Data Processing Addendum

This agreement governs the processing of personal data that Open2b Software S.n.c. ( "Open2b" ), as the "Data Processor", performs on behalf of the Customer, as the "Data Controller", within the scope of an existing agreement between "Open2b" and the Customer for the provision of a service ( "Service" ) and is an addendum to that agreement.

1. Definitions

"Regulation" means Regulation (EU) 2016/679 on the processing of personal data of natural persons.

"Personal Data", "Processing", "Data Controller", "Data Processor", "Data Subject" and "Consent" shall have the meanings defined in the "Regulation".

2. Data processing

  1. Open2b processes the Personal Data for which the Customer is the Data Controller solely for the purpose of providing the Service requested by the Customer.
  2. Personal Data are processed by Open2b only on the Customer's documented instructions.
  3. Open2b ensures that the persons authorized to process the data are committed to confidentiality or are subject to an appropriate legal obligation of confidentiality.
  4. Open2b implements and maintains appropriate technical and organizational measures to protect personal data from unauthorized processing or processing contrary to law and from accidental loss, destruction, damage, theft, alteration or disclosure.
  5. For the purpose of providing the Service, Open2b may transfer Personal Data to other countries, including the United States. These transfers will comply with the Regulation.
  6. After the Service ends, Open2b will delete the Personal Data unless Union or Member State law requires data retention.
  7. Open2b shall, taking into account the nature of the processing and to the extent that the Customer is unable to access the relevant Personal Data in the use of the Service, assist the Customer, at the Customer's expense, with appropriate technical and organizational measures, insofar as possible, in order to meet the Customer's obligation to respond to any requests from individuals or applicable data protection authorities in relation to the processing of personal data under this agreement.
  8. In the event that the above requests are submitted directly to Open2b, Open2b will respond directly only after the Customer's prior authorization, unless legally required to do so. If Open2b is required to respond to such a request, Open2b will promptly inform the Customer and provide a copy of the request, unless legally prohibited from doing so.

3. Customer obligations

  1. The Customer declares that it complies with the obligations that the Regulation imposes on the Data Controller in relation to the processing instructions provided to Open2b.
  2. The Customer declares that it has provided the data processing notice to Data Subjects and obtained all Consents to the processing when required by the Regulation with respect to the Personal Data being processed.

4. Use of other Data Processors

  1. The Customer authorizes Open2b to use other Data Processors for the purpose of processing Personal Data.
  2. Open2b must inform the Customer (an email will suffice) in the event of any planned changes regarding the addition or replacement of other Data Processors. The Customer has the right to object to such changes by notifying Open2b within 5 days of receipt, explaining the reasonable grounds for the objection. The parties will discuss the matter in good faith and, if they do not reach a commercial agreement, both parties may terminate the Services affected by the change.
  3. Open2b must have a contract in place with each other Data Processor with terms that oblige the other Data Processor to protect Personal Data as required by the Regulation.
  4. Open2b is responsible for the fulfillment of obligations by other Data Processors.

5. Other

  1. In the event of a conflict between this addendum and the agreement for the provision of the Service, the provisions of this addendum shall prevail.
  2. The Customer acknowledges and approves that Open2b may amend this addendum from time to time by publishing the changes and the amended addendum on the Open2b website at https://www.open2b.com/en/legal/dpa and these amendments shall become effective on the date of publication. The Customer's use of the Service after the amended addendum has been published on the Open2b website constitutes the Customer's acceptance of the amended addendum. If the Customer does not approve the changes made to the addendum, it will refrain from continuing to use the Service.