Data Processing Agreement

Definitions

  • Controller: A Dattico customer who has a hosting contract, collects and manages personal data in order to process and use them.
  • Processor: Dattico, which processes personal data on behalf of the Controller.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Special Categories of Data: Data revealing racial or ethnic origin, political opinions, religious beliefs, or other sensitive information as defined by the GDPR.

Purpose of the Agreement

Dattico processes personal data exclusively on behalf of the Controller for:

  1. Hosting and related services.
  2. Data management as defined in Annex 1.
  3. Ensuring compliance with GDPR and applicable data protection laws.

Dattico does not process data for its purposes or for third parties without prior written consent from the Controller.

Processor Obligations

  1. Confidentiality: Dattico ensures strict confidentiality of all personal data.
  2. Security Measures: Organizational and technical measures are implemented to protect the data, including encryption, access control, and backup systems.
  3. Data Breaches: Dattico will notify the Controller without undue delay in the event of any data breach.
  4. Sub-Processing: Third-party access to personal data will only occur with prior written consent, as outlined in Annex 1.
  5. Audit Rights: The Controller may audit Dattico’s compliance with this Agreement upon reasonable notice.

Controller Obligations

  1. Ensure that all personal data provided to Dattico is lawfully obtained.
  2. Notify Dattico of any changes to the scope of processing as outlined in Annex 1.
  3. Ensure that all processing activities comply with GDPR requirements.

Data Transfer

  • Personal data will not be transferred outside the European Economic Area unless adequate protections are in place and approved by the Controller.
  • Transfers requiring Standard Contractual Clauses will be implemented as necessary.

Termination and Data Return

Upon termination of services:

  • Dattico will return or delete all personal data as requested by the Controller.
  • Any retained data will be stored only as required by law.

Governing Law

This Agreement is governed by Belgian law. Disputes will be resolved exclusively in the competent courts of Belgium.

Contact Information

For inquiries related to this Agreement or data processing activities: