Data Processing Agreement<\/h2>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\tGiven that<\/p>\n
\n- \n
This agreement is an integral part of the general conditions of service and the specific conditions relating to web services and cloud services by Next Data (hereinafter, service or main contract).<\/p>\n<\/li>\n
- \n
This agreement describes the duties, tasks and specific requirements for the processing of personal data by the Data Processor.<\/p>\n<\/li>\n
- \n
With reference to data processing, in the event of a discrepancy between this document and the main contract, this agreement shall prevail.<\/p>\n<\/li>\n
- \n
Any breach of this agreement will constitute a material breach of the Master Agreement.<\/p>\n<\/li>\n
- \n
The Client company assumes, pursuant to art. 4 GDPR, the qualification of Data Controller of personal data and that Next Data srl assumes the qualification of Data Processor (hereinafter, the Parties).<\/p>\n<\/li>\n<\/ul>\n
Having said this and considered an integral part of this agreement, the Parties stipulate the following:<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t1. Authorization<\/h2>\n
The Data Controller authorizes the Data Processor to process personal data subject to the service referred to in the introduction. The person in charge of the processing of personal data undertakes to process the data lawfully, fairly and in full compliance with all the provisions issued regarding the processing of personal data, as well as the following specific instructions. The controller also specifies that he is able to offer sufficient guarantees to implement technical and organizational measures in such a way that the processing meets the requirements of the GDPR and guarantees the protection of the rights of the data subjects.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t2. Object<\/h2>\n
The object of this agreement is the definition of the methods and conditions related to the data processing carried out by the Data Processor on behalf of the Data Controller with reference to the service contract referred to in the introduction. By signing this agreement, the Parties undertake to comply with current national or supra-national legislation on the protection of personal data of individuals. The parties acknowledge and accept that any breach of this agreement by the Data Processor or the Data Controller constitutes a breach of the service supply contract and that, in this case and without prejudice to any other right or remedy available, the Data Controller o the Manager may choose to immediately terminate the main Contract in accordance with the provisions of the termination provisions set forth therein.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t3. Duration<\/h2>\n
This agreement will produce effects between the Parties for the entire duration of the service supply contract by Next Data and will no longer be effective when the Customer terminates or wishes to conclude the main contract.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t4. Origin of the data<\/h2>\n
The Data Controller ensures that the data covered by this agreement have been collected lawfully and in compliance with current legislation and that the information transmitted to the data controller does not in any way violate the rights of the data subjects.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t5. Types and nature of personal data<\/h2>\n
The Data Processor will not process personal data other than those necessary for the execution of the main Contract, unless the processing is required by the laws and regulations on Data Protection to which the Data Processor is subject. The Data Controller instructs the Data Processor to process only personal data as reasonably necessary for the provision of the service and in accordance with the terms and conditions of the main contract and this agreement. The type of personal data required for the implementation of the service by Next Data is of the personal data type, in addition to contact information. The nature of the operations carried out on personal data refers to the maintenance, assistance and updating of the service. For the execution of the main contract, the Data Controller makes any necessary information requested available to the Manager.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t6. Personnel of the Data Processor<\/h2>\n
Data processing will be carried out only by personnel of the Data Processor previously authorized for processing, pursuant to art. 29 GDPR and art. 2-quaterdecies of Legislative Decree 196\/2003 and duly instructed on their responsibilities. The data controller guarantees that the staff dedicated to the execution of the main contract have been made aware of the confidential nature of the information received from the Data Controller. The Data Processor also guarantees that access to personal data is limited to personnel who need to access the relevant personal data, to the extent strictly necessary, for the purposes set out in the main contract and in this agreement.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t7. Obligations of the Manager<\/h2>\n
The Data Processor entrusted with the data processing on behalf of the Data Controller undertakes to observe the following obligations for the execution of the main contract:<\/p>\n
7.1 Owner's instructions<\/strong><\/h3>\nThe Manager must process the data for the purposes indicated above and for the execution of the contractual services undertaken. The Data Processor must process the data in accordance with the provisions of art. 32 GDPR.<\/p>\n
7.2 Place of processing<\/strong><\/h3>\nThe data will be stored and processed by the Data Processor within the European territory and if in the future the processing should be carried out in non-EU countries, the Data Processor will notify the Data Controller to agree on the appropriate guarantees that the same requires depending on the place where the treatment will be carried out. In the event that the Data Processor is required to transfer data to a third country or an international organization by virtue of the laws of the Union or of the Member State of origin, he must inform the Data Controller of this obligation in order to to obtain authorization prior to the transfer. Personal data will be stored on behalf of the data controller at the following datacenters:<\/p>\n
\n- \n
DC OV1 \u2013 59100 Roubaix, Nord-Pas-de-Calais-Picardie (Francia)<\/p>\n<\/li>\n
- \n
DC AR1 \u2013 Via S. Clemente, 53, 24036 Ponte San Pietro\u00a0 – Bergamo (Italia)<\/p>\n<\/li>\n
- \n
DC FX1 \u2013 Via Bologna 714 44124 Ferrara (Italia)<\/p>\n<\/li>\n<\/ul>\n
7.3 Confidentiality<\/strong><\/h3>\nThe Data Processor guarantees the confidentiality of the personal data processed as part of the execution of the main contract. The Data Processor guarantees that its authorized personnel have signed a legal obligation of confidentiality and that they have received the necessary training in the field of processing and protection of personal data.<\/p>\n
7.4 Security<\/strong><\/h3>\nThe data controller will proceed with the data processing in the presence of the measures required pursuant to art. 32 GDPR. The Data Processor adopts adequate technical and organizational measures to protect the security, confidentiality and integrity of personal data. These measures include, where appropriate:<\/p>\n
\n- \n
the assessment of the adequate level of security, in particular of all risks associated with the processing, for example due to accidental or illegal destruction, loss, or alteration, storage, access, communication or unauthorized or illegal access of personal data;<\/p>\n<\/li>\n
- \n
the pseudonymisation and encryption of personal data;<\/p>\n<\/li>\n
- \n
the ability to guarantee the confidentiality, integrity, availability and resilience of the processing systems and services on a permanent basis;<\/p>\n<\/li>\n
- \n
the ability to restore availability and access to personal data, in a timely manner, in the event of a physical or technical incident;<\/p>\n<\/li>\n
- \n
a procedure for testing, determining and periodically evaluating the effectiveness of the technical and organizational measures aimed at guaranteeing the security of the processing of personal data;<\/p>\n<\/li>\n
- \n
measures to identify vulnerabilities relating to the processing of personal data in the systems used to provide the service to the Data Controller.<\/p>\n<\/li>\n<\/ul>\n
The Data Processor takes into account the risks concerning the processing of personal data, in particular to prevent any breach of security or other substantially similar events, as defined by the laws and regulations on data protection.<\/p>\n
7.5 Information<\/strong><\/h3>\nThe Data Processor immediately informs the Data Controller if, in his opinion, any instruction by the Data Controller may differ from the GDPR or other data protection provisions of the Member States or any other applicable legislation.<\/p>\n
7.6 Impact assessment and prior consultation<\/strong><\/h3>\nThe Data Processor will provide the Data Controller with reasonable assistance with any data protection impact assessment required by Article 35 of the GDPR and after consultation with any supervisory authority by the Data Controller that is required pursuant to Article 36 of the GDPR, in any case only in relation to the processing of the personal data of the Data Controller by the Data Processor.<\/p>\n
7.7 Codes of conduct<\/strong><\/h3>\nAt the request of the Data Controller, the Data Processor must comply with any Code of Conduct approved pursuant to Article 40 of the GDPR and obtain any certification approved by Article 42 of the EU GDPR, regarding the processing of the Personal Data of the Data Controller.<\/p>\n
7.8 Audit<\/strong><\/h3>\nThe Data Processor must make available to the Data Controller, upon request, all the information necessary to demonstrate compliance with the obligations set out in this agreement and allow and contribute to the audit activities, including inspections, carried out by the Data Controller or by another person appointed by them of any location in which the processing of personal data of the Data Controller takes place. Any audit activity by the Data Controller must be agreed with the Data Processor. If these activities involve charges and expenses not foreseen by this agreement or by the main contract, all the requests of the Data Controller must be managed at the project level with an estimate of the costs necessary for their implementation (whether these are penetration test, vulnerability assessment or other activities. ).<\/p>\n
7.9 Rights of interested parties<\/strong><\/h3>\nThe Data Processor must promptly notify the Data Controller, within the limits permitted by law, if he receives requests from an interested party regarding his right of access, the right of rectification, limitation of treatment, cancellation ("right to be forgotten" ), data portability, the right to oppose the processing, or your right not to be subject to an automated decision-making process, or any other question or information regarding the personal data processed by the Data Processor in accordance with the provisions of the main Contract. At the request of the Data Controller, the Data Processor must assist the Data Controller in responding to the requests of the interested parties. Taking into account the nature of the processing, the Data Processor must assist the Data Controller by means of adequate technical and organizational measures, as far as possible, for the fulfillment of the Data Controller's obligations in response to the requests of the interested party provided for by the applicable laws and regulations on the subject. of data protection.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
Given that<\/p>\n
- \n
- \n
This agreement is an integral part of the general conditions of service and the specific conditions relating to web services and cloud services by Next Data (hereinafter, service or main contract).<\/p>\n<\/li>\n
- \n
This agreement describes the duties, tasks and specific requirements for the processing of personal data by the Data Processor.<\/p>\n<\/li>\n
- \n
With reference to data processing, in the event of a discrepancy between this document and the main contract, this agreement shall prevail.<\/p>\n<\/li>\n
- \n
Any breach of this agreement will constitute a material breach of the Master Agreement.<\/p>\n<\/li>\n
- \n
The Client company assumes, pursuant to art. 4 GDPR, the qualification of Data Controller of personal data and that Next Data srl assumes the qualification of Data Processor (hereinafter, the Parties).<\/p>\n<\/li>\n<\/ul>\n
Having said this and considered an integral part of this agreement, the Parties stipulate the following:<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t1. Authorization<\/h2>\n
The Data Controller authorizes the Data Processor to process personal data subject to the service referred to in the introduction. The person in charge of the processing of personal data undertakes to process the data lawfully, fairly and in full compliance with all the provisions issued regarding the processing of personal data, as well as the following specific instructions. The controller also specifies that he is able to offer sufficient guarantees to implement technical and organizational measures in such a way that the processing meets the requirements of the GDPR and guarantees the protection of the rights of the data subjects.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t2. Object<\/h2>\n
The object of this agreement is the definition of the methods and conditions related to the data processing carried out by the Data Processor on behalf of the Data Controller with reference to the service contract referred to in the introduction. By signing this agreement, the Parties undertake to comply with current national or supra-national legislation on the protection of personal data of individuals. The parties acknowledge and accept that any breach of this agreement by the Data Processor or the Data Controller constitutes a breach of the service supply contract and that, in this case and without prejudice to any other right or remedy available, the Data Controller o the Manager may choose to immediately terminate the main Contract in accordance with the provisions of the termination provisions set forth therein.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t3. Duration<\/h2>\n
This agreement will produce effects between the Parties for the entire duration of the service supply contract by Next Data and will no longer be effective when the Customer terminates or wishes to conclude the main contract.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t4. Origin of the data<\/h2>\n
The Data Controller ensures that the data covered by this agreement have been collected lawfully and in compliance with current legislation and that the information transmitted to the data controller does not in any way violate the rights of the data subjects.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t5. Types and nature of personal data<\/h2>\n
The Data Processor will not process personal data other than those necessary for the execution of the main Contract, unless the processing is required by the laws and regulations on Data Protection to which the Data Processor is subject. The Data Controller instructs the Data Processor to process only personal data as reasonably necessary for the provision of the service and in accordance with the terms and conditions of the main contract and this agreement. The type of personal data required for the implementation of the service by Next Data is of the personal data type, in addition to contact information. The nature of the operations carried out on personal data refers to the maintenance, assistance and updating of the service. For the execution of the main contract, the Data Controller makes any necessary information requested available to the Manager.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t6. Personnel of the Data Processor<\/h2>\n
Data processing will be carried out only by personnel of the Data Processor previously authorized for processing, pursuant to art. 29 GDPR and art. 2-quaterdecies of Legislative Decree 196\/2003 and duly instructed on their responsibilities. The data controller guarantees that the staff dedicated to the execution of the main contract have been made aware of the confidential nature of the information received from the Data Controller. The Data Processor also guarantees that access to personal data is limited to personnel who need to access the relevant personal data, to the extent strictly necessary, for the purposes set out in the main contract and in this agreement.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
<\/div><\/div><\/div>\n\t\n\t\t\n\t\t\t\n\t\t\t\t\n\n\t\n\t\t7. Obligations of the Manager<\/h2>\n
The Data Processor entrusted with the data processing on behalf of the Data Controller undertakes to observe the following obligations for the execution of the main contract:<\/p>\n
7.1 Owner's instructions<\/strong><\/h3>\n
The Manager must process the data for the purposes indicated above and for the execution of the contractual services undertaken. The Data Processor must process the data in accordance with the provisions of art. 32 GDPR.<\/p>\n
7.2 Place of processing<\/strong><\/h3>\n
The data will be stored and processed by the Data Processor within the European territory and if in the future the processing should be carried out in non-EU countries, the Data Processor will notify the Data Controller to agree on the appropriate guarantees that the same requires depending on the place where the treatment will be carried out. In the event that the Data Processor is required to transfer data to a third country or an international organization by virtue of the laws of the Union or of the Member State of origin, he must inform the Data Controller of this obligation in order to to obtain authorization prior to the transfer. Personal data will be stored on behalf of the data controller at the following datacenters:<\/p>\n
- \n
- \n
DC OV1 \u2013 59100 Roubaix, Nord-Pas-de-Calais-Picardie (Francia)<\/p>\n<\/li>\n
- \n
DC AR1 \u2013 Via S. Clemente, 53, 24036 Ponte San Pietro\u00a0 – Bergamo (Italia)<\/p>\n<\/li>\n
- \n
DC FX1 \u2013 Via Bologna 714 44124 Ferrara (Italia)<\/p>\n<\/li>\n<\/ul>\n
7.3 Confidentiality<\/strong><\/h3>\n
The Data Processor guarantees the confidentiality of the personal data processed as part of the execution of the main contract. The Data Processor guarantees that its authorized personnel have signed a legal obligation of confidentiality and that they have received the necessary training in the field of processing and protection of personal data.<\/p>\n
7.4 Security<\/strong><\/h3>\n
The data controller will proceed with the data processing in the presence of the measures required pursuant to art. 32 GDPR. The Data Processor adopts adequate technical and organizational measures to protect the security, confidentiality and integrity of personal data. These measures include, where appropriate:<\/p>\n
- \n
- \n
the assessment of the adequate level of security, in particular of all risks associated with the processing, for example due to accidental or illegal destruction, loss, or alteration, storage, access, communication or unauthorized or illegal access of personal data;<\/p>\n<\/li>\n
- \n
the pseudonymisation and encryption of personal data;<\/p>\n<\/li>\n
- \n
the ability to guarantee the confidentiality, integrity, availability and resilience of the processing systems and services on a permanent basis;<\/p>\n<\/li>\n
- \n
the ability to restore availability and access to personal data, in a timely manner, in the event of a physical or technical incident;<\/p>\n<\/li>\n
- \n
a procedure for testing, determining and periodically evaluating the effectiveness of the technical and organizational measures aimed at guaranteeing the security of the processing of personal data;<\/p>\n<\/li>\n
- \n
measures to identify vulnerabilities relating to the processing of personal data in the systems used to provide the service to the Data Controller.<\/p>\n<\/li>\n<\/ul>\n
The Data Processor takes into account the risks concerning the processing of personal data, in particular to prevent any breach of security or other substantially similar events, as defined by the laws and regulations on data protection.<\/p>\n
7.5 Information<\/strong><\/h3>\n
The Data Processor immediately informs the Data Controller if, in his opinion, any instruction by the Data Controller may differ from the GDPR or other data protection provisions of the Member States or any other applicable legislation.<\/p>\n
7.6 Impact assessment and prior consultation<\/strong><\/h3>\n
The Data Processor will provide the Data Controller with reasonable assistance with any data protection impact assessment required by Article 35 of the GDPR and after consultation with any supervisory authority by the Data Controller that is required pursuant to Article 36 of the GDPR, in any case only in relation to the processing of the personal data of the Data Controller by the Data Processor.<\/p>\n
7.7 Codes of conduct<\/strong><\/h3>\n
At the request of the Data Controller, the Data Processor must comply with any Code of Conduct approved pursuant to Article 40 of the GDPR and obtain any certification approved by Article 42 of the EU GDPR, regarding the processing of the Personal Data of the Data Controller.<\/p>\n
7.8 Audit<\/strong><\/h3>\n
The Data Processor must make available to the Data Controller, upon request, all the information necessary to demonstrate compliance with the obligations set out in this agreement and allow and contribute to the audit activities, including inspections, carried out by the Data Controller or by another person appointed by them of any location in which the processing of personal data of the Data Controller takes place. Any audit activity by the Data Controller must be agreed with the Data Processor. If these activities involve charges and expenses not foreseen by this agreement or by the main contract, all the requests of the Data Controller must be managed at the project level with an estimate of the costs necessary for their implementation (whether these are penetration test, vulnerability assessment or other activities. ).<\/p>\n
7.9 Rights of interested parties<\/strong><\/h3>\n
The Data Processor must promptly notify the Data Controller, within the limits permitted by law, if he receives requests from an interested party regarding his right of access, the right of rectification, limitation of treatment, cancellation ("right to be forgotten" ), data portability, the right to oppose the processing, or your right not to be subject to an automated decision-making process, or any other question or information regarding the personal data processed by the Data Processor in accordance with the provisions of the main Contract. At the request of the Data Controller, the Data Processor must assist the Data Controller in responding to the requests of the interested parties. Taking into account the nature of the processing, the Data Processor must assist the Data Controller by means of adequate technical and organizational measures, as far as possible, for the fulfillment of the Data Controller's obligations in response to the requests of the interested party provided for by the applicable laws and regulations on the subject. of data protection.<\/p>\n\t<\/div>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t
- \n
- \n