Introduction
This data processing agreement (verwerkersovereenkomst) (hereinafter: "Agreement") forms part of the hosting services supplied by Webosa. In supplying those services, Webosa processes personal data on behalf of and by order of the customer. In this relationship, the customer is the controller and Webosa is the processor within the meaning of the General Data Protection Regulation (GDPR/AVG). This Agreement sets out the arrangements that are mandatory under Article 28 GDPR.
1. Roles and definitions
- Controller (verwerkingsverantwoordelijke): the customer, who determines which personal data is processed via Webosa's services and for what purpose.
- Processor (verwerker): Webosa, which processes personal data exclusively by order of the customer, in accordance with the customer's instructions.
- Personal data: any information about an identified or identifiable natural person that is processed via the services (for example data in the customer's website, mailboxes or databases).
- Sub-processor: a third party engaged by Webosa that processes personal data in the context of the services.
2. Subject matter, nature and purpose of the processing
- Nature and purpose: the supply of hosting, e-mail, VPS, storage and related services, including storage, backup, security and technical management.
- Type of personal data: depending on what the customer itself processes via the services, for example name, contact details, IP addresses, account data and the content of messages.
- Categories of data subjects: the customers, users and business relations of the controller.
- Duration: for as long as the underlying agreement and the services are in effect (see article 8).
3. Instructions and confidentiality
- Webosa processes personal data exclusively on the basis of written or electronic instructions from the customer, unless a legal obligation requires otherwise. In the latter case, Webosa informs the customer in advance, unless the law prohibits this.
- Webosa does not process personal data for its own purposes.
- All persons processing personal data under Webosa's authority are bound by a duty of confidentiality.
4. Security (Article 32 GDPR)
Webosa takes appropriate technical and organisational measures to secure personal data against loss or unlawful processing. These include, among others: encrypted connections (TLS/SSL), access management, separated environments, daily backups, monitoring and a certified data centre (ISO 27001, ISAE 3402). The level of security is aligned with the nature of the data and the state of the art.
5. Sub-processors
- The customer grants Webosa general authorisation to engage sub-processors that are necessary for the provision of the services (such as data centre, network and security partners).
- Webosa imposes on sub-processors at least the same obligations as those set out in this Agreement.
- A current overview of sub-processors is available on request. In the event of an intended change, the customer may object.
6. Transfers outside the EEA
Webosa processes personal data in principle within the European Economic Area (EEA). If a transfer to a country outside the EEA takes place, this only happens with a valid transfer mechanism, such as the standard contractual clauses adopted by the European Commission (Standard Contractual Clauses).
7. Assistance, data breaches and rights of data subjects
- Webosa notifies the customer without undue delay, and at the latest within 48 hours of discovery, of a data breach concerning the customer's personal data, with the information the customer needs in order to comply with its own notification obligation.
- Webosa provides the customer with reasonable assistance with requests from data subjects (access, rectification, erasure, objection) and with security, notification and DPIA obligations.
8. Term, return and deletion
- This Agreement applies for as long as Webosa processes personal data by order of the customer.
- After the services end, Webosa deletes the personal data or returns it, at the customer's choice, unless a statutory retention obligation requires otherwise. Deleted data is unrecoverable; the customer is itself responsible for securing its data in good time.
9. Audit
The customer may, at most once a year and after reasonable notice, have compliance with this Agreement verified, for example on the basis of certifications, audit reports or an investigation by an independent expert, without unnecessarily disrupting Webosa's business operations.
10. Applicable law
This Agreement is governed by Dutch law. In the event of a conflict with the general terms and conditions (algemene voorwaarden), this Agreement prevails on the point of data protection.
¿Preguntas sobre este documento? Póngase en contacto con nosotros.
Nuestro centro de datos cuenta con las certificaciones ISO 27001, ISAE 3402, NEN 1010 y NEN 3140.