entered into between:
the Processor's Client signing below, expressing its intention to enter into this Agreement and requesting that the Processor enter into this Agreement pursuant to a declaration of intent made electronically in connection with registration of an Account in the Processor's Service (in accordance with the Camp Tempo Service Terms),
hereinafter referred to as the “Controller”,
and
WOJCIECH KOGUCKI SOFTWARE DEVELOPMENT, ul. Walerego Wróblewskiego 21B/64, 93-578 Łódź, Poland, REGON: 389465520, NIP: 7272851388,
hereinafter referred to as the “Processor”,
jointly hereinafter referred to as the “Parties”.
§ 1. General provisions
In connection with the Parties entering into an agreement for registration of the Controller's Account in the Camp Tempo Service (hereinafter: the “Main Agreement”), the Controller entrusts the Processor with the processing of Personal Data specified in this Data Processing Agreement (hereinafter: the “Agreement”) on the terms and for the purpose specified in the Agreement.
Matters not governed by this Agreement are subject to the Camp Tempo Terms and Conditions available at: Camp Tempo Service Terms
The Processor undertakes to process the Personal Data entrusted to it in accordance with the Agreement, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter the “GDPR”, and other generally applicable law.
The Controller represents that it is the controller of the Personal Data whose processing it entrusts to the Processor.
The Processor represents that it applies security measures meeting the requirements of the GDPR.
§ 2. Scope and purpose of Personal Data processing
An instruction to perform a service placed under the Main Agreement that requires access to data and has been documented in the manner specified in that service instruction constitutes, in each case, an instruction from the Controller to the Processor to process Personal Data.
The Processor will process the following Personal Data of the persons referred to above (belonging to ordinary categories of data):
first name,
surname,
business name,
address details,
email address,
telephone number,
NIP tax identification number,
REGON statistical identification number,
bank account number.
The entrusted data will relate to the following categories of persons:
the Controller,
the Controller's representatives,
the Controller's contractors,
the Controller's associates.
The Processor will process the Personal Data solely for the purpose of performing the Main Agreement.
The Controller authorises the Processor to perform the following operations on Personal Data: storage, copying, anonymisation, erasure, collection, recording, organisation, updating, archiving, modification and retrieval, provided that the Processor will perform anonymisation and erasure only after the Agreement has ended.
The Processor will process data in the following locations: European Union countries and the United States.
§ 3. Obligations of the Processor and the Controller
The Processor undertakes to secure the Personal Data being processed by applying appropriate technical and organisational measures that ensure a proper level of security corresponding to the risk associated with processing Personal Data, in accordance with Article 32 GDPR. The Processor applies measures ensuring a level of security appropriate to the risk, scope, context and purposes of processing, including technical and organisational measures. In particular, the Processor applies:
pseudonymisation and encryption of Personal Data,
the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services,
the ability to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident,
regular testing, assessing and evaluating of the effectiveness of technical and organisational measures for ensuring the security of processing.
The Processor ensures that it regularly reviews and evaluates the effectiveness of security measures, at least every 3 months.
The Processor undertakes to authorise all persons who will process the entrusted data for the purpose of performing the Agreement to process Personal Data, or to enter into appropriate data processing agreements.
The Processor undertakes to ensure that the persons it authorises to process Personal Data for the purpose of performing the Agreement commit themselves to confidentiality in relation to the Personal Data processed, both during their employment by the Processor and after it ends.
After the provision of processing-related services ends, the Processor will erase all Personal Data and any existing copies of it unless Union or Member State law requires the Personal Data to be retained.
After destroying the Personal Data, the Processor will provide the Controller, at the Controller's request, with a record or statement confirming destruction of the Personal Data.
The Processor will assist the Controller to the necessary extent in meeting its obligation to respond to requests from data subjects and in complying with the obligations set out in Articles 32–36 GDPR.
After becoming aware of a Personal Data breach, the Processor will notify the Controller without undue delay and no later than within 24 hours.
The Processor represents that it will not use the data entrusted to it under the Agreement for purposes other than those specified in the Agreement, in particular that it will not use the data for its own purposes or disclose it in any form to unauthorised persons.
The Controller will ensure that all necessary consents to the processing of third parties' Personal Data are obtained, where necessary and justified under generally applicable law.
§ 4. Right of audit
The Controller has the right to audit whether the measures applied by the Processor when processing the entrusted Personal Data comply with the Agreement.
The Controller will exercise the right of audit on at least 3 days' prior notice.
The Processor undertakes to remedy any deficiencies identified during an audit without undue delay and no later than within 7 days.
The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR.
§ 5. Subprocessing of Personal Data
The Processor may entrust Personal Data to subcontractors for further processing solely for the purpose of performing the Agreement and after obtaining the Controller's prior written consent.
A subcontractor should meet the same guarantees and obligations as those imposed on the Processor in the Agreement.
The Processor is fully liable to the Controller for proper performance by subcontractors of their data protection obligations.
Data may be transferred to a third country only on the written instructions of the Controller unless such a requirement is imposed by European Union or Member State law to which the Processor is subject. In that case, the Processor will inform the Controller of that legal requirement unless the law prohibits such information on important grounds of public interest.
§ 6. Liability of the Processor
The Processor is liable for disclosure or use of Personal Data contrary to the Agreement, in particular for making Personal Data entrusted for processing available to unauthorised persons.
The Processor undertakes to inform the Controller without undue delay about any proceedings, in particular administrative or judicial proceedings, concerning the Processor's processing of Personal Data covered by the Agreement, any administrative decision or judgment concerning the processing of Personal Data covered by the Agreement, and any audits and inspections concerning the Processor's processing of Personal Data covered by the Agreement.
§ 7. Duration of the Agreement
The Agreement is entered into for a fixed period, namely the term of the Main Agreement.
The Controller may terminate the Agreement before the end of the period specified in paragraph 1 in the cases set out in § 8.
§ 8. Termination of the Agreement by the Controller
The Controller may terminate the Agreement with immediate effect if the Processor:
fails, within the prescribed time limit, to remedy deficiencies identified during an audit conducted by the Controller despite being required to do so,
has entrusted the processing of Personal Data to a third party without the Controller's consent.
§ 9. Confidentiality
The Processor undertakes to keep confidential all information, materials, documents and Personal Data received from the Controller and persons cooperating with the Controller, recorded in any form and obtained by the Processor in any manner, whether orally, in writing or electronically.
The Processor represents that, in connection with its obligation to keep confidential data secret, such data will not be used, disclosed or made available without the Controller's written consent for any purpose other than performance of the Agreement, unless the need to disclose the information held follows from law or the Agreement.
§ 10. Final provisions
The Controller undertakes, on behalf of the Processor, to comply with the information obligation referred to in Article 14 GDPR towards persons whose Personal Data it provides to the Processor in connection with the Agreement (employees/associates and representatives). The Controller confirms that it has received from the Processor a document containing the information referred to in the preceding sentence, constituting Appendix 1 to the Agreement.
Amendments to the Agreement must be made in documentary form to be valid.
Matters not governed by the Agreement are subject to the Civil Code, the GDPR and other relevant law.
The court with territorial jurisdiction over the Processor has jurisdiction over disputes arising from the Agreement.
The appendices form an integral part of the Agreement.
The Agreement has been drawn up in documentary form. Each copy of the Agreement bearing the Parties' signatures and downloaded from the information and communications technology system is an original.
Appendices
Processor's information notice — Article 14 GDPR.
Signatures of the Parties
Controller
Processor
Appendix 1
INFORMATION NOTICE FOR REPRESENTATIVES AND PERSONS DESIGNATED FOR CONTACT BY CONTRACTORS
In compliance with the information obligation set out in Article 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter the GDPR, we provide the following information concerning the processing of your Personal Data.
The controller of your Personal Data is WOJCIECH KOGUCKI SOFTWARE DEVELOPMENT, ul. Walerego Wróblewskiego 21B/64, 93-578 Łódź, Poland, REGON: 389465520, NIP: 7272851388, email: contact@camptempo.com.
You may contact the Controller by post at the Controller's address or by email at: contact@camptempo.com.
Your Personal Data was obtained directly from our Contractor by whom you are employed, with whom you cooperate or whom you represent.
The Controller will process the following Personal Data:
full name,
position/function held,
address details,
additional contact details (telephone number and email address).
We process your Personal Data for the purpose of entering into, performing and settling agreements between the Controller and the Contractor whom you represent (Article 6(1)(b) GDPR), or for whom you work or with whom you cooperate. The legal basis for the processing of Personal Data is also the Controller's legitimate interest (Article 6(1)(f) GDPR), which we consider to include:
establishing a relationship with the Contractor,
verifying persons authorised to represent the Contractor,
communication activities and identifying persons responsible for performance and authorised to maintain contact in connection with performance of the agreement,
establishing, pursuing and protecting claims or rights related to performance of the agreement.
In addition, we may process your Personal Data (Article 6(1)(c) GDPR) in order to comply with our obligations under applicable law.
Your Personal Data may be transferred to other external entities that process data under an agreement with the Controller or applicable law, including providers responsible for IT services and the operation of IT systems and equipment, and entities providing legal services.
The Controller will not transfer Personal Data to a third country or international organisation, except where using entities that provide hosting services or dedicated servers. In the case of those providers, data may be transferred to the USA. The transfer then takes place on the basis of standard contractual clauses (Article 46(2) GDPR).
We will process Personal Data for the term of the agreement between the Controller and the Contractor, and not earlier than after the expiry of the periods arising from applicable law, including the limitation period for claims.
The data subject has:
the right of access to Personal Data,
the right to request rectification of Personal Data,
the right to request erasure of Personal Data,
the right to request restriction of the processing of Personal Data,
the right to object to processing,
the right to data portability.
You also have the right to lodge a complaint with the competent supervisory authority, the President of the Personal Data Protection Office, if you consider that the processing of your Personal Data infringes data protection law, including the GDPR.
Your Personal Data is not subject to automated decision-making, including profiling.