- Data Processing Agreement
Data Processing Agreement
| Navn | Tjeneste | Formål | Jurisdiktion | Privatlivspolitik |
|---|---|---|---|---|
| CookieConsent™ (AWORK CMP) | Samtykkestyring (Consent Management) | Overholdelse af GDPR og dokumentation af samtykke | EU | Privatlivspolitik |
| Hetzner Online GmbH | Serverhosting og datastyring | Primær hostingpartner - data lagres krypteret på ISO 27001-certificerede servere i Falkenstein, Tyskland (EU) | EU | Privatlivspolitik |
| Cloudflare Inc. | CDN & sikkerhed | Optimering, hjemmesidesikkerhed og indlæsningstid | EU, USA, Singapore, Australien, UAE | Privatlivspolitik |
| Google Ireland Limited | Google Analytics | Analyse og marketing | EU, USA, Singapore, Chile, Taiwan | Privatlivspolitik |
| Google Ireland Limited | Google Fonts | Visning og levering af skrifttyper | EU, USA, Singapore, Taiwan, Chile | Privatlivspolitik |
| Google LLC | Google Maps | Kortintegration og visning af geografisk placering | EU, USA, Singapore, Taiwan, Chile | Privatlivspolitik |
| Google Ireland Limited | Google Tag Manager | Tagadministration og scriptstyring | EU, USA, Singapore, Taiwan, Chile | Privatlivspolitik |
Data Processing Agreement
This Data Processing Agreement forms the basis for how Obiyen handles personal data on behalf of our customers. The agreement enters into force when the customer signs up as a user of our services.
This Data Processing Agreement has been established in accordance with Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”) to regulate Obiyen’s processing of personal data on your behalf as a customer.
The agreement is entered into between:
Data Controller:
[Company name, address, and CVR number]
Contact person:
[Contact person and contact information]
Data Processor:
Obiyen v/ AWORK Innovate A/S
Dronning Olgas Vej 2, 1st floor
2000 Frederiksberg
CVR: 34725845
Hereinafter, the parties are referred to respectively as “the Data Controller” and “the Data Processor.” Collectively, they are referred to as “the Parties.”
1. Purpose and basis
1.1 Terms such as “personal data,” “special categories of personal data,” “data processing,” “the data subject,” “data controller,” and “data processor” shall be understood in accordance with the definitions in the GDPR.
1.2 The purpose of this agreement is to ensure compliance with applicable data protection legislation and to document the Data Controller’s instructions to the Data Processor. The processing of personal data is carried out to support the Data Controller’s use of Obiyen’s software solution, as further described in our terms and conditions.
1.3 This agreement specifies the Parties’ responsibilities and obligations regarding the processing of personal data, where Obiyen acts on behalf of the Data Controller.
1.4 This agreement shall prevail in the event of any conflict with other terms concerning the processing of personal data between the Parties. The agreement remains valid for as long as the Data Controller uses Obiyen’s software.
1.5 Nothing in this agreement relieves the Data Processor of the obligations imposed under applicable data protection legislation.
2. The Data Controller’s obligations and rights
2.1 The Data Controller must ensure that all processing of personal data in connection with the use of Obiyen’s software solution takes place in accordance with Article 24 of the GDPR, as well as other relevant EU or national legislation and this agreement.
2.2 The Data Controller has the exclusive right to make decisions regarding the purposes and means of the processing of personal data, including what is processed and entered into Obiyen’s system.
2.3 It is the Data Controller’s responsibility to ensure that there is a lawful basis for the processing and sharing of personal data carried out by the Data Processor, including with any subprocessors used by the Data Processor and listed in the currently applicable overview.
2.4 The Data Controller is responsible for ensuring that the personal data processed by the Data Processor is accurate, reliable, and lawfully collected.
2.5 The Data Controller must ensure that all necessary authorizations and notification requirements to relevant authorities are fulfilled in relation to the processing of personal data.
2.6 It is the responsibility of the Data Controller to inform the data subjects about the processing of their personal data in accordance with applicable data protection legislation.
2.7 The Data Controller declares that Obiyen has implemented appropriate technical and organizational security measures to protect the rights and data of the data subjects.
3. Processing in accordance with instructions
3.1 The Data Processor may only process personal data in accordance with documented instructions from the Data Controller, unless otherwise required under EU or national law. By entering into this agreement, the Data Controller instructs the Data Processor to process personal data in the following ways:
3.1.1 In accordance with applicable law;
3.1.2 To fulfill obligations under Obiyen’s terms for use of the system;
3.1.3 As further described in this agreement.
3.2 If an instruction from the Data Controller is deemed to conflict with applicable data protection legislation, the Data Processor must immediately notify the Data Controller.
4. Security of processing
4.1 The Data Processor shall maintain a high level of security by implementing relevant organizational, technical, and physical security measures.
4.2 Access to personal data may only be granted to persons who are subject to confidentiality obligations, and only to the extent necessary to fulfill this agreement. The confidentiality obligation also applies after termination of the agreement.
4.3 Obiyen has implemented several security measures, including:
4.3.1 Conducting regular risk assessments to ensure that technical and organizational measures are sufficient;
4.3.2 Encryption of personal data during transmission over the internet;
4.3.3 Training employees in data protection and IT security;
4.3.4 Restricting access to personal data to relevant persons only;
4.3.5 Control systems to identify and report security breaches;
4.3.6 Ongoing testing of systems and procedures to maintain security.
5. Use of subprocessors
5.1 This agreement constitutes the Data Controller’s general written authorization for the use of subprocessors, both within and outside the EU/EEA, provided that the transfer takes place with appropriate safeguards in accordance with Chapter V of the GDPR, such as the EU Commission’s Standard Contractual Clauses. Obiyen currently uses only data processors with server locations in the EU/EEA, and if the server location changes, the Data Controller will be informed in advance.
5.2 Obiyen ensures that subprocessors comply with the same obligations as those set out in this agreement. The Data Controller must be informed at least 30 days before a new subprocessor is engaged and has the right to object if the data protection legislation is not complied with. If no agreement can be reached, the Data Controller may terminate the subscription at short notice.
6. Transfer to third countries
6.1 Any transfer of personal data to a third country or an international organization must be based on a valid transfer mechanism, such as the EU Standard Contractual Clauses (SCCs).
7. Assistance to the Data Controller
7.1 The Data Processor assists the Data Controller in ensuring compliance with the General Data Protection Regulation, including security of processing, notification of data breaches, and compliance with the rights of data subjects.
7.2 The Data Processor may not respond to inquiries from data subjects without permission from the Data Controller and may not disclose information without a legal obligation to do so.
8. Notification of data breaches
8.1 The Data Processor must immediately notify the Data Controller of security breaches involving personal data so that the Data Controller can fulfill its obligations under the General Data Protection Regulation.
9. Return and deletion of data
9.1 Upon termination of the subscription, the Data Controller may have its data returned. Thereafter, the Data Processor will delete or anonymize all personal data in accordance with applicable rules.
10. Audit and inspection
10.1 The Data Controller has the right to carry out an audit of the Data Processor’s compliance with this agreement. Obiyen will cooperate with any audits and provide the necessary documentation.
11. Duration of the agreement
11.1 This agreement remains valid for as long as Obiyen processes personal data on behalf of the Data Controller.
12. Amendments to the agreement
12.1 Amendments to this agreement will be notified 30 days before they take effect. Continued use of Obiyen’s services after such amendments is considered acceptance of the new terms.
13. Liability
13.1 Liability in connection with breaches of this agreement is governed by Obiyen’s general terms and conditions.
14. Governing law and jurisdiction
14.1 This agreement is governed by Danish law, and any dispute shall be settled by the Court in Helsingør.
Appendix A – Categories of Personal Data
a. Personal data that may be processed includes, among other things:
- Name
- Title
- Telephone number
- Address
- Other relevant information
Appendix B – Sub-processors
Obiyen uses several subprocessors to deliver our services. We ensure that valid agreements are in place with all subprocessors in order to protect your data in the best possible way.
Please contact us at support@aworkone.dk
if you have any questions about our use of subprocessors.