This data processing agreement applies to all forms of processing of personal data carried out by Qweb Internet Services B.V., registered with the Chamber of Commerce under number 24304157, hereinafter referred to as 'Processor' and 'Qweb', on behalf of a counterparty to whom it provides services, hereinafter referred to as 'Controller'.
Jointly referred to as 'Parties' and individually as 'Party'.
Whereas:
A. Parties have entered into an agreement regarding hosting services and domain name registrations, hereinafter referred to as 'Agreement'. In performing the Agreement, the Processor processes Personal Data on behalf of the Controller.
B. Parties wish to handle the Personal Data processed under the Agreement carefully and in accordance with the GDPR and other applicable legislation regarding the Processing of Personal Data.
C. Parties wish to record their rights and obligations regarding the Processing of Personal Data of Data Subjects in this Data Processing Agreement, in accordance with the GDPR and other applicable legislation.
D. Only the Controller determines the purpose of and means for the processing of personal data; the Processor has no influence on this.
1.1 Data Subject: the person to whom a Personal Data item relates.
1.2 Data Breach: a breach of the security of Personal Data that has serious adverse consequences for the protection of Personal Data.
1.3 Personnel: persons engaged by the Parties for the performance of this Data Processing Agreement, who shall work under their responsibility.
1.4 Personal Data: any data relating to an identified or identifiable natural person. This also includes (traceable) pseudonymised personal data.
1.5 Sub-processor: a third party engaged by the Processor to process Personal Data on behalf of the Processor, without being subject to the Processor's direct authority.
1.6 Controller: the party responsible for Processing within the meaning of the General Data Protection Regulation (GDPR) and other applicable legislation.
1.7 Processor: the party that processes Personal Data on behalf of the Controller without being subject to the Controller's direct authority.
1.8 Processing: any operation or set of operations performed on Personal Data, including at least the collection, recording, organisation, storage, updating, modification, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, combining, linking, as well as the blocking, erasure or destruction of data.
2.1 If the Processor has access to Personal Data only, without an obligation to process it, the Processor shall comply with national and international legislation regarding personal data and with the provisions of this Data Processing Agreement; provided that and to the extent that the Controller has timely notified the Processor in advance of the presence of Personal Data and where it is located.
2.2 If the Processor has committed in the Agreement to processing Personal Data, it shall do so with great care and in accordance with the purposes of the processing, complying with national and international legislation regarding personal data and with the provisions of this Data Processing Agreement; provided that and to the extent that the Controller has timely notified the Processor in advance of the presence of Personal Data and where it is located.
3.1 The Controller shall notify the Processor in a timely manner, in principle within 10 business days, of any changes to the Processing (if applicable) and the possible consequences thereof.
3.2 The Controller warrants that the instruction to Process the Personal Data (if applicable) is not unlawful and does not infringe the rights of third parties.
4.1 The Processor shall only access and/or process Personal Data to the extent necessary for the performance of the Agreement and shall follow all reasonable instructions of the Controller.
4.2 The Processor shall only transfer Personal Data to a country outside the European Economic Area if that country ensures an adequate level of protection and meets other applicable obligations. For its products 'Office 365 (Hosted Exchange)', 'Duo Security (two-factor authentication)' and 'G Suite (Qweb email)', Qweb transfers Personal Data to a processor in the United States on the basis of an EU standard contractual clause. This product is therefore registered under the EU Privacy Shield. If the client transfers personal data to countries outside the European Union via the services, the client shall indemnify Qweb against all legal claims from third parties based on the allegation that such personal data is transferred in violation of the GDPR.
4.3 The Processor shall ensure that its Personnel complies with this Data Processing Agreement to the extent they are involved in the Processing of Personal Data. The Processor's employees are bound by a confidentiality obligation.
4.4 The Processor shall, at the first request of the Controller, immediately destroy all copies of Personal Data originating from or processed on behalf of the Controller. The Controller is responsible for timely exporting their Personal Data.
4.5 The Processor shall implement appropriate technical and organisational security measures to protect Personal Data against loss and against unlawful processing. These measures shall, taking into account the state of the art and the costs of implementation, ensure an appropriate level of security given the risks of the processing and the nature of the data.
4.6 The Processor shall maintain a register of all categories of processing activities carried out on behalf of the Controller.
4.7 The Processor shall provide the Controller with full and timely cooperation to allow Data Subjects to access their personal data, have it deleted or corrected, and/or to demonstrate that such data has been deleted or corrected or, if the Controller disputes the Data Subject's position, to record that the Data Subject considers their data to be incorrect.
4.8 The Processor shall implement adequate internal management measures to comply with the obligations of this agreement and shall document these in a manner that allows easy monitoring of compliance. When Processing Personal Data, activities and incidents relating to Personal Data shall be recorded in log files.
4.9 At the direction of the Controller, the Processor shall cooperate with encryption and pseudonymisation of Personal Data. If this leads to additional costs for the Processor, the Controller shall reimburse these costs.
4.10 The Controller may have the Processing of Personal Data audited once a year for correct compliance with this Data Processing Agreement by an independent registered EDP-Auditor. The Auditor shall be required to maintain confidentiality. The Processor shall provide all information requested by the Auditor. The Auditor shall report to the Controller in general terms but shall not disclose details of security measures implemented. The costs of the audit shall be borne by the Controller.
4.11 The content and scope of the processing assignment and the remuneration therefor are as agreed in the Agreement. The Processor shall follow the Controller's instructions regarding the processing and/or storage of Personal Data.
5.1 The Processor may outsource the performance of this Data Processing Agreement in whole or in part to a Sub-processor. The Processor shall at all times remain the point of contact for the Controller and remain responsible for compliance with the provisions of this Data Processing Agreement.
5.2 The Processor shall impose on the Sub-processor the same obligations as apply to itself under this Data Processing Agreement and shall document these in a written contract, and shall monitor Sub-processor compliance. The Processor shall be fully liable to the Controller for the consequences of outsourcing work to a Sub-processor.
5.3 An exception to articles 5.1 and 5.2 applies to the outsourcing of domain name registrations. Depending on the Top Level Domain, your personal data may be made public and/or the Processor may not be able to guarantee the security of your personal data.
6.1 The Processor shall not disclose Personal Data to anyone other than the Controller, unless required by legal obligation or necessary for the agreement with the Controller.
6.2 If the Processor is required by law to disclose Personal Data, it shall:
- verify the basis of the request and the identity of the requester and inform the Controller prior to disclosure;
- limit the disclosure to what is legally required;
- enable the Controller to exercise the rights of the Controller and Data Subjects and to defend their interests;
- when providing data to a Data Subject, provide it in a structured, commonly used and machine-readable format.
7.1 The Processor shall make every effort to implement sufficient technical and organisational measures with respect to the processing operations to be carried out, to protect against loss or any form of unlawful processing (such as unauthorised access, damage, alteration or disclosure of personal data). These measures are tailored to the risk of the processing. An overview of these measures and the relevant policies are included in Annex A.
7.2 The Processor does not warrant that the security will be effective under all circumstances. Where an explicitly defined security level is absent from this Data Processing Agreement, the Processor shall endeavour to ensure that security meets a level that, given the state of technology, the sensitivity of the personal data and the costs of implementing security measures, is not unreasonable.
7.3 The Controller shall only make personal data available to the Processor for processing after having ensured that the required security measures are in place. The Controller is responsible for compliance with the agreed measures.
8.1 The Controller shall at all times be responsible for notifying a security breach and/or data breach to the relevant supervisory authority and/or data subjects. To enable the Controller to meet this statutory obligation, the Processor shall notify the Controller without delay, but in any case within 36 hours, of any security breach and/or data breach.
8.2 A notification must always be made, but only if the event has actually occurred.
8.3 The notification obligation includes at least reporting the fact that a breach occurred. In addition, the notification shall include, to the extent known to the Processor:
- the nature of the personal data breach, where possible specifying the categories of data subjects and personal data concerned and, approximately, the number of data subjects and personal data records involved;
- the name and contact details of the data protection officer or other contact point;
- the (suspected) cause of the breach;
- the observed and probable consequences of the personal data breach;
- the measures the Processor has proposed or taken to address the breach, including measures to limit its possible adverse effects.
9.1 If a Data Subject submits a request to exercise their legal rights to the Processor, the Parties shall handle the request in mutual consultation. The Controller shall remain ultimately responsible for handling the request.
10.1 All data of the Controller and its clients is confidential and shall be treated as such by the Processor. The Processor is bound to confidentiality with respect to all Personal Data and information it processes or becomes aware of in the context of the Agreement or this Data Processing Agreement.
10.2 Confidentiality does not apply to information that:
- is publicly known without this being the result of an unauthorised act;
- whose disclosure is required by law or court order, subject to prior written notice to the disclosing party;
- was independently developed by a Party;
- was already in a Party's possession without a confidentiality obligation.
After termination of this Data Processing Agreement, this article and the confidentiality obligation set out herein shall remain in force.
11.1 All intellectual property rights including copyrights, database rights and all other intellectual property rights as well as similar information protection rights on the collection of data and Personal Data, copies or adaptations thereof, shall vest in the Controller (or a client of the Controller).
11.2 All intellectual property rights — including copyrights, database rights and all other intellectual property rights as well as similar information protection rights — in the products and services of the Processor, shall vest in the Processor.
12.1 The liability of the Parties for damage resulting from an attributable failure to comply with this Data Processing Agreement, or from tort or otherwise, is excluded. To the extent that such liability cannot be excluded, it is limited per incident (a series of consecutive incidents constitutes one incident) to direct damage, up to a maximum of the fees received by the other Party for work under this Data Processing Agreement in the month preceding the incident. The total liability of the Parties for direct damage shall in no case exceed €1,000.00.
12.2 Direct damage shall mean only: damage directly caused to physical property; reasonable and demonstrable costs to put the relevant party in notice of default to duly comply with the Data Processing Agreement; reasonable costs to establish the cause and extent of the damage, to the extent relating to direct damage as defined herein; and reasonable and demonstrable costs incurred by the Controller to prevent or limit direct damage as referred to in this article.
12.3 Indirect damage is excluded from liability. Indirect damage includes all damage that is not direct damage, including but not limited to consequential loss, lost profits, missed savings, reduced goodwill, business interruption, loss due to failure to achieve marketing objectives, damage related to the use of data or data files prescribed by the Controller, or loss, corruption or destruction of data or data files.
12.4 The exclusions and limitations in this article shall cease to apply if and to the extent the damage results from wilful misconduct or gross negligence on the part of the relevant Party or its management.
12.5 Unless performance by the relevant Party is permanently impossible, liability for an attributable failure arises only if one Party gives the other Party immediate written notice of default, setting a reasonable period for remedying the failure, and the other Party continues to fail to fulfil its obligations after that period. The notice of default must contain a description of the failure that is as complete and detailed as possible, so that the relevant Party has the opportunity to respond adequately.
12.6 Any claim for damages by one Party against the other that has not been specifically and explicitly reported shall lapse after the passage of twelve (12) months from the date on which the claim arose.
12.7 Parties shall maintain and keep in place adequate insurance for liability in accordance with this article throughout the term of the Data Processing Agreement.
13.1 This Data Processing Agreement enters into force when the general terms and conditions are accepted.
13.2 The provisions on term and termination of the Agreement apply as provisions on term and termination of this Data Processing Agreement. When the Agreement ends for any reason, this Data Processing Agreement also ends.
13.3 Upon termination of this Data Processing Agreement, the Processor shall transfer all Personal Data to the Controller, or, at the explicit written request of the Controller, destroy the Personal Data in its possession.
13.4 Obligations that by their nature are intended to continue after termination of this Data Processing Agreement shall remain in force after termination. These include, among others, provisions regarding confidentiality, transfer and destruction, liability and applicable law.
14.1 Either Party may dissolve the Agreement in whole or in part if the other Party is attributably in default in performing its obligations under this Data Processing Agreement and fails to remedy the default even after notice of default, without prejudice to the right to damages.
14.2 Either Party may dissolve the Agreement with immediate effect without notice of default, in whole or in part, if the other Party is granted suspension of payments, if bankruptcy is filed against the other Party, or if the other Party's business is liquidated or terminated other than for the purpose of reconstruction or merger of businesses.
15.1 Amendments to or additions to this Agreement shall be agreed in writing between the Processor and the Controller. Amendments or additions shall be recorded in an addendum to this agreement and shall be binding once signed by both Parties.
15.2 Any disputes arising from this agreement that cannot be resolved by mutual consultation shall be settled by arbitration in accordance with the rules and procedures of the Netherlands Arbitration Institute, with the arbitrator(s) applying Dutch law.
The Processor has implemented the following technical and organisational measures to protect personal data against loss or unlawful processing.
The minimum measures implemented by the Processor:
1. Employees of the Processor involved in the processing of personal data are bound by a confidentiality obligation/code of integrity and, where applicable, a background check was carried out prior to employment.
2. All employees of the organisation and, where applicable, contracted and external users receive appropriate training and regular refresher training on the organisation's information security policies and procedures, to the extent relevant to their role. Training explicitly covers the handling of personal data.
3. IT systems and equipment are physically protected against unauthorised access and against damage and disruption.
4. Adequate logical access control using two-factor authentication for critical systems.
5. Procedures are in place to grant authorised users access to the information systems and services they need for their duties and to prevent unauthorised access.
6. When transmitting information explicitly designated as confidential by the Controller over networks, adequate encryption must always be applied.
7. Procedures are in place for the acquisition, development, maintenance and disposal of data and information systems.
8. Security measures are built into all application systems, including adequate access management.
9. The network and information systems are actively monitored and managed. A procedure is also available to handle any data breaches, including notification of the Controller.
10. The Processor installs security patches released by suppliers in a timely manner, exclusively where the software concerned is delivered, used or maintained by the Processor on behalf of the Controller.
11. Procedures are in place for the timely and effective handling of information security incidents and security vulnerabilities, once reported.
12. The Controller reports data breaches that fall under a statutory reporting obligation to the relevant supervisory authority (typically the Dutch Data Protection Authority, Autoriteit Persoonsgegevens).