer, who’s Personal Data may, for any reason become subject to processing by Prodactivein relation to Customer’s use of the Prodactive Product (s).
IV. Categories of data
The Personal Data processed concern the following categories of data of the Data subjects:
Identification data : name, e-mail address, position in the company, phone number, nickname and avatar created within the Haveloc Product (s).
Behavioral data regarding performance of employment duties.
Processing operations
The Personal Data processed will be subject to the following basic processing activities:
Havelock, acting as a Processor, will, depending on the scope of its engagement, process the Personal Data provided by the Customer, to comply with its statutory and regulatory obligations, to maintain accounts and records and to conduct analysis in order to improve its products and services. This will involve, among other things, the collection, storage, analysis (including – automated profiling) and disclosure of Personal Data that Prodactive receives from the Controller within the course of provision of the ProdactiveProducts (s).
Personal Data shall be stored, through the cloud service providers of Prodactive only in the territory of EU and will not, for whatever reason be exported to any Third Countries without the explicit written approval of the Customer.
ANNEX 2
Security Measures
In satisfaction of its obligation under clause 5.2 of this DPP, Prodactive shall implement the following:
Organizational management and dedicated staff responsible for the development, implementation and maintenance of Prodactive information security program.
Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Havelock’s organization, monitoring and maintaining compliance with Prodactivepolicies and procedures, and reporting the condition of its information security and compliance to internal senior management.
Data security controls which include at a minimum, but may not be limited to, logical segregation of data, restricted (e.g. role-based) access and monitoring, and utilization of commercially available and industry standard encryption technologies for Personal Data that is:
3.1 transmitted over public networks (i.e. the Internet) or when transmitted wirelessly; or
3.2 at rest or stored on portable or removable media (i.e. laptop computers, CD/DVD, USB drives, back-up tapes).
Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, (e.g. granting access on a need-to-know and least privilege basis, use of unique IDs and passwords for all users, periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).
Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords and requiring that Prodactive passwords that are assigned to its employees: (i) be at least eight (8) characters in length, (ii) not be stored in readable format on Prodactive computer systems; (iii) must be changed every ninety (90) days; must have defined complexity; (v) must have a history threshold to prevent reuse of recent passwords; and (vi) newly issued passwords must be changed after first use.
System audit or event logging and related monitoring procedures to proactively record user access and system activity for routine review.
Physical and environmental security of data center, server room facilities and other areas containing Personal Data designed to: (i) protect information assets from unauthorised physical access, (ii) manage, monitor and log movement of persons into and out of Prodactive facilities, and (iii) guard against environmental hazards such as heat, fire and water damage.
Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems according to prescribed internal and adopted industry standards, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Prodactive possession.
Change management procedures and tracking mechanisms designed to test, approve and monitor all changes to Prodactive technology and information assets.
Incident / problem management procedures designed to allow Prodactive to investigate, respond to, mitigate and notify of events related to Prodactive technology and information assets.
Network security controls that provide for the use of enterprise firewalls and intrusion detection systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack.
Vulnerability assessment, patch management, and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergency situations or disasters.
Prodactive reserves the right to revise the security measures set out in this Annex 2 at any time, without notice, so long as any such revisions will not materially reduce or weaken the protection provided for Personal Data that Prodactive processes in the course of providing the Service to the Customer.