Legal CentreDocument
Data Processing Addendum
Draft status and how to incorporate
#This DPA becomes effective between Prodia Systems Limited (as processor) and the customer (as controller) only on execution of an order form or master agreement that expressly incorporates it. Where the customer acts as a processor to a third party controller, the customer represents that it has authority to enter this DPA on the controller's behalf.
Definitions
#Terms defined in the GDPR have the meaning given in the GDPR. Terms defined in the Platform and Console Terms have the meaning given there. "Customer Personal Data" means personal data contained in Customer Inputs or Outputs and processed by Prodia Systems Limited on behalf of the customer.
Subject matter, duration, nature and purpose
#The subject matter is the processing of Customer Personal Data by Prodia Systems Limited to provide the Verinex platform to the customer. The duration is the term of the underlying agreement, plus any post-termination period during which processing is required. The nature and purpose of processing are those necessary to provide, secure and support the Verinex platform for the customer. The types of personal data and categories of data subjects are those submitted by or on behalf of the customer.
Roles of the parties
#The customer is the controller of Customer Personal Data. Prodia Systems Limited acts as processor on the customer's behalf for Customer Personal Data, and as controller for other personal data described in the Privacy Notice, including account administration and security telemetry.
Processing on documented instructions
#Prodia Systems Limited will process Customer Personal Data only on the documented instructions of the customer, including as set out in the underlying agreement, the customer's configuration of the Verinex platform, and any additional written instructions given from time to time, unless required to process by applicable law. Where such law applies, Prodia Systems Limited will inform the customer before processing unless the law prohibits such notice.
Confidentiality of personnel
#Prodia Systems Limited will ensure that personnel authorised to process Customer Personal Data are subject to appropriate obligations of confidentiality.
Security of processing
#Prodia Systems Limited will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, including the measures summarised in the Security and Trust statement as updated from time to time.
Subprocessors
#The customer provides a general authorisation for the engagement of subprocessors, subject to notice of intended changes and the right to object on reasonable data-protection grounds. Current subprocessors are listed in the Subprocessor Register. Prodia Systems Limited will impose on each subprocessor data-protection obligations that are no less protective than those set out in this DPA.
Assistance with data subject rights
#Taking into account the nature of processing, Prodia Systems Limited will assist the customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligations to respond to requests for exercising data subject rights.
Assistance to the controller
#Taking into account the nature of processing and the information available to it, Prodia Systems Limited will assist the customer in ensuring compliance with the obligations under Articles 32 to 36 of the GDPR.
Personal data breach notification
#Prodia Systems Limited will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, providing such information as is reasonably available at the time and updating the customer as further information becomes known.
Deletion and return of data
#On termination or expiry of the underlying agreement, Prodia Systems Limitedwill, at the customer's choice, delete or return Customer Personal Data unless applicable law requires storage of the personal data.
Audits and inspections
#Prodia Systems Limited will make available to the customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the customer or another auditor mandated by the customer, on reasonable prior notice and subject to appropriate confidentiality obligations. Frequency, scope and cost of audits will be as agreed in the order form.
International transfers
#Where Prodia Systems Limited transfers Customer Personal Data outside the European Economic Area, it will do so on the basis of an appropriate transfer mechanism under Chapter V of the GDPR, including standard contractual clauses where applicable, and will implement supplementary measures where required. Details of specific transfers will be reflected in the Subprocessor Register.
Liability and indemnity
#Liability under this DPA is governed by the underlying agreement, including any agreed liability cap and carve-outs.
Governing law and jurisdiction
#This DPA is governed by the laws of Ireland and is subject to the exclusive jurisdiction of the courts of Ireland, without prejudice to mandatory rules of the GDPR and applicable national data-protection law.
Contact
#Operator
Prodia Systems Limited
Public brand: Verinex — https://verinex.dev
Registered office
Pending verification
Company number
Pending verification
VAT number
Pending verification
Privacy contact
Pending verification