ADDENDUM DATA PROCESSING
This Data Processing Addendum, including Appendix 1, (hereinafter: “Processing Agreement”) is an addendum and forms part of the General Terms and Conditions of Service AdPage.io or any other written or electronic agreement between AdPage.io and Customer for the purchase of Server-Side Tracking services from AdPage.io (identified as “Services” or otherwise in the applicable agreement, and hereinafter defined as “Services”) (hereinafter: the “Agreement”) to shape the agreement between the Parties regarding the Processing of Personal Data. The Customer enters into this Data Processing Agreement on behalf of itself and, as required by applicable data protection laws and regulations. While providing the Services to the Customer under the Agreement, AdPage.io may process Personal Data on behalf of the Customer, and the Parties agree to comply with the following provisions with regard to Personal Data, each acting reasonably and in good faith.
HOW TO EXECUTE THIS PROCESSOR AGREEMENT:
This Data Processing Agreement consists of two parts: the main body of the Data Processing Agreement, Annex 1 and the associated annexes.
This Data Processing Agreement is a pre-signed agreement on behalf of AdPage.io as the processor. Appendix I is a pre-signed agreement by AdPage.io as the data importer.
To complete this Data Processing Agreement, the Customer must: complete the information in the signature box and sign on pages 5 and 19. Sign the document in the AdPage Tagging portal.
HOW THIS PROCESSOR AGREEMENT APPLIES
Unless expressly stated otherwise in the Agreement, this Processor Agreement shall become legally binding upon AdPage.io’s receipt of the duly completed Processor Agreement at support@adpage.io.
Om twijfel te voorkomen, wordt ondertekening van de Verwerkersovereenkomst op pagina 5 beschouwd als ondertekening en aanvaarding van de Standaard Contractuele Clausules, inclusief Bijlage II en Bijlage III. Als de Klant die deze Verwerkersovereenkomst ondertekent partij is bij de Overeenkomst, dan is deze Verwerkersovereenkomst een addendum bij en maakt deel uit van de Overeenkomst. In dat geval is AdPage.io partij bij deze Verwerkersovereenkomst.
IS AGREED AS FOLLOWS
1. Definitions and interpretation
1.1 In this Data Processing Agreement, the following terms shall have the meanings ascribed to them below:
AdPage.io: is a trading name of AdPage BV (KVK: 75440482), with its registered office at: Velmolenweg 54 A 5404 LD, Uden Netherlands. Also referred to as “Processor”.
Agreement: means a written or electronic agreement between AdPage.io and Customer for the purchase of Server Side Tracking services from AdPage.io.
Provisions: module two (Controller to processor) of the Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, as set out in annex 1 to this processor agreement.
Customer: means the legal entity or Consumer with whom AdPage.io has entered into a legally binding agreement. Also referred to as “Data Controller”.
Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Customer Data: includes all data and information provided by or for the Customer to AdPage.io in order to provide Services.
Data Processing Agreement: means this data processing addendum, including the schedules, as amended from time to time.
Data Protection Laws means all applicable laws relating to the protection of personal data or privacy from time to time in force in the European Economic Area and the United Kingdom, including (but not limited to) the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, and any other applicable law relating to data protection or privacy of individuals.
EU GDPR (‘AVG’) stands for General Data Protection Regulation 2016/679 of the EU. Parties: Both AdPage.io and Customer.
Personal data means any information relating to an identified or identifiable living individual that is processed by the Processor on behalf of the Controller as a result of, or in connection with, the provision of the Services under the Agreement, the details of which are set out in Part B of Schedule 1 to Schedule 1 of this Processor Agreement, which may be amended from time to time by mutual agreement between the Parties.
Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.
Services: All services made available to Customers via the AdPage.io online platform, plugins, third-party websites, or any other service offered by AdPage.io.
1.2 The terms “third country”, “member state”, “data subject”, “personal data breach”, “processing” and “supervisory authority” shall have the same meaning as in the EU GDPR, and their corresponding terms shall be interpreted accordingly.
1.3 In the event of conflict or ambiguity between:
1.3.1 a provision in the operative part of this Data Processing Agreement and a provision in Appendix 1, the provision in Appendix 1 shall prevail; and
1.3.2 one of the provisions of this Processor Agreement and the provisions of the Agreement itself, the provisions of this Processor Agreement shall prevail with regard to the subject matter of this Processor Agreement.
BACKGROUND
The client has a website or webshop and wants to generate more leads and sales.
(B) AdPage.io is a provider of specialised Server Side Tracking Analytics Services, and the Client wishes to procure AdPage.io’s services relating to the correct measurement of advertising results by using a proxy server.
The parties have entered into an Agreement that sets out the legal framework under which AdPage.io will assist the Client and under which AdPage.io has agreed to provide the Services to the Client.
(D) The Services provided by AdPage.io under the Agreement enable AdPage.io to access and process Personal Data (as defined above) as a Processor on behalf of the Customer (who acts as Controller).
(E) To guarantee the secure, correct and lawful processing of Personal Data by AdPage.io on behalf of the Client, the Parties have agreed to the terms set out in this data processing addendum.
2. Roles and responsibilities of the parties
2.1 The Client and AdPage.io agree and acknowledge that:
2.1.1. For the purposes of the Data Protection Laws, AdPage.io shall act as a Processor on behalf of the Customer (who shall act as Controller);
2.1.2 the processing of Personal Data by AdPage.io shall be governed by the Standard Contractual Clauses (as set out in Annex 1 to this DPA); and
2.1.3 for the purposes of the Standard Contractual Clauses, the customer is the data exporter and AdPage.io is the data importer;
2.1.4 It is the responsibility of the Customer to enable pseudonymisation of personal data. If pseudonymisation is disabled, Adpage cannot guarantee that adequate supplementary measures have been taken to ensure essential equivalence with EU protection levels.
3. Delection or return of personal data from the controller
3.1 Subject to Article 5.3 (Term and Termination), AdPage.io's obligations as set out in Article 8.5 of the General Terms and
Conditions of Service are met within 30 days of the end of the provision of the Services under the Agreement, unless the parties agree a
a different retention period has been agreed as determined in Annex I.B.
3.2 AdPage.io may retain Personal Data to the extent required by the legislation of the EU, the UK or a Member State and only to the extent and for as long as required by the legislation of the EU, the UK or a Member State and always on the condition that AdPage.io shall ensure the confidentiality of all such Personal Data and shall ensure that such Personal Data is processed only to the extent necessary for the purpose or purposes specified in the relevant legislation of the EU, the UK or a Member State requiring its storage and for no other purpose.
3.3 The Customer, as data controller, determines the retention period for Personal Data within the frameworks mentioned in Annex I.B. The Customer is
responsible for the lawfulness and proportionality of the chosen retention period in accordance with the GDPR and must be able to substantiate and record this choice in its own privacy statement.
4. Assistance provided in accordance with ANNEX 1
4.1. AdPage.io shall provide the assistance described in Articles 8.3, 8.6, and 10 of the Model Contractual Clauses at no additional cost to the Customer.
5. Term and termination
5.1 This Data Processing Agreement shall come into effect upon receipt by AdPage.io of the duly completed Data Processing Agreement at the email address and shall terminate on the later of the following dates:
(i) the date on which the Agreement terminates; or
(ii) the date on which AdPage.io ceases to process Personal Data.
5.2 Any provision of this Processor Agreement that expressly or implicitly is intended to take effect or remain in force on or after the termination of this Processor Agreement shall remain in full force and effect.
5.3 The termination or expiry of this Processor Agreement shall not affect the rights, remedies, obligations or liabilities of the Parties that have accrued up to the date of termination or expiry, including the right to claim damages in respect of any breach of this Processor Agreement which existed at or before the date of termination or expiry.
6. liability
6.1 Except as provided in clause 6.2, the liability of each Party in respect of all claims, losses, proceedings, actions or liabilities arising out of or in connection with this DPA shall be governed by the provisions of the Agreement and shall not be amended by this DPA.
6.2 Notwithstanding the foregoing, nothing in this Processor Agreement or the Agreement shall limit a Party's liability with respect to its obligations under the Standard Contractual Clauses.
7. diverse
7.1 All notices to a Party under this DPA shall be in writing and sent to the address at the beginning of this DPA or to any other address that has been notified in writing by a Party.
7.2 The failure of a Party to exercise its rights under or in connection with this Processor Agreement shall not constitute a waiver of such rights, nor shall it otherwise prejudice such rights.
7.3 This Processor Agreement may only be amended by a written agreement between the Parties.
7.4 If any provision of this Data Processing Agreement is declared void or unenforceable by a court or tribunal of competent jurisdiction, the remaining provisions of this Data Processing Agreement shall remain in full force and effect, unless the latter provisions are deemed to be intrinsically linked to the void or unenforceable provision. In the event that the other provisions remain valid, both Parties shall endeavour to replace the void or unenforceable provision with a valid provision that reflects the original intent of the Parties as closely as possible.
8. Applicable law
This Data Processing Agreement and any disputes or claims arising out of or in connection with this Data Processing Agreement (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of the Netherlands. Each Party irrevocably agrees that the courts of Den Bosch, Netherlands shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Data Processing Agreement (including non-contractual disputes or claims).
Executed in two (2) originals, each party confirming receipt of one (1) original.
ATTENTION: THIS IS A COPY OF THE PROCESSOR AGREEMENT.
APPENDIX 1 – STANDARD CONTRACTUAL CLAUSES
SECTION I
Provision 1
Purpose and scope
(a) These standard contractual clauses are designed to ensure compliance with the requirements set out in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR, General Data Protection Regulation) (1) for the transfer of personal data to a third country.
(b) The parties:
(i) the natural or legal persons and public institutions, bodies and agencies (hereinafter referred to as “entities”) that transfer the personal data referred to in Annex I.A (hereinafter referred to as the “data exporter”), and
(ii) any entities in a third country receiving the personal data from the data exporter, either directly or indirectly through another entity also party to these provisions, as set out in Annex I.A (hereinafter referred to as the “data importer”)
these standard contract provisions (hereinafter referred to as the “Provisions”) are hereby agreed.
(c) These provisions apply to the transfer of personal data as set out in Annex I.B.
(d) The annex to these provisions, which contains the appendices referred to therein, forms an integral part of these provisions.
Provision 2
Effect and immutability of the provisions
(a) These provisions establish appropriate safeguards, including enforceable rights for data subjects and effective remedies, in accordance with Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679 as well as, with regard to data transfers from controllers to processors and/or from processors to processors, standard contractual clauses in accordance with Article 28(7) of Regulation (EU) 2016/679, provided that they are not amended except to select the appropriate module(s) or to add or subtract information in the appendix. This does not preclude the parties from incorporating the standard contractual clauses laid down in these provisions into a broader contract and/or appending other provisions or additional safeguards, provided that they do not directly or indirectly conflict with these provisions and do not prejudice the fundamental rights or freedoms of data subjects.
(b) These provisions do not prejudice the obligations incumbent on the data exporter under Regulation (EU) 2016/679.
Provision 3
Third-party beneficiaries
Interested parties may invoke and enforce these provisions as third-party beneficiaries against the data exporter and/or the data importer, with the following exceptions:
Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;
(ii) Determination 8 — module one: Determination 8.5, point e) and determination 8.9, point b); Module two: Determination 8.1, point b), determination 8.9, points a), c), d) and e); Module three: Determination 8.1, points a), c) and d) and determination 8.9, points a), c), d), e), f) and g); Module four: Determination 8.1, point b) and determination 8.3, point b);
(iii) Clause 9 — module two: Clause 9, points a), c), d) and e); Module three: Clause 9, points a), c), d) and e);
(iv) Provision 12 — Module one: Provision 12, points a) and d); Modules two and three: Provision 12, points a), d) and f);
Provision 13;
(vi) Clause 15.1, points c), d) and e);
(vii) Regulation 16, point (e);
(viii) Provision 18 — modules one, two and three: Provision 18, points a) and b); Module four: Provision 18. Point a) does not prejudice the rights of data subjects under Regulation (EU) 2016/679.
Provision 4
Interpretation
(a) When terms defined in Regulation (EU) 2016/679 are used in these provisions, those terms have the same meaning as in that Regulation.
(b) These provisions shall be read and interpreted in light of the provisions of Regulation (EU) 2016/679.
(c) These provisions shall not be interpreted in a manner that contradicts the rights and obligations established in Regulation (EU) 2016/679.
Clause 5
Hierarchy
In the event of any conflict between these provisions and the provisions of related agreements entered into by the parties at the time these provisions were agreed or subsequently, these provisions shall prevail.
Clause 6
Description of the transfer(s)
The details of the transfer(s), and in particular the categories of personal data being transferred and the purpose for which they are being transferred, are further specified in Annex I.B.
Provision 7 — Optional
Docking specification
(omitted)
SECTION II — OBLIGATIONS OF THE PARTIES
Provision 8
Data protection safeguards
The data exporter warrants that it has used reasonable efforts to determine whether the data importer, by the implementation of appropriate technical and organisational measures, is capable of fulfilling its obligations under these provisions.
8.1. Instructies
(a) The data importer shall process the personal data only on documented instructions from the data exporter. The data exporter may give such instructions throughout the duration of the Agreement.
(b) The data importer shall immediately inform the data exporter if it is unable to follow those instructions.
8.2. Doelbinding
The data importer shall process the personal data only for the specific purpose of the transfer, as set out in Annex I.B, unless otherwise instructed by the data exporter.
8.3. Transparantie
The data exporter shall, upon request, provide a copy of these provisions, including the annex completed by the parties, which shall be made available to the data subject free of charge. To the extent necessary to protect business secrets or other confidential information, including the measures described in Annex II and personal data, the data exporter may redact a portion of the text of the annex to these provisions before sharing a copy, but it shall provide a relevant summary if the data subject would otherwise be unable to understand its content or exercise his/her rights. Upon request, the parties shall inform the data subject of the reasons for redaction, to the extent possible without revealing the redacted information. This provision does not affect the obligations of the data exporter under Articles 13 and 14 of Regulation (EU) 2016/679.
8.4. Nauwkeurigheid
If the data importer becomes aware that the personal data it has received are inaccurate or outdated, it shall promptly inform the data exporter. In this case, the data importer shall cooperate with the data exporter to erase or rectify the data.
8.5. Duur van verwerking en wissing of terugbezorging van gegevens
Processing by the data importer shall only take place for the duration specified in Annex I.B. Upon completion of the provision of processing services, the data importer shall, at the data exporter's choice, delete all personal data processed on behalf of the data exporter and certify to the data exporter that it has done so, or return to the data exporter all personal data processed on its behalf and delete existing copies. Until such data have been deleted or returned, the data importer shall continue to ensure compliance with these provisions. In the event of local law applicable to the data importer that prohibits the return or deletion of the transferred personal data, the data importer shall guarantee that it will continue to comply with these provisions and will only process the personal data to the extent and for as long as required by that local law. This shall not affect clause 14, in particular the requirement for the data importer under clause 14(e) to notify the data exporter throughout the duration of the contract of any reasons to believe that it is or has become subject to laws or practices that do not conform with the requirements of clause 14(a).
8.6. Beveiliging van de verwerking
(a) The data importer and, during transit, also the data exporter, shall implement appropriate technical and organisational measures to ensure the security of the data, including protection against a security breach that leads, accidentally or unlawfully, to the destruction, loss, alteration or unauthorised disclosure or unauthorised access to that data (hereinafter referred to as a “personal data breach”). When assessing the appropriate level of security, the parties shall take due account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks the processing poses to individuals. The parties shall particularly consider using encryption or pseudonymisation, including during transit, in such a way that the purpose of the processing can be achieved thereby. Where pseudonymisation is used, additional data for linking the personal data to a specific data subject shall remain under the exclusive control of the data exporter, where possible. In fulfilling its obligations under this point, the data importer shall implement at least the technical and organisational measures set out in Annex II. The data importer shall carry out regular checks to ensure that these measures continue to provide an appropriate level of security.
(b) The data importer shall only grant its personnel access to the personal data to the extent strictly necessary for the performance, management and follow-up of the agreement. It shall ensure that persons authorised to process the personal data have undertaken to observe confidentiality or are under an appropriate statutory obligation of confidentiality.
(c) In the event of a personal data breach concerning personal data processed by the data importer under these provisions, the data importer shall take appropriate measures to address the breach, including measures to mitigate its adverse consequences. Upon becoming aware of the breach, the data importer shall also notify the data exporter without undue delay. Such notification shall include details of a contact point from whom further information can be obtained, a description of the nature of the breach including, where possible, the categories and approximate number of data subjects and personal data records concerned and, at a minimum, the likely consequences of the personal data breach and the measures taken or proposed to be taken to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. Where and in so far as it is not possible to provide all information at the same time, an initial notification shall be made and further information shall be provided as soon as reasonably possible thereafter.
(d) Taking into account the nature of the processing and the information available to it, the data importer shall cooperate with and assist the data exporter in enabling the data exporter to fulfil its obligations under Regulation (EU) 2016/679, in particular to notify the competent supervisory authority and the affected data subjects.
8.7. Gevoelige gegevens
If the transfer concerns personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation, or data relating to criminal convictions and offences (hereinafter referred to as “sensitive data”), the data importer shall apply the specific restrictions and/or additional safeguards described in Annex I.B.
8.8. Verdere doorgiften
The data importer shall only provide personal data to a third party upon written instructions from the data exporter. Furthermore, data shall only be provided to a third party established outside the European Union (4) (in the same country as the data importer or in another third country; hereinafter referred to as “further transfer”) if the third party is bound by these provisions or agrees to be bound by these provisions, by virtue of the appropriate module, or if:
(i) onward transfer to a country that benefits from an adequacy decision pursuant to Article 45 of Regulation (EU) 2016/679 where the onward transfer falls within that decision;
(ii) the third party otherwise provides appropriate safeguards for the processing in question in accordance with Article 46 or 47 of Regulation (EU) 2016/679;
(iii) further processing is necessary for the establishment, exercise or defence of a legal claim in the context of specific administrative, regulatory or judicial proceedings, or
(iv) the further transfer is necessary to protect the vital interests of the data subject or of another natural person. Further transfers may only take place if the data importer complies with all other safeguards under these provisions, in particular purpose limitation.
8.9. Documentatie en naleving
(a) The data importer shall promptly and duly respond to the data exporter’s requests in relation to processing under these provisions.
(b) The parties shall be able to demonstrate compliance with these provisions. In particular, the data importer shall keep appropriate documentation on processing activities carried out on behalf of the data exporter under its responsibility.
(c) Upon request of the data exporter, the data importer shall make available to the data exporter all information necessary to demonstrate compliance with the obligations established in these provisions, and shall facilitate and contribute to audits of the processing activities covered by these provisions, at reasonable intervals or when there are indications of non-compliance. When deciding on a review or audit, the data exporter may take into account relevant certifications held by the data importer.
(d) The data exporter may choose to carry out the audit itself or appoint an independent auditor to do so. Audits may include inspections of the data importer's business premises or physical facilities and shall, where applicable, be carried out with reasonable prior notice.
(e) The parties shall make the information referred to in points (b) and (c), including the results of any audits, available to the competent supervisory authority upon request.
Provision 9
Use of sub-processors
(a) The data importer has the data exporter's general consent to engage sub-processors from an agreed list. The data importer shall notify the data exporter in writing of any intended changes to that list, including changes for the purpose of engaging or replacing sub-processors, at least [specify time period] in advance, providing the data exporter with sufficient time to object to such changes before the sub-processor(s) are engaged. The data importer shall provide the data exporter with the information it requires to exercise its right to object.
(b) Where the data importer engages a sub-processor to carry out specific processing activities (on behalf of the data exporter), it shall do so through a written agreement that, in its substance, provides for the same data protection obligations as those binding upon the data importer under these provisions, including in particular, but not limited to, the provisions regarding third-party beneficiary rights for data subjects (8). The parties agree that the data importer fulfils its obligations under provision 8.8 by complying with this provision. The data importer shall ensure that the sub-processor adheres to the obligations to which the data importer is bound in accordance with these provisions.
(c) The data importer shall provide the data exporter with a copy of that agreement with the sub-processor and of any subsequent amendments to it upon request by the data exporter. To the extent necessary to protect trade secrets or other confidential information, including personal data, the data importer may redact the text of the agreement before sharing a copy.
(d) The data importer shall remain fully responsible to the data exporter for the fulfilment of its obligations by the sub-processor under its contract with the data importer. The data importer shall inform the data exporter of any non-compliance by the sub-processor with its obligations under that contract.
(e) The data importer agrees to a third-party clause with the sub-processor, whereby the data exporter, in the event that the data importer ceases to exist in fact, permanently ceases to exist in law, or enters bankruptcy, has the right to terminate the agreement with the sub-processor and instruct the sub-processor to erase or return the personal data.
Provision 10
The rights of data subjects
(a) The data importer shall immediately inform the data exporter of any requests it receives from a data subject. It shall not respond to such request itself, unless authorised to do so by the data exporter.
(b) The data importer shall assist the data exporter in fulfilling its obligations to respond to data subject requests to exercise their rights under Regulation (EU) 2016/679. In this regard, the Parties shall establish in Annex II the appropriate technical and organisational measures, taking into account the nature of the processing for which assistance is provided, as well as the scope and extent of the assistance required.
(c) In fulfilling its obligations under points a) and b), the data importer shall follow the instructions of the data exporter.
Provision 11
Story
(a) The data importer shall inform data subjects via an individual communication or on its website, in a transparent and easily accessible format, of a contact point authorised to handle complaints. It shall handle any complaints received from a data subject without undue delay.
(b) In the event of a dispute between a data subject and one of the parties concerning compliance with these provisions, that party shall make every effort to resolve the matter amicably and in a timely manner. The parties shall keep each other informed of any such disputes and shall cooperate, where appropriate, to resolve them.
(c) Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer agrees to the data subject’s decision to:
(i) to lodge a complaint with the supervisory authority in the Member State of his or her habitual residence or place of work, or with the competent supervisory authority under Chapter 13;
(ii) to submit the dispute to the competent courts within the meaning of clause 18.
(d) The parties accept that the data subject may be represented by a body, organisation or association without legal personality under the conditions referred to in Article 80(1) of Regulation (EU) 2016/679.
(e) The data importer shall comply with a decision of binding effect which falls within the scope of the applicable Union or Member State law.The data importer agrees that the choice of the data subject does not prejudice his/her substantive and procedural rights to seek redress in accordance with applicable law.
Provision 12
Liability
(a) Each party shall be liable to the other party(ies) for damage caused to the other party(ies) through breaches of these provisions.
(b) The data importer shall be liable to the data subject and the data subject shall be entitled to claim compensation for material or non-material damage suffered by the data subject as a result of a breach by the data importer or its sub-processor of the third-party beneficiary rights provided for in this clause.
(c) Notwithstanding point b), the data exporter shall be liable to the data subject for any material or immaterial damage that the data exporter or the data importer (or its sub-processor) may cause to the data subject by infringing the rights for the benefit of third parties under these provisions. This is without prejudice to the liability of the data exporter and, where the data exporter is a processor acting on behalf of a controller, to the liability of the controller under Regulation (EU) 2016/679 or Regulation (EU) 2018/1725, as applicable.
(d) The parties agree that if the data exporter is held liable under point (c) for damage caused by the data importer (or its sub-processor), it shall have the right to recover from the data importer the portion of the compensation corresponding to the data importer’s liability for the damage.
(e) Where multiple parties are responsible for damage caused to the data subject as a result of breaches of these provisions, all responsible parties shall be jointly and severally liable, and the data subject shall have the right to take legal proceedings against these parties.
The parties agree that if one of the parties is held liable pursuant to point (e), that party shall have the right to recover from the other party(ies) the portion of the damages corresponding to his/her/their share of liability for the damage.
(g) The data importer shall not rely on the conduct of a sub-processor to evade its own liabilities.
Provision 13
Supervision
(a) The supervisory authority that monitors the compliance of the data exporter with Regulation (EU) 2016/679 regarding the data transfer, as indicated in Annex I.C, shall act as the competent supervisory authority.
(b) The data importer agrees to submit to the jurisdiction of and cooperate with the competent supervisory authority in proceedings aimed at ensuring compliance with these provisions. In particular, the data importer agrees to answer questions, submit to audits, and abide by any measures determined by the supervisory authority, including corrective and compensatory measures. It shall provide the supervisory authority with written confirmation that the necessary measures have been taken.
SECTION III — LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY GOVERNMENT AUTHORITIES
Provision 14
Local laws and practices with consequences for compliance with provisions
(a) The parties guarantee that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of personal data by the data importer, including requirements to disclose personal data or measures allowing access by public authorities, prevent the data importer from fulfilling its obligations under these provisions. This is without prejudice to laws and practices that respect the essential content of fundamental rights and freedoms and that do not go beyond what is necessary and proportionate in a democratic society to safeguard the objectives referred to in Article 23(1) of Regulation (EU) 2016/679.
(b) The parties declare that when providing the guarantee referred to in point (a), they have taken due account of the following elements in particular:
(i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the channels used for transmission; intended further transfers; the type of recipient; the purpose of the processing; the categories and format of the personal data transferred; the economic sector in which the transfer takes place; the location where the transferred data is stored;
(ii) the laws and practices of the third country of destination — including laws and practices that require the provision of data to public authorities or allow access by such authorities — that are relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards (12);
(iii) all relevant contractual, technical or organisational safeguards put in place in addition to the safeguards under these provisions, including measures applied during the transfer and on the processing of the personal data in the country of destination.
(c) The data importer warrants that in performing the assessment under point (b) it has made every effort to provide the data exporter with all relevant information and agrees to continue to co-operate with the data exporter to ensure compliance with these provisions.
(d) The parties agree to document the assessment under point b) and to make it available to the competent supervisory authority upon request.
(e) The data importer agrees to notify the data exporter without delay if, after having agreed to these provisions and for the duration of the agreement, it has reasons to believe that it falls or has come to fall under laws or practices that do not comply with the requirements under point (a), including as a result of a change in the laws in the third country or a measure (such as a request for disclosure) indicating an application of those laws in practice that does not comply with the requirements in point (a). [For module three: The data exporter forwards the notification to the controller.]
(f) Following a notification under point (e), or if the data exporter otherwise has reason to believe that the data importer is no longer able to fulfil its obligations under these provisions, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure reliability and confidentiality) to be implemented by the data exporter and/or the data importer to address the situation, [for module three: where applicable in consultation with the controller]. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards can be warranted for such transfer or on instruction from [for module three: the controller or] the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract in so far as it concerns the processing of personal data under these provisions. Where more than two parties are involved in the contract, the data exporter may only exercise its right to terminate the contract with regard to the party concerned, unless otherwise agreed by the parties. If the contract is terminated under these provisions, provision 16, points (d) and (e), shall apply.
Provision 15
Data Importer Obligations in Case of Government Access
15.1. Kennisgeving
(a) The data importer agrees to promptly notify the data exporter and, as far as possible, the data subject (if necessary with the assistance of the data exporter) if it:
(i) receives a legally binding request for disclosure of personal data transferred in accordance with this provision from a public authority, including judicial authorities, under the law of the destination country; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response given, or
(ii) has been informed of the direct access by public authorities to the personal data transferred under these provisions in accordance with the legislation of the destination country; such notification shall include all information of which the data importer is aware.
(b) If the data importer is prohibited by the law of the destination country from notifying the data exporter and/or the data subject, the data importer agrees to do its utmost to obtain a waiver of the prohibition in order to be able to communicate as much information as possible as soon as possible. The data importer agrees to document these efforts so that they can be demonstrated upon request by the data exporter.
(c) Where permitted by the law of the destination country, the data importer shall agree to provide the data exporter, at regular intervals during the term of the agreement, with as much relevant information as possible concerning requests received (in particular, the number of requests, the type of data requested, the requesting authority/authorities, whether any requests were contested and their outcome etc.). [For Module Three: the Data exporter shall forward the information to the controller.]
(d) The data importer agrees to retain the information in accordance with points (a) to (c) for the duration of the agreement and to make it available to the competent supervisory authority upon request.
(e) Points (a) to (c) do not prejudice the data importer's obligation under Clause 14(e) and Clause 16 to promptly notify the data exporter when it is unable to comply with these provisions.
15.2. Wettigheidstoetsing en gegevensminimalisering
(a) The data importer agrees to verify the legality of the disclosure request, in particular whether it stays within the powers conferred to the requesting public authority, and to challenge the request if it concludes, after careful consideration, that there are reasonable grounds to believe that the request is unlawful under the law of the destination country, applicable obligations of international law and principles of international comity. In these circumstances, the data importer avails itself of the appeal avenues. When challenging a request, the data importer takes provisional measures to suspend the effects of the request until the competent judicial authority has ruled on its merits. It shall not disclose the requested personal data until it is required to do so under applicable procedural rules. These requirements do not prejudice the data importer’s obligations under clause 14(e).
(b) The data importer agrees to document its legal assessment and any challenges to a disclosure request and, to the extent permitted by the law of the destination country, make such documentation available to the data exporter. It shall also make these documents available to the competent supervisory authority upon request. [For Module Three: The data exporter shall make the assessment available to the controller.]
(c) The data importer agrees to provide the minimum amount of information permitted when responding to a request for disclosure, based on a reasonable interpretation of the request.
SECTION IV - FINAL PROVISIONS
Provision 16
Non-compliance with the provisions and termination
(a) The data importer shall inform the data exporter without undue delay if it is unable to comply with these provisions for any reason whatsoever.
(b) If the data importer breaches these provisions or is unable to comply with them, the data exporter shall suspend the transfer of personal data to the data importer until compliance is resumed or until the contract is terminated. This does not affect provision 14(f).
(c) The data exporter shall have the right to terminate the agreement, in so far as it relates to the processing of personal data under these provisions, when:
(i) the data exporter has suspended the transfer of personal data to the data importer pursuant to point (b) and the provisions are not complied with again within a reasonable period and in any case within one month of the suspension;
(ii) the data importer materially and persistently breaches these provisions, or
(iii) the data importer fails to comply with a binding decision of a competent court or competent authority regarding its obligations under these provisions.
In these cases, he shall inform the competent supervisory authority [for module three: and the controller] of that non-compliance. Where more than two parties are involved in the contract, the data exporter may exercise his right to terminate the contract only with regard to the party concerned, unless otherwise agreed by the parties.
(d) Personal data transferred prior to the termination of the agreement in accordance with point (c) shall, at the choice of the data exporter, be immediately and fully returned to the data exporter or erased. The same applies to any copies of the data. The data importer assures the data exporter that the data has been erased. Until the data has been erased or returned, the data importer shall continue to ensure compliance with these provisions. In the event that local law applicable to the data importer prohibits the return or erasure of the transferred personal data, the data importer guarantees that it will continue to adhere to these provisions and will only process the data to the extent and for as long as required by that local law.
(e) Either party may withdraw its consent to be bound by these provisions when i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 concerning the transfer of personal data to which these provisions apply; or ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data are transferred. This does not affect any other obligations that apply to the relevant processing under Regulation (EU) 2016/679.
Determination 17
Applicable law
These provisions are governed by the law of one of the EU Member States, provided that that law affords rights for the benefit of third parties. The parties agree that this shall be the law of the Netherlands.
Determination 18
Forum and jurisdiction selection
(a) Disputes arising from these provisions shall be settled by the courts of an EU Member State.
(b) The parties agree that these are the dishes of the Netherlands.
(c) An individual may also bring legal proceedings against the data exporter and/or the data importer before the courts of the Member State in which he or she habitually resides.
(d) The parties agree to submit to the jurisdiction of those courts.
ANNEX IA.
LIST OF PARTIES
Data Exporter(s):
Name: [Name]
Address: Name, position and contact details of the contact person: Activities relevant to the data transferred under these provisions: The receipt by the exporter of specialised Server Side Tracking analytics services from the importer concerning the correct measurement of advertising results using a proxy server as further described in the Agreement between the exporter and the importer.
ATTENTION: THIS IS A COPY OF THE PROCESSOR AGREEMENT.
Data Importers:
Name: AdPage BV
Address: Velmolenweg 54 A 5404 LD, Uden, Netherlands
Name, position, and contact details of the contact person:
Activities relevant to the data transferred under these provisions: The importer's provision of specialised analytics Server Side Tracking services to the exporter relating to the accurate measurement of advertising results using a proxy server, as further set out in the Agreement between the exporter and the importer.
B. BESCHRIJVING VAN DE DOORGIFTE
Categories of data subjects whose personal data are being transferred
The Client's customers, leads, and website visitors.
Categories of personal data processed
The data that needs to be transferred to analyse and measure advertising results consists of:
Website;
– Link tracking in URLs;
– User identification;
IP address;
– Other identifiers (CRM, unique identification, etc.);
– Other identifying details such as e-mail address, first name, surname, telephone number; and
Pseudonymised data.
Sensitive data being transmitted and applicable restrictions or safeguards
The Personal Data provided concern the following special categories of data: [tick]
personal data revealing racial or ethnic origin;
political views;
Religious or philosophical beliefs;
trade union membership;
genetic data;
biometric data aimed at the unique identification of a natural person;
health data;
data concerning a natural person's sex life or sexual orientation.
The frequency of defecation
The data transfer is continuously dependent on the use of the Services.
Nature of processing
The transferred Personal Data will be subject to the following processing activities:
– The data is pseudonymised and forwarded to Google Tag Manager Server Side;
Filtered data is used to measure the results of advertisements.
Purpose of data transfer and further processing
The purpose of the transfer and processing is necessary to perform the services of analysis and measurement of advertising results as instructed by the Data Controller.
Period during which personal data are stored
The Customer, as the data controller, determines the retention period for personal data, appropriate to the processing purposes. Common
Retention periods for analytics data are 26-60 months. The Customer instructs AdPage on the desired retention period at the start or during
the agreement.
Unless the data exporter instructs the data importer to return or delete the data earlier, or has another term
Personal data shall be stored in accordance with the period instructed by the Customer.
Following this period, all personal data will be irrevocably deleted, unless legal obligations require longer retention.
The Customer is responsible for informing stakeholders about the retention period in their privacy statement and being able to justify the
chosen retention period in accordance with the GDPR.
Transfers to (sub)processors
Personal data may be transferred to sub-processors. Annex III contains a full list of approved sub-processors.
C. COMPETENT SUPERVISORY AUTHORITY
In accordance with Clause 13, the competent supervisory authority is the Dutch Data Protection Authority, 2509 AJ The Hague, Netherlands.
APPENDIX II
TECHNICAL AND ORGANISATIONAL MEASURES, INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Adpage shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
– Pseudonymisation and encryption measures for personal data;
– Measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
– Measures to ensure that the availability of and access to personal data can be restored in a timely manner in the event of a physical or technical incident;
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures to ensure the security of processing.
If enabled by the Consumer, Adpage will ensure that the data is pseudonymised before it is shared with Google Tag Manager Server Side.
Taking into account Recommendation 01/2020 of the European Data Protection Board (EDPB) on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, version 2.0, adopted on 18 June 2021, it is assumed that pseudonymisation is a sufficient and effective supplementary measure to ensure data security when the transfer takes place to a third country; if the processor first pseudonymises the data it holds and then transfers it to a third country for analysis, for example for the purpose of ad tracking.
The foregoing is justified under four conditions:
The data exporter shall transfer the processed personal data in such a way that the personal data can no longer be attributed to a specific data subject, nor be used to single out the data subject in a larger group, without the use of additional data.
2. the supplementary data are held exclusively by the data exporter and are kept separately in a Member State or in a third country, geographical area or one or more specified sectors within a third country, or by an international organisation for which the Commission has established, in accordance with Article 45 of the GDPR, that a sufficient level of protection is ensured,
3. The provision or unauthorised use of supplementary data is prevented by appropriate technical and organisational safeguards, with the assurance that the data exporter alone has control over the algorithm or register by which the data can be re-identified using the supplementary data, and
4. The data controller, by means of a thorough analysis of the data in question and taking into account possible information held by the government authorities of the receiving country, has determined that the pseudonymised personal data cannot be linked to an identified or identifiable natural person, even if such information were combined and compared with the personal data,
It is the responsibility of the Data Controller to take appropriate measures to prevent data from being merged, for example by using other third-party cookies or trackers.
Security measures for sub-processors are described in Annex III.
APPENDIX III
LIST OF SUB-PROCESSORS
The exporter has given permission for the use of the following sub-processors:
Scaleway
Registered office: 8 rue de la Ville l’Evêque, 75008 Paris, France
VAT number: FR 35 433115904
Director of Publications: Arnaud Brindejonc de Bermingham
Housed by: SCALEWAY SAS BP 438 75366 PARIS CEDEX 08 FRANCE
Scaleway offers choice in the world of cloud computing, enabling customers to choose where their customer data is located, to choose which architecture best suits their business, and to choose a more responsible way of scaling.
Scaleway processes personal data to provide the services requested or authorised by AdPage as an integral part of the contract for the provision of Scaleway's services entered into between AdPage and Scaleway and governs cases where Scaleway processes Personal Data on behalf of AdPage as a Data Processor within the meaning of the GDPR.
The Scaleway Data Processing Addendum can be found here. (last viewed on 10 January 2023)
You can find Scaleway's General Terms and Conditions here. (last updated 10 January 2023)
Scaleway takes all necessary measures to protect the personal data processed and carefully selects all its partners and service providers who may need access to customer data. The data is processed electronically and/or manually, and in both cases, Scaleway ensures an appropriate level of security, protection and confidentiality based on the sensitivity of the data, taking administrative, technical and physical measures to prevent loss or theft or unauthorised use, disclosure or modification of customer data.
Scaleway's Information System Security Policy can be found here. (last viewed 10 January 2023)
Personal data is processed by Scaleway, its subcontractors and partners, in order to manage the contract and provide the services that customers have requested or have given their consent to.
The customer's data may also be transferred to third parties who provide services or support and advice to Scaleway.
Upon request, they can also be disclosed to the persons and authorities who have access to personal data by virtue of applicable laws and regulations or provisions established by legally competent authorities.
AdPage will notify you of any new sub-processors or changes to the list of sub-processors in Annex III of this Processor Agreement and give you the opportunity to object to such changes.