Andrea360

DATA PROCESSING AGREEMENT

Version 1.0

This Data Processing Agreement („DPA“) forms part of and supplements the agreement governing the use of the Andrea360 platform and related services (the „Services“) provided by Andrea Technologies DOO Novi Sad, Republic of Serbia („Andrea Technologies“, „Processor“) to the customer identified in the applicable service agreement („Customer“, „Controller“).

This DPA sets out the terms under which Andrea Technologies processes Personal Data on behalf of the Customer in connection with the provision of the Services.

1. DEFINITIONS

For the purposes of this DPA:

Controller means the entity that determines the purposes and means of processing Personal Data.

Processor means the entity that processes Personal Data on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable natural person.

Customer Data means any data, including Personal Data, submitted, uploaded, stored, transmitted, or otherwise processed through the Services by or on behalf of the Customer.

Data Subject means an identified or identifiable natural person whose Personal Data is processed.

Applicable Data Protection Laws means all applicable laws and regulations relating to privacy, data protection, and the processing of Personal Data, including the General Data Protection Regulation (EU) 2016/679 („GDPR“), where applicable.

Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. SCOPE AND PURPOSE OF PROCESSING

Andrea Technologies shall process Personal Data solely for the purpose of providing, maintaining, securing, supporting, and improving the Services in accordance with the Customer’s documented instructions and the terms of the applicable agreement.

Andrea Technologies shall not sell, disclose or transfer Customer Data containing Personal Data to third parties except as required to provide the Services or comply with applicable law.

Aggregated, anonymized, de-identified and non-identifiable information derived from Customer Data may be used by Andrea Technologies for analytics, benchmarking, reporting, research, artificial intelligence, machine learning, service improvement, product development and other lawful business purposes, provided such information cannot reasonably identify any individual or Customer.

3. ROLES OF THE PARTIES

The parties acknowledge and agree that:

– The Customer acts as the Controller.

– Andrea Technologies acts as the Processor.

The Customer determines the purposes and means of processing Personal Data through the Services.

Andrea Technologies processes Personal Data solely on behalf of the Customer and in accordance with this DPA.

4. CATEGORIES OF DATA SUBJECTS

Depending on the Customer’s use of the Services, Data Subjects may include:

– Members and customers of the Customer;

– Prospective customers and leads;

– Employees, instructors, trainers, contractors, and representatives of the Customer;

– Individuals whose Personal Data is uploaded or entered into the Services by the Customer.

5. CATEGORIES OF PERSONAL DATA

Depending on the Customer’s use of the Services, Personal Data may include:

– First name;

– Last name;

– Email address;

– Telephone number;

– Date of birth;

– Gender;

– Address;

– Profile photographs;

– Membership and subscription information;

– Booking and attendance records;

– Purchase and transaction records;

– RFID card identifiers;

– Employee information;

– Documents and attachments uploaded by the Customer;

– Any other Personal Data submitted through the Services by the Customer.

6. CUSTOMER RESPONSIBILITIES

The Customer is solely responsible for:

– Determining the lawful basis for processing Personal Data;

– Obtaining any necessary consents;

– Providing privacy notices where required;

– Ensuring that Personal Data entered into the Services is processed in accordance with Applicable Data Protection Laws.

The Customer represents and warrants that it has all rights, permissions, and legal bases necessary for Andrea Technologies to process Personal Data in accordance with this DPA.

The Customer acknowledges that documents, attachments, and files uploaded to the Services may contain sensitive or special categories of personal data. The Customer is solely responsible for determining whether such uploads are lawful and for obtaining any required consents, notices, authorizations, or legal bases for such processing.

7. CONFIDENTIALITY

Andrea Technologies shall ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

Access to Customer Data by Andrea Technologies personnel shall be limited to individuals who require such access for the provision, maintenance, support, security, or improvement of the Services.

8. SECURITY MEASURES

Andrea Technologies maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Such measures may include:

– Secure authentication mechanisms;

– Password hashing;

– Role-based access controls;

– Encryption of data in transit using TLS;

– Monitoring and logging systems;

– Regular backup procedures;

– Security updates and maintenance practices.

Andrea Technologies may modify or enhance its security measures from time to time, provided that such modifications do not materially reduce the overall level of protection.

9. SUBPROCESSORS

The Customer authorizes Andrea Technologies to engage subprocessors as reasonably necessary for the provision of the Services.

Current subprocessors may include:

Subprocessor and purpose:

  1. Hetzner – Hosting infrastructure and storage
  2. Firebase – Mobile services and notifications
  3. OneSignal – Push notifications
  4. Postmark – Transactional email delivery
  5. Stripe – Payment processing (when enabled by Customer)
  6. Payspot – Payment processing (when enabled by Customer)
  7. Google Analytics – Usage analytics

Andrea Technologies may engage additional subprocessors from time to time as reasonably required for operation and improvement of the Services.

Andrea Technologies shall use reasonable efforts to ensure that subprocessors engaged in connection with the Services provide an appropriate level of protection for Personal Data.

10. PERSONAL DATA BREACHES

Andrea Technologies shall notify the Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a Personal Data Breach affecting Customer Data.

Such notification shall include information reasonably available to Andrea Technologies regarding:

– The nature of the incident;

– The categories of affected data;

– The likely consequences of the incident;

– Measures taken or proposed to address the incident.

11. INTERNATIONAL DATA TRANSFERS

Andrea Technologies shall not intentionally transfer Personal Data outside jurisdictions permitted under Applicable Data Protection Laws unless appropriate safeguards are implemented.

12. DATA EXPORT

Upon request and prior to termination of the Services, the Customer may obtain a copy of Customer Data in a commonly used electronic format.

Andrea Technologies shall make commercially reasonable efforts to provide such export.

Exported data may include, where applicable:

– Members;

– Employees;

– Memberships;

– Attendance records;

– Sales records;

– Other Customer Data maintained through the Services.

13. DATA RETENTION AND DELETION

Following termination of the applicable agreement, Andrea Technologies may retain Customer Data for a transitional period not exceeding one hundred eighty (180) days.

After such period, Customer Data shall be deleted or permanently anonymized unless retention is required by applicable law.

The Customer is responsible for requesting any required data exports before expiration of the retention period.

The Customer is responsible for requesting any desired export of Customer Data before expiration of the retention period.

14. AUDIT RIGHTS

Upon reasonable written request, the Customer may request information regarding Andrea Technologies’ security and privacy practices relevant to the Services.

Any audit, assessment, or review requested by the Customer shall:

– Be reasonable in scope;

– Not unreasonably interfere with Andrea Technologies’ operations;

– Be subject to confidentiality obligations;

– Be conducted no more than once per calendar year unless required by law.

15. LIABILITY

The liability of the parties arising under this DPA shall be subject to the limitations of liability set forth in the applicable service agreement unless prohibited by applicable law.

16. TERM

This DPA shall remain in effect for as long as Andrea Technologies processes Personal Data on behalf of the Customer.

17. USE OF ANONYMIZED INFORMATION

Nothing in this DPA shall restrict Andrea Technologies from creating, generating, analyzing, using, publishing, licensing, or otherwise commercializing aggregated, anonymized, de-identified or non-identifiable information derived from Customer Data, provided that such information cannot reasonably identify any individual, Customer, or business operation.

18. GOVERNING LAW

This DPA shall be governed by and construed in accordance with the laws of the Republic of Serbia.

19. CONTACT INFORMATION

Questions regarding this DPA or privacy matters may be directed to:

Andrea Technologies DOO Novi Sad  

Email: support@andrea360.com