Data Processing Agreement (DPA)

Last update: 21.06.2018

Dieses Rechtsdokument wird in seiner verbindlichen englischen Fassung bereitgestellt.

wservices (the Processor) takes the security and privacy of data subjects (Customers) seriously. This Data Processing Agreement ("DPA") is required of the European Data Protection Regulation ("GDPR"). It is an additional agreement to the Terms of Service ("Agreement") between wservices, LLC ("wservices") and the Customer.

Definitions

  • "Controller", "Processor", "Process/Processes/Processing/Processed", "Personal Data", "Special Categories of Data" shall have the same meaning as in Directive 95/46/EC of the European Parliament.
  • "Affiliate" the Company and any other entity that, directly or indirectly through one or more intermediaries, controls, is controlled by, or is under common control with, the Company.
  • "Data Protection Laws" means all data protection and privacy laws and regulations applicable to the processing of Personal Data under the Agreement, including GDPR.
  • "Security Breach" means any attempted or successful unauthorized access, use, disclosure, modification, or destruction of information.
  • "Services" means any product or service provided by wservices to Customer pursuant to and as more particularly described in the Agreement.
  • "Sub-processor" means any Processor engaged by wservices or its Affiliates to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA. Sub-processors may include third parties or any wservices Affiliate.

1. Scope and Applicability

1.1 This DPA applies where and only to the extent that wservices processes Personal Data on behalf of the Customer in the course of providing the Services and such Personal Data is subject to Data Protection Laws of the European Union. The parties agree to comply with the terms and conditions in this DPA.

1.2 Role of the Parties. As between wservices and Customer, Customer is the Controller of Personal Data and wservices shall process Personal Data only as a Processor on behalf of Customer. Nothing in the Agreement or this DPA shall prevent wservices from using or sharing any data that wservices would otherwise collect and process independently of Customer's use of the Services.

1.3 Customer Obligations. Customer agrees that:

  • 1.3.1 it shall comply with its obligations as a Controller under Data Protection Laws.
  • 1.3.2 it has provided notice and shall obtain all consents and rights necessary under Data Protection Laws for wservices to process Personal Data and provide the Services pursuant to the Agreement and this DPA.

2. Security

2.1 Security Measures. wservices and the Customer shall implement and maintain proper technical and organizational security measures for the protection of Personal Data. wservices’s security standards are described in Annex A ("Technical and organizational security measures").

2.2 Updates to Security Measures. Customer acknowledges that the Security Measures are subject to technical progress and development and that wservices may update or modify the Security Measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by the Customer.

2.3 Security Breach Response. Upon becoming aware of a Security Breach, wservices shall notify Customer without undue delay and shall provide timely information relating to the Security Breach as it becomes known or as is reasonably requested by Customer.

2.4 Confidentiality of Processing. wservices shall ensure that any person who is authorized by wservices to process Personal Data (including its subcontractors, agents, and staff) shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty).

3. Processing of Personal Data

3.1 Purposes. wservices shall process Personal Data fairly and lawfully and only for the following purposes:

  • for its legitimate business purposes, such as billing, account management, technical support, product development, sales and marketing
  • to perform the Services
  • to perform any steps necessary for the performance of the DPA
  • to provide, maintain and improve the Services provided to Customer
  • disclosures as required by law or otherwise set forth in the Agreement

For other purposes, a prior written agreement between Customer and wservices is required.

3.2 Processing Locations. wservices stores and processes Customer Data in data centers and offices located inside and outside the European Union. The data centers and offices comply with the GDPR or have an adequate level of protection.

4. Subprocessing

4.1 Authorized Sub-processors. Customer agrees that wservices may engage Sub-processors to process Personal Data on Customer's behalf. The Sub-processors currently engaged by wservices and authorized by Customer are listed in Annex B.

4.2 Sub-processor Obligations. wservices shall only work with GDPR compliant Sub-processors or with an adequate level of protection.

4.3 Changes to Sub-processors. wservices shall regularly update the list of Sub-processors listed in Annex B.

5. Cooperation

5.1 To the extent that Customer is unable to independently access the relevant Personal Data within the Services, wservices shall, provide reasonable cooperation to assist Customer by appropriate technical and organizational measures, in so far as is possible, to respond to any requests from individuals or applicable data protection authorities relating to the processing of Personal Data under the Agreement. If any such request is made directly to wservices, wservices shall not respond to such communication directly without Customer's prior authorization, unless legally compelled to do so. If wservices is required to respond to such a request, wservices shall promptly notify Customer and provide it with a copy of the request unless legally prohibited from doing so.

5.2 To the extent wservices is required under Data Protection Law, wservices shall (at Customer's expense) provide reasonably requested information regarding wservices's processing of Personal Data under the Agreement to enable the Customer to carry out data protection impact assessments or prior consultations with data protection authorities as required by law.

6. Return or Deletion of Data

6.1 Personal data shall not be kept for longer than is necessary. Upon deletion of the Services, Personal Data shall be deleted, save that this requirement shall not apply to the extent wservices is required by applicable law to retain some or all of the Personal Data, or to Personal Data it has archived on backup systems, which such Personal Data wservices shall securely isolate and protect from any further processing, except to the extent required by applicable law.

7. Miscellaneous

7.1 If there is any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict.

7.2 This DPA is a part of and incorporated into the Agreement, so references to "Agreement" in the Agreement shall include this DPA.

7.3 This DPA shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement unless required otherwise by Data Protection Laws.

wservices, LLC

Name: Pascal Bader