GDPR
Příloha č. 2 EN
smlouvy o dílo a o zpřístupnění systému Objednáme
Annex No. 2
to the Contract for Work and for Granting Access to the Objednáme System
Processing of Personal Data by Objednáme s.r.o.
1. Introductory Provisions and Definitions
1.1
The company
Objednáme s.r.o.
, with its registered office at Mlýnská 942/13, 737 01 Český Těšín, Identification No.: 06419518, registered in the Commercial Register maintained by the Regional Court in Ostrava, File No. C 71855 (hereinafter the
“Provider”
), has entered into an agreement with the Customer for the use of the Objednáme system (hereinafter the
“Agreement”
or the
“System Use Agreement”
), under which the Customer is entitled to use the Objednáme system intended for receiving and recording customer orders of the Customer (hereinafter the
“System”
).
1.2
Given that the System is hosted on the Provider’s servers, to which the Customer’s data are transmitted and stored via local System applications, including personal data of the Customer’s customers (hereinafter the
“Customer’s Customers”
), the Provider acts as a processor within the meaning of Article 4(8) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of personal data (hereinafter the
“Regulation”
).
The Customer acts as the controller of personal data entered into the System, whether by the Customer or directly by the Customer’s Customers.
1.3
As the Customer is the controller of personal data entered into the System (i.e., stored on the Provider’s servers), and the Provider is the processor of such personal data within the meaning of the Regulation, this document constitutes Annex No. 2 to the Agreement concluded between the Customer and the Provider.
As this Annex No. 2 contains the mandatory content pursuant to Article 28 of the Regulation, it shall hereinafter be referred to as the
“Data Processing Agreement”
.
2. Subject of Processing
2.1 Nature, Purpose and Scope of Processing
2.1.1
The subject of processing is the Provider’s obligation to process personal data on the basis of the Customer’s documented instructions.
2.1.2
The purpose of processing is primarily the fulfillment of the Provider’s obligations arising from the Agreement on granting access to the System, or another purpose resulting from the Customer’s instructions.
2.1.3
In connection with the operation of the System, the following processing operations typically occur:
a) storage of personal data on the Provider’s server,
b) structuring, sorting, organizing, adapting or modifying personal data stored on the Provider’s server,
c) access to personal data (only occasionally in connection with resolving and remedying incidents or System defects),
d) deletion or destruction of personal data upon termination of the Agreement or based on the Customer’s instruction.
2.2 Categories of Data Subjects and Personal Data
2.2.1
The data subjects whose personal data are temporarily processed by the Provider include:
a) employees of the Customer,
b) Customer’s Customers and other persons whose personal data are processed by the Customer as controller in connection with the use of the System.
2.2.2
The Customer acknowledges that for the duration of the Agreement, the Provider will process, based on the Customer’s instructions and in the manner specified in Article 2.1.3, the following categories of personal data:
a) identification data (e.g. name, surname, date of birth, for self-employed persons also tax identification number and company identification number) and contact data (e.g. residential address, email address, telephone or mobile phone number),
b) descriptive data (including academic titles),
c) access credentials (login data of the Customer’s Customers to their user/customer account),
d) data on the use of the Customer’s services by the Customer’s Customers (e.g. purchase history, call recordings, records of other communication).
2.2.3
The System is not intended for processing or storing sensitive personal data constituting special categories of personal data within the meaning of Article 9 of the Regulation (e.g. data on sexual orientation, health status, etc.).
However, as the Customer may create and manage forms within the System administration, it cannot be excluded that sensitive personal data may be entered into the System. In such a case, the Customer must explicitly notify the Provider of this fact.
2.3 Method and Place of Processing, Transfers to Third Countries
2.3.1
Personal data are processed primarily within the Czech Republic or another Member State of the European Union. The Provider is not authorized to transfer personal data to third countries or international organizations, nor to process personal data using resources located in third countries.
2.3.2
Processing of personal data in a third country outside the EU is permitted only with the prior written consent of the Customer and only if the conditions for transfer pursuant to Articles 44 et seq. of the Regulation are met.
2.4 Engagement of Sub-processors
2.4.1
The Customer acknowledges and agrees that the System is operated on servers located in the hosting center of
ČMIS s.r.o.
, Identification No.: 26368641, VAT No.: CZ26368641, which acts as a sub-processor within the meaning of Article 28(2) of the Regulation.
2.4.2
The Provider is entitled to engage additional hosting, cloud or other service providers as sub-processors or to replace ČMIS s.r.o. or any other sub-processor with another provider. The Provider shall inform the Customer of such changes via email sent to the contact person specified in the Specification (Annex No. 1 to the System Use Agreement) sufficiently in advance to allow the Customer to raise objections.
2.4.3
The Provider shall ensure that any sub-processor complies with processing conditions at least equivalent to those set out in this Data Processing Agreement, particularly with respect to technical and organizational measures under Article 5.2.
If a sub-processor fails to fulfill its obligations, the Provider shall remain fully liable.
3. Processing Based on Customer’s Instructions
3.1
Pursuant to Article 28(3)(a) of the Regulation, the Provider shall process personal data solely on documented instructions from the Customer as controller.
3.2
This Data Processing Agreement constitutes the Customer’s instruction to process personal data within the scope arising from the Provider’s performance under the Agreement. No additional instructions are required for personal data entered into the System by the Customer, its Customers or third parties. The Provider shall observe all limitations set out herein.
3.3
Beyond processing under Article 3.2, the Provider may process personal data based on a separate written instruction from the Customer, including electronic instructions via email with a qualified electronic signature or via data mailbox. Such instructions may include, in particular, requests for secure deletion of personal data.
Data export or download may be performed by the Customer independently via the System at any time. The Provider shall archive all such separate instructions.
3.4
Persons authorized to issue instructions are members of the Customer’s statutory body and contact persons explicitly listed in the Agreement. Authorization of additional persons must be documented in writing.
4. Duration of Processing
4.1
Processing is agreed for a fixed period until termination or expiration of the System Use Agreement. This Data Processing Agreement automatically terminates upon termination of the System Use Agreement.
4.2
Upon termination of the System Use Agreement, the Provider shall delete all Customer data, including personal data, without possibility of recovery, in accordance with Article 7.4.4 of the Terms and Conditions. All backups shall be deleted unless EU or Member State law requires retention, no later than six (6) months after termination.
4.3
The Provider shall create a record (confirmation) of the deletion and send it to the Customer’s contact email address.
4.4
The Provider acknowledges that without a valid data processing agreement it is not entitled to process personal data provided by the Customer.
5. Confidentiality and Security Measures
5.1 Confidentiality
5.1.1
The Provider shall adopt appropriate organizational measures and ensure that all employees and authorized persons are bound by confidentiality obligations regarding personal data, confidential information, trade secrets, and security measures, without limitation in time.
5.2 Technical and Organizational Measures
5.2.1
The Provider shall implement appropriate technical measures taking into account the state of the art, scope, nature, context and purposes of processing and the risks to individuals.
5.2.2
Implemented technical measures include:
a) physical security of Provider’s premises,
b) secure data transmission via TLS / HTTPS,
c) firewalls and monitoring systems,
d) user roles and passwords,
e) encrypted password storage,
f) secured IT infrastructure and endpoints (firewalls, backups, disk encryption, passwords, biometric security).
5.2.3
Organizational measures include:
a) employee confidentiality training,
b) controlled access to processing resources,
c) employee training on GDPR obligations and data subject rights,
d) regular testing and evaluation of security measures documented in internal regulations.
6. Cooperation and Liability
6.1 Cooperation
The Provider shall cooperate with supervisory authority inspections and enable audits conducted by the Customer or authorized auditors.
6.2 Assistance
The Provider shall assist the Customer in complying with Articles 32–36 of the Regulation, including:
a) breach impact assessment,
b) breach notification to authorities and data subjects.
The Provider shall notify the Customer of any data breach without undue delay, preferably within 48 hours.
Requests for assistance in fulfilling data subject rights may be subject to reasonable remuneration calculated at CZK 1,500 excl. VAT per hour.
6.3 Liability
The Provider is liable for damage caused by breach of this Agreement unless it proves it bears no responsibility.
The Customer remains primarily responsible as controller and must ensure GDPR compliance, including data minimization, storage limitation and transparency.
7. Final Provisions
7.1
This Data Processing Agreement is governed by Czech law.
7.2
If standard contractual clauses are adopted by the EU Commission or supervisory authority, the parties shall amend this Agreement accordingly.
7.3
This Agreement is executed electronically and constitutes Annex No. 2 to the System Use Agreement.
7.4
The Provider may engage additional processors and update technical and organizational measures and publish updated versions of this Agreement without requiring amendments.