Databehandleraftale
Hvordan Nodavio behandler personoplysninger på jeres vegne, og på hvilke vilkår.
Sprog
Dokumentet er kun tilgængeligt på engelsk. Nodavios juridiske dokumenter foreligger i en engelsk udgave, som er den gældende. En dansk oversættelse er under udarbejdelse. Spørgsmål kan sendes til legal@nodavio.dk.
Databehandleraftale
This Data Processing Agreement forms part of the agreement between Nodavio and the customer concerning the provision of the Nodavio service.
1. Parties
Data Controller:
The customer identified in the applicable subscription or customer account.
Data Processor:
Nodavio
Kaj Munks Vej 11
7400 Herning
Denmark
Email: legal@nodavio.dk
For purposes of this Agreement, the customer is referred to as the Controller and Nodavio as the Processor.
2. Purpose
This Agreement governs the processing of personal data by Nodavio on behalf of the Controller in connection with the provision of the Nodavio service.
The Processor shall process personal data only as necessary to provide, secure, maintain and support the service and in accordance with the Controller's documented instructions.
3. Controller's responsibilities
The Controller is responsible for:
- determining the purposes and means of processing;
- ensuring that processing is lawful;
- providing any required information to data subjects;
- determining which personal data is entered into Nodavio;
- ensuring that users are appropriately authorised;
- ensuring that processing complies with applicable employment and data protection requirements; and
- giving lawful and documented instructions to the Processor.
The Controller shall not instruct the Processor to process personal data in a manner that would violate applicable law.
4. Processor's responsibilities
The Processor shall:
- process personal data only on documented instructions from the Controller;
- ensure that persons authorised to process personal data are subject to confidentiality obligations;
- implement appropriate technical and organisational security measures;
- assist the Controller in complying with applicable data protection obligations;
- notify the Controller of relevant personal data breaches without undue delay;
- assist with data subject requests where reasonably necessary;
- assist with security, impact assessment and consultation obligations where required;
- delete or return personal data following termination as required by this Agreement; and
- make available information reasonably necessary to demonstrate compliance with the Processor's obligations.
5. Processing instructions
The Processor is authorised to process personal data for the following purposes:
- providing the Nodavio service;
- hosting and storing customer data;
- enabling customer users to access and manage customer data;
- maintaining audit and activity records;
- providing support;
- securing the service;
- maintaining backups;
- diagnosing technical problems;
- maintaining and improving the reliability and security of the service; and
- complying with legal obligations applicable to the Processor.
The Processor shall not use customer personal data for independent advertising or sale of personal data.
6. Categories of personal data
Depending on the Controller's use of the service, personal data may include:
- names;
- professional email addresses;
- user account information;
- organisation and department information;
- device assignment information;
- computer and device identifiers;
- IP addresses;
- device and operating system information;
- maintenance and repair records;
- notes and other free text entered by users;
- audit and activity records;
- authentication and security information; and
- other personal data entered by the Controller or its users.
7. Categories of data subjects
The personal data may concern:
- employees;
- contractors;
- temporary workers;
- customer personnel;
- other authorised users;
- individuals associated with IT equipment; and
- other individuals whose information is lawfully entered into the service by the Controller.
8. Special categories of personal data
Nodavio is not designed as a service for processing special categories of personal data.
The Controller shall not intentionally enter special categories of personal data into free text fields unless such processing is necessary, lawful and appropriate.
If the Processor becomes aware that special category data has been entered, the Processor may take reasonable steps to protect the information, including requesting that the Controller remove it.
9. Confidentiality
The Processor shall ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations.
The Processor shall not disclose customer personal data except as authorised by the Controller, required to provide the service, required by law or otherwise permitted by this Agreement.
10. Security measures
The Processor shall maintain appropriate technical and organisational measures appropriate to the risks associated with the processing.
Measures currently include, where applicable:
- encryption in transit;
- password hashing;
- two factor authentication;
- role based access controls;
- tenant isolation;
- rate limiting;
- access logging;
- action logging;
- backups;
- controlled access to production systems; and
- security monitoring appropriate to the service.
The Processor may update its security measures provided that the overall level of protection is not materially reduced.
11. Subprocessors
The Controller authorises the Processor to use subprocessors where necessary to provide the service.
Subprocessors may provide services including:
- hosting;
- database and storage;
- email delivery;
- authentication and two factor authentication;
- backups;
- logging and monitoring; and
- analytics and related technical services.
The Processor shall impose appropriate data protection obligations on subprocessors.
The Processor remains responsible for the performance of its subprocessors to the extent required by applicable law.
The Processor shall maintain information concerning its relevant subprocessors and provide the Controller with appropriate information upon request.
12. International transfers
The Processor shall not intentionally transfer customer personal data outside the EEA unless a lawful transfer mechanism and appropriate safeguards are in place.
Where a transfer relies on a European Commission adequacy decision, Standard Contractual Clauses or another lawful mechanism, the Processor shall comply with the applicable requirements.
13. Data subject rights
Taking into account the nature of the processing, the Processor shall reasonably assist the Controller in responding to requests from data subjects concerning their rights under applicable data protection law.
The Processor may direct a data subject to the Controller where the Controller is responsible for responding to the request.
The Processor shall not independently respond to a data subject request concerning customer data except where required by law or otherwise authorised by the Controller.
14. Personal data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting customer personal data.
Where reasonably available, the notification shall include:
- the nature of the breach;
- the categories of affected personal data;
- the likely consequences;
- measures taken or proposed to address the breach; and
- information necessary for the Controller to assess and manage the incident.
The Processor shall reasonably cooperate with the Controller in relation to the breach.
15. Assistance with compliance
Taking into account the nature of the processing and the information available to the Processor, the Processor shall reasonably assist the Controller with:
- security obligations;
- notifications and assessments relating to personal data breaches;
- data protection impact assessments;
- consultations with supervisory authorities where required; and
- other obligations under applicable data protection law.
The Processor may charge reasonable costs for assistance that is materially outside the ordinary scope of the service.
16. Audits and information
The Processor shall make available information reasonably necessary to demonstrate compliance with its obligations under applicable data protection law.
The Controller may request reasonable information concerning the Processor's security and data protection measures.
Audits shall:
- be requested with reasonable advance notice;
- take place during normal business hours;
- avoid unnecessary disruption to the Processor's operations;
- respect confidentiality and security requirements; and
- not provide access to information concerning other customers.
Where appropriate, documentation such as security descriptions, certifications or independent assessments may be used instead of an on site audit.
17. Deletion and return
Following termination of the customer's subscription, access to the application ends. The Processor retains the Controller's data for 14 days following the final paid subscription period, during which the Controller may request a copy of it by writing to support@nodavio.dk.
Following that period, the Processor may delete customer data.
Within the active service, deleted records may be retained in a soft deleted state for up to 90 days before permanent deletion from the production database.
Backup copies may retain deleted information for a limited additional period until those backups are overwritten in accordance with the Processor's backup procedures.
The Processor shall not restore deleted customer data except where necessary for backup recovery, legal obligations or other legitimate technical purposes.
18. Duration
This Agreement remains in force for as long as the Processor processes personal data on behalf of the Controller.
The obligations relating to confidentiality, security, deletion and any other provisions that by their nature should survive termination shall continue for the relevant period.
19. Controller instructions
The Controller may provide documented instructions concerning the processing of personal data.
If the Processor reasonably believes that an instruction violates applicable data protection law, it shall inform the Controller before carrying out the instruction unless prohibited by law.
20. Liability
The parties' liability relating to processing of personal data is governed by the applicable agreement between the parties and applicable mandatory data protection law.
Nothing in this Agreement excludes or limits liability to the extent such exclusion or limitation is prohibited by applicable law.
21. Governing law
This Agreement is governed by Danish law.
Any dispute arising from this Agreement shall be subject to the jurisdiction of the Danish courts, subject to mandatory rules of applicable law.
22. Order of precedence
If this Agreement conflicts with the Terms of Service, this Agreement takes precedence concerning the processing of personal data.
