Data Processing Agreement (DPA)
Annex · TOS
1. Purpose
1.1 The Parties enter into this Data Processing Agreement (DPA) to ensure that the processing…
The Parties enter into this Data Processing Agreement (DPA) to ensure that the processing by SMARTFENSE of Personal Data within the Service, by the PARTNER and/or on its behalf, is carried out in accordance with applicable data protection regulations.
1.2 This Data Processing Agreement forms an integral part of the SMARTFENSE Sales Agreement…
This Data Processing Agreement forms an integral part of the SMARTFENSE Sales Agreement (hereinafter “SSA”).
1.3 SMARTFENSE, the PARTNER and the CLIENT undertake to comply at all times with the…
SMARTFENSE, the PARTNER and the CLIENT undertake to comply at all times with the following provisions and with the data protection regulations to which they are subject.
2. Definitions
Unless otherwise defined in the SSA, all terms used in this DPA shall have the meanings given to them below. “Personal Data”, “Personal Data Breach”, “processing”, “process”, “processor”, “controller” and “data subject” shall have the same meaning as in the Applicable Data Protection Law and may be written in lowercase or uppercase.
2.1 Applicable Data Protection Law: means, in addition to the regulations applicable to…
Applicable Data Protection Law: means, in addition to the regulations applicable to certain jurisdictions referred to in the region-specific Terms set out in the SSA, the following data protection laws, as applicable, including subsequent amendments, modifications and revisions thereto: (i) EU Regulation 2016/679 titled “On the protection of natural persons with regard to the processing of personal data and on the free movement of such data” (“GDPR”) and any applicable national law implemented by member countries of the European Economic Area (“EEA”); (ii) Argentina’s Personal Data Protection Law, Law Number 25.326 (as amended or replaced).
2.2 Subscriber: means the party that contracts the service and is granted a license to access…
Subscriber: means the party that contracts the service and is granted a license to access and use the Service during the Subscription Term. Partners authorized to commercialize the service shall also be considered Subscribers, and shall act as Data Processors of the end Client, leaving SMARTFENSE with the role of Sub-Processor. In providing the Service, SMARTFENSE will process, on behalf of the Subscriber, the Personal Data submitted and stored in the Service by the Subscriber or by third parties with whom the Subscriber transacts using the Service. Any reference to the Subscriber within this DPA, unless otherwise specified, shall include the Subscriber and its Affiliates.
2.3 Processor Group: means SMARTFENSE and any entity that controls, is controlled by,…
Processor Group: means SMARTFENSE and any entity that controls, is controlled by, or is under common control with SMARTFENSE.
2.4 Service Data: means a subset of Confidential Information composed of electronic data,…
Service Data: means a subset of Confidential Information composed of electronic data, text, messages, communications or other materials submitted to and stored within the Service by the Subscriber, its Agents and end Users in connection with the Subscriber’s use of the Service, including, without limitation, Personal Data.
2.5 Sub-Processor: means any third-party data processor engaged by SMARTFENSE,…
Sub-Processor: means any third-party data processor engaged by SMARTFENSE, including entities of the Processor Group, that receives Personal Data from SMARTFENSE to process it on behalf of the Subscriber and in accordance with the Subscriber’s instructions (as communicated by SMARTFENSE) and the terms of its written sub-contract.
2.6 Supervisory Authority: means any data protection supervisory authority as defined in the…
Supervisory Authority: means any data protection supervisory authority as defined in the European Data Protection Regulation.
2.7 Website: refers to the web page available at: https://smartfense.com/
Website: refers to the web page available at: https://smartfense.com/
3. Processing and Service Data
3.1 As between the Parties, all Service Data processed under the terms of this DPA and the…
As between the Parties, all Service Data processed under the terms of this DPA and the SSA shall remain the property of the Subscriber. Under no circumstances shall SMARTFENSE act, or be deemed to act, as a “controller” (or an equivalent concept) of the Service Data under any applicable data protection regulation.
3.2 SMARTFENSE shall be considered “Data Processor” (hereinafter THE PROCESSOR), as,…
SMARTFENSE shall be considered “Data Processor” (hereinafter THE PROCESSOR), as, in accordance with its role as ultimate service provider, it needs to collect, store, process, handle and/or use the personal data made available by the CLIENT for the use of the service itself.
3.3 SMARTFENSE, in its role as Data Processor, carries out processing of Personal Data on…
SMARTFENSE, in its role as Data Processor, carries out processing of Personal Data on behalf and by order of the CLIENT, who is legally considered “Data Controller”, since the CLIENT is the party that orders and generates the service instructions it deems necessary and appropriate (for example, ordering SMARTFENSE to send an awareness campaign to a database of email addresses of its employees).
3.4 The processing of personal data shall be carried out solely under reasonable and…
The processing of personal data shall be carried out solely under reasonable and documented instructions from the Data Controller, and at no time shall SMARTFENSE carry out processing on its own account, nor process such data outside the declared purposes.
3.5 The existence and participation of a PARTNER as an intermediary in the commercialization…
The existence and participation of a PARTNER as an intermediary in the commercialization of the service implies that such PARTNER shall be considered the Data Processor, and SMARTFENSE shall in turn be considered the Sub-Processor.
3.6 The CLIENT shall at all times remain the Data Controller,…
The CLIENT shall at all times remain the Data Controller, and the provisions of this Annex shall continue to apply in full.
4. Obligations of the Parties
4.1 The Parties agree that the duration of the processing carried out by SMARTFENSE under…
The Parties agree that the duration of the processing carried out by SMARTFENSE under this DPA, including the nature and purpose of the processing, the type of Personal Data and the categories of data subjects, shall be as described in section 7 of this DPA.
4.2 The Parties considered Processor or Sub-Processor undertake to comply with the…
The Parties considered Processor or Sub-Processor undertake to comply with the obligations imposed on them by virtue of their role as Data Processor, as set out in Regulation (EU) 2016/679, including:
- to process Personal Data in accordance with the Subscriber’s instructions as set out in the SSA and this DPA, including with respect to transfers of Personal Data to a third country or an international organization in accordance with Article 28(3)(a) of the GDPR, unless required to do otherwise by Union or Member State law to which SMARTFENSE is subject. In such case, SMARTFENSE shall inform the Subscriber of that legal requirement upon becoming aware of it (except where prohibited by applicable law);
- to ensure that all personnel and management of any member of the processor are fully aware of their responsibilities to protect Personal Data in accordance with this DPA and have committed to confidentiality or are under a legal obligation of confidentiality in accordance with Article 28(3)(b) of the GDPR;
- to implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized, accidental or unlawful destruction, loss, alteration, disclosure or access, provided that such measures take into account the state of the art, implementation costs, nature, scope, context and purposes of the processing and the risks involved in the processing, and shall include the measures described in Annex II;
- to notify the Subscriber, in accordance with Article 33(2) of the GDPR, without undue delay and in any case within forty-eight (48) hours, of a confirmed Personal Data Breach affecting the Subscriber’s Personal Data, and to take appropriate measures to mitigate its possible adverse effects;
- to assist the Subscriber, taking into account the nature of the processing and to the extent commercially reasonable, in complying with the Subscriber’s obligation to respond to data subject requests to exercise their rights under the Applicable Data Protection Law (a “Data Subject Request”). In the event that SMARTFENSE receives a Data Subject Request directly from a data subject, it shall, unless prohibited by law, direct the data subject to the Subscriber. Where the Subscriber is unable to address the Data Subject Request, taking into account the nature of the processing and the information available to SMARTFENSE, SMARTFENSE shall, at the Subscriber’s request and at the Subscriber’s reasonable expense (agreed upon prior to SMARTFENSE’s response to the Data Subject Request), address the Data Subject Request as required by the Applicable Data Protection Law;
- upon request, to provide the Subscriber with commercially reasonable information and assistance, taking into account the nature of the processing and the information available to SMARTFENSE, to help the Subscriber carry out any data protection impact assessment, data transfer impact assessment or consultation with the Supervisory Authority; upon termination of the Subscriber’s access to and use of the Service, to comply with the requirements of Section 8 of this DPA (Return and Destruction of Personal Data);
- to comply with the requirements of Section 5 of this DPA (Audit) to make available to the Subscriber information demonstrating SMARTFENSE’s compliance with this DPA; and
- to appoint a security officer who shall act as the Subscriber’s point of contact, and shall coordinate and oversee compliance with the security provisions of this DPA, including the measures detailed in SMARTFENSE’s Security, Trust and Assurance in the Cloud document.
4.3 SMARTFENSE shall immediately inform the Subscriber if, in its opinion,…
SMARTFENSE shall immediately inform the Subscriber if, in its opinion, the Subscriber’s processing instructions infringe any law or regulation. In such case, SMARTFENSE is entitled to refuse the processing of personal data that it deems to violate any law or regulation.
4.4 The PARTNER understands and accepts that, in accordance with the obligations set out in…
The PARTNER understands and accepts that, in accordance with the obligations set out in this data processing agreement, it shall in turn establish its own data processing agreement (DPA), in order to regulate and obtain express and informed consent to legitimize the processing of the personal data obtained from the CLIENT.
4.5 The PARTNER assumes responsibility for evidencing acceptance of such data processing…
The PARTNER assumes responsibility for evidencing acceptance of such data processing agreement before the PRODUCER.
4.6 In cases where the PARTNER is also SUBSCRIBER of the service under the terms of section…
In cases where the PARTNER is also SUBSCRIBER of the service under the terms of section 2, administering the service on behalf of third parties (end clients), from a legal perspective, the PARTNER shall be considered the Data Processor (as described in clause 2.5), and shall be bound to comply with the obligations regulated in section 3.2 of this DPA.
5. Use of Sub-Processors
5.1 The Subscriber hereby confirms its general written authorization for the use by…
The Subscriber hereby confirms its general written authorization for the use by SMARTFENSE of the Sub-Processors listed at https://smartfense.com/en/data-sub-processors-policy/ (“Sub-Processors Policy”) in accordance with Article 28 of the GDPR to assist SMARTFENSE in providing the Service and processing Personal Data, provided that such Sub-Processors:
- agree to act only under SMARTFENSE’s instructions when processing Personal Data, instructions that shall be consistent with the Subscriber’s processing instructions to SMARTFENSE, in accordance with the provisions of SMARTFENSE’s Sub-Processors Policy.
- agree to protect Personal Data to a standard consistent with the requirements of this DPA, including the implementation and maintenance of appropriate technical and organizational measures to protect the Personal Data they process in accordance with the security standards described in SMARTFENSE’s Sub-Processors Policy.
5.2 SMARTFENSE shall remain liable to the Subscriber for the subcontracted processing…
SMARTFENSE shall remain liable to the Subscriber for the subcontracted processing services of any of its Sub-Processors under this DPA. SMARTFENSE undertakes to keep the Sub-Processors Policy up to date on its website, including any sub-processor at least thirty (30) days prior to its incorporation into data processing. The Subscriber understands and accepts that it must review the Sub-Processors Policy in order to check the list of such sub-processors.
5.3 Should the Subscriber object to the processing of its Personal Data by any newly…
Should the Subscriber object to the processing of its Personal Data by any newly designated Sub-Processor, as described in Section 4.2, it shall inform SMARTFENSE within thirty (30) days of the update to its Sub-Processor Policy on the website. In such case, SMARTFENSE shall (a) instruct the Sub-Processor to stop processing the Subscriber’s Personal Data, in which case this DPA shall not be affected, or (b) allow the Subscriber to terminate this DPA and any related services agreement with SMARTFENSE immediately.
5.4 In some cases the Service provides links to integrations with third-party non-SMARTFENSE…
In some cases the Service provides links to integrations with third-party non-SMARTFENSE services, which may optionally be integrated directly into the Subscriber’s account or instance in the Service. If the Subscriber chooses to enable, access or use such third-party non-SMARTFENSE services, its access to and use of such Services is governed solely by the terms and conditions and privacy policies of such Services, and SMARTFENSE does not endorse and is not responsible for any aspect of such non-SMARTFENSE Services, including but not limited to their content or the way they handle Service Data (including Personal Data) or any interaction between the Subscriber and the provider of such non-SMARTFENSE Services. Providers of non-SMARTFENSE Services shall not be considered Sub-Processors for any purpose under this DPA.
6. Audit
6.1 The Parties acknowledge that SMARTFENSE uses external auditors to verify the adequacy of…
The Parties acknowledge that SMARTFENSE uses external auditors to verify the adequacy of its security measures, including the security of the physical data centers from which SMARTFENSE provides its data processing services. This audit:
- shall be carried out at least once a year;
- shall be carried out in accordance with the ISO 27001 standards or other alternative standards equivalent to ISO 27001;
- shall be carried out by independent external security professionals of SMARTFENSE’s choice; and
- shall result in the generation of an audit report affirming that SMARTFENSE’s data security controls comply with prevailing industry standards (“Report”).
6.2 SMARTFENSE currently complies with the security requirements required by Spain’s National…
SMARTFENSE currently complies with the security requirements required by Spain’s National Cryptologic Center (CCN), being authorized to handle sensitive information under the National Security Scheme (ENS). Consequently, SMARTFENSE is included in the Catalogue of Security Products for Information and Communication Technologies (CPSTIC) under the category “Security Conformity and Governance”.
6.3 Upon written request from the Subscriber and at no charge,…
Upon written request from the Subscriber and at no charge, SMARTFENSE shall provide a summary of the Report (“Summary Report”) so that the Subscriber may reasonably verify SMARTFENSE’s compliance with the security and audit obligations under this DPA. The Summary Report shall be considered SMARTFENSE’s confidential information under the confidentiality provisions of the SMARTFENSE SSA.
6.4 In the event that the Subscriber considers the documentation and annual audit “Reports”…
In the event that the Subscriber considers the documentation and annual audit “Reports” insufficient to demonstrate compliance with the appropriate measures on the processing activities carried out on behalf of the Subscriber, the Subscriber shall always have the option to exercise the right to conduct an audit during normal business hours on SMARTFENSE’s premises for the purpose of demonstrating compliance with the organizational and security measures on the processing activities, limited to the data relevant to the Subscriber. To exercise such right, notice must be given to privacy@smartfense.com, and SMARTFENSE shall use all commercially reasonable efforts to comply with such request. The Parties shall mutually agree in advance and in good faith on the terms of such audit, provided that:
- if the request may, in SMARTFENSE’s reasonable opinion, create a risk to another customer’s environment, SMARTFENSE and the Subscriber shall agree on an alternative way to address the request in order to provide the Subscriber with a similar level of assurance. For the avoidance of doubt, the Subscriber acknowledges that the granting of potential access as set forth in this DPA shall in no way be deemed to constitute access or potential access to the Service Data of other subscribers, whether in aggregate storage at rest, or in multi-user data flows during processing; and
- unless otherwise agreed in writing by the Parties, the Subscriber shall reimburse SMARTFENSE for the time spent on such on-site access at SMARTFENSE’s then-current professional services rates, which shall be made available to the Subscriber upon request.
7. International Data Transfers
7.1 The Subscriber acknowledges that SMARTFENSE and its Sub-Processors may process Personal…
The Subscriber acknowledges that SMARTFENSE and its Sub-Processors may process Personal Data in countries outside the EEA, the United Kingdom and Switzerland (“European Countries”). If personal data is transferred to a country or territory outside the European Countries, such transfer shall only take place if: (a) the country ensures an adequate level of data protection; (b) one of the conditions listed in Article 46 of the GDPR (or its equivalent in any subsequent legislation) is met; or (c) the Personal Data is transferred on the basis of SMARTFENSE’s Binding Corporate Rules, as set out in Section 6.2 and which establish appropriate security measures for such Personal Data and are legally binding on SMARTFENSE.
7.2 Binding Corporate Rules: Where SMARTFENSE processes or allows any Sub-Processor within…
Binding Corporate Rules: Where SMARTFENSE processes or allows any Sub-Processor within the Processor Group to process Personal Data outside the EEA or Switzerland, SMARTFENSE shall fully comply with the requirements of SMARTFENSE’s Binding Corporate Rules to provide adequate protections for the Personal Data it processes on behalf of the Subscriber, which are available at smartfense.com/privacy/gdpr. In the event that the Services are covered by more than one transfer mechanism, the transfer of Personal Data shall be subject to a single transfer mechanism in the following order: (1) SMARTFENSE’s Binding Corporate Rules; (2) applicable Standard Contractual Clauses; and if neither (1) nor (2) applies, then other applicable data transfer mechanisms allowed under the Applicable Data Protection Law.
7.3 Standard Contractual Clauses: Where SMARTFENSE processes Personal Data in countries…
Standard Contractual Clauses: Where SMARTFENSE processes Personal Data in countries outside the EEA, SMARTFENSE shall comply with the EU Commission’s Standard Contractual Clauses (annexed to EU Commission Decision 2021/914/EU of 4 June 2021) (the “EU SCCs”) which, if Clause 6.2 (Binding Corporate Rules) does not apply, shall be entered into and incorporated into this DPA by this reference.
8. Details of Data Processing
8.1 Nature and purpose of processing : SMARTFENSE shall process Personal Data in the course…
Nature and purpose of processing: SMARTFENSE shall process Personal Data in the course of providing the Services under the SSA, which may include operating a cloud-based customer service platform. For more information about the functionalities of the service, please refer to smartfense.com. SMARTFENSE shall process Personal Data as processor in accordance with the SUBSCRIBER’s instructions.
8.2 Processing activities : the personal data contained in the service data shall be subject…
Processing activities: the personal data contained in the service data shall be subject to the hosting and processing activities of the provision of the services.
8.3 Duration of Processing : The processing of Personal Data shall last for the Subscription…
Duration of Processing: The processing of Personal Data shall last for the Subscription Term under the SSA and this DPA on an ongoing basis.
8.4 Data subjects : the Subscriber may, at its sole discretion,…
Data subjects: the Subscriber may, at its sole discretion, submit Personal Data to the Services, which may include, without limitation, the following categories of data subjects: employees (including contractors and temporary workers), employee-related persons, family members of employees, customers, prospective customers, service providers, business partners, vendors, end Users, advisors (all of them natural persons) of the Subscriber, and any natural person authorized by the Subscriber to use the Service.
8.5 Categories of Personal Data : The Subscriber may, at its sole discretion,…
Categories of Personal Data: The Subscriber may, at its sole discretion, transfer Personal Data to the SMARTFENSE Services, which may include, without limitation, the following categories of Personal Data: first and last name, email address, title, job position, employer, contact information (company, email, telephone numbers, physical address), date of birth, gender, communications (telephone recordings, voicemail) and customer service information.
8.6 Special categories of data (if applicable) : Sensitive Data may, from time to time,…
Special categories of data (if applicable): Sensitive Data may, from time to time, be included in the processing through the Services when the Subscriber or its end Users choose to include Sensitive Data within the Services. The Subscriber is responsible for ensuring that appropriate security measures are in place before transmission or processing, or before allowing the Subscriber’s end Users to transmit or process Sensitive Data through the Services.
8.7 Retention : SMARTFENSE shall process and retain Personal Data in accordance with Section…
Retention: SMARTFENSE shall process and retain Personal Data in accordance with Section 8 (Return and Destruction of Personal Data) of this DPA.
9. Return and Destruction of Personal Data
9.1 Upon termination of the Subscriber’s access and use of the Service, SMARTFENSE,…
Upon termination of the Subscriber’s access and use of the Service, SMARTFENSE, within thirty (30) days of such termination, at the Subscriber’s option: (a) shall allow the Subscriber to export its Service Data, at the Subscriber’s expense; or (b) delete all Service Data in accordance with the Service’s capabilities and Article 28(3)(g) of the GDPR. After such period, SMARTFENSE shall delete all Service Data stored or processed by SMARTFENSE on behalf of the Subscriber in accordance with SMARTFENSE’s deletion policies and procedures. The Subscriber expressly consents to such deletion.
10. Term and Limitation of Liability
10.1 This DPA shall remain in force for as long as SMARTFENSE processes Personal Data on…
This DPA shall remain in force for as long as SMARTFENSE processes Personal Data on behalf of the Subscriber under the SSA. Upon termination of the SSA, this agreement shall be deemed to terminate together with the principal agreement.
10.2 This DPA shall be subject to the limitations of liability agreed between the Parties as…
This DPA shall be subject to the limitations of liability agreed between the Parties as set forth in the SSA, and any reference to a Party’s liability means that Party and its Affiliates collectively. For the avoidance of doubt, this section shall not be construed as a limitation of either Party’s liability with respect to claims brought by data subjects.
11. General Provisions
11.1 This DPA may not be amended or modified except by consent of both Parties.…
This DPA may not be amended or modified except by consent of both Parties. This DPA may be executed in counterparts. The rights and obligations of each Party with respect to assignment and delegation under this DPA shall be as described in the SSA. Subject to the foregoing restrictions, this DPA shall be fully binding on the Parties and their respective successors and assigns, shall inure to their benefit, and shall be enforceable by them. This DPA, together with the SSA, constitutes the entire agreement between the Parties with respect to the subject matter hereof and shall supersede any other agreement, negotiation or discussion between the Parties regarding that subject matter.
11.2 To the extent that the terms of the SSA conflict with the substantive terms of this DPA…
To the extent that the terms of the SSA conflict with the substantive terms of this DPA (as regards the protection of Personal Data), the terms of this DPA shall prevail.