GDPR - Statement of Personal Data Processing
Declaration on processing personal data in accordance with General Data Protection Regulation (EU679/2016)
DHH Ltd, Nobileova 20, Pula, PIN: 25444746329, as Service Provider, hereby confirms
1. Recitals
1.1 By accepting the Terms of Services and payment of pro – forma invoice for services (hereinafter referred to as: Contracted Services), User has entered into contractual relationship with Provider which subject are agreed Contracted Services.
1.2 Subject Declaration is part of contractual relation and it defines harmonization of mutual relations with General Data Protection Regulation EU679/2016 (hereinafter referred to as: Regulation).
1.3 User of Services has, pursuant to Regulation, status of Controller (hereinafter referred to as: Controller).
1.4 Provider of Services has, pursuant to Regulation, status of Processor (hereinafter referred to as: Processor).
1.5 Expressions used in this Contract have the same meaning as stated in Regulation.
1.6 Processor keeps registry of type/category of received data, that are included in personal data processing and providing Contracted Services.
1.7 Received personal shall shall also represent personal data that Processor shall unintentionally be in contact with during performance of Contracted Services.
1.8 Processor shall use received personal data only for purposes of execution of Contracted Services. (Enclosure 1: Contracted Services, personal data, purpose of processing and personal data processing).
2. Information safety and harmonization with Regulation
2.1 Processor confirms that during performance of all its business activities it takes strict technical and organizational measures aimed at personal data protection and ensuring rights of data subjects in terms of Arts. 28 and 32 of Regulation.
2.2 Minimal technical and organizational measures, that decrease probability of unintentional or intentional authorized change, destruction, loss or unauthorized personal data processing, include:
- physical, technical and logistic protection of premises, equipment and system programming equipment, including IKT enter-exit units,
- technical and logistic protection of User’s program equipment,
- technical and logistic prevention of unauthorized approaches to personal data during their transfer, including transfer by telecommunication means and networks,
- efficient methods of blocking, destruction, deletion or anonymisation of personal data, when purposes of data processing are fulfilled,
- ensuring and operation of revision traces intended for establishing time of entering certain data in personal data registry, use, transfer, overview, other processing and identification of processor of such activities,
- responsibility, familiarity and qualifications of employees and other participants of Processor in relation to personal data protection, requirements and requests of Regulation and good practices of information safety,
- documented warranties of employees and other assistant of Processor in relation to clauses 8.7, 8.8 and 8.9 of Regulation,
- other measures, as listed in Regulation (Art. 32).
2.3 Processor guarantees that, when performing certain Contracted Services, it shall honor and fulfill all requirements, requests and standards defined by their mutual agreements, Regulation and good practices of information safety in relation to personal data protection.
2.4 Processor fulfills all requirements of Regulation and good practice of information safety in relation to formation and conducting revision traces.
3. Collecting, processing, transfer and storing of Personal Data
3.1 Controller confirms that all personal and connected data that are subject to processing i.e. Performing Contracted Services, are obtained legally and in accordance with requirements stated under Art. 6 (1), 7 (1), 8 and 9 (2) of the Regulation.
3.2 Controller confirms that all data subjects have been clearly, with understanding and in writing informed on requirements of collecting, processing, transfer and storing of Personal Data, in accordance Art. 5. of the Regulation.
4. Rights of data subjects
4.1 Controller enables execution of all rights to all data subjects, related to their personal data, stated under Art. 12 to 22 and 46 (5) of the Regulation.
4.2 Processor has, pursuant to provisions of Art. 37, 38 and 39 of the Regulation, nominated Personal Data Protection Representative and had defined its authorizations, obligations and responsibilities.
5. Rights of Controller
5.1 Controller is entitled to check performance of Contracted Services and technical, organizational and human resources measures ensuring information safety and personal data protection, as well as complying with the Regulation and good practices of information safety at any time, at its own expense and in cooperation with independent auditor, at Processor.
5.2 Controller is entitled to limit or prohibit cooperation with certain sub-contractor to Processor, in performing activities necessary for providing Contracted Services.
6. Obligations of Controller
6.1 Controller is obligated to forward all requests and inquiries related to Contracted Services to Processor, in writing.
6.2 Processor is obligated to ensure legality of using of information means that are subject to Contracted Services and upon which Processor, in accordance with contracted provisions, has no direct control or other possibility of influence.
7. Rights of Processor
7.1 In case of doubt that acting upon Controller’s instructions shall result in breach of valid laws, Processor is entitled to temporarily suspend performance of Contracted Services, until instructions are altered.
7.2 Processor is obligated to notify Controller on potential breach of valid laws and intention on suspension of performance of Contracted Services, timely and without delay.
7.3 In cases or misuse or illegal use of information means that are subject of Contracted Services, Processor is entitled to cancel such activity without delay.
7.4 Processor is entitled to conclude contract with sub-processor for performance of Contracted Services, specifically in scope and within the purpose of cooperation previously approved by Controller. Should there be no limitations set by Controller, Processor is entitled to conclude the contract with sub-processor by choice.
8. Obligations of Processor
8.1 Processor is obligated to perform Contracted Services only within scope and for the purposes agreed upon in Fundamental Contract, Annexes and written requests and instruction of Controller.
8.2 When performing Contracted Services Processor shall fulfill all requirements of the Regulation related to formation and registering revision traces.
8.3 Processor shall, in accordance with Regulation and good practice of information safety, continuously make and upgrade all technical and organizational measures ensuring protection of personal and other data connected therewith, of data subjects and Controller by constantly ensuring confidentiality, availability and resistance of system and Services.
8.4 Processor shall conclude written contracts with approved sub-processors.
8.5 It is Processors responsibility to take care that chosen sub-processors offer information safety and personal data protection at least on the same level as Processor.
8.6 In case of receipt of data subject request related to realization of rights provided by the Regulation and if it is possible to connect data subject with Controller on the basis of available information, Processor is obligated to forward such request to Controller without delay and in writing.
8.7 All employees and other parties participating in performance of Contracted Services on the side of Processor, are obligated to comply with instructions and standards of Controller, as well as requirements stated under Art. 28, 28, 32 of the Regulation.
8.8 All employees and other parties participating in performance of Contracted Services on the side of Processor, are obligated to protect business secret policies.
8.9 Obligation to protect business secret policies is also applies after termination of employment or other contractual relations or upon termination of cooperation between Controller and Processor.
8.10 Processor shall, in cases defined by the Regulation and on the basis of written request of Controller, cooperate with Personal Data Protection Agency (AZOP).
8.11 Upon completion of Contracted Services, Processor is obligated to return all receipt personal data records to Controller, within 30 days the latest.
8.12 Unless otherwise is requested by Controller or storing is not prescribed by laws, Processor is obligated to permanently destroy all copies and remaining of traces of personal data records that were subject of Contracted Services and/or with whom it has been in unintentional contact during performance of Contracted Services, within 60 days starting from termination of cooperation.
9. Incident Management
9.1 Processor confirms that it performs all technical and organizational measures within its organization, ensuring management and performance of adequate activities in cases of suspicion or confirmation of safety incident and/or loss of confidentiality.
9.2 In case of suspicion of confirmation of safety incident and/or loss of confidentiality, Controller and Processor are obligated to react in accordance with Art. 33 and 34 of the Regulation, without delay.
9.3 In case of suspicion of confirmation of safety incident and/or loss of confidentiality, apart from all activities prescribed by their internal acts, Controller and Processor are obligated to inform each other of such circumstances.
9.4 Controller and Processor shall mutual exchange results of sample and circumstances analysis related to identified safety incidents and loss of confidentiality.
9.5 All findings and analysis results shall be used for improvements and upgrades of systems and internal processes.
10. Final provisions
10.1 Controller and Processor agree that neither individual provision of Declaration or Fundamental contractual relation or Annexes or written requests deprives individual obligations of complying with clauses of the Regulation and individual liabilities deriving from it.
10.2 In case of disputes related to personal data safety, provisions of this Declaration are superior then provisions of the Fundamental Contract and Annexes.
10.3 All possible disputes arising out of or connected with this Declaration shall be solved amicably by the Contracting parties. Otherwise they agree to competence of the court in Pula, with application of the law of the Republic of Croatia.
10.4 Invalidity or non – enforce-ability of certain clauses of this Declaration shall have to effect on validity or other valid provisions. Contracting parties are obligated to alter every invalid provisions without delay.
10.5 This Declaration is valid for Controller starting from the moment of delivery or confirmation of its order or payment the latest. For existing contractual partners such Declaration is valid starting from the moment of its publication on DHH Ltd sites.
10.6 This Declaration is valid during the period of validity of Fundamental Contract and Annexes.