1. Definitions
“Applicable Data Protection Law” means the General Data Protection Regulation (“GDPR”) and relevant implementation acts, and any amendments and/or changes thereto.
“Company Affiliate” means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with the Company, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity.
“Data Subjects” means the individuals to whom the Data relate.
“Data” means data as defined in the Applicable Data Protection Law that will be processed by INQQA in connection with the performance of the Services.
“Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, data transmitted, stored or otherwise processed.
“Public Authorities” means any Dutch or foreign regulatory authority, law enforcement authority or national security authority that has statutory authority to supervise the relevant data collection and data processing activities.
“Services” means the software capabilities, services and other activities to be supplied to or carried out by or on behalf of INQQA for the Company.
“Third Countries” means all countries outside of the European Union (EU), excluding countries which provide an adequate level of protection for data as determined by the European Commission from time to time.
2. Processing of Company Data
In the performance of the Services, the Company shall be the data controller and INQQA shall be the data processor as defined in the Applicable Data Protection Law.
The Company instructs INQQA to Process Non-Personal Data as INQQA considers reasonably necessary for the provision of the Services and warrants that it is and will at all relevant times remain duly and effectively authorized to give this instruction on behalf of each relevant Company Affiliate.
INQQA shall comply with the Applicable Data Protection Law in the Processing of the Data, and shall not Process Data other than on the Company's documented instructions unless INQQA is required to otherwise Process or transfer the Data under the laws of the European Union or one of its Member States.
3. Technical and Organizational Security Measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, INQQA shall in relation to the Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including the measures referred to in Article 32(1) of the GDPR.
INQQA shall notify the Company without undue delay upon INQQA becoming aware of a Data Breach affecting Data, providing the Company with sufficient information to allow the Company to meet any obligations to report or inform Data Subjects of the Data Breach under the Applicable Data Protection Law.
INQQA shall co-operate with the Company and take such reasonable commercial steps as are directed by the Company to assist in the investigation, mitigation, and remediation of each such Data Breach.
4. International Transfers
INQQA shall be permitted to transfer Data within the European Union (“EU”) in accordance with this Clause.
In the event that INQQA Processes, accesses, stores and/or transfers Data in or to any country outside the EU or to any country that does not provide an adequate level of protection for data, INQQA shall comply with the (international transfer) obligations under the Applicable Data Protection Law by ensuring that appropriate safeguards are put in place to provide an adequate level of protection in relation to the Processing of the transferred Data.
5. Sub-Processors and Employees
INQQA will respect the conditions referred to in paragraphs 2 and 4 of Article 28 of the GDPR for engaging another data processor.
INQQA will ensure that all of its employees authorized to have access to (or otherwise to Process) the Data have committed themselves to confidentiality on appropriate terms or are under an appropriate statutory obligation of confidentiality.
6. Co-operation
INQQA will take appropriate technical and organizational measures, insofar as is possible, to assist the Company in responding to requests from data subjects for access to or rectification, erasure or portability of Data or for restriction of Processing or objections to Processing of Data.
INQQA will give the Company such assistance as the Company reasonably requests and INQQA is reasonably able to provide to ensure compliance with the Company's security, data protection impact assessment and obligations imposed by the Public Authorities under the Applicable Data Protection Law.
7. Audit Rights
INQQA shall make available to the Company all information in respect of its Processing of Data as may validly be required to demonstrate compliance with the obligations laid down in this Data Processing Agreement and allow for and contribute to audits, including inspections, conducted by the Company or another auditor mandated by the Company.
This does not require INQQA to disclose to the Company or the Company's auditors any information disclosed to INQQA in confidence by, or otherwise held by INQQA in confidence on behalf of, any of INQQA's other clients or any other person.
8. Deletion or Return of Data
When provision of the Services is complete, or earlier if the Company withdraws their instructions, INQQA will as soon as is practicable delete (or return to the Company, at the Company's option) any Data in INQQA's possession or under INQQA's control which is subject to the Applicable Data Protection Law.
This does not require INQQA to delete or return Processed Data which INQQA is required to retain by the law or regulation of a member state of the European Union, or copies of Data which it is not technically practicable for INQQA to locate and delete or return.
9. Indemnity
Each Party indemnifies the other Party for any claims of third parties, including Data Subjects, or penalties imposed by the relevant supervisory authorities, to the extent that such penalties and/or claims can be attributed to the Indemnifying Party and/or are a result of non-compliance with the Indemnifying Party's obligations under this Data Processing Agreement and/or the Applicable Data Protection Law.
10. Term and Termination
This Data Processing Agreement shall become effective on the date of signing hereof.
This Data Processing Agreement will terminate automatically, without any notice being required, as per the date that the Services are being terminated.
11. General
In the event of any changes to the Applicable Data Protection Law, the Parties shall consult each other and discuss and agree on the required amendments to this Data Processing Agreement to ensure continued compliance.
In the event that any of the provisions of this Data Processing Agreement are declared void or otherwise not enforceable, the remaining provisions will remain unimpaired.
Any general or special terms and conditions of Company shall not apply to this Data Processing Agreement and are hereby explicitly declined by INQQA.
This Data Processing Agreement shall be governed by and construed in accordance with the laws of the Netherlands.
All disputes arising under or in connection with this Data Processing Agreement shall exclusively be submitted to the competent court of Amsterdam, the Netherlands.
