Data Processing Agreement (DPA)
Controller to Processor Agreement
This agreement is part of HORISEN’s Framework Agreement for its Services and is entered on Effective Date into by and between
HORISEN AG, a company organised and existing under the laws of Switzerland, having its registered office at Hauptstrasse 65, 9400 Rorschach, Switzerland,
hereinafter referred to as “Data Processor”
the other signing contracting party of the Framework Agreement,
hereinafter referred to as “Data Controller”.
Both hereinafter referred to as the “Parties”.
The following terms are defined in addition to the definitions of the Agreement, and those terms shall have the meaning given to them under GDPR, and particularly:
Applicable Law(s)in this Agreement means: each legislation applicable to each party hereto (including regulation and Data Protection Legislation for the avoidance of any doubt).
Data Controllermeans an entity (legal person under this Agreement) which determines the purposes and means of the Processing of Personal Data.
Data Processormeans an entity (legal person under this Agreement) which processes Personal Data on behalf of the controller.
Data Protection Officer (DPO)means a natural person who ensures, in an independent manner, that an organization applies the laws protecting individuals' Personal Data.
Data Subjectmeans the identified or identifiable natural person to whom Personal Data relates as defined by Data Protection Laws and Regulations.
GDPRmeans the EU General Data Protection Regulation (EU) 2016/679, which is a regulation in EU law on data protection and privacy for all individuals within the European Union. It replaces the prior Data Protection Directive (95/46/EC) of 1995.
Personal Datameans any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processingmeans any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Personal Data Breachmeans a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Third Party Contractorsmeans companies currently engaged by Data Processor which are listed at Third Party Contractors.
Sub-Processormeans a third party engaged by Data Processor that is processing Data Controller’s Personal Data for a specific purpose.
Party(ies)means the entity signing this Agreement.
HORISEN Groupmeans an economic entity formed of a set of companies which are listed at horisen-group.
Data Controller and Data Processor signed a Framework Agreement for the provision of HORISEN’s Services (‘’Framework Agreement’’) pursuant to which the Data Processor must perform Services as may be ordered by Data Controller.
In order to fulfil the requirements of the Data Protection Legislation pertaining to the Framework Agreement, the Parties now wish to additionally enter into this Controller-to-Processor Agreement (“Agreement”).
The construction of the capitalized terms used in this Agreement are to be primarily construed as defined in the Framework Agreement and if not capitalized herein or not defined in the Framework Agreement or in this Agreement, with the meaning that could be reasonably attributed to those terms by the Parties.
The Data Controller processes its Personal Data as well as Personal Data of other entities of the Data Controller group of companies.
The Data Controller wishes to outsource to the Data Processor certain processing procedures with respect to such Data Processor and the Data Processor is willing to supply such processing services to the Data Controller on the terms and conditions contained in this Agreement.
The signature of this Agreement does not create any obligation to transfer any processing activity from the Data Controller or any Data Controller Company to the Data Processor. The signature of any Order pursuant to the Framework Agreement may trigger the processing of Personal Data by Data Processor in which case such activities shall be governed by this Agreement and the applicable terms and conditions of the Framework Agreement.
This Agreement is incorporated into the Framework Agreement and the Framework Agreement shall fully apply to and prevail over this Agreement unless a term or condition of this Agreement expressly deviates from the Framework Agreement in which case such deviating term or condition shall apply for this Agreement only.
NOW IT IS AGREED AS FOLLOWS
For the avoidance of any doubt, the recitals of this Agreement are part of this Agreement. Any breach of this Agreement by Data Processor shall be construed as a material breach of the Framework Agreement, and liability (if any) of the Data Processor shall be governed by the terms and conditions of the Framework Agreement.
The Data Controller and the Data Processor each must always comply with Applicable Laws and the provisions of this Agreement.
NATURE AND PURPOSE OF THE PERSONAL DATA PROCESSING
1.1 Processing of the Personal Data consists of storing of the Personal Data, its processing for the purpose of providing Services defined in the Framework Agreement and processing for the purpose of providing the Support based on the other Party’s request.
1.2 The purposes for which the Personal Data shall be processed is for providing services to Data Controller, related to horisen.pro platform including all applications and services, which are determined by Framework Agreement.
1.3 Personal Data that Data Processor processes for the purpose of providing Services defined in the Framework Agreement are deemed confidential, in accordance with the Confidentiality and Non-disclosure Agreement signed by both Parties.
RIGHTS AND OBLIGATIONS OF THE DATA CONTROLLER
2.1 The Data Controller has the right and obligation to make decisions about the purposes and means of the Processing of Personal Data.
2.2 The Data Controller shall be responsible, among other, to ensure that the Processing of Personal Data, which the Data Processor is instructed to perform, has a legal basis.
2.3 The Data Controller shall be responsible for ensuring that the Processing of Personal Data takes place in compliance with the Applicable Laws.
2.4 The Data Controller shall transfer to the Data Processor only Personal Data obtained in compliance with the relevant provisions of the applicable Data Protection Legislation for the purposes stated in this Agreement.
2.5 The Data Controller shall keep up to date and correct all Personal Data transferred to the Data Processor whenever required in particular as set out by the relevant provisions of the applicable Data Protection Legislation.
2.6 The Data Controller is solely obliged to provide Data Subjects with all information and explanations as required under Applicable Laws. As between Data Processor and Data Controller, the Data Controller is also solely responsible for dealing with Data Subjects in relation to their rights to access their respective data in accordance with Applicable Laws.
OBLIGATIONS OF THE DATA PROCESSOR
3.1 The Data Processor shall process the Personal Data on behalf of the Data Controller pursuant to the written instructions of the Data Controller in accordance with Applicable Laws and the terms and conditions set forth in the Agreement.
3.2 The Data Processor shall correct, modify, block or erase (as instructed by the Data Controller) any Personal Data processed by Data Processor in case it is not possible for the Data Controller to do so.
3.3 The Data Processor warrants and represents that it has implemented (and shall maintain during the term of this Agreement and as long as required by Laws) the technical and organizational security measures for the protection of Personal Data before processing the Personal Data which are transferred, and additional security measures as mutually agreed by the Data Processor and the Data Controller in an Order. Data Processor has been adopting security measures. All of organizational and technical measures are applied in accordance with appropriate information security (e.g. ISO 27001) practices and GDPR requirements.
3.4 The Data Processor shall not less than once per calendar year test implemented measures.
3.5 In order to ensure compliance with such security measures, the Data Processor shall permit the Data Controller to conduct periodic inspections of its premises and the implemented security measures during usual business hours. The Data Controller shall provide the Data Processor with reasonable (but in no event less than thirty  days) advance notice of each inspection.
3.6 The Data Processor must ensure that its personnel engaged in the processing of Personal Data comply and shall always comply with the data secrecy requirements.
3.7 The Data Processor shall only allow access to the Personal Data to its staff or consultants where and to the extent that such access is required for the performance of the Services and subject to such staff and consultants having entered into an adequate non-disclosure agreement.
3.8 In the event that the Data Processor shall discover that the Data Controller is in breach of any of its obligations provided by the relevant Data Protection Legislation, the Data Processor shall without delay notify the Data Controller of this fact and suspend the performance of the suspected infringing processing until such time as the breach is remedied.
3.9 The Data Processor undertakes to inform the Data Controller without delay about any complaints, requests or other communications received by it from data subjects, data protection regulator(s) or third parties related to the processing of Personal Data by the Data Processor and/or the Data Controller.
3.10 The Data Processor shall immediately inform the Data Controller if instructions given by the Data Controller, in the opinion of the Data Processor, contravene the APPLICABLE LAWS.
3.11 The Data Processor must always comply with this Agreement.
ASSISTANCE TO THE DATA CONTROLLER
4.1 Taking into account the nature of the Processing, the Data Processor shall assist the Data Controller in the fulfilment of the Data Controller’s obligations to respond to requests for exercising the Data Subject’s rights laid in the Applicable Laws.
4.2 The Data Processor shall assist the Data Controller in ensuring compliance with:
a) the Data Controller’s obligation to, without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the Personal Data Breach to the competent supervisory authority, unless the Personal Data Breach is unlikely to result in a risk to the rights and freedoms of natural persons;
b) the Data Controller’s obligation to without undue delay communicate Personal Data Breach to the Data Subject, when the Personal Data Breach is likely to result in a high risk to the rights and freedoms of Data Subject;
c) the Data Controller’s obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of Personal Data (a data protection impact assessment).
PERSONAL DATA BREACHES AND REPORTING PROCEDURES
5.1 The Data Processor is under a strict obligation to immediately notify the Data Controller of any Personal Data Breach and no later than within 24 hours of the Data Processor becoming aware of the breach, to enable the Data Controller to comply with the Data Controller’s obligation to notify the Personal Data Breach to competent supervisory authority.
5.2 The Data Controller is under obligation to without due delay communicate the Personal Data Breach to the Data Subject, when the Personal Data Breach is likely to result in a high risk to the rights and freedoms of Data Subject.
5.3 The Data Processor agrees to provide any reasonable assistance as is required by the Data Controller or the Data Protection Authority to facilitate the handling of any Personal Data Breach in an expeditious and compliant manner.
5.4 In respect of any Personal Data Breach, Data Processor shall provide the following details regarding the Personal Data Breach to the Data Controller:
a) the description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subject concerned as well as categories and an estimated number of Personal Data records concerned;
b) name and contact details of the Data Protection Officer (DPO) or other contact point for further relevant inquires;
c) the description of the likely consequences of the Personal Data Breach;
d) the description of the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
RETENTION PERIOD AND LIQUIDATION OF PERSONAL DATA
6.1 The Personal Data shall be retained by the Data Processor in order to perform the Services for the time periods as defined by Data Controller and in any case no longer than what is strictly necessary for the Data Processor to (i) process the Personal Data in line with this Agreement or (ii) as the case may be, to meet any of its legal obligations (in particular statutory archival and retention obligations).
6.2 Subject to any legal obligations or request from Data Controller to archive or retain Personal Data, at the request of the Data Controller, the Data Processor shall carry out the liquidation of any or all the Personal Data without undue delay after all the specific purposes for which the Personal Data were processed cease to exist or upon receipt of a written request of the Data Controller.
6.3 On the instructions of the Data Controller, the Data Processor shall ensure that the Personal Data processed under this Agreement are returned to the Data Controller or destroyed in accordance with the Data Controller’s instructions. If those instructions are not in contradiction with Applicable Laws. The Data Controller reserves the right to issue instructions to the Data Processor under this Clause at any time. In case, that instructions are not in accordance with Applicable Laws, Applicable Laws shall prevail.
6.4 Following the deletion of Personal Data under this clause, the Data Processor shall notify the Data Controller that the Personal Data in question has been deleted. Where applicable, the Data Processor shall also provide confirmation that the Personal Data has been destroyed in accordance with any instructions issued by the Data Controller, if those instructions are not in contradiction with Applicable Laws. In case, that instructions are not in accordance with Applicable Laws, Applicable Laws shall prevail.
7.1 The Data Processor agrees to maintain records of all Personal Data processed under the Agreement and its processing activities. The Data Controller reserves the right to inspect the records maintained by the Data Processor under this clause at any time, with reasonable (but in no event less than 30 days) advance notice of each inspection.
7.2 If Data Subject in any case requires information from Data Controller on subject of what type of that subject’s Personal Data is being processed under this Agreement, and if Data Controller is not able to provide this type of information without Data Processor’s help, Data Processor is obliged to provide any reasonable help.
7.3 The records shall be in writing, including in electronic form.
7.4 The Data Controller or Data Processor and, where applicable, the Data Controller or the Data Processor’s representative, shall make the record available to the supervisory authority on request.
7.5 The Data Controller reserves the right to inspect the records maintained by the Data Processor under this clause at any time, with reasonable (but in no event less than 30 days) advance notice of each inspection.
7.6 If Data Subject in any case requires information from Data Controller on subject of what type of that subject’s Personal Data is being processed under this Agreement, and if Data Controller is not able to provide this type of information without Data Processor’s help, Data Processor is obliged to provide any reasonable help.
8.1 The Data Processor shall only grant access to the Personal Data being processed on behalf of the Data Controller to persons under the Data Processor’s authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality and only on a need-to-know basis. The list of persons to whom access has been granted shall be kept under periodic review. Based on this periodic review, such access to Personal Data can be withdrawn, if access is no longer necessary and Personal Data shall consequently not be accessible anymore to those persons.
8.2 The Data Processor shall at the request of the Data Controller demonstrate that the concerned persons under the Data Processor’s authority are subject to the above-mentioned confidentiality.
9.1 In order to provide services, to the standard required by the client (Data Controller) as agreed in the Framework Agreement, Data Processor might engage companies from HORISEN Group. All members of HORISEN Group have the same information security policies and procedures established in accordance with ISO 27001 standard and data protection policies and procedures in accordance with GDPR requirements. By signing this Agreement Data Controller agrees that other members of HORISEN Group are considered as Sub-Processors.
9.2 By signing this Agreement Data Controller agrees that Data Processor may at any time engage another processor, which should be considered as a Sub-Processor, but in that case Data Controller must be informed by Data Processor about addition or replacement of Sub-Processors. Data Processor should make sure there is signed Data Processing Agreement, between Data Processor and Sub-Processor, in place and that any engaged Sub-Processor at least complies with the obligations to which the Data Processor is subject pursuant to this Data Processing Agreement and the applicable legislation. Data Controller reserves the right to object to these changes. Data Processor reserves the right to engage telecom provider or third-party telecom supplier for providing services that require their engagement (e.g. SMS or voice traffic).
9.3 Third Party Contractors are only engaged in website analytics and internally used tools and non of them is engaged as sub-processor and they are not processing any of our customer's data.
9.4 Data Processor shall store Personal Data originating from and sent to a country located in the EU/EEA or Switzerland solely in countries situated in the EU/EEA or Switzerland and not cause any cross-border transfer of Personal Data from a country situated in the EU/EEA or Switzerland to any country situated outside the EU/EEA or Switzerland unless it is requested specifically by Data Controller.
DATA CONTROLLER’S RIGHTS TO MONITOR AND AUDIT DATA PROCESSOR
10.1 In addition to the monitoring and/or audit rights set out in the Agreement, the Data Controller is entitled to proceed to any and all verifications (including on the Data Processor’s site(s)) during usual business hours provided the Data Controller gives reasonable (but in any event no less than 30 days’) prior written notice to the Data Processor.
10.2 The Data Processor shall duly and promptly cooperate with the Data Controller, upon request of the Data Controller, by giving access to all the documents, infrastructures, premises, information and/or staff reasonably required by the Data Controller to ensure such Data Processing is compliant with this Agreement.
10.3 The costs and consequences of the monitoring and audits shall be borne by the Data Controller including support costs.
TRANSFER OF DATA
11.1 Any transfer of Personal Data by the Data Processor shall be performed only within the companies belonging to the HORISEN GROUP and only for the purpose of providing the services defined in the Framework Agreement.
11.2 Transfer of Personal Data shall be made only upon Data Controller’s request for the purpose of providing it the requested Support.
12.1 Any notice or other communication which is given under this Agreement to a Party will be addressed and sent to that Party at the address as specified in Framework Agreement, or at any other address as otherwise notified to the other Party (including for the avoidance of doubt in a Statement of Work).
12.2 For data privacy and security related questions and concerns Data Controller should contact Data Processor’s DPO.
CHANGES TO APPLICABLE LAW
13.1 In case the applicable data protection and Applicable Laws change in a way that the Agreement is no longer adequate for the purpose of governing lawful data sharing exercises, the Parties will amend the Agreement. In such circumstances, the Data Processor agrees to implement any changes to its processing activities as are necessary to comply with the amended terms of the Agreement.
14.1 This Agreement is entered into as of its Effective Date and for the whole term of the Agreement. For the avoidance of any doubt, it will follow the term of the Framework Agreement and shall be automatically terminated whenever the Framework Agreement is terminated or expired. Termination or expiry of this Agreement shall not terminate the Framework Agreement.
14.2 In addition, the Data Controller may terminate this Agreement with a 30 days prior notice to the Data Processor without any termination fees or penalty.
14.3 This Agreement constitutes the entire agreement between the Parties with respect to the subject matter contained herein.
14.4 This Agreement may be altered or supplemented only in writing and provided any such amendment is signed by the duly authorized representatives of both Parties.
14.5 If any provision of this Agreement is held invalid, illegal, or unenforceable for any reason, such provision shall be severed, and the remainder of the provisions hereof shall continue in full force and effect as if this Agreement has been executed with the invalid, illegal or unenforceable provision eliminated, and the Parties shall rapidly discuss and amend the Agreement with a valid, legal and enforceable provision.
14.6 This Agreement is governed by the laws of Switzerland and GDPR, without regard to their conflicts of law principles.
Last update: 24th of January, 2022.