Compliance Translator
Draft. This text has not been reviewed yet and is not in force.

Data processing agreement (Article 28 GDPR)

Between the customer (controller) and Igor Kazazic, Segeparksgatan 18, 212 50 Malmö, Sweden (processor). Part of the Terms of service. Contact for this agreement: contact@dppmaker.com.

1. Subject matter, duration, nature and purpose

The processor processes personal data contained in documents, supplier contacts and user accounts to provide the service: storing documents, extracting values, sending supplier requests, producing evidence packs and audit trails. For the duration of the customer's use of the service and until deletion under section 8.

2. Types of personal data and data subjects

Names, work email addresses, phone numbers and signatures of the customer's users and of supplier contacts, as they appear in uploaded documents or are entered. The service is not intended for special categories of data.

3. Processor obligations

The processor will: * process personal data only on documented instructions from the controller, including these terms (Art. 28(3)(a)); * ensure that persons authorised to process the data are bound by confidentiality (Art. 28(3)(b)); * implement the measures in Annex 1 (Art. 32); * engage sub-processors only as set out in section 4; * assist the controller with data subject requests and with Articles 32 to 36, taking into account the nature of the processing; * delete or return all personal data at the end of the service (section 8); * make available the information needed to demonstrate compliance and allow for audits (section 7).

4. Sub-processors

The controller authorises the sub-processors listed on https://www.dppmaker.com/security. The processor will give at least [30] days' notice of new sub-processors; the controller may object and terminate. [TO BE REVIEWED]

5. International transfers

[TO BE REVIEWED: list any transfer outside the EU/EEA and the safeguard used.]

6. Personal data breaches

The processor notifies the controller without undue delay, and no later than [48] hours, after becoming aware of a personal data breach, with the information required by Article 33(3) as far as available.

7. Audits

The processor provides the information reasonably needed to demonstrate compliance. On-site audits by the controller or an independent auditor bound by confidentiality, with [30] days' notice, at the controller's cost.

8. Deletion

On termination, or when the controller deletes its organisation in the service, the processor deletes the personal data. Backups are overwritten within 14 days.

Annex 1: technical and organisational measures (as implemented in the service)

Version 3d30aaddf58a