PRIVACY POLICY
DATA PROCESSING AGREEMENT
§1. General Provisions
- This Privacy Policy (hereinafter "Policy") specifies the rules of processing personal data in connection with the use of the Application made available by RGS sp. z o.o. (hereinafter: "Provider") to the Customer, as also contains the provisions constituting a Personal Data Processing Agreement within the meaning of Art. 28 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter "GDPR").
- The Policy constitutes an integral part of the General Terms and Conditions of Agreements (GTC) and applies to all agreements concluded between the Supplier and the Customer.
- The terms spelled with capital letter and not defined in this Policy, shall have the meanings provided in GTC.
§2. Roles in Personal Data Processing
- The Customer acts as the Personal Data Controller (hereinafter referred to as "Personal Data Controller") within the meaning of Art. 4(7) of the GDPR with respect to the personal data of Moderators, Operators, Staff, and other individuals whose data has been entered into the Application by the Customer or persons acting on their behalf. The Customer independently specifies the purposes and ways of processing such data, and the Application serves solely as a tool for achieving those purposes.
- The Provider acts as the Processor within the meaning of Art. 4(8) of the GDPR with respect to the personal data that the Customer entrusts to the Provider in order to provide the Service, including, in particular, maintenance of the Application, technical support, provision of security and backup copies.
- Notwithstanding the foregoing, the Provider acts as a separate Personal Data Controller with respect to the data necessary to:
- create and maintain Accounts in the Application (including the Accounts of the Customer, Moderators, Operators, and Staff),
- manage Accounts, including verification of the identities, handling login and authentication processes,
- maintain and ensure continuity of the Application, including resolving technical issues,
- fulfill the Provider's legal obligations,
- pursue or defend against claims.
- To the extent the Provider acts as a data Controller, the legal basis for processing is:
- Art. 6, sec. 1, letter a of the GDPR – consent of the Staff, in particular as regards direct marketing.
- Art. 6, sec. 1, letter b of the GDPR – necessity for the performance of the agreement or undertaking steps prior to entering into the agreement,
- Art. 6, sec. 1, letter c of the GDPR – compliance with the Provider's legal obligation,
- Art. 6, sec. 1, letter f of the GDPR – the Provider's legitimate interest, in particular ensuring security of the Application, pursuing claims, and developing services.
§3. Entrusting Personal Data Processing
- The Customer (acting as the Personal Data Controller) entrusts the Provider (Processor) with the processing of personal data under the terms specified in this Policy, as per Art. 28 of the GDPR. Acceptance of the GTC by the Customer constitutes at the same time the conclusion of a personal data processing agreement within the meaning of Art. 28, sec. 3 of the GDPR.
- Subject of Processing: processing of personal data of Moderators, Operators, and Staff whose data has been entered into the Application in connection with the provision of the Service.
- Purpose of Processing: operation of the Website, provision of the Service to the Customer, maintenance and development of the Application, ensuring data security, creating backup copies, and fulfilling obligations arising out of the GTC.
- Nature of Processing: automated and non-automated processing, including in particular: collecting, recording, organizing, structuring, storing, adapting, modifying, downloading, viewing, using, disclosing by transmission, deleting, or destroying data.
- Types of Personal Data: in particular:
- name and surname,
- email address,
- telephone number (if provided),
- data regarding position and role in the Customer's organization,
- data regarding attendance, work time, and absence,
- data regarding tasks and work results,
- login data and activity in the Application,
- other data entered into the Application by the Customer, Moderator, Operator, or Staff.
- Categories of Data Subjects: Customer, Moderators, Operators, Staff.
- Processing Period: personal data shall be processed by the Provider for the duration of the Agreement between the Customer and the Provider and for the period necessary to settle the Agreement and fulfill legal obligations, however not longer than until the data is permanently deleted from the Application as per the provisions of the GTC.
§4. Obligations of the Provider as Processor
- The Provider undertakes to process personal data only based on documented instructions of the Customer (Personal Data Controller), including the transfer of personal data to a third country or international organization, unless such an obligation is imposed on the Provider by European Union or Member State law.
- The Provider shall ensure that persons authorized to process personal data are obliged to maintain confidentiality or are subject to an appropriate statutory obligation of confidentiality
- The Provider shall take any and all measures required under Art. 32 GDPR, in particular, shall implement appropriate technical and organizational measures to ensure the level of security appropriate to the risk, including, but not limited to:
- pseudonymization and encryption of personal data, where justified,
- ability to continuously ensure confidentiality, integrity, availability and resilience of systems and processing services,
- ability to quickly restore availability and access to personal data in the event of a physical or technical incident,
- regular testing, measuring and evaluating the effectiveness of technical and organizational measures aiming at ensuring the security of processing.
- The Provider complies with the terms and conditions of use of the services of another processor (sub-processor) referred to in §5 of this Policy.
- The Provider, taking into account the nature of processing, shall, to the extent possible, assist the Customer in fulfilling the obligation to respond to requests from data subjects regarding the exercise of their rights specified in Chapter III of the GDPR.
- The Provider shall assist the Customer in fulfilling the obligations specified in Art. 32–36 of the GDPR, taking into account the nature of processing and the information available to the Customer.
- Upon termination of the Service, the Provider, at the Customer's discretion, shall delete or return every personal data to the Customer and delete its existing copies, unless European Union or Member State law requires the storage of personal data. The principles for data export and deletion are specified in §13 of the GTC.
- The Provider shall provide the Customer with every information necessary to demonstrate compliance with the obligations specified in Art. 28 of the GDPR and shall allow the Customer or its authorized auditor to conduct audits, including inspections, and shall contribute to them, provided that the audit:
- is conducted with the observance of confidentially principles and after a prior arrangement with the Provider,
- does not disrupt the Provider's normal operations,
- is taking place not more frequently than once every 12 months, unless there is a reasonable suspicion of a personal data breach,
- the costs of the audit are borne by the Customer.
- The Provider shall immediately notify the Customer if, in its opinion, an instruction it has been given constitutes a breach of the GDPR or other European Union or Member State data protection regulations.
§5. Further Processing by a Sub-Processor (Sub-Processing)
- The Customer generally consents to the Provider making use of the services of sub-processors to the extent necessary to provide the Service, in particular the providers of hosting, cloud, technical support and backup services.
- The Provider shall notify the Customer of any intended changes concerning the addition or replacement of sub-processors, giving the Customer the opportunity to object to such changes within 14 days of receiving the notification.
- If the Customer objects, the Parties shall negotiate to find a solution. If the Parties fail to reach an agreement within 30 days, the Customer has the right to terminate the Agreement with immediate effect.
- The Provider shall ensure that sub-processors are bound by personal data protection obligations which are at least equivalent to those arising from this Policy.
- The Provider shall be fully liable to the Customer for the fulfillment of obligations by sub-processors.
- An up-to-date list of sub-processors shall be available at the Customer's request.
§6. Breach of Security of Personal Data
- Having discovered breach of personal data, the Provider shall notify the Customer (Personal Data Controller) of such an instance without undue delay, however not later than within 48 hours.
- A breach report shall include at least:
- description of the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects,
- name and surname and the contact details of the person from whom more information can be obtained,
- description of the possible consequences of the breach,
- description of the measures taken or proposed to address the breach.
- The Provider shall take immediate action to minimize the effects of the breach and protect personal data from further breach.
- The decision to report the breach to the supervisory authority and to notify data subjects rests solely with the Customer as the Personal Data Controller.
§7. Customer's Information Obligations towards Data Subjects
- The Customer, as the Personal Data Controller, is obligated to fulfill the information obligations towards Moderators, Operators, Staff and all other persons whose data is processed in the Application, as per Art. 13 or Art. 14 of the GDPR.
- The Customer is obligated, in particular, to inform data subjects about:
- the identity and contact details of the Customer as the Personal Data Controller,
- the purposes of personal data processing and the legal basis for processing,
- the recipients of personal data or categories of recipients, including the entrustment of data processing to the Provider (RGS sp. z o.o.) for the purpose of providing the Service,
- the intention to transfer personal data to a third country (if applicable),
- the period for which personal data will be stored,
- the rights of data subjects (right of access, rectification, erasure, restriction of processing, data portability, objection),
- the right to lodge a complaint with the supervisory authority (President of the Personal Data Protection Office),
- the fact that personal data is also processed by the Provider as a separate Controller to the extent specified in §2.3 of this Policy.
- The Customer is obligated to provide the above information to its employees, collaborators, and subcontractors prior to granting them access to the Application or immediately after entering their data into the Application.
- The Provider shall provide the Customer with a template of the information clause that can be used by the Customer to fulfill its information obligations. Use of the template does not relieve the Customer of the liability to fulfill its information obligations in a manner consistent with the GDPR.
- The Customer may place its own information documents (clauses, policies) in the Application during the Account configuration process to fulfill its information obligations towards data subjects.
§8. Rights of Data Subjects
- Individuals whose personal data is processed in connection with the use of the Application have rights arising from the GDPR, in particular:
- the right to access data (Art. 15 of the GDPR),
- the right to rectify data (Art. 16 of the GDPR),
- the right to erase data (Art. 17 of the GDPR),
- the right to restrict processing (Art. 18 of the GDPR),
- the right to data portability (Art. 20 of the GDPR),
- the right to object (Art. 21 of the GDPR),
- the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office.
- With respect to data for which the Customer is the Controller, requests from data subjects should be addressed directly to the Customer. The Provider, as the Processor, supports the Customer in fulfilling such requests to the extent technically feasible.
- With respect to data for which the Provider is the Controller (as per §2, sec. 3), the requests should be directed to the Provider at the address indicated in the GTC or at the Provider's website.
§9. Transfer of Data to Third Countries
- The Provider does not transfer personal data to third countries outside the European Economic Area (EEA), unless:
- it is necessary to use third-party infrastructure to provide the Service,
- the transfer is based on standard contractual clauses adopted by the European Commission or another mechanism provided for in the GDPR,
- the Customer has been notified in advance of such transfer.
§10. Technical and Organizational Measures
- The Provider shall implement and maintain appropriate technical and organizational measures to protect personal data processed in the Application, in particular:
- access control to systems and data on a least privilege basis,
- encryption of data transmission (SSL/TLS),
- separate instances of the application environment for each Customer,
- regular backups,
- monitor security and detect incidents,
- training staff on personal data protection,
- procedures for responding to security incidents.
- The Provider shall regularly review and update the applied security measures to ensure they are adequate to current threats.
§11. Data Retention Period
- Personal data processed on the basis of this entrustment shall be stored for the duration of the Agreement and subsequently deleted as per the provisions of the GTC (§13 of the GTC).
- Personal data processed by the Provider as a Controller (as per §2, sec. 3) shall be stored for the period necessary to achieve the processing purposes, and then for the period required by law or until any claims have expired.
§12. Liability
- The Customer shall be fully liable for the compliance of personal data processing with the provisions of the GDPR to the extent to which it acts as a Data Controller.
- The Customer shall indemnify and hold the Provider harmless from any claims, administrative penalties, fines or decisions of supervisory authorities arising from the Customer's breach of personal data protection regulations, including, in particular, failure to comply with the information obligations or the lack of legal basis for processing.
- The Provider's liability as a Processor shall be limited to cases in which the Provider has failed to fulfill its obligations under the GDPR imposed directly on processors or has acted outside of or contrary to the Customer's lawful instructions.
§13. Final Provisions
- This Policy comes into effect on the date of its acceptance by the Customer as part of the GTC.
- For any matters related to personal data protection, please contact the Provider at the following email address: gdpr@appme.works.
- The Provider reserves the right to amend the Policy. Any amendments to the Policy shall become effective upon the expiry of 14 days from the date of notification of the amendment, unless the Customer terminates the Agreement within that period.
- In matters not covered by this Policy, the provisions of the GDPR and the Personal Data Protection Act shall apply.