Data Processing Addendum
If you prefer a mroe traditional file format, you can download the Data Processing Addendum as a PDF.
-
Purpose
This Data Processing Addendum (“Addendum”) governs Dubrink’s processing of Personal Data under the Master Subscription Agreement (“MSA”) and applicable Data Protection Laws. This Addendum is incorporated into the MSA and takes precedence in matters of data protection. All other provisions, including Governing Law and Dispute Resolution, are governed by the MSA.
-
Definitions
Capitalized terms used in this Addendum shall have the meanings set forth below.
Authorized Affiliates
“Authorized Affiliates” means the Customer’s Affiliate(s) which is bound by the terms of this Data Processing Addendum, that is subject to the Data Protection Laws of the European Union (“EU”), the European Economic Area (“EEA”) and/or their Member States, Switzerland and/or United Kingdom, and/or all other applicable Data Protection Laws and is permitted to use the Services pursuant to the MSA executed between the Customer and Dubrink but has not signed its own Order with Dubrink, being Customer is responsible for ensuring that Affiliate(s) is aware of the Processing activities that may be carried out by Dubrink and that all authorizations from Affiliate(s) for such processing activity are collected.
Breach Event
“Breach Event” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by Dubrink.
Controller
“Controller” means the Customer or any of its Authorized Affiliates or any other entity that the Customer appoints to provide instructions to Dubrink as the natural or legal person who determines the purposes and means of Processing of the Personal Data.
Customer’s Personal Data
“Customer’s Personal Data” means any Personal Data Processed by Dubrink or another Sub-Processor on behalf of the Customer, which is transmitted to or given access to Dubrink by the Customer pursuant to or in connection with the MSA.
Data Subject
“Data Subject” means the identified or identifiable natural person whose Personal Data is Processed.
Data Protection Laws
“Data Protection Laws” means all applicable data protection and privacy laws and regulations, including, where applicable, the General Data Protection Regulation (GDPR), UK Data Protection Act, Swiss Federal Act on Data Protection, U.S. state privacy laws (e.g., CCPA, CPRA), and any other laws governing the processing of Personal Data in jurisdictions where the Customer operates.
GDPR
“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
List of Sub-processors
“List of Sub-Processors” means the list of Sub-processors engaged by Dubrink as made available in Annex II.
Personal Data
“Personal Data” means any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, a location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, as well as the categories of data referred to in Annex I (“Processing Activities”), which may be supplied to and Processed by Dubrink on behalf of the Controller pursuant to or in connection with the MSA.
Personnel
“Personnel” means Dubrink’s employees or other individuals with a contractual relationship with Dubrink.
Processing
“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Processor
“Processor” means Dubrink as the legal person who processes Personal Data on behalf of the Controller.
Restricted Transfers
“Restricted Transfers” means the transfer of Personal Data to countries that do not ensure an adequate level of data protection within the meaning of Data Protection Laws, to the extent such transfers are subject to such Data Protection Laws. Restricted Transfers include transfers of Customer’s Personal Data to Dubrink and onward transfers of Customer’s Personal Data from Dubrink to a Sub-Processor and from a Sub-Processor to another Sub-Processor or between two establishments of a Sub-Processor.
Services
“Services” means the Dubrink Platform provided on cloud (platform as a service) and the Support and Updates jointly provided through a Subscription and/or the Professional Services provided by Dubrink, as defined in the MSA.
Standard Contractual Clauses
“Standard Contractual Clauses” (SCCs) means the standard contractual clauses approved by the European Commission Decision 2021/914 of 4 June 2021, or any subsequent updates or replacements thereof, for the transfer of personal data to third countries under Regulation (EU) 2016/679 (GDPR).
Where applicable, the SCCs shall include the UK International Data Transfer Addendum issued by the UK Information Commissioner’s Office (“UK SCCs”).
The applicable SCCs shall be incorporated by reference and deemed executed between the Parties where required for compliance with applicable Data Protection Laws.
Sub-Processor
“Sub-Processor” means an entity engaged by the Processor exclusively for the Processing activities to be carried out pursuant to or in connection with this Addendum and the MSA on behalf of the Customer and in accordance with its instructions, as transmitted by the Customer.
Third-Party Services
“Third-Party Services” means certain services and applications, including Non-Dubrink Applications and Add-ons, operated by third parties chosen and directly contracted by Customer, that integrate with the Services. The providers of said Third Party Services are not Dubrink Sub-Processors.
-
Processing of Personal Data
-
Roles of the Parties
The parties acknowledge and agree that:
-
The Customer is the Controller of Personal Data and determines the purposes and means of its processing.
-
Dubrink acts as the Processor and processes Personal Data solely to comply with the CBAM Regulation and for the purposes described in this section.
-
The Customer may engage a Partner to act on its behalf. In such cases:
-
The Partner shall be considered as acting under the Customer’s authority.
-
Dubrink may also act as a Partner, in which case it will process Personal Data strictly within the scope of its role as a Processor under this Addendum.
-
-
For customers outside the EU/EEA, Dubrink shall comply with applicable data protection laws in those jurisdictions where such laws impose similar obligations to GDPR. Where no specific regulation applies, Dubrink shall process data in accordance with recognized industry best practices.
-
-
Processing for CBAM Compliance
-
For the purpose of fulfilling its obligations under the CBAM Regulation, Dubrink is authorized to contact relevant Supply Chain Stakeholders.
-
This includes collecting only the necessary data and information related to CBAM compliance.
-
Dubrink shall process this data strictly in accordance with this Addendum and applicable data protection laws.
-
-
Customer’s Processing of Personal Data
-
Customer represents and warrants that it has obtained all necessary rights, consents, and legal bases required under applicable Data Protection Laws for the collection, processing, and transfer of such Personal Data to Dubrink.
-
Customer shall ensure that it only submits Personal Data to the Services when it has a valid legal basis to do so under applicable Data Protection Laws. This includes any Personal Data related to Tier 2 suppliers or other third parties, such as their employees or representatives. The Customer must not upload or share Personal Data that it is not authorized to process or that is unrelated to the intended and lawful use of the Services.
-
Dubrink shall not be liable for any unlawful or unauthorized processing of data submitted by the Customer.
-
-
Details of Processing
-
The subject matter of the Processing of Personal Data by Dubrink is the provision of services under the MSA.
-
The nature and purpose of the Processing, the categories of Data Subjects, and the types of Personal Data Processed under this Data Processing Addendum are further specified in Annex I.
-
-
Duration of the Processing
-
The Processing of Personal Data shall continue for the duration of the MSA, unless otherwise required by law or agreed upon in writing by the Parties.
-
Upon termination or expiration of the MSA, Dubrink shall, at the Customer’s choice, return or delete the Personal Data Processed on behalf of the Customer and delete all existing copies, unless applicable law requires continued storage of the Personal Data. The applicable procedure and timelines for such return or deletion shall be governed by Section 6.8.
-
-
-
Technical and Organizational Measures
Dubrink has implemented and shall maintain appropriate technical and organisational measures designed to ensure the confidentiality, integrity, and availability (CIA) associated with the processing of Personal Data, in accordance with applicable Data Protection Laws.
Dubrink may update these measures from time to time to reflect technological developments, security risks and improvements to its services, provided that such updates do not materially reduce the overall level of protection afforded to Personal Data.
Dubrink maintains an information security management system certified to ISO/IEC 27001:2022, audited by Bureau Veritas. This certification provides independent assurance regarding Dubrink’s information security governance and complements the specific technical and organisational measures described in Annex IV.
-
Dubrink’s Personnel
Dubrink ensures that any Personnel with access to or involved in the Processing of Customer’s Personal Data is subject to binding confidentiality obligations, whether through employment contracts, professional duties, or statutory requirements.
-
Cooperation
-
General Scope of Assistance and Fees
-
Dubrink shall provide the assistance required of a Processor under applicable Data Protection Laws, including the assistance required pursuant to Article 28(3)(e) and (f) GDPR, in accordance with this Section 6.
-
Such assistance shall include assistance necessary to enable the Customer to comply with its obligations concerning:
- the exercise of Data Subject rights;
- the security of Processing;
- notification of Personal Data breaches to Supervisory Authorities;
- communication of Personal Data breaches to affected Data Subjects;
- Data Protection Impact Assessments; and
- prior consultation with Supervisory Authorities.
-
Dubrink shall not charge additional fees for assistance that Dubrink is required to provide under this Addendum or applicable Data Protection Laws.
-
Where the Customer requests activities that clearly exceed Dubrink’s obligations under this Addendum and applicable Data Protection Laws, Dubrink may charge additional fees, provided that the scope of the additional activities and the applicable fees are agreed upon by the Parties in writing in advance. The absence of such agreement shall not delay or limit the performance of Dubrink’s obligations under applicable Data Protection Laws.
-
No additional fees shall apply to assistance required as a result of a breach of this Addendum or applicable Data Protection Laws by Dubrink or any of its Sub-Processors.
-
-
Assistance in the Event of a Breach
-
Without limiting Section 7, in the event of a Breach Event, Dubrink shall cooperate with and assist the Customer in ensuring compliance with the Customer’s obligations under applicable Data Protection Laws, including Articles 33 and 34 GDPR.
-
Taking into account the nature of the Processing and the information available to Dubrink, such assistance shall include:
- providing the information available to Dubrink that is required for any notification to a Supervisory Authority or communication to affected Data Subjects;
- assisting the Customer in assessing the nature, scope, consequences, and risks of the Breach Event; and
- assisting with measures to contain, investigate, remedy, and mitigate the effects of the Breach Event.
Dubrink shall provide such assistance without undue delay and sufficiently in advance to enable the Customer to comply with its applicable statutory deadlines.
-
-
Information Requests and Documentation
-
Upon the Customer’s request, Dubrink shall make available to the Customer all information necessary to demonstrate compliance with the obligations applicable to Dubrink under this Addendum and Article 28 GDPR.
-
Dubrink shall respond promptly and adequately to enquiries from the Customer concerning the Processing of Personal Data under this Addendum.
-
Dubrink shall ensure that its Sub-Processors are contractually bound to provide the information and assistance necessary for Dubrink to comply with this Section. Dubrink may redact information only to the extent necessary to protect confidential information, trade secrets, security-sensitive information, or Personal Data relating to other customers, provided that such redaction does not prevent the Customer from assessing Dubrink’s compliance with this Addendum.
-
-
Data Protection Impact Assessments and Prior Consultation
-
Taking into account the nature of the Processing and the information available to Dubrink, Dubrink shall assist the Customer in complying with its obligations concerning:
- Data Protection Impact Assessments under Article 35 GDPR; and
- prior consultation with a Supervisory Authority under Article 36 GDPR.
-
Such assistance shall include providing relevant information available to Dubrink concerning the Processing activities, applicable technical and organizational measures, identified risks, and measures implemented or proposed to address those risks.
-
The Customer remains responsible for determining whether a Data Protection Impact Assessment or prior consultation is required and for preparing, approving, and submitting the relevant assessment or consultation request. Dubrink shall not be required to provide legal advice or make decisions that are the responsibility of the Customer as Controller.
-
Dubrink shall provide such assistance without undue delay and sufficiently in advance to enable the Customer to comply with its obligations under applicable Data Protection Laws.
-
-
Data Subject Requests
-
Dubrink shall notify the Customer without undue delay if it receives a request from a Data Subject concerning Personal Data Processed on behalf of the Customer.
-
Dubrink shall not respond to such a request unless instructed to do so by the Customer or required to do so under applicable law. Where Dubrink is required by law to respond directly, it shall inform the Customer of that legal requirement before responding, unless applicable law prohibits such notification.
-
Taking into account the nature of the Processing, Dubrink shall assist the Customer through appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests concerning the exercise of Data Subject rights under applicable Data Protection Laws.
-
Dubrink shall provide such notification and assistance without undue delay and sufficiently in advance to enable the Customer to comply with the applicable statutory deadlines.
-
The Customer remains responsible for assessing and responding to Data Subject requests in its capacity as Controller.
-
-
Authority Requests
-
Unless prohibited by applicable law, Dubrink shall notify the Customer without undue delay if it receives a communication, correspondence, or request from a regulatory, supervisory, judicial, or governmental authority that relates directly to the Processing of Personal Data on behalf of the Customer.
-
Where permitted by applicable law, Dubrink shall provide the Customer with the relevant details of the request and shall assist the Customer in responding to or otherwise addressing the request to the extent required under applicable Data Protection Laws.
-
Dubrink may redact or restrict the disclosure of information only to the extent required by applicable law or necessary to protect confidential information, security-sensitive information, or Personal Data relating to other customers.
-
Dubrink shall ensure that its Sub-Processors are subject to corresponding notification and cooperation obligations.
-
-
Data Quality
-
Dubrink shall Process Personal Data in accordance with the Customer’s documented instructions and shall inform the Customer without undue delay if Dubrink becomes aware that Personal Data Processed on behalf of the Customer is inaccurate or outdated.
-
Upon the Customer’s documented request, Dubrink shall update, amend, correct, restrict, or delete Personal Data to the extent required under applicable Data Protection Laws and technically possible within the Services.
-
Dubrink shall ensure that its Sub-Processors comply with corresponding obligations concerning the accuracy, amendment, restriction, and deletion of Personal Data.
-
-
Deletion, Destruction or Return of Personal Data
-
Upon termination or expiration of the MSA, Dubrink shall, in accordance with the Customer’s written instructions:
- return all Personal Data Processed on behalf of the Customer and subsequently delete all existing copies in Dubrink’s possession or control; or
- delete all Personal Data Processed on behalf of the Customer and all existing copies in Dubrink’s possession or control.
-
The Customer shall provide its return or deletion instructions within thirty (30) days following termination or expiration of the MSA. If the Customer does not provide such instructions within this period, the Customer shall be deemed to have instructed Dubrink to delete the Personal Data.
-
Dubrink shall complete the requested return or deletion within a commercially reasonable timeframe, taking into account applicable technical constraints, backup cycles, and legal obligations. Personal Data retained in backup systems shall remain protected in accordance with this Addendum, shall not be restored or otherwise Processed except where required for disaster recovery, security, or compliance with applicable law, and shall be permanently deleted in accordance with Dubrink’s ordinary backup-retention cycle.
-
Dubrink shall ensure that its Sub-Processors comply with the return and deletion obligations set out in this Section.
-
Notwithstanding the foregoing, Dubrink may retain Personal Data to the extent and for the period required by applicable law. Any Personal Data so retained shall remain protected in accordance with this Addendum, shall be Processed only for the purpose for which its continued storage is legally required, and shall be deleted when the applicable retention requirement ends.
-
-
-
Breach Event
-
Breach Notification
Dubrink shall notify the Customer without undue delay and within thirty-six (36) hours after becoming aware of any Breach Event, in accordance with applicable Data Protection Laws. Where and in so far as it is not possible to provide all relevant information at the same time, the information may be provided in phases without undue delay.
-
Cooperation
Dubrink shall fully and promptly cooperate with the Customer in satisfying its obligations with respect to a Breach Event, as determined by the applicable Data Protection Laws.
-
-
Sub-Processors
-
General Authorization
-
The Customer grants Dubrink general written authorization to engage the Sub-Processors identified in Annex II for the Processing of Personal Data on behalf of the Customer.
-
Annex II shall contain up-to-date information concerning each Sub-Processor, including at least:
- its legal name;
- the country or countries in which the Processing takes place;
- the nature and purpose of the Processing performed on behalf of the Customer; and
- where relevant, the applicable mechanism governing a Restricted Transfer.
-
Dubrink shall make the current List of Sub-Processors available to the Customer throughout the term of the MSA.
-
-
Changes to Sub-Processors
-
Dubrink shall specifically inform the Customer in writing of any intended addition or replacement of a Sub-Processor at least thirty (30) days before the proposed Sub-Processor commences Processing Personal Data on behalf of the Customer.
-
The notice shall include the information reasonably necessary for the Customer to assess the proposed change, including the proposed Sub-Processor’s identity, location of Processing, and the nature and purpose of the Processing to be performed.
-
The proposed Sub-Processor shall not commence Processing Personal Data on behalf of the Customer before the applicable notice period has expired, unless the Customer has expressly accepted the proposed change in writing before that date.
-
-
Objections to Sub-Processors
-
The Customer may object to the intended addition or replacement of a Sub-Processor by providing Dubrink with a written and reasoned objection within thirty (30) days following receipt of the notice under Section 8.2.
-
An objection shall be considered reasonable where it is based on substantiated concerns that the proposed Sub-Processor would be unable to comply with applicable Data Protection Laws or the data protection obligations applicable to the Processing under this Addendum.
-
If the Customer raises a reasonable objection, the Parties shall cooperate in good faith to identify a commercially reasonable solution. Such a solution may include:
- not appointing the proposed Sub-Processor;
- implementing additional safeguards;
- using an alternative Sub-Processor; or
- modifying the affected Services to avoid the use of the proposed Sub-Processor.
-
The proposed Sub-Processor shall not Process the Customer’s Personal Data while a timely and reasonable objection remains unresolved.
If the Parties are unable to resolve a reasonable objection within thirty (30) days after Dubrink receives it, either Party may terminate the Services directly affected by the proposed Sub-Processor by written notice. The Customer shall not incur any termination charge or penalty in respect of the affected Services and shall receive a pro-rata refund of prepaid fees attributable to the unused period of those Services.
-
-
Support and Professional Services
-
The Customer shall avoid including or otherwise making Personal Data available to Dubrink in connection with Support or Professional Services unless such Personal Data is reasonably necessary for the provision of the relevant Services.
-
Where Personal Data is reasonably necessary, the Customer shall limit the Personal Data disclosed to what is adequate, relevant, and necessary for the relevant Support or Professional Services. Where reasonably practicable, the Customer shall redact, anonymize, or pseudonymize Personal Data before making it available to Dubrink.
-
Any Personal Data accessed, received, or otherwise Processed by Dubrink in connection with Support or Professional Services shall remain subject to this Addendum and applicable Data Protection Laws.
-
Dubrink shall Process such Personal Data solely:
- on the Customer’s documented instructions;
- to the extent necessary to provide the relevant Support or Professional Services; and
- for no independent or incompatible purpose.
-
Unless otherwise specified by the Customer, the Customer’s submission of a support request, error report, system log, screenshot, file, or other information containing Personal Data shall constitute a documented instruction to Dubrink to Process that Personal Data solely to investigate, respond to, and resolve the relevant request.
-
Dubrink shall restrict access to such Personal Data to Personnel and Sub-Processors who require access for the provision of the relevant Support or Professional Services and who are subject to the confidentiality and data protection obligations set out in this Addendum.
-
Personal Data Processed under this Section shall be retained only for as long as necessary to provide the relevant Support or Professional Services or as otherwise required by applicable law, after which it shall be deleted in accordance with Dubrink’s applicable retention procedures and this Addendum.
-
-
Third-Party Services
If Customer subscribes to any Third-Party Services, even if they have some interaction with the Services, Customer shall perform its own due diligence from a data protection, privacy and security perspective. Said Third-Party Services providers are not Dubrink Sub-Processors and Dubrink is not liable for the processing of Customer’s Personal Data by Third-Party Providers.
-
Obligations and Liability for Sub-Processors
-
Before permitting a Sub-Processor to Process Personal Data on behalf of the Customer, Dubrink shall enter into a binding written agreement with that Sub-Processor.
-
The agreement shall impose on the Sub-Processor the same data protection obligations as those imposed on Dubrink under this Addendum, to the extent applicable to the Processing performed by that Sub-Processor, including appropriate obligations concerning:
- Processing only on documented instructions;
- confidentiality;
- security of Processing;
- assistance with Data Subject rights and the Customer’s compliance obligations;
- notification of Personal Data breaches;
- deletion or return of Personal Data;
- Restricted Transfers; and
- the provision of information necessary to demonstrate compliance.
-
Dubrink shall ensure that each Sub-Processor provides sufficient guarantees to implement appropriate technical and organizational measures so that the Processing complies with applicable Data Protection Laws.
-
Dubrink shall remain fully liable to the Customer for the performance of each Sub-Processor’s data protection obligations.
Upon the Customer’s reasonable request, Dubrink shall provide information sufficient to demonstrate that the obligations required by this Section have been imposed on the relevant Sub-Processor. Dubrink may redact commercially confidential, security-sensitive, or unrelated information, provided that such redaction does not prevent the Customer from reasonably assessing compliance with this Section.
-
-
-
Audit Rights
-
Information
Dubrink shall, upon request, make available to the Customer information reasonably necessary to demonstrate compliance with this Data Processing Addendum and applicable Data Protection Laws.
-
Compliance Documentation
-
Dubrink shall maintain appropriate documentation concerning its Processing of Personal Data and the technical and organizational measures implemented under this Addendum.
-
Dubrink’s annual Data Protection Impact Assessment summary, relevant certifications, independent audit reports, security documentation, and other compliance materials made available under Section 9.1 shall serve as the primary means of demonstrating Dubrink’s compliance with this Addendum and applicable Data Protection Laws.
-
Upon the Customer’s reasonable written request, Dubrink shall provide additional information necessary to demonstrate compliance with the obligations applicable to Dubrink as a Processor, subject to appropriate measures to protect:
- the confidentiality and security of Dubrink’s systems;
- commercially sensitive information and trade secrets;
- Personal Data and confidential information relating to other customers; and
- information that Dubrink is prohibited from disclosing by law or contractual obligation.
-
The provision of a DPIA summary, certification, audit report, or other compliance documentation shall not, by itself, prevent the Customer from exercising its audit rights under Section 9.3 where the information provided is insufficient to reasonably demonstrate Dubrink’s compliance.
-
-
Audits
-
Dubrink shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor appointed by the Customer, where:
- the information and documentation provided under Sections 9.1 and 9.2 are insufficient to reasonably demonstrate Dubrink’s compliance with this Addendum or applicable Data Protection Laws;
- the Customer has reasonable and documented grounds to suspect that Dubrink is not complying with its obligations under this Addendum or applicable Data Protection Laws;
- an audit is required by a Supervisory Authority or applicable Data Protection Laws; or
- a confirmed or reasonably suspected Breach Event materially affecting the Customer has occurred.
-
Before requesting an audit, the Customer shall, where appropriate, first allow Dubrink a reasonable opportunity to address the Customer’s request through the provision of additional information or documentation.
-
Unless a shorter period is required by applicable law, a Supervisory Authority, a Breach Event, or other urgent and substantiated circumstances, the Customer shall provide Dubrink with at least thirty (30) days’ prior written notice of an audit.
-
Audits shall:
- be limited to the Processing of Personal Data performed by Dubrink on behalf of the Customer and to matters relevant to compliance with this Addendum;
- be conducted during normal business hours and in a manner that avoids unnecessary disruption to Dubrink’s operations;
- not provide access to Personal Data or confidential information relating to other customers;
- comply with Dubrink’s reasonable security and confidentiality requirements; and
- be conducted by appropriately qualified persons who are subject to binding confidentiality obligations and who are not competitors of Dubrink.
-
Unless an on-site inspection is required by applicable law or a Supervisory Authority, or a remote audit is insufficient to reasonably verify compliance, audits shall initially be conducted remotely through the review of relevant documentation, interviews, certifications, and audit reports.
-
Where a remote audit is insufficient to reasonably demonstrate compliance, Dubrink shall permit a proportionate on-site inspection, subject to the safeguards set out in this Section.
-
The Customer shall not conduct more than one audit in any twelve-month period unless:
- a Supervisory Authority or applicable law requires an additional audit;
- a Breach Event materially affecting the Customer has occurred; or
- the Customer has reasonable and documented grounds to suspect a material breach of this Addendum or applicable Data Protection Laws.
-
The Customer shall bear its own audit costs and reimburse Dubrink for reasonable costs incurred in connection with an audit that exceeds Dubrink’s ordinary statutory cooperation obligations. No such reimbursement shall be payable where the audit identifies a material breach of this Addendum or applicable Data Protection Laws by Dubrink.
-
-
-
Restricted Transfers
-
General Requirements
-
Dubrink shall not make or permit a Restricted Transfer of Personal Data except:
- on the Customer’s documented instructions; and
- in compliance with Chapter V GDPR and all other applicable Data Protection Laws.
-
Each Restricted Transfer shall be subject to a valid transfer mechanism applicable to the relevant recipient and transfer, including, as applicable:
- an adequacy decision adopted by the European Commission;
- the Standard Contractual Clauses;
- binding corporate rules;
- another transfer mechanism permitted under Article 46 GDPR; or
- a derogation under Article 49 GDPR, where the conditions for relying on that derogation are satisfied.
-
Where Dubrink is required by applicable EU or Member State law to make a Restricted Transfer without the Customer’s documented instructions, Dubrink shall inform the Customer of that legal requirement before the relevant Processing takes place, unless the applicable law prohibits such notification on important grounds of public interest.
-
-
Standard Contractual Clauses and Transfer Assessments
-
Where the Standard Contractual Clauses are relied upon, the applicable module or modules of the Standard Contractual Clauses shall be incorporated by reference and deemed executed between the relevant parties.
-
Where required under the Standard Contractual Clauses or applicable Data Protection Laws, Dubrink shall assess and document whether the laws and practices of the relevant third country may prevent the relevant recipient from complying with the Standard Contractual Clauses or otherwise affect the effectiveness of the safeguards provided by the applicable transfer mechanism.
-
Such assessment shall take into account, as applicable:
- the circumstances and nature of the Restricted Transfer;
- the categories and sensitivity of the Personal Data;
- the relevant recipient and Processing activities;
- the laws and practices of the relevant third country;
- the likelihood and potential impact of access by public authorities; and
- the technical, contractual, and organizational safeguards applicable to the Restricted Transfer.
-
Where the assessment identifies that the applicable transfer mechanism does not, by itself, provide an essentially equivalent level of protection, Dubrink shall implement appropriate supplementary technical, contractual, or organizational measures before commencing or continuing the Restricted Transfer.
-
Dubrink shall periodically review the continued validity of the relevant assessment and safeguards where required by applicable Data Protection Laws or where circumstances affecting the Restricted Transfer materially change.
-
-
Information and Transparency
-
Dubrink shall maintain up-to-date information concerning Restricted Transfers made in connection with the Services, including, as applicable:
- the identity of the relevant recipient or category of recipients;
- the country or countries in which the Personal Data is Processed;
- the nature and purpose of the Processing;
- the applicable transfer mechanism; and
- a description of any material supplementary safeguards implemented in connection with the transfer.
-
Upon the Customer’s reasonable written request, Dubrink shall provide the information reasonably necessary for the Customer to assess the lawfulness of the Restricted Transfers made on its behalf.
-
Dubrink may redact or withhold information to the extent necessary to protect:
- confidential or commercially sensitive information;
- the security of Dubrink’s systems or those of its Sub-Processors;
- Personal Data or confidential information relating to other customers;
- legally privileged information; or
- information that Dubrink is prohibited from disclosing by applicable law or contractual obligation,
provided that such redaction or withholding does not prevent the Customer from reasonably assessing compliance with this Section.
-
-
Material Changes
-
Dubrink shall notify the Customer without undue delay if it becomes aware of a material change that adversely affects:
- the validity of the applicable transfer mechanism;
- the conclusions of a relevant transfer assessment;
- the effectiveness of any supplementary safeguards; or
- the relevant recipient’s ability to comply with its obligations under the applicable transfer mechanism.
-
Where the applicable transfer mechanism or safeguards cease to provide a lawful basis for the Restricted Transfer, Dubrink shall, as applicable:
- implement additional or alternative safeguards;
- rely on another valid transfer mechanism;
- suspend the affected Restricted Transfer; or
- cease the affected Processing.
-
Dubrink shall inform the Customer of the measures taken under this Section.
-
-
Sub-Processors and Onward Transfers
-
Dubrink shall ensure that each Sub-Processor making or receiving a Restricted Transfer complies with Chapter V GDPR and the requirements of this Section.
-
Dubrink shall ensure that any onward transfer by a Sub-Processor is subject to:
- a valid transfer mechanism applicable to the relevant onward recipient and transfer;
- data protection obligations that are no less protective than the obligations applicable to the Sub-Processor; and
- any supplementary safeguards required to ensure an essentially equivalent level of protection.
-
Dubrink shall remain responsible to the Customer for ensuring that its Sub-Processors comply with the obligations set out in this Section.
-
-
-
Limitation of Liability
-
General Limitation of Liability
The liability of each Party under this Addendum shall be subject to the limitations and exclusions of liability set out in the MSA, except to the extent that:
-
such limitation or exclusion is not permitted under applicable Data Protection Laws; or
-
liability arises from Dubrink’s breach of obligations specifically imposed on Processors under applicable Data Protection Laws, Dubrink’s Processing outside or contrary to the Customer’s lawful documented instructions, or Dubrink’s fraud or wilful misconduct.
Nothing in this Addendum shall limit or alter the allocation of responsibility between Controllers and Processors arising directly under Article 82 GDPR.
-
-
Allocation of Responsibility
Dubrink shall be liable to the Customer for reasonable and documented losses, damages, costs and expenses, including legally recoverable administrative fines and compensation paid to Data Subjects, only to the extent directly caused by:
-
Dubrink’s breach of this Addendum or applicable Data Protection Laws;
-
Dubrink’s Processing of Personal Data outside or contrary to the Customer’s lawful documented instructions;
-
Dubrink’s breach of its confidentiality or security obligations;
-
Dubrink’s unlawful engagement of a Sub-Processor; or
-
a Restricted Transfer made by Dubrink without a valid transfer mechanism.
Dubrink shall not be liable to the extent that the relevant loss, damage, cost, claim, fine or liability was caused or contributed to by:
-
the Customer’s breach of this Addendum or applicable Data Protection Laws;
-
an unlawful, inaccurate or incomplete instruction provided by or on behalf of the Customer;
-
Personal Data submitted or otherwise made available by or through the Customer’s account or environment without an appropriate legal basis or outside the agreed scope of the Services; or
-
any act or omission of the Customer or a person acting under the Customer’s authority or using access granted by the Customer.
The Customer remains responsible for determining whether Personal Data submitted to the Services may lawfully be Processed and for ensuring that persons permitted to use its account or environment comply with the Customer’s obligations under applicable Data Protection Laws.
Nothing in this Section shall exclude Dubrink’s liability to the extent that Dubrink independently caused or materially contributed to the relevant breach or damage. Dubrink shall not be liable to the extent that it proves it was not responsible for the event giving rise to the damage.
-
-
-
Notices
Any notice, consent, or other communication under this Addendum (“Notice”) must be in writing and sent either by email or registered mail. Notices to Dubrink shall be sent to privacy@dubrink.com, and Notices to the Customer shall be sent to the email address provided by the Customer. Notices sent by email shall be deemed effective upon receipt, unless received outside business hours, in which case it will be deemed effective the next business day on the date of receipt or, if delivery is refused, the date of such refusal. Notices must be sent to the contacts listed in the signature section of this Addendum, and either Party may update its Notice address by notifying the other Party in accordance with this clause. All Notices must be in English.