Third Party Index

Snapshot 64097

Document
Data processing addendum
URL
https://www.123formbuilder.com//wp-content/uploads/2025/02/123FormBuilder_-_Data_Processing_Amendment_-_US_Server_v5_2025%20presigned.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
274725 bytes
SHA-256 (raw)
9b0aff172a4733a72eca9a91d02c23b1755522ab726eaa864e33aec4c71fad6d
SHA-256 (normalized text)
a590e717990bdc07e4cc008be5f4a76027b3e9967152970bdd87461289fbbceb

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Docusign Envelope ID: 9175C3DB-B449-4ED8-9D88-1871786429FF

                                       Data Processing Amendment

             The Parties

             123FormBuilder SRL, headquartered in Gheorghe Lazar street, no. 24, Fructus Plaza, second floor, SAD
             13, Timisoara 300081, Timis, Romania, EU, registered at the national registries under no. J35/2122/2011,
             RO29147442, using official e-mail contact@123formbuilder.com, legally represented by Dr. Björn Momsen
             and Dario Perfettibile (acting as Managing Directors), as a PROVIDER,

             and

             ____________________________, headquartered in ________________________________________,
             registered under no. ___________________________________________________, using official e-mail
             _________________________________ legally represented by ___________________________ (acting
             as ________________), as a BENEFICIARY,

             have agreed to conclude this additional act, in addition to:
                ● The Terms of Service (referer also as TOS), mentioned on the site of the Provider
                    https://www.123formbuilder.com/termsofservice.html
                ● (only if applicable) Contract _________ signed on date _________

             The amendment becomes effective on the date both parties have signed the document. The duration of
             data processing is based on the term of the service agreement that will be signed by the BENEFICIARY
             AND PROVIDER.

             Art. 1. Privacy. Protection of personal data

             1. With regard to the processing of Personal Data controlled by the PROVIDER, under the Contract, the
                parties acknowledge that the BENEFICIARY is the Data Controller and that the PROVIDER is the
                authorized entity, by the Data Controller. The parties agree to comply with all obligations under the
                applicable Personal Data Protection laws. The PROVIDER will process such personal data on behalf
                of the BENEFICIARY, in so far as it is necessary for the purposes of the Contract.

             2. In accordance with Art. 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council
                on the protection of individuals with regard to the processing of personal data and on the free movement
                of such data (the Regulation or the GDPR), the parties agree to the provisions contained in Art. 1.3
                below on the Processing of Personal Data under the Contract. All capitalized words in this section will
                have the meaning assigned to GDPR.

             3. Annex 1 to this Agreement contains certain information regarding the processing of Personal Data in
                accordance with Article 28 Section (3) of the GDPR and possibly the equivalent requirements of other
                data protection laws.

                   3.1. Under this Section, the Provider:

                                                                 -1-
Docusign Envelope ID: 9175C3DB-B449-4ED8-9D88-1871786429FF

                     3.1.1. Will process personal data only with documented instructions from the Beneficiary, unless
                           that obligation lies with the Provider under Union or national law applicable to him or her; in
                           this case, the Provider will notify this legal obligation to the Beneficiary before processing,
                           unless the law concerned prohibits such notification for important public interest reasons;
                     3.1.2. Ensure that the authorized people to process personal data are committed to maintaining
                           their confidentiality or that they have an appropriate statutory duty of confidentiality;
                     3.1.3. Will take all necessary measures in accordance with Article 32 of the GDPR "Security of
                           Service" as set forth in the TOS mentioned on the Site of the Provider
                     3.1.4. Will comply with the conditions set out in paragraphs 2 and 4 of Article 28 of the GDPR for
                           hiring another person for processing (sub-processor);
                     3.1.5. Taking into account the nature of the processing will assist the Beneficiary by appropriate
                           technical and organizational measures described in the TOS mentioned on the site, as far as
                           is possible, to fulfill the Operator's obligation to respond to requests for the exercise of the
                           Target Person's rights provided in Chapter III of the GDPR;
                     3.1.6. Will assist the Data Controller in complying with its obligations under Articles 32-36 of the
                           GDPR and as described in the TOS stated on the site, taking into account the nature of
                           processing and information available;
                     3.1.7. At the request of the Beneficiary, will delete or return all Personal Data to the Beneficiary
                           after the termination of the provision of the Processing Services, and will remove existing
                           copies, unless Union or national law requires the storage of specific Personal Data;
                     3.1.8. Will immediately inform the Beneficiary if, in the opinion of the Provider, a Data Controller
                           instruction referred to in the above paragraph violates the GDPR or other Union or national
                           law on the protection of personal data.
                 3.2. The Provider may transfer Personal Data to a Sub-processor in accordance with personal data
                      protection laws, including, where applicable, in accordance with any necessary prior formalities
                      and rights of Target Persons, such as information and/or consent when required by applicable law.
                 3.3. When processing Personal Data is subcontracted to Sub-processors located outside the EEA, the
                      Provider will sign on behalf of the Beneficiary the Standard Contractual Terms for the Transfer of
                      Personal Data to Third-Party Sub-Processors in accordance with Commission Implementing
                      Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://eur-
                      lex.europa.eu/eli/dec_impl/2021/914/oj or equivalent standard clauses of personal data protection
                      in accordance with EU law.
                 3.4. Only the Beneficiary may determine the purposes and means of processing Personal Data by the
                      Provider in the course of fulfilling his obligations under this Agreement. Only the Provider may
                      approve the security measures applicable to the protection of Personal Data as defined in
                      Appendix 1. The Provider remains solely responsible for the accuracy and adequacy of the
                      aforementioned purposes and means.
                 3.5. Any change in security measures that have or could have an adverse effect on the protection of
                      Personal Data, including compliance with the applicable laws, will be notified to the Beneficiary,
                      thus having the opportunity to discuss the measures if necessary and possibly refusing to continue
                      the activity.
                 3.6. The Provider shall, upon request, provide the Beneficiary with all the information necessary to
                      demonstrate compliance with this Agreement and allow and contribute to audits, including
                      inspections, performed by the Beneficiary or an auditor mandated by him in connection with the
                      processing of Personal Data. The Provider shall offer a reasonable notice of any audit or inspection
                      to be performed and avoid damage, injury or disturbance to the premises, equipment, staff, and
                      activity of the Provider, while his staff is in those locations in the course of such an audit or
                      inspection.

                                                                  -2-
Docusign Envelope ID: 9175C3DB-B449-4ED8-9D88-1871786429FF

                 3.7. The Beneficiary will decide the retention period of the data he collects. If the Beneficiary asks for
                      his subscription to be canceled and his account to be deleted, the Provider will delete the
                      Beneficiary's data and collected data from all its systems within 60 days, unless retention
                      obligations apply.

             This Amendment completes the Terms of Service and existing Contracts (if any), fully retaining their entire
             content, being concluded in two original copies, one for each party.

             PROVIDER                                          123FormBuilder SRL
                                                               Managing Directors

                    Björn Momsen                                                Dario Perfettibile
             _______________________________                            _________________________________

             BENEFICIARY                                       _______________________________

             Date                                              _______________________________

                                                                  -3-
Docusign Envelope ID: 9175C3DB-B449-4ED8-9D88-1871786429FF

                                      Annex 1 - Description of the Processing of Personal Data

             The name of the Data Protection Officer

             Provider                                               Beneficiary

             Cristian Raiescu
             gdpr@123formbuilder.com

             Individuals
             Personal data refers to the following categories of Target Persons: the contact persons of the specified
             parties, and the persons who complete the forms covered by this contract.

             Data categories
             Personal Data refers to the following categories of data:
                 A. any data collected by the Beneficiary through the forms provided by the Provider
                 B. name, location, e-mail, or other data required to meet the contractual obligations.
                    .

             Special categories of data

             (This refers to racial or ethnic origin, political opinions, religious or philosophical beliefs, membership of
             trade unions, and data processing on health or sexual life, criminal record, and personal data on unlawful
             conduct or behavioral hindrance to a ban imposed on that behavior, such as photos, film images, medical
             data, etc.)
             The Provider does not collect special data of the Beneficiary. If the Beneficiary collects special data, he
             will ensure that he implements the necessary safety measures.
             Subcontractors are used only for the purpose of ensuring the technical means necessary for the optimal
             operation of the services provided by the PROVIDER.
             The names and locations of the subprocessors to which personal data is transferred and the data
             categories that are transferred

              Entity            Main location                    Data categories

              Amazon Web        Washington, DC, USA              Type A
              Services

              Google            California, USA                  Type B

              Sendgrid          Colorado, USA                    Type B

              Zendesk           California, USA                  Type B

                                                                  -4-
Docusign Envelope ID: 9175C3DB-B449-4ED8-9D88-1871786429FF

              Customer.IO      Oregon, USA                    Type B

              InnerTrends      Romania, EU                    Type B

              SnapEngage       Colorado, USA                  Type B

             The Provider will periodically (every 6 months) review and update the list of subprocessors to which
             personal data is transferred. The Provider will make sure all new subprocessors are GDPR compliant.
             Any notification regarding data processed by subcontractors can be sent to the DPO, using the following
             e-mail address: gdpr@123formbuilder.com
             General description of organizational and technical security measures (if possible)
             The security measures are described here: https://www.123formbuilder.com/how-do-we-handle-service-
             security

                                                                -5-