This data processing agreement (the "Data Processing Agreement") is entered between the Licensee and DbVis Software AB, the Licensor and forms an integrated part of the EULA. By using the Software the Licensee accepts to be bound by the terms and conditions of the Data Processing Agreement. The Licensor and the Licensee are hereinafter jointly referred to as the "Parties" and each individually as a "Party".
DOWNLOAD ADDENDUM
Introduction
1. Definitions
Unless the circumstances clearly indicate otherwise, definitions or terms used in this document shall be defined as set forth below and any such definition or term which is used in the General Data Protection Regulation and which is not stated below shall be defined as follows from Article 4 of the General Data Protection Regulation. Definitions are also set out in the EULA.
"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
"Data Subject" means the living natural person whose Personal Data is Processed.
"General Data Protection Regulation" means Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.
"Instruction" means the instructions the Licensee gives the Licensor within the scope of this Data Processing Agreement.
"Other Regulatory Regime" means national laws applicable from time to time to Processing of Personal Data (excluding the General Data Protection Regulation).
"Personal Data" means any information relating to an identified or identifiable natural person, where an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Processor" means a natural or legal person, public authority, agency or another body which Processes Personal Data on behalf of the Controller.
2. Documents
3. Generally Regarding the Processing
4. Purpose and type of Personal Data etc.
The Instruction shall, inter alia, state the subject of the Processing, the duration, nature and purpose of the Processing, the type of Personal Data, and the categories of Data Subjects.
5. The Licensor’s Personnel etc.
6. Security
7. Personal Data Breach
8. Impact Assessment and Prior Consultation
The Licensor shall, taking into account the nature of the Processing and the information available to the Licensor, assist the Licensee in fulfilling its obligations, if any, regarding the performance of a data protection impact assessment and/or prior consultation with a supervisory authority in accordance with Articles 35 and 36 of the General Data Protection Regulation.
9. Instruction
The Licensor may only Process Personal Data covered by this Data Processing Agreement based on the Licensee’s documented instructions (including in respect of transfers of Personal Data to a third country or an international organisation, unless such Processing is required by EU law or by a Member State’s national law to which the Licensor is subject, in which case the Licensor shall inform the Licensee of the legal requirement prior to Processing of the data, unless such information is prohibited on grounds of important public interest under the relevant national law).
10. Subprocessors
11. Transfer to Third Countries
All of the Licensor’s Processing of Personal Data on behalf of the Licensee takes place within the EU/EEA or the US. The Licensor warrants that no Personal Data will be moved, stored, transferred, or otherwise Processed outside the EU/EEA or the US. All transferring of Personal Data outside the EU/EEA, will be in compliance with applicable transfer mechanisms.
12. Request for Information
13. Right to Transparency
14. Remuneration
The Licensor shall receive remuneration for measures that it takes in respect of Processing of Personal Data in accordance with this Data Processing Agreement, or in accordance with the EULA and appendices in general.
15. Liability
A Party is liable to compensate for damage/loss that it, or another party for which it is liable, has caused to the other Party in connection with Processing of Personal Data, or in the event of actions in breach of this Data Processing Agreement, covered by the limitation of liability in clause 9 of the EULA. Notwithstanding the foregoing, the Licensor’s liability in relation to the Licensee will never exceed an amount corresponding to the fees paid or payable by Licensee for the Software in the twelve (12) months preceding the claim.
16. Termination of the Data Processing Agreement
Definitions used in this Instruction shall have the same meaning as in the Data Processing Agreement, unless the circumstances clearly indicate otherwise.
Subject Matter of the Processing
The subject matter of the Licensor’s Processing of Personal Data on behalf of the Licensee is:
Purpose of each Processing
The purpose of the Licensor’s Processing of Personal Data on behalf of the Licensee is:
Categories of Processing
The measures carried out by the Licensor as part of the Processing of Personal Data on behalf of the Licensee are:
Categories of Personal Data
The Licensor is entitled to Process the following categories of Personal Data on behalf of the Licensee:
Categories of Data Subjects
The Licensor is entitled to Process Personal Data relating to the following categories of Data Subjects:
Duration of the Processing
The Licensor will Process Personal Data during the following time period:
Technical and Organisational Security Measures
The Licensor shall take the following technical and organisational security measures as part of the Processing of Personal Data on behalf of the Licensee:
Storage Minimization
Personal Data may not be stored longer than is necessary for the purpose of the Processing.
Approved Subprocessors
The Licensee has approved the Licensor’s use of the following subprocessors: