Snapshot 39955
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to main content Data Processing Agreement (DPA) WHEREAS: BOOND has designed and developed an integrated, standard, and configurable management software application, accessible online (hereinafter referred to as the "Software"), intended notably for digital service companies and consulting and engineering firms (hereinafter referred to as the "Clients"), whose functions allow for the optimization of HR, commercial, and administrative processes. Within the scope of providing services to the Client as provided for in the Agreement, BOOND is entrusted with personal data by its Client. This document governs the processing of personal data carried out by BOOND on behalf of the Client within the framework of the Agreement. In the event of conflict, divergence, or inconsistency between the provisions of this document and those of the Agreement, it is understood that the provisions of this document shall prevail. The purpose of this document, established in application of Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as "GDPR"), is to define the conditions under which BOONDMANAGER undertakes to carry out personal data processing operations according to the terms defined below. Within the framework of their contractual relations, the Parties undertake to comply with the regulations in force applicable to the processing of personal data and, in particular, the aforementioned Regulation (EU) 2016/679 applicable from May 25, 2018, the Law "Informatique et libertés" No. 78-17 of January 6, 1978, as amended, and regulations regarding industrial and intellectual property (hereinafter referred to as the "Applicable Regulations"). THIS HAVING BEEN STATED, IT HAS BEEN AGREED AND DECIDED AS FOLLOWS: DEFINITIONS Within the framework of this document and its annexes, words or expressions beginning with a capital letter, whether used in the singular or plural, shall have the following meaning: "Document": designates this document attached to the Agreement, supplemented by the following annex: Annex 1: Description of Data Processing "Regulatory Authority": designates any authority competent in matters of Personal Data protection; "Client": designates BOOND's Client, benefiting from BOOND's Services within the framework of the Agreement; "Agreement": designates the contract detailing the services provided by BOOND and allowing the Client to benefit from the Services proposed on the Software; "Data": designates all types of information and/or data to which the Parties have access within the framework of contractual relations, regardless of the format or medium, whether they are Personal Data (defined below) or not (e.g., financial data, operators, clients, partners, strategic, technical, professional, administrative, commercial, legal, accounting...); "Personal Data" or "Personal Data": designates any information relating to an identified or identifiable natural person, either directly or indirectly by grouping information, by reference to an identification number or to elements specific to them: name, address, telephone number, IP address, email address, identifier/login, password, connection data, etc.; "Software": designates the software application from which Users can access the Services; "Data Subject": designates all persons whose Personal Data is subject to Data Processing; "Controller": designates the person who determines the means and purposes of the Processing; "Services": designates the means and functionalities made available to Users on the Software; "Processor": designates the person processing Personal Data on behalf of the Controller; they act under the authority of the Controller and on their instruction; "Processing": designates all operations relating to information, regardless of the process used (automated or non-automated); thus covering all forms of Data processing, whether on computer medium or other (paper, video recording, audio, …). Regarding Personal Data in particular, this may involve operations of collection, recording, organization, storage, adaptation, modification, extraction, consultation/viewing, dissemination, or making available; "User": designates any collaborator of the Client who uses the Software and accesses and uses the Services; "Personal Data Breach": designates a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed. OBJECT This Document sets out the data protection conditions and obligations that apply when BOOND processes Personal Data of Users for the provision of Services under the Agreement with the Client. The Parties have agreed to conclude this Document in order to address the rights and obligations of the Parties under the Applicable Regulations regarding data protection concerning the Processing of Personal Data of Users by BOOND on behalf of the Client. This Document concerns the Data Processing detailed in Annex 1. DURATION This Document enters into force upon signature of the Agreement and shall remain in force for the entire duration of the Agreement between BOOND and the Client. ROLES OF THE PARTIES It is expressly stipulated between the Parties that BOOND acts solely in the capacity of Processor within the meaning of the Applicable Regulations. The Client is the Controller within the meaning of the Applicable Regulations. Each of the Parties undertakes to comply with the provisions of the Applicable Regulations. INSTRUCTIONS FOR DATA PROCESSING Within the framework of the execution of the Agreement, BOOND will act exclusively on behalf of the Client, based on the stipulations of the Agreement and this Document which constitute the instructions of the Controller with regard to the Processor within the meaning of the Applicable Regulations. BOOND expressly undertakes not to exploit or use the Personal Data for its own needs or on behalf of third parties not expressly authorized by the Client. OBLIGATIONS OF THE PARTIES Obligations of the Client The Client undertakes to document in writing any instruction concerning Data Processing by BOOND. The Client undertakes to ensure, beforehand and throughout the duration of the Processing, compliance with the obligations provided for by the Applicable Regulations. The Client undertakes to supervise the Processing, including carrying out audits and inspections of BOOND. It is the Client's responsibility to use the Software in compliance with its own privacy policy and applicable legal obligations, notably the Applicable Regulations. Before any use of the Software by the Client and throughout the duration of the Agreement, the Client guarantees to BOOND that in its capacity as controller: the Client has collected and processed the Data in a lawful, fair, and transparent manner, for specific, explicit, and legitimate purposes determined solely by the Client and of which BOOND cannot be aware. The Client is solely responsible for the accuracy, quality, and legality of the collected Data; the Client can prove having previously informed the persons whose personal data it processes of all its obligations towards them (notably the determination of the legal basis of its processing and its precise purposes); the Client has informed the data subjects that their rights (access, rectification, erasure, objection, etc.) must be exercised directly with the Client and not BOOND, in accordance with Article 8 herein. BOOND undertakes to comply with any written and lawful instruction from the Client in this regard. Obligations of BOOND BOOND undertakes to: respect the principle of lawfulness of Processing provided for in Article 6 of the GDPR; process the Data only for the sole purpose(s) of the Processing; process the Data in accordance with the documented instructions of the Client; assign qualified teams to Data Processing possessing the necessary functional and/or technical skills and trained in the Applicable Regulations; guarantee the confidentiality of Personal Data processed within the framework of this Document; ensure that persons authorized to process Personal Data under this Document undertake to respect confidentiality or are subject to an appropriate legal obligation of confidentiality and receive the necessary training regarding Personal Data protection; take into account, regarding its tools, products, applications, or services, the principles of Data protection by design and Data protection by default; designate a privileged contact person who will be endowed with the experience, competence, authority, and means necessary for the exercise of their mission; assist, to the extent possible, the Client in fulfilling its obligations to respond to requests for exercising the rights of Data Subjects; ensure, beforehand and throughout the duration of the Processing, compliance with the obligations provided for by the Applicable Regulations; not use User Data for purposes other than those expressly listed in Annex 1; not carry out commercial prospecting of any kind whatsoever towards Users; ensure the security of Data and notably implement all security measures in accordance with Article 13 herein; and delete the Data at the end of the necessary period. PROSPECTING / PROFILING BOOND particularly draws the Client's attention to the fact that certain functionalities of the Software are likely to constitute profiling (Article 4.4 of the GDPR) of Client Data, and that as such, the Client is required to inform its Users (clients / prospects / candidates / collaborators / partners / suppliers / etc.) of the existence of the right to object to prospecting including profiling (Article 21 of the GDPR). It is the Client's responsibility to ensure the systematic updating of its Data files in which those of Data Subjects having exercised their right to object (Article 21 GDPR) will be deleted. The Client consequently guarantees that processing by the Software only concerns Data of persons who have not exercised their right to object to prospecting/profiling with the Client, which BOOND is not in a position to verify. DATA OWNERSHIP User Data is the property of the Client, as is all Data, personal or otherwise, concerning these Users, whether this data was communicated directly by the Users or whether it results from the provision of Services by BOOND. The Parties remain the sole owners of their respective databases. The personal data processing operation does not confer, in any way, a property right over the database of either of the Parties. INFORMATION AND RIGHTS OF PERSONS Information of Data Subjects The Client will be responsible for providing information to the Data Subjects concerned by the processing operations, at the time of Data collection. This information will be delivered by any means and notably through the Client's privacy policy. The Client will be free in editing the information notices, provided that they include at a minimum all information required by Articles 13 and 14 of the GDPR. Management of Data Subject Rights The Parties expressly agree that the Client is responsible for assuming the role of single point of contact in order to facilitate the exercise of the rights of Data Subjects regarding Data Processing. The designated person responsible for processing rights exercise requests is subject to professional secrecy as well as an obligation of confidentiality. The Client undertakes to respond to this request within a maximum period of thirty (30) days from the receipt of the request. The Client may pass the request on to BOOND, who undertakes to provide all its assistance and cooperation for the implementation of Data Subjects' rights: right of access, rectification, erasure, and objection, right to restriction of processing, right to data portability, right not to be subject to an automated individual decision (including profiling), right to organize the fate of their personal data after death notably. In the event that Data Subjects formulate requests to BOOND to exercise their rights concerning processing carried out on the Software, BOOND undertakes to indicate to the Data Subjects that BOOND is not the controller and that they must contact the Client directly. In the event that BOOND refuses to exercise the rights of the Data Subject upon the Client's request, it must justify this refusal to the Client. PERSONAL DATA BREACH Each of the Parties undertakes to notify the other as soon as possible by email of any loss, abuse, accidental or unauthorized deletion, modification, disclosure, or unauthorized access, proven or suspected, including, without limitation, penetration into its network or computer resources or those of its sub-processors with the aim of obtaining Personal Data or any other violation of the Applicable Regulations. In the event of a Data Breach, BOOND undertakes (i) to take as quickly as possible any appropriate technical correction measure of the Software to stop the identified Breach, notably to make the Data incomprehensible to any person not authorized to access it and apply them to the concerned Data and (ii) to justify this in writing and without delay to the Client. It is solely the Client's responsibility to inform (i) the Supervisory Authority on which it depends and (ii) the data subjects, when this Personal Data Breach is reported to it by BOOND. BOOND undertakes to provide the Client in writing, within seventy-two (72) hours at the latest after having become aware of it, with the following elements: the name and contact details of the data protection officer or another contact point where more information can be obtained; the description of the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; the description of the likely consequences of the personal data breach; and the description of the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. When this notification cannot be made within the seventy-two (72) hour period, BOOND will present legitimate and valid reasons for the delay. If, and to the extent that it is not possible to provide all this information at the same time, the information may be provided in phases without undue delay. The notification will be accompanied by any useful documentation to allow assessment of the Breach. BOOND undertakes to accompany the notification with any useful documentation to allow the Client, if necessary, to proceed with a notification of this Breach to the competent Supervisory Authority or the Data Subjects. The Client undertakes to communicate the Personal Data Breach to the Data Subjects as soon as possible, when this Breach is likely to result in a high risk to the rights and freedoms of a natural person. The communication to the Data Subjects must describe, in clear and plain language, the nature of the Personal Data Breach and contain at least: the name and contact details of the data protection officer or another contact point where more information can be obtained; the description of the likely consequences of the personal data breach; and the description of the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. COOPERATION FOR COMPLIANCE The Parties implement all necessary means to help each other and assist each other in their compliance. The Parties communicate to each other the name and contact details of the data protection officers designated by them, or failing that, their representative. BOOND agrees to process quickly and appropriately all reasonable requests from the Client concerning the Processing of Personal Data carried out on its behalf. It undertakes to modify or delete, following instructions from the Client, Personal Data notably following the exercise by a Data Subject of their right of access and rectification, so that the Data is continuously accurate and up to date. BOOND further undertakes to provide reasonable assistance, at the Client's expense, if the latter must respond to requests from the Regulatory Authority, proceed with risk assessments (PIA), investigations, inspections, or audits relating to the processing of Personal Data. The Parties undertake to collaborate transparently and to communicate to the other Party all elements of information exchanged with the Regulatory Authority concerning the Services provided by BOOND. BOOND undertakes, in the event of control by any administrative or judicial authority relating to the Data processed under the Services, to provide its assistance to the Client so that the latter can answer questions asked by the supervisory authority and for which BOOND's intervention would be necessary. BOOND will inform the Client without delay of any legally binding request for disclosure of Personal Data from an administrative or police authority, unless the law or a judicial or administrative decision prohibits it from doing so. Each Party undertakes to inform the other Party without delay if it officially adheres to a certification mechanism (Article 42 of the GDPR) or a code of conduct (Article 40 of the GDPR), so that the other Party can take any measure allowing it to meet the technical and contractual expectations of the certification mechanism or the selected code of conduct. AUDIT BOOND undertakes to make available to the Client all information necessary to demonstrate compliance with the Applicable Regulations and this Document. BOOND also undertakes to provide reasonable assistance and to allow for and contribute to audits by the Client or another auditor mandated by the Client, in accordance with the provisions below. BOOND undertakes to develop and integrate into its internal audit program the verification of its compliance with the Applicable Regulations and this Document. Furthermore, the Client may request BOOND to carry out audits to assess its compliance or the compliance of its subsequent Sub-processors with this Document and the Applicable Regulations under the following conditions: audit costs will be borne by the Client; audits will be carried out at reasonable intervals and at most once (1) per year; audits will be requested subject to a five (5) week notice period, except in emergencies (proven case or high probability of Personal Data Breach); and audits will be carried out directly by the Client or through any independent external service provider, not a direct competitor of BOOND. Any audit of the Software leading to vulnerability tests or attempted intrusion into a computerized data system must be the subject of a tripartite agreement between the Client, BOOND, and the third party responsible for carrying out the tests on behalf of the Client, specifying the duration of the tests, their nature, and releasing BOOND from any liability for the consequences induced by the tests ordered by the Client. Any draft report prepared by the auditors must, before being final, be transmitted to BOOND to allow it to formulate observations, which are transcribed in the final report. A copy of the final audit report is given to each of the Parties. BOOND acknowledges that Regulatory Authorities as well as the Client, if directly impacted by the audit, may request communication of the audit results; BOOND therefore undertakes to allow access to such results, upon request. SUBSEQUENT SUB-PROCESSORS BOOND's obligations may be executed via subcontracting by a BOOND service provider. BOOND undertakes not to subcontract its own services to a sub-sub-processor who does not respect the GDPR and will prioritize in its choice providers who have adhered to a code of conduct or are subject to certification. The Client authorizes BOOND to entrust the Processing of User Personal Data to Sub-processors presenting sufficient guarantees, subject to compliance with the restrictions described below. The list of subsequent Sub-processors is available online in our document "Declaration of sub-processors". BOOND undertakes to guarantee that Sub-processors only access and use User Personal Data in accordance with the provisions of this Document and that they are bound by written agreements obliging them to offer at least the level of protection required by this Document. If the Sub-processor(s) selected by BOOND do not fulfill their data protection obligations, BOOND shall remain fully liable to the Client for the performance of the Sub-processor's obligations. In addition to specifically defining (i) the subject-matter and duration of the planned processing, (ii) the nature and purpose of the planned processing, (iii) the type of personal data and categories of data subjects, each subcontracting contract concluded by BOOND must provide for at least an undertaking by the sub-processor: to process personal data only on documented instructions from BOOND and/or the Client, including regarding Data transfers to a country outside the EU (unless required to do so by French law for BOOND; in such a case, BOOND undertakes to inform the Client of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest); to ensure that persons authorized to process Personal Data undertake to respect confidentiality or are subject to a legal obligation of confidentiality; to take all security measures required pursuant to Article 32 of the GDPR; not to further sub-contract all or part of the services to be performed for BOOND and the Client to another provider without all the commitments referred to in this article being respected by the sub-processor's sub-processor; to assist the Client, by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of its obligation to respond to requests for exercising the data subject's rights; to assist the Client in ensuring compliance with the obligations of (i) security (Article 32 of the GDPR), (ii) notification to the CNIL (Article 33 of the GDPR) of potential Personal Data Breaches (Article 33 of the GDPR), (iii) communication to any data subject regarding the Data Breach (Article 34 of the GDPR), particularly regarding any potential unauthorized copy of personal data, (iv) prior conduct of a data protection impact assessment (Article 35 of the GDPR) and (v) mandatory consultation with the CNIL in case of conduct of an impact assessment, taking into account the nature of processing and the information available to BOOND; to delete all Data after returning it to BOOND at the end of the provision of services, and to destroy existing copies; to make available to the Client all information necessary to demonstrate compliance with the obligations laid down in this article and allow for and contribute to audits, including inspections, conducted by the Client (or another auditor) and contribute to such audits. SECURITY MEASURES Each of the Parties implements all appropriate technical and organizational measures to protect the Personal Data it processes against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure or access, notably within the framework of data transmission in a network, as well as against any other form of unlawful processing. BOOND undertakes in particular to: implement technical and organizational security measures generally consistent with the state of the art as well as contractual instructions in this matter; take all reasonable decisions to guarantee the reliability of personnel having access to Personal Data; ensure that all data storage media containing Personal Data and all copies or reproductions thereof are carefully stored without allowing access to third parties except to authorized (subsequent) sub-processors; and guarantee that its employees and potential sub-processors involved in the processing of Personal Data are contractually bound to preserve the confidential nature of Personal Data and to respect the Applicable Regulations. BOOND undertakes to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia, as appropriate: the pseudonymization and encryption of personal data; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing. The details of BOOND's technical and organizational security measures are indicated in the Agreement. BOOND undertakes to maintain these measures throughout the duration of the Agreement. It is the Client's responsibility to ensure that the technical and organizational security measures implemented by BOOND meet its own security constraints and, failing that, to give precise written instructions to BOOND on the additional security measures to be implemented. In the absence of specific instruction, the Client acknowledges that BOOND's security measures are sufficient. DATA TRANSFERS OUTSIDE THE EUROPEAN UNION BOOND undertakes not to transfer Personal Data to countries outside the European Union that do not ensure an adequate level of Personal Data protection in accordance with the requirements of the Applicable Regulations without the Client's agreement and without previously implementing one or other of the appropriate safeguards provided for by the Applicable Regulations to frame said transfer, notably by using standard contractual clauses approved by the European Commission. The Client undertakes to facilitate the implementation of these safeguards. In the event that BOOND is required to transfer data to a third country or an international organization, under Union law or Member State law to which it is subject, it shall inform the Client of that legal requirement before the transfer, unless that law prohibits such information on important grounds of public interest. RECORD OF PROCESSING ACTIVITIES BOOND undertakes to maintain a record of all categories of processing activities carried out on behalf of the Client, containing: the name and contact details of the controller on behalf of which it is acting, any sub-processors and, where applicable, the data protection officer; the categories of processing carried out on behalf of the controller; where applicable, transfers of personal data to a third country or an international organization, including the identification of that third country or international organization and, in the case of transfers referred to in the second subparagraph of Article 49(1) of the GDPR, the documentation of suitable safeguards; and where possible, a general description of the technical and organizational security measures. LIABILITY Each Party is liable for all direct damages suffered by the other Party and caused by a proven breach of its obligations under this Document and arising from a violation of its obligations by the defaulting Party, its employees, representatives, agents and, where applicable, its subsequent Sub-processors. In the event of liability of one of the Parties towards the other or towards any third party due to poor performance or non-performance of its obligations under this Document and the Applicable Regulations, the defaulting Party shall be liable for direct damages suffered by the other party and for all direct damages related to a security failure leading to unavailability, loss of traceability, doubt about integrity, or lack of confidentiality of Personal Data. The defaulting Party shall handle any potential proceedings arising from the fault and, in the event of criminal, contractual liability, or an administrative sanction imposed by the Regulatory Authority, shall pay the fines and compensations, financial or otherwise, arising from the fault. AGREEMENT ON PROOF By express agreement, the Parties accept electronic communications exchanged between the Parties as a mode of proof. The printout of these electronic communications is considered an original writing serving as evidence between the Parties. This Document represents the entire agreement of the Parties relating to the framework of the Processing detailed in the Special Conditions. It cancels and replaces all prior documents, agreements, contracts, verbal or written, between the Parties having the same object. Only an amendment written and signed by a representative duly authorized by each Party may modify the commitments provided for within this Document, any written exchange (email, fax, or other) being deemed null and void. CONSEQUENCES OF CONTRACT TERMINATION At the latest within thirty (30) days of the effective date of termination of the Agreement, for whatever cause, BOOND undertakes to return to the Client free of charge all Data processed by the Software, without keeping a copy of any kind and not to exercise any right of retention over this Data, for any reason whatsoever. The Data is returned free of charge to the Client in a standard market format (.xls, .csv, etc.) that does not require the use of the Software to be reused. ANNEX 1 DESCRIPTION OF PERSONAL DATA PROCESSING GENERAL INFORMATION CLIENT BOOND Role Controller Processor Contact Point <Defined in the Agreement> Mikaël PIRIO [email protected] DPO <Defined in the Agreement> HASHTAG AVOCATS [email protected] Processing Management of activity and collaborators Purposes of processing Recruitment management Follow-up of collaborators Prospecting Project management Collection of times, absences and expense reports Invoicing Purchasing management Matching of profiles and needs according to provided criteria CATEGORIES OF PROCESSED PERSONAL DATA Current Data User Personal Data First name, last name, title, date of birth, phone number, email Professional Data Professional phone number, professional email, data from CV and job board content, diplomas, qualifications, skills, classification, coefficient, level, clearances acquired and declared by the person, certifications acquired and declared by the person, training, professional experiences, history of interventions/missions Sensitive Data or perceived as sensitive Data revealing racial or ethnic origin N/A Data revealing political opinions N/A Data revealing religious or philosophical beliefs N/A Data revealing trade union membership N/A Genetic data N/A Biometric data for the purpose of uniquely identifying a natural person N/A Data concerning health N/A Data concerning sex life or sexual orientation N/A Data relating to criminal convictions or offenses N/A Unique national identification number (NIR for France) Social security number CATEGORIES OF DATA SUBJECTS Categories of persons Client Users: employees, candidates and service providers SUBSEQUENT SUB-PROCESSORS cf document Declaration of sub-processors END OF CONTRACT End of contract option Restitution of data