Data Processing Terms
These Data Processing Terms (hereinafter also the "Processing Terms") regulate the relationship between TOPefekt s.r.o., registered office B. Němcové 767/13, 787 01 Šumperk, ID No.: 294 44 268 (hereinafter also the "Processor") and you, i.e. the registered user of the application available at www.bulkgate.com and associated applications (hereinafter also the "Application"), who alone or together with others determines the purposes and means of processing personal data entered or imported into the Application (hereinafter also the "Controller") (hereinafter also the "Controller and the Processor" together as the "Parties" or separately as a "Party"). These Processing Terms govern the relationship between the Controller and the Processor of the personal data.
1. INTRODUCTORY PROVISIONS
1.1. The Processor provides the Controller with the services listed in Article 2 of the Terms and Conditions available here: https://portal.bulkgate.com/page/terms-and-conditions (hereinafter also "Services"), which the Controller has agreed to when registering for the Application (hereinafter also "Terms and Conditions"). While providing the Services, personal data will be processed. For the purposes of these Processing Terms, personal data means personal data of data subjects, which are all persons about whom personal data has been provided to the Processor for the purpose of providing the Services and performing other obligations under the Terms and Conditions (hereinafter as "Personal Data").
1.2. These Processing Terms govern the processing of Personal Data by the Processor as a processor of personal data within the meaning of Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter also as the "GDPR").
1.3. The Parties acknowledge and agree that:
-A. The Processor is processor or sub-processor of the Personal Data,
-B. The Controller is the controller or processor of the Personal Data (if the Processor is a sub-processor of the Personal Data),
-C. Both Parties undertake to comply with their obligations under applicable law relating to the processing of Personal Data.
1.4. Where the Controller acts as a processor, the Controller warrants to the Processor that the relevant controller has approved the Controller's instructions and actions in relation to the Personal Data, including the authorisation of the Processor as an additional processor.
1.5. Where these Processing Terms require the Processor or the Controller to take a particular action in writing, an action taken solely by email shall be deemed to be a written action.
2. SUBJECT MATTER AND PURPOSE OF THESE PROCESSING TERMS
2.1. The Processor will process the Personal Data listed below in accordance with these Processing Terms. The Processor will process the Personal Data for the duration of the contractual relationship with the Controller and for the duration of these Processing Terms, processing the Personal Data mainly in electronic form. The subject of the processing will be the storage of Personal Data, its transmission to service providers for sending out the required messages, structuring of Personal Data, visualization of success outcomes within the framework of the Services provided, analysis in connection with targeting specific partners of the Controller and other activities to which the Controller authorizes the Processor. Any instruction made via email, via communication means in the Application or via the functionalities located in the Application itself shall also be considered as a documented instruction within the meaning of Article 28 (3) (a) of the GDPR.
2.2. The purpose of these Processing Terms is to authorize the Processor by the Controller to process Personal Data in connection with the provision of the Services and to regulate the mutual rights and obligations arising for the Controller and the Processor from the relevant legislation on the protection of Personal Data, in particular the GDPR.
3. NATURE AND SCOPE OF PROCESSING, CATEGORIES OF DATA SUBJECTS AND TYPE OF PERSONAL DATA
3.1. The Processor is authorised and undertakes to process Personal Data under these Processing Terms solely for the purpose of and in accordance with the Terms and Conditions and these Processing Terms.
3.2. The Processor processes for the Controller Personal Data relating to its contractual partners, which the Controller enters or imports into the Application, or other persons whose Personal Data the Controller imports into the Application. The Controller is solely responsible for the Personal Data entered or imported into the Application, as the Processor has no ability to influence the type of Personal Data provided.
3.3. In particular, the Processor processes the following types of data for the Controller in relation to the above categories of data subjects:
- Identification information: name, surname
- Contact information: phone number, e-mail, postal address
- Other information: website URL, gender, title, billing data, location data and other data provided to the Controller by the data subject
The Controller undertakes not to upload information to the Application that is defined as special categories of personal data within the meaning of Article 9 of the GDPR. It further undertakes not to upload or otherwise input information relating to identity cards, birth numbers, identification documents and other information that is sensitive in nature to data subjects.
3.4. The Processor is entitled to process, to a reasonable extent, other Personal Data that it strictly needs to perform its activities under the Terms and Conditions or to fulfill its obligations under the law. The Processor is entitled to refuse the Controller's instruction if it has doubts about the legality of sending a commercial communication.
4. RIGHTS AND DUTIES OF THE PROCESSOR
4.1. The Processor warrants to the Controller that, when processing Personal Data, it implements such technical and organizational measures to ensure compliance with all the principles for processing Personal Data set out in the relevant legislation. To this end, the Processor shall:
-
A. minimize the number of persons who have access to Personal Data (granting access to particular types of Personal Data only to certain persons with specific user authorization and storing data carriers in secure facilities);
-
B. conduct training of its employees;
-
C. carry out checks on the compliance of employees with their obligations under the Personal Data protection regulations and the Processor's organizational measures;
-
D. follow its internal directives when processing Personal Data;
-
E. implement such technical measures for the protection of Personal Data as are appropriate to the relevant risk to the rights of data subjects, based on the state of the art, the cost of implementing the measures, the nature, scope, context and purposes of the processing, and test and control these measures on an ongoing basis. The technical measures implemented by the Processor include:
-
HTTPS transmission security;
-
two-factor authorization for access to the Application;
-
monitoring of access to the Application, operation of the Application and security incidents;
-
physical security of the server by providing fire protection, building access security and physical access to the server; security certification of the room in which the server hardware is located;
-
limited number of login attempts;
-
control of logging into the Application from a foreign device;
-
use of recommended server settings;
-
separate storage of encrypted data.
4.2. The Processor undertakes to:
-
A. provide the Controller, at the Controller's request, with the information necessary to demonstrate compliance with legal obligations and information about the level of security of Personal Data;
-
B. if the Controller and the Processor so agree, to provide the Controller with assistance in fulfilling the Controller's information obligation.
-
C. if it becomes aware of a breach or threatened breach of security of Personal Data, accidental or unlawful destruction, loss, alteration or unauthorised disclosure or access to processed Personal Data, it shall immediately, but no later than within 48 hours, inform the Controller in writing and describe to the best of its ability the security risk incurred or threatened, and shall inform the Controller of appropriate measures to prevent or minimise the security breach and take all necessary measures to minimise the damage;
-
D. will process Personal Data in the territory as instructed by the Controller. For example, if the Controller requires the Services to be provided in third countries outside the EU, the Processor will follow these instructions. The Controller is responsible for ensuring that appropriate safeguards are in place for transfers to third countries. In the event that the Processor incurs any damages in connection with such transfer, the Controller shall pay such damages without undue delay, but no later than 5 working days after being requested to do so by the Processor, on the basis of an invoice or, where applicable, such amount may be deducted from the credit earned in accordance with the Terms and Conditions;
-
E. ensure, through appropriate technical and organizational measures, that the Controller cooperates within 14 (fourteen) days of the Controller's request to comply with the Controller's obligation to respond to requests to exercise the data subject's rights;
4.3. The Processor is obliged to:
-
A. protect the Personal Data as well as the media on which the data is stored from misuse;
-
B. prevent the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of Personal Data and the media on which it is stored; this is without prejudice to the possibility of deleting User Content within the meaning of Article 9 of the Terms and Conditions;
-
C. ensure that Personal Data is processed only by persons who are bound by an obligation of confidentiality or for whom the obligation of confidentiality arises by law.
4.4. The Processor is entitled to:
-
A. delegate the processing of Personal Data to other processors under the conditions set out in Article 6 of these Processing Terms;
-
B. refuse to carry out the Controller's instruction if it would be contrary to the legislation on the protection of Personal Data. The Data Processor shall notify the Controller of such conflict of instructions with applicable law. The responsibility for the compliance of the instruction with the legislation always lies with the Controller, even if the Processor does not draw the Controller's attention to the inconsistency of the instruction with the applicable legislation.
4.5. If the Processor receives any request from the Data Subject in relation to the Personal Data in the course of processing the Personal Data, the Processor shall inform the Data Subject to contact the Controller directly with the request. The Controller shall be responsible for dealing with such request. The Processor undertakes to provide the Controller with all the necessary cooperation to deal with the Data Subject's request.
5. RIGHTS AND DUTIES OF THE CONTROLLER
5.1. The Controller is obliged to:
-
A. ensure that Personal Data is collected and processed in accordance with applicable law;
-
B. comply with information obligations to data subjects under the relevant legislation;
-
C. provide and ensure the provision of Personal Data to the Processor that is accurate, up-to-date, and consistent with performance under the Terms and Conditions in providing the Services;
-
D. to transmit Personal Data to the Processor in a timely manner and to provide the Processor with the cooperation necessary for performance under these Processing Terms.
5.2. When processing Personal Data, the Controller is obliged to implement such technical and organizational measures to ensure compliance with all the principles of processing set out in the relevant legislation. To this end, the Controller shall:
-
A. minimize the amount of Personal Data it processes;
-
B. minimize the number of persons who have access to Personal Data;
-
C. implement such technical measures for the protection of Personal Data as are appropriate to the relevant risk to the rights of data subjects, based on the state of the art, the cost of implementing the measures, the nature, scope, context and purposes of the processing.
5.3. As stated in the Terms and Conditions, if the Processor provides marketing activities for the Controller, the Controller guarantees that it has a lawful reason for processing Personal Data necessary for carrying out marketing activities and fulfills all obligations arising from the GDPR and Act No. 480/2004 Coll., on certain information society services. The Processor shall not be liable for any damage incurred by the Controller in connection with the processing of Personal Data for marketing purposes. The Processor shall be entitled to refuse the Controller's instruction in the event that it would be contrary to the aforementioned legislation.
5.4. If the Processor is subject to an inspection by a supervisory authority in connection with the processing of Personal Data under these Processing Terms, or if an administrative or other proceeding is initiated in connection with the processing of Personal Data, resulting in the imposition of a fine on the Processor, the Controller shall reimburse the Processor for the full amount of the fine within 30 days of the final decision of the relevant authority. The obligation to compensate also applies to decisions in relation to claims brought by data subjects.
5.5. The Processor shall allow the Controller or a person authorised by the Controller to check (including audit or inspection) compliance with these Processing Terms and the obligations for processing Personal Data arising therefrom, and shall contribute to such checks as reasonably instructed by the Controller, on the terms set out below.
5.6. The Processor shall provide the Controller or an independent third party auditor with such information and documentation as may be reasonably requested to satisfy itself that the Processor is complying with the obligations set out in these Processing Terms.
5.7. The Controller may request a more detailed audit, in addition to reviewing the Processor's documentation as described in Article 5.6 of the Processing Terms, subject to the following conditions:
-
A. If the Controller has reasonable grounds to suspect that the Processor is not fulfilling the obligations set out in these Processing Terms, in which case the detailed audit shall be limited to once per twelve-month period.
-
B. The Controller shall notify the Processor in writing of the detailed audit (at least 30 days, unless the Supervisory Authority requires an earlier audit of the Processor under mandatory legislation), to the email address dpo@topefekt.com.
-
C. The Controller shall conduct a more detailed audit at a reasonable time, on terms agreed in advance between the Controller and the Processor, during normal business hours and in compliance with the Processor's security policies. The more detailed audit shall not unreasonably interfere with the Processor's business operations.
-
D. The Processor may object in writing to any auditor appointed by the Controller if, in the opinion of the Processor, the auditor is not sufficiently qualified, is not independent, is in a competitive position with the Processor, or is otherwise manifestly unsuitable. Upon objection, the Controller shall be obliged to appoint another auditor or to carry out the audit itself.
-
E. The Processor shall promptly remedy the audit findings. If the Processor is unable to remedy the audit observations, it shall notify the Controller.
5.8. The Processor shall be entitled to charge the costs incurred by the Processor in carrying out a more detailed audit on the basis of the Processor's hourly rate, including any relevant third party costs.
6. OTHER PROCESSING
6.1. The Controller grants the Processor consent to involve other processors to the processing of Personal Data where this is necessary for the provision of the Services. The Processor shall ensure that the other Processors comply with the same data protection obligations as set out in these Processing Terms.
6.2. The Processor is expressly entitled to transfer Personal Data to other sub-processors for the above purposes, in particular mobile operators, SMS aggregators and other telecommunications service providers that provide the services ordered by the Controller for the Processor. Upon written request, the Processor shall inform the Controller of the specific processors involved in the processing in question, whereby the Controller may object in writing to such involvement within 14 days from the date of the information. If the Processor deems such objections to be justified, it may decide not to use the processor in question or to terminate the contractual relationship covered by these Processing Terms, or part of such relationship, without the Controller being entitled to any compensation.
6.3. The Controller hereby grants the Processor express general consent to the transfer of Personal Data to third countries for the purpose of performance under the Terms and Conditions and these Processing Terms.
6.4. The Controller expressly consents to the involvement of the Processor's employees who provide services to the Processor. At the same time, the Controller expressly consents to the involvement of storage providers who provide storage of Personal Data, namely O2 Czech Republic a.s., T-Mobile Czech Republic a.s. and VSHosting s.r.o. The Controller also expressly consents to the involvement of OpenAI, which provides services for the Processor related to the integration of the ChatGPT tool into the services provided, if the Controller wishes to use them.
7. PERIOD OF PROCESSING
7.1. The duration of the processing of Personal Data corresponds to the duration of the provision of Services according to the Terms and Conditions agreed between the Controller and the Processor. Upon termination of the provision of the Services, regardless of the manner and reason for termination, the Controller may export the directory and history from the Application, failing which the Processor shall not be obliged to perform any export of Personal Data for the Controller. After the expiry of the time limit set out in Article 9.2.2 of the Terms and Conditions, the Personal Data on all devices and media other than those owned or used by the Processor shall be permanently destroyed by the Controller, except where the storage of Personal Data is required by the law of the Czech Republic or the European Union (in particular in relation to Personal Data which constitute operational data within the meaning of the Electronic Communications Act). The Controller agrees that the Processor shall use the anonymised data for the further development of the Services provided and to ensure its protection against any claims by the Controller.
7.2. After the termination of the contractual relationship, the Processor is entitled to process Personal Data to the extent and in the manner set out in the Terms and Conditions and to the extent required by EU or Member State law. In such case, the Processor shall be in the position of an independent controller of Personal Data.
8. FINAL PROVISIONS
8.1. The Processor shall be entitled to charge the Controller for the reasonable costs incurred in dealing with any request referred to in these Processing Terms or the inspection referred to in Article 5.5 of the Processing Terms. The Processor shall invoice the Controller for such costs within thirty (30) days of incurring them on the basis of an invoice, the details of which shall be consistent with the invoicing for the provision of the Service. The Controller undertakes to reimburse the Processor for such costs incurred in accordance with the invoice issued.
8.2. The Processor shall not be liable for damage caused by circumstances beyond the control of the Processor or for damage caused by the actions of the Controller or third parties.
8.3. In the event that the Processor is obliged to compensate the Controller for damages (whether pecuniary or non-pecuniary) despite the provisions of Articles 8.2 and 5.3 of the Processing Terms, the amount of the damages is limited to the amount paid to the Processor for the calendar month in which the damages occurred, but no more than CZK 5,000. However, this does not apply if the damage is caused by the Processor intentionally or through gross negligence.
8.4. These Processing Terms and the rights and obligations arising from them are governed by the applicable laws of the Czech Republic.
8.5. These Processing Terms come into force and effect when the "I agree to the Data Processing Terms" box is ticked by the Controller (or their representative) when registering account in the Application and the registration process is successfully completed.
8.6. The provisions of Article 10.2 of the Terms and Conditions shall apply mutatis mutandis in connection with a change to the Processing Conditions.
8.7. The Processing Terms are effective from 1.7.2024.