Data processing agreement (Article 28 GDPR)
Between the customer (controller) and Igor Kazazic, Segeparksgatan 18, 212 50 Malmö, Sweden (processor). Part of the Terms of service. Contact for this agreement: contact@dppmaker.com.
1. Subject matter, duration, nature and purpose
The processor processes personal data contained in documents, supplier contacts and user accounts to provide the service: storing documents, extracting values, sending supplier requests, producing evidence packs and audit trails. For the duration of the customer's use of the service and until deletion under section 8.
2. Types of personal data and data subjects
Names, work email addresses, phone numbers and signatures of the customer's users and of supplier contacts, as they appear in uploaded documents or are entered. The service is not intended for special categories of data.
3. Processor obligations
The processor will: * process personal data only on documented instructions from the controller, including these terms (Art. 28(3)(a)); * ensure that persons authorised to process the data are bound by confidentiality (Art. 28(3)(b)); * implement the measures in Annex 1 (Art. 32); * engage sub-processors only as set out in section 4; * assist the controller with data subject requests and with Articles 32 to 36, taking into account the nature of the processing; * delete or return all personal data at the end of the service (section 8); * make available the information needed to demonstrate compliance and allow for audits (section 7).
4. Sub-processors
The controller authorises the sub-processors listed on https://www.dppmaker.com/security. The processor will give at least [30] days' notice of new sub-processors; the controller may object and terminate. [TO BE REVIEWED]
5. International transfers
[TO BE REVIEWED: list any transfer outside the EU/EEA and the safeguard used.]
6. Personal data breaches
The processor notifies the controller without undue delay, and no later than [48] hours, after becoming aware of a personal data breach, with the information required by Article 33(3) as far as available.
7. Audits
The processor provides the information reasonably needed to demonstrate compliance. On-site audits by the controller or an independent auditor bound by confidentiality, with [30] days' notice, at the controller's cost.
8. Deletion
On termination, or when the controller deletes its organisation in the service, the processor deletes the personal data. Backups are overwritten within 14 days.
Annex 1: technical and organisational measures (as implemented in the service)
- Separation of customers' data by organisation in every query; roles (admin, member, read-only auditor).
- Confidential supplier documents visible only to admins and auditors, excluded from evidence packs.
- Append-only, hash-chained audit trail of uploads, extractions, reviews, requests, exports and access.
- Passwords stored as salted hashes; rate limits on sign-in, password reset and supplier links.
- HTTPS for all connections. [TO BE REVIEWED: encryption at rest as provided by the host.]
- Virus scanning of uploads where configured; encrypted daily backups kept for 14 days.
- Free gap-check files deleted after 60 minutes unless saved.
Version 3d30aaddf58a