Customer service

About

More

Jobs

Contact

EN

Customer Service

About

More

Jobs

Contact

EN

Data Processing Agreement

Data Processing Agreement

When you work with us and we process personal data on your behalf, we ensure everything is carefully documented in a data processing agreement. This gives you peace of mind that all is compliant with the GDPR.

This Data Processing Agreement is an integral part of the arrangements between the Parties (hereinafter: “the Agreement”).

Parties

  • Client, who has entered into an agreement for the Phone Service product on the website of ContactCare B.V. (hereinafter “Controller”);

  • ContactCare B.V., located at Piet Mondriaanplein 23 in Amersfoort, registered with the Chamber of Commerce under number 32136618 and lawfully represented by Mr. J.M. Meerding (hereinafter: “Processor”);

considering that

  • The Controller is involved in handling contacts via various communication channels.

  • The Processor assists the Controller in providing services for the aforementioned communication channels and, in this capacity, processes (special) personal data for the Controller.

  • The Controller and Processor have entered into an agreement on [date] regarding the acquisition of services from the Processor by the Controller, of which this Data Processing Agreement is a part.

  • The Processor, in performing the Agreement, can be regarded as a Processor within the meaning of Article 4(8) of the General Data Protection Regulation (hereinafter: “GDPR”);

  • The Controller is regarded as a controller within the meaning of Article 4(8) of the GDPR;

  • Where personal data is mentioned in this Data Processing Agreement, it is understood as personal data within the meaning of Article 4(1) of the GDPR;

  • The Controller designates the purposes and means for processing, to which the conditions mentioned herein apply;

  • The Processor is willing to comply with the obligations regarding security and other aspects of the General Data Protection Regulation (hereinafter: “GDPR”), within its capabilities;

  • The GDPR imposes a duty on the Controller to ensure that the Processor provides sufficient guarantees concerning technical and organisational security measures regarding the processing activities to be performed;

  • The GDPR also imposes a duty on the Controller to supervise compliance with those measures;

  • The Parties, in view of the requirement from Article 28(3) of the GDPR, wish to establish their rights and obligations in writing through this Data Processing Agreement (hereinafter: “Data Processing Agreement”);

have agreed as follows

Article 1. Purposes of processing

1.1 The Processor commits to processing personal data on behalf of the Controller under the terms of this Data Processing Agreement. Processing will take place exclusively as part of the Data Processing Agreement to efficiently execute the services for which the Processor was engaged and for those purposes established with further consent.

1.2 The personal data processed by the Processor under the Agreement, and the categories of data subjects from which these originate, are listed in Annex 1. The Processor shall not process personal data for any purpose other than as set by the Controller. The Controller will inform the Processor of the processing purposes if they are not already listed in this Data Processing Agreement.

1.3 The Processor does not have control over the purpose and means of the processing of personal data. The Processor makes no independent decisions on the receipt and use of personal data, the provision to third parties, and the duration of data storage.

1.4 The standard retention period for personal data at the Processor is 76 days, within which the Controller has the option to transfer the data to its own storage. It is the responsibility of the Controller to determine the retention periods for the personal data. If the data is no longer necessary for the purpose for which it was obtained, and there is no other basis to retain it, the Controller will delete the data immediately or instruct the Processor to do so.

Article 2. Obligations of the Processor

2.1 Regarding the processing referred to in Article 1, the Processor will ensure compliance with the conditions set by the GDPR for the processing of personal data by the Processor in its role.

2.2 The Processor will inform the Controller, upon request and within a reasonable period, about the measures it has taken concerning its obligations under this Data Processing Agreement.

2.3 The obligations of the Processor arising from this Data Processing Agreement also apply to those processing personal data under the authority of the Processor.

Article 3. Transfer of personal data

3.1 The Processor may process personal data in countries within the European Union. Processing may also occur in countries outside the European Union, provided that the European Commission has determined that the country in question ensures an adequate level of protection, or that the Processor has concluded an EC Model Contract with the relevant third party outside the European Union, or that the legal conditions for transfer have otherwise been met.

Article 4. Distribution of responsibility

4.1 The authorised processing will be carried out by the Processor within a (semi-) automated environment.

4.2 The Processor is only responsible for processing personal data under this Data Processing Agreement, following the instructions of the Controller and under the express (final) responsibility of the Controller. The Processor is not responsible for all other processing of personal data, including, but not limited to, the collection of data by the Controller, processing for purposes not reported by the Controller to the Processor, processing by third parties and/or for other purposes. The responsibility for these processes lies solely with the Controller.

4.3 The Controller ensures that the content, use and assignment of the personal data processing as intended in this Data Processing Agreement are not unlawful and do not infringe upon any rights of third parties.

Article 5. Involving third parties or subcontractors

5.1 The Controller hereby authorises the Processor to engage third parties for processing personal data under this Data Processing Agreement, subject to applicable privacy legislation.

5.2 Upon request of the Controller, the Processor will inform the Controller as soon as possible about the third parties engaged. The Controller has the right to object to any third party engaged by the Processor. If the Controller objects to the third parties engaged by the Processor, the Parties shall consult each other to reach a solution.

5.3 The Processor ensures that these third parties adopt the same obligations in writing as agreed between the Controller and the Processor. The Processor guarantees proper compliance with these obligations by these third parties and is liable for any errors by these third parties as if it had committed the errors itself.

Article 6. Security

6.1 The Processor will endeavour to take appropriate technical and organisational measures regarding the processing of personal data, to prevent loss or any form of unlawful processing (such as unauthorised access to, alteration, or provision of personal data). The Processor implements the following measures:

  • logical access control

  • purpose-bound access limitation

  • random checks on compliance and functioning of the security policy

  • physical security measures for access control

  • conducting external security audits

  • confidentiality obligation for employees

6.2 The Processor will strive to ensure that the security meets a level that is, considering the state of technology, the sensitivity of personal data, and the costs of implementation, not unreasonable.

6.3 The Controller only makes personal data available to the Processor for processing if it has ensured that the required security measures have been met. The Controller is responsible for the compliance with the measures agreed upon by the Parties.

Article 7. Liability

7.1 The Processor only accepts liability for damages suffered by the Controller to the extent that the Processor is accountable for deficiencies in implementing the security measures agreed upon in the Data Processing Agreement. The liability of the Processor is limited as specified in the Processor's General Terms and Conditions.

7.2 The Processor explicitly does not accept liability for damage to the Controller and/or third parties that occurred because the security measures used were later found not to be adequate or sufficient.

Article 8. Obligation to report

8.1 In case of a data breach (which means a breach of security that accidentally or unlawfully leads to destruction, loss, alteration, or unauthorised disclosure of, or access to transmitted, stored or otherwise processed data), the Processor will use best efforts to inform the Controller thereof promptly or within, at most, forty-eight (48) hours, which will allow the Controller to determine whether to inform supervisory authorities and/or data subjects. The Processor will strive to ensure the information provided is complete, correct and accurate. The obligation to report only applies if the breach has actually occurred, and if there is reasonably a risk to the rights and freedoms of individuals.

8.2 The Controller will ensure compliance with any (legal) reporting obligations. Should the law and/or regulations require this, the Processor will cooperate in informing the relevant authorities and potentially involved parties.

8.3 The obligation to report, in any case, includes reporting the fact that a breach has occurred, as well as:

  • the date on which the breach occurred (if the exact date is not known: the period within which the breach occurred);

  • the (suspected) cause of the breach;)

  • the (suspected) cause of the breach;

  • the date and time at which the breach became known to the Processor or a third party or subcontractor engaged by it;

  • the number of individuals whose data has been leaked (if not an exact number is known: the minimum and maximum number of individuals whose data has been leaked);

  • a description of the group of individuals whose data has been leaked, including the type(s) of personal data leaked;

  • whether the data is encrypted, hashed or otherwise made unintelligible or inaccessible to unauthorised persons;

  • the intended and/or already taken measures to close the breach and limit the consequences of the breach;

  • contact details for following up on the report.

Article 9. Rights of the data subject

9.1 Should a data subject submit a request to exercise their statutory rights to the Processor, the Processor will forward the request to the Controller and inform the data subject thereof. The Controller will then independently handle the request. If it appears that the Controller needs assistance from the Processor for the execution of a data subject’s request, the Processor should be informed. The Processor will handle the request.

Article 10. Confidentiality obligation

10.1 All personal data received by the Processor from the Controller and/or collected by the Processor in the context of this Data Processing Agreement are subject to a duty of confidentiality towards third parties. The Processor shall not use this information for any purpose other than for which it was obtained, unless it is rendered in such a form that it cannot be traced back to the data subject.

10.2 This confidentiality obligation does not apply insofar as the Controller has granted explicit permission to provide the information to third parties, if disclosure of the information to third parties is logically necessary given the nature of the order provided and the execution of this Data Processing Agreement, or if there is a legal obligation to disclose the information to a third party.

10.3 The Processor shall have all employees involved in executing the Agreement sign a confidentiality declaration – whether or not included in the employment contract with those employees – which, in any case, shall include that these employees must observe confidentiality regarding the Personal Data. The Processor shall take measures, such as screening employees and securing data carriers, to ensure compliance with this confidentiality obligation.

Article 11. Audit

11.1 The Controller has the right to have audits conducted by an independent expert bound to confidentiality to verify compliance with all aspects of this Data Processing Agreement.

11.2 This audit will only take place after the Controller has requested and reviewed similar audit reports from the Processor and has provided reasonable arguments that a Controller-initiated audit is still justified. Such an audit is justified when the similar audit reports available at the Processor do not or insufficiently verify compliance with this Data Processing Agreement by the Processor. The Controller-initiated audit will occur two weeks after prior announcement by the Controller, and no more than once a year.

11.3 The Processor shall cooperate with the audit and provide all reasonably relevant information, including supporting data such as system logs and staff, as promptly as possible and within a reasonable timeframe, where a maximum of two weeks is reasonable unless an urgent interest opposes this. The Controller shall ensure that the audit causes as little disruption to the Processor's business activities as possible.

11.4 The findings from the audit shall be assessed in mutual consultation by the Parties and, as a result thereof, may or may not be implemented by one or both Parties together.

11.5 The Controller shall bear the costs for the audit, provided that the costs for the engaged third party shall always be borne by the Controller.

Article 12. Duration and termination

12.1 This Data Processing Agreement is entered into for the duration as specified in the Agreement between the Parties and, in the absence thereof, for at least the duration of the collaboration.

12.2 The Data Processing Agreement cannot be terminated prematurely.

12.3 The Parties may only amend this Data Processing Agreement by mutual written consent.

12.4 Upon termination of the Data Processing Agreement, the Processor shall delete the personal data received from the Controller without delay unless otherwise agreed by the parties.

Article 13. Other provisions

13.1 The Data Processing Agreement and its performance are governed by Dutch law.

13.2 Any disputes arising between the Parties in connection with the Data Processing Agreement shall be submitted to the competent court in the district of the court that is also competent to judge in the framework of the Agreement.

13.3 If one or more provisions of the Data Processing Agreement are found not to be legally valid, the remainder of the Data Processing Agreement shall remain in force. The Parties will then consult on the provisions that are not legally valid to reach an alternative arrangement that is legally valid and aligns as closely as possible with the intent of the provision being replaced.

13.4 If the privacy legislation changes, the parties shall cooperate to amend this Data Processing Agreement to meet this legislation.

13.5 In the event of conflicts between different documents or their annexes, the following hierarchy shall apply:

  1. the Agreement;

  2. this Data Processing Agreement;

  3. the General Terms and Conditions of the Processor;

  4. any additional conditions.

Agreed and approved in this way.

Annex 1: Specification of personal data and data subjects

Personal data

The Processor shall process the following (special) personal data from the individuals addressed by the Processor on behalf of the Controller in the context of the Agreement:

  • Gender

  • Name

  • Phone number

  • Email address

  • Note/message

  • Any other desired data that the Controller wishes within the MyCare environment.

  • Call recordings for training and quality purposes (caller receives a notification that it is being recorded)

The Controller ensures that the personal data and categories of data subjects described in this Annex 1 are complete and correct and indemnifies the Processor for any defects and claims resulting from a incorrect representation by the Controller.

Adjusting, viewing or deleting your data

You have the right to view, adjust or delete your personal data. Send an email to info@contactcare.nl with the subject 'view customer data'. In the email message, indicate as fully as possible which data you want to view and what you want to do with it: adjust or delete.

ContactCare will respond within 30 days. If you wish to delete personal data, we will do so as quickly as possible, unless we are required by law to retain the data or there are other important reasons to retain the data. We will send you a confirmation message. If we do not delete all data, we will explain why we do not.

If it is unclear which data you want to view, adjust or delete, we may ask you to clarify your request. We will only adjust your data after you have provided that clarification.

orange gradient ball

Ready to effectively help your customers?

orange gradient ball

Ready to effectively help your customers?