Order processing agreement
Subject of the contract
This data processing agreement ("DPA") is concluded between the parties regarding the processing of personal data under the main contract (hereinafter referred to as the "main contract"). The provision of services under the main contract (“Services”) requires the processing of data. If and to the extent that such data consists of or contains personal data, the data processor acts as data processor with respect to such data, while the controller remains the controller of such data in accordance with Article 28 of the General Data Protection Regulation (hereinafter referred to as "GDPR").
The Services are provided by the Data Processor in such a way that the Controller provides its own data, controls its transmission to the Data Processor and, in the case of Software-as-a-Service (SaaS) models, directly controls the handling of such data uploaded to the Services. The Controller agrees and understands that the Data Processor does not monitor the Data Controller's data or the Controller's handling of such data unless the Controller specifically requests access to such data from the Data Processor. Therefore, it is the sole responsibility and obligation of the Controller to ensure that the Controller's data is collected and transferred in accordance with applicable data protection laws and, in particular, that there is a legal basis for this and that data subjects are properly informed about the collection and processing of their personal data.
As a Data Processor, the Data Processor will only process the Controller's Personal Data in accordance with the provisions of this Data Processing Agreement (DPA) and the Controller's documented instructions. If the data processor is required by Union law or the law of the Member States to which it is subject to further processing of personal data, the data processor shall inform the controller of those legal requirements before processing, unless the relevant law prohibits such notification on grounds of important public interest; in the latter case, the data processor informs the controller of further processing as soon as this is legally permissible. The Data Processor shall ensure and regularly verify that the processing of Personal Data within its area of responsibility, including any sub-processors engaged by it, is carried out in accordance with the provisions of this DPA, applicable data protection laws and in particular the GDPR.
Details of processing
The details of the processing are described in the following provisions and in the main contract. Taking into account its obligations as a controller, the controller will inform the processor if it is necessary to supplement the provisions set out in the main contract.
The Processor will process Personal Data as described in the Main Contract.
The processor will generally process personal data for the duration of the main contract and this contract processing agreement, unless otherwise agreed in writing.
place of data processing; Transfer to third countries
The Processor processes Personal Data exclusively on its own premises or on the premises of its authorized sub-processors. All processing operations are generally carried out in the member states of the European Union or in another state that is a party to the Agreement on the European Economic Area.
Any processing of personal data outside the EU/EEA is only permitted with prior agreement between the parties and only if the requirements of Article 44 et seq. GDPR are met.
Instructions from the person responsible
The parties agree that this DPA contains the Controller's general instructions regarding the processing of Personal Data on behalf of the Processor.
Any specific instructions from the Controller that deviate from the provisions of this Data Processing Agreement or impose new, additional obligations on the Processor require the consent of the Processor to be effective. For such specific instructions, the parties will apply the modification procedure agreed in the main contract, if applicable.
It is the responsibility of the Controller to ensure that the instructions it gives regarding the processing of personal data on behalf of the Controller comply with applicable data protection laws and that the Processor can process personal data in accordance with those instructions without breaching applicable data protection laws, in particular the GDPR. If the Processor believes that an instruction from the Controller violates applicable data protection laws, the Processor will inform the Controller accordingly. In such cases, the processor is entitled to refuse to carry out the instruction until the controller confirms it.
Specific instructions from the person responsible must be given in writing or at least in text form by persons authorized to do so on behalf of the person responsible. Instructions given verbally must be confirmed immediately by one of the authorized persons and at least in text form in order to be effective.
Data Processor Representations
Employees of the data processor: (i) to the extent that they are authorized to process personal data, are obliged to maintain confidentiality or are subject to an appropriate legal duty of confidentiality; (ii) process personal data only in accordance with the data processor's instructions, unless there is an obligation to process otherwise under applicable data protection laws; and (iii) will be regularly informed of the obligations under this DPA and applicable data protection laws, in particular the GDPR.
The data processor may not make copies or duplicates of the personal data processed on behalf of the controller without the prior consent of the controller. This excludes copies that are necessary to ensure proper data processing and proper provision of services (including data backup), as well as copies that are necessary to fulfill legal retention obligations.
The processor appoints a knowledgeable and reliable data protection officer if and as long as the legal requirements for the appointment of a data protection officer exist. The processor provides the controller with the contact details of such an appointed data protection officer.
Technical and organizational measures
Before starting processing, the data processor implements the following www.fitness-nation.com/support/tom.html technical and organizational measures listed and maintains them throughout the entire term of this order processing agreement. These technical and organizational measures are designed to ensure a level of security appropriate to the risk in terms of confidentiality, integrity, availability and resilience of the systems. The state of the art, the costs of implementation as well as the nature, scope, context and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons within the meaning of Article 32 paragraph 1 GDPR must be taken into account.
Since technical and organizational measures are subject to technical progress and technological developments, the Data Processor is permitted to implement alternative and appropriate measures, provided that this does not result in a security standard not lower than that set out below www.fitness-nation.com/support/tom.html specified.
Use of sub-processors
The data processor may only engage sub-processors to process personal data on behalf of the controller with the prior consent of the controller. The person responsible hereby gives his consent to the use of the following www.fitness-nation.com/support/subunternehmen.html listed sub-processors.
The Data Processor imposes on each Sub-Processor data protection, confidentiality and data security obligations that are at least as stringent as the Data Processor's obligations to the Controller set out in this Processing Agreement. If a sub-processor fails to comply with these obligations imposed on it, the data processor will be liable for these breaches as if they were its own fault.
The Processor shall notify the Controller in writing of any new engagement of a sub-processor. If the Controller objects to the assignment within thirty (30) days of receiving such notification, citing a plausible reason, the parties will seek an amicable solution. In such a case, if an amicable solution cannot be found within two (2) months, the Controller has the right to terminate the main contract in relation to those services for which the engagement of the proposed sub-processor is necessary.
The parties agree that providers of mere ancillary services are not data processors within the meaning of data protection laws; This includes in particular transport services provided by postal or courier services, as well as cash transport services, telecommunications services, security services and cleaning services. Notwithstanding the foregoing, the Data Processor will enter into industry-standard confidentiality agreements with such subcontractors.
The provisions of this Section 7 also apply if a sub-processor is engaged in a third country outside the EU or EEA. Subject to the Controller's consent to the use of the sub-processor, the Controller hereby authorizes the Processor to enter into a contract on behalf of the Controller with a sub-processor that processes the Controller's data outside the EU or EEA, incorporating the EU Standard Contractual Clauses for the transfer of personal data to processors in third countries from 5. February 2010 or, if applicable, standard data protection clauses subsequently adopted by the EU Commission or the relevant supervisory authority.
Obligation to support the person responsible
Upon written request from the Controller, the Processor will provide the Controller with appropriate assistance in the event of an investigation or request by a data protection supervisory authority, to the extent that such investigation or request relates to the Services. The Processor shall provide the Controller with reasonable assistance in fulfilling all obligations in connection with such investigation or request. Should a data protection supervisory authority initiate an investigation directly with the Processor or make a corresponding request directly to the Processor, the Processor shall, to the extent permitted, immediately inform the Controller and cooperate with such investigation or request.
The Processor shall inform the Controller without unreasonable delay if it discovers a personal data breach in connection with the processing of Personal Data under this Data Processing Agreement. If, as a result of such notification, the Controller is subject to reporting obligations to data protection supervisory authorities and/or data subjects (in particular under Articles 33 and 34 of the GDPR), the Processor shall provide the Controller with appropriate and necessary assistance in fulfilling these reporting obligations. To the extent that the Processor is not responsible for a reportable data breach, the Processor is entitled to charge for the support services in accordance with the remuneration rates agreed in the main contract.
The Processor shall assist the Controller, taking into account the nature of the processing and the information available to the Processor, in any data protection impact assessment that the Controller may need to carry out in relation to the processing of personal data, including, where appropriate, consultation with the relevant data protection supervisory authority (Articles 35 and 36 GDPR). The processor is entitled to charge for the support services in accordance with the remuneration rates agreed in the main contract.
The Processor shall inform the Controller without unreasonable delay if a data subject contacts the Processor directly to lodge a complaint, request or exercise their rights. The Processor does not respond to the request itself unless the Controller has expressly instructed the Processor to do so. The Processor shall provide the Controller with appropriate assistance in responding to such complaints, inquiries and data subject requests. The processor is entitled to charge for the support provided in accordance with the remuneration rates agreed in the main contract.
Return or deletion of personal data
Upon reasonable instructions from the Controller, during the term of this Data Processing Agreement (DPA) or after its termination or upon termination of the processing of Personal Data under the relevant Specific Agreement, the Processor will destroy, delete or return the data processed on behalf of the Controller. If applicable laws prevent the Processor from destroying, deleting or returning the Personal Data processed on behalf of the Controller, the Processor will nevertheless stop actively processing such data, but will continue to store them only to comply with legal requirements, in particular legal retention obligations, and will destroy, delete or return them to the Controller as soon as the legal impediment no longer exists, in accordance with the Controller's original instructions.
The processor creates proof of any destruction or deletion of personal data, which is made available to the controller upon request.
Audit Rights
The Controller is entitled, during normal business hours (Monday to Friday from 9:00 a.m. to 5:00 p.m.), at its own expense, without disrupting operations and in strict compliance with the confidentiality of the Processor's trade secrets and trade secrets, to enter the Processor's premises where the Controller's data is processed, in order to verify compliance with this order processing agreement. The controller will generally provide sufficient notice (at least two weeks in advance) of such an on-site inspection.
As a rule, the person responsible is entitled to one on-site inspection per calendar year, as mentioned in the previous paragraph. This does not affect the controller's right to carry out further on-site inspections in the event of special incidents.
If the Controller commissions a third party to carry out the review, the Controller must commit the third party in writing to the same extent as the Controller is obliged to the Processor under this Data Processing Agreement. In addition, the person responsible must oblige the third party to maintain confidentiality and secrecy, unless the third party is subject to a professional obligation of confidentiality. At the request of the processor, the controller must immediately provide the processor with the confidentiality agreements with the third party. The person responsible may not commission a competitor of the processor to carry out the test.
Instead of an on-site inspection, evidence of compliance with this DPA may also be provided through compliance with approved codes of conduct in accordance with Article 40 of the GDPR, certification under an approved certification mechanism in accordance with Article 42 of the GDPR, or by providing an appropriate, current certificate, reports or extracts from reports from independent bodies (e.g. auditor, internal audit, data protection officer, IT security department, data protection auditors or quality auditors) or a suitable certification through IT security or data protection audit - e.g. B. in accordance with ISO 27001 - ("Test Report"), provided that the Test Report enables the Controller to reasonably be satisfied with compliance with this DPA.
If and to the extent that an on-site inspection was not caused by misconduct on the part of the processor, the processor is entitled to charge for the expenses incurred during the on-site inspections in accordance with the remuneration rates agreed in the main contract.
Other provisions
These General Terms and Conditions are governed by the same law as the Main Contract and the courts agreed by the parties in the Main Contract will have exclusive jurisdiction over any dispute arising out of or in connection with these General Terms and Conditions.
Changes or additions to these general administrative regulations are only effective if made in writing.
If any provision of these Terms and Conditions is held to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions will remain in full force and effect.
This data processing agreement (DPA) comes into force upon conclusion of the main contract as an integral part thereof. It remains in force regardless of the end of the term of the main contract until and expires automatically as soon as all personal data have been deleted by the data processor and/or all commissioned sub-processors.