DATA PROCESSING AGREEMENT
Version 1.0
This Data Processing Agreement („DPA“) forms part of and supplements the agreement governing the use of the Andrea360 platform and related services (the „Services“) provided by Andrea Technologies DOO Novi Sad, Republic of Serbia („Andrea Technologies,“ „Processor“) to the customer identified in the applicable service agreement („Customer,“ „Controller“).
This DPA sets out the terms under which Andrea Technologies processes Personal Data on behalf of the Customer in connection with the provision of the Services.
1. DEFINITIONS
For the purposes of this DPA:
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means the entity that processes Personal Data on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable natural person.
Customer Data means any data, including Personal Data, submitted, uploaded, stored, transmitted, or otherwise processed through the Services by or on behalf of the Customer.
Data Subject means an identified or identifiable natural person whose Personal Data is processed.
Applicable Data Protection Laws means all applicable laws and regulations relating to privacy, data protection, and the processing of Personal Data, including the General Data Protection Regulation (EU) 2016/679 („GDPR“), where applicable.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
2. SCOPE AND PURPOSE OF PROCESSING
Andrea Technologies shall process Personal Data solely for the purpose of providing, maintaining, securing, supporting, and improving the Services in accordance with the Customer’s documented instructions and the terms of the applicable agreement.
Andrea Technologies shall not sell, disclose, or transfer Customer Data containing Personal Data to third parties except as required to provide the Services or comply with applicable law.
Aggregated, anonymized, de-identified, and non-identifiable information derived from Customer Data may be used by Andrea Technologies for analytics, benchmarking, reporting, research, artificial intelligence, machine learning, service improvement, product development, and other lawful business purposes, provided such information cannot reasonably identify any individual or Customer.
3. ROLES OF THE PARTIES
The parties acknowledge and agree that:
– The Customer acts as the Controller.
– Andrea Technologies acts as the Processor.
The Customer determines the purposes and means of processing Personal Data through the Services.
Andrea Technologies processes Personal Data solely on behalf of the Customer and in accordance with this DPA.
4. CATEGORIES OF DATA SUBJECTS
Depending on how the Customer uses the Services, Data Subjects may include:
– Members and customers of the Customer;
Prospective customers and leads;
Employees, instructors, trainers, contractors, and representatives of the Customer;
Individuals whose Personal Data is uploaded or entered into the Services by the Customer.
5. CATEGORIES OF PERSONAL DATA
Depending on the Customer's use of the Services, Personal Data may include:
First name;
– Last name;
Email address;
– Phone number;
– Date of birth;
Gender;
– Address;
Profile pictures;
– Membership and subscription information;
– Booking and attendance records;
– Purchase and transaction records;
– RFID card identifiers;
– Employee information;
– Documents and attachments uploaded by the Customer;
– Any other Personal Data submitted through the Services by the Customer.
6. CUSTOMER RESPONSIBILITIES
The Customer is solely responsible for:
– Determining the lawful basis for processing Personal Data;
– Obtaining any necessary consents;
– Providing privacy notices where required;
– Ensuring that Personal Data entered into the Services is processed in accordance with Applicable Data Protection Laws.
The Customer represents and warrants that it has all rights, permissions, and legal bases necessary for Andrea Technologies to process Personal Data in accordance with this DPA.
The Customer acknowledges that documents, attachments, and files uploaded to the Services may contain sensitive or special categories of personal data. The Customer is solely responsible for determining whether such uploads are lawful and for obtaining any required consents, notices, authorizations, or legal bases for such processing.
7. CONFIDENTIALITY
Andrea Technologies shall ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
Access to customer data by Andrea Technologies personnel shall be limited to individuals who require such access for the provision, maintenance, support, security, or improvement of the Services.
8. SECURITY MEASURES
Andrea Technologies maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Such measures may include:
– Secure authentication mechanisms;
Password hashing;
Role-based access controls;
Encryption of data in transit using TLS;
– Monitoring and logging systems;
– Regular backup procedures;
– Security updates and maintenance practices.
Andrea Technologies may modify or enhance its security measures from time to time, provided that such modifications do not materially reduce the overall level of protection.
9. SUBCONTRACTORS
The Customer authorizes Andrea Technologies to engage subprocessors as reasonably necessary for the provision of the Services.
Current subprocessors may include:
Subprocessor and purpose:
- Hetzner – Hosting infrastructure and storage
- Firebase – Mobile services and notifications
- OneSignal – Push Notifications
- Postmark – Delivery of transactional emails
- Stripe – Payment processing (when enabled by Customer)
- Payspot – Payment processing (when enabled by Customer)
- Google Analytics – Usage Analytics
Andrea Technologies may engage additional subprocessors from time to time as reasonably required for operation and improvement of the Services.
Andrea Technologies shall use reasonable efforts to ensure that subprocessors engaged in connection with the Services provide an appropriate level of protection for Personal Data.
10. PERSONAL DATA BREACHES
Andrea Technologies shall notify the Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a Personal Data Breach affecting Customer Data.
Such notification shall include information reasonably available to Andrea Technologies regarding:
The nature of the incident;
– The categories of data affected;
– The likely consequences of the incident;
– Measures taken or proposed to address the incident.
11. INTERNATIONAL DATA TRANSFERS
Andrea Technologies shall not intentionally transfer Personal Data outside of jurisdictions permitted under Applicable Data Protection Laws unless appropriate safeguards are implemented.
12. DATA EXPORT
Upon request and prior to termination of the Services, the Customer may obtain a copy of Customer Data in a commonly used electronic format.
Andrea Technologies will make commercially reasonable efforts to provide such export.
Exported data may include, where applicable:
Members;
– Employees;
Memberships;
– Attendance records;
Sales records;
– Other Customer Data maintained through the Services.
13. DATA RETENTION AND DELETION
Following termination of the applicable agreement, Andrea Technologies may retain Customer Data for a transitional period not exceeding one hundred eighty (180) days.
After such period, Customer Data shall be deleted or permanently anonymized unless retention is required by applicable law.
The customer is responsible for requesting any required data exports before the expiration of the retention period.
The Customer is responsible for requesting any desired export of Customer Data before the expiration of the retention period.
14. AUDIT RIGHTS
Upon reasonable written request, the Customer may request information regarding Andrea Technologies’ security and privacy practices relevant to the Services.
Any audit, assessment, or review requested by the Customer shall:
Be reasonable in scope;
– Not to unreasonably interfere with Andrea Technologies’ operations;
– Be subject to confidentiality obligations;
– Be conducted no more than once per calendar year unless required by law.
15. LIABILITY
The parties' liability arising under this DPA shall be subject to the limitations of liability set forth in the applicable service agreement, unless prohibited by applicable law.
16. TERM
This DPA shall remain in effect for as long as Andrea Technologies processes Personal Data on behalf of the Customer.
17. USE OF ANONYMIZED INFORMATION
Nothing in this DPA shall restrict Andrea Technologies from creating, generating, analyzing, using, publishing, licensing, or otherwise commercializing aggregated, anonymized, de-identified, or non-identifiable information derived from Customer Data, provided that such information cannot reasonably identify any individual, Customer, or business operation.
18. GOVERNING LAW
This DPA shall be governed by and construed in accordance with the laws of the Republic of Serbia.
19. CONTACT INFORMATION
Questions regarding this DPA or privacy matters may be directed to:
Andrea Technologies DOO Novi Sad
Email: support@andrea360.com