Confidentiality Agreement
Confidentiality agreement and processing of personal data.
By virtue of the contract entered into by Imaweb 2000, S.L. and the contracting party for the use of the programme owned by Imaweb 2000, S.L., called CRM_imaweb_VO, Imaweb 2000, S.L. agrees to the present Confidentiality Agreement by reading it, governed by the following terms:
- Imaweb 2000, S.L. undertakes to keep the information classified as confidential with the utmost discretion. Confidential information shall be any piece of data owned by the Contracting party, and to which Imaweb 2000, S.L. has access by virtue of the above-mentioned contract, especially the information and personal data of the Contracting party accessed by Imaweb 2000, S.L. during the execution of said contract. Imaweb 2000, S.L. undertakes not to disclose said Confidential Information, or to publish it by any other means, either directly or through third-party individuals or companies, or to make it available to third parties without the prior written consent of the Contracting party.
- Furthermore, Imaweb 2000, S.L. undertakes to return to the Contracting party the files and/or databases, as well as any medium or document where personal data and/or Confidential information is included, once the Service Contract term is over, without keeping any copy thereof. The foregoing shall be so, except for all the information which, in compliance with the regulations currently in force, Imaweb 2000, S.L. is obliged to keep as a record to verify its activity, exclusively based on the pertinent legal effects and during the terms provided by law. In this latter case Imaweb 2000, S.L. shall keep the above-mentioned information duly blocked and under the pertinent safety measures.
- The obligations established for Imaweb 2000, S.L. under the present agreement must be observed by its personnel, collaborators and subcontractors; therefore, Imaweb 2000, S.L. shall be liable vis-à-vis the Contracting party if such obligations are not complied with by said employees, collaborators and subcontractors. Imaweb 2000, S.L. undertakes to inform its personnel, collaborators and subcontractors on the obligations set forth in the present confidentiality agreement. Imaweb 2000, S.L. shall issue as many warnings and sign as many documents as necessary with its personnel, collaborators and subcontractors, in order to ensure compliance with such obligations.
-
The Regulation 2016/679 of 27 April 2016 GDPR of the European Parliament and of the Council with as many implementing provisions published (hereinafter, "Applicable Data Protection Regulations") being fully applicable, pursuant to section 28.1 of the above-mentioned regulation, the Data processor is obliged to offer the Data controller adequate guarantees to apply technical and organizational measures, so that the processing is performed in accordance with the legal requirements and ensures the protection of the rights of the parties affected by said processing, the Data processor undertaking to do the following:
- to process the Personal Data only by following documented instructions of the data controller, even concerning Personal Data transfers to a third country or international organization except he/she is obliged to do so by virtue of the European Union or the member states’ law applied to the data processor; in such case, the data processor shall inform the data controller on said legal requirement prior to the processing, unless said Law prohibits it due to reasons of substantial public interest.
- to ensure that the persons authorised to process the personal data have undertaken to observe confidentiality or are subject to a confidentiality obligation of a statutory nature.
- to take all the necessary measures pursuant to section 32 of GDPR.
- to observe the conditions stated in sections 28.2 and 28.4 to resort to another data processor.
- to assist the data controller, considering the nature of the processing, through suitable technical and organizational measures, as long as it is possible, so the data controller may comply with his/her obligation to respond to the requests aimed at the exercise of the rights of the interested parties provided for in the GDPR.
- to help the data controller to ensure compliance with the obligations provided for in sections 32 through 36 of the GDPR, considering the nature of the processing and the information available to the data processor.
- to provide the data controller with all the necessary information to prove compliance with the GDPR obligations, as well as to allow and contribute to the performance of audits, including inspections, by the data controller or another auditor authorised by said data controller.
-
Imaweb 2000, S.L. acknowledges that the Applicable Data Protection Regulations provide for a series of obligations in the processing of personal data applicable to the data processors. To such purpose, Imaweb 2000, S.L.:
- shall only access the data that the Contracting party inputs in the programme CRM_imaweb_VO through its DMS, and provided this access is necessary to comply with the obligations set forth for Imaweb 2000, S.L. in the Contract.
-
undertakes to:
- use the personal data it has access to only and exclusively to comply with its contract-derived obligations vis-à-vis the Contracting party, at all times following the instructions the Contracting party may receive and said actions observing the provisions of the present agreement.
- make, in writing and in the cases the Applicable Data Protection Regulations require so, a record of all the categories of processing activities performed by the Data controller.
- appoint a Data Protection Officer in case it was necessary, by virtue of the Applicable Data Protection Regulations, in which case Imaweb 2000, S.L. shall communicate the Data controller the identity of the Data Protection Officer and his/her contact details.
- fully and strictly comply with the regulations in force at all times and especially comply with the General Data Protection Regulations 2016/679, implementing the necessary technical and organizational measures.
- in no case communicate to third parties the personal data it has access to, not even for storage purposes.
- notwithstanding the foregoing, Imaweb may subcontract the services foreseen in the contract and the storage of information derived from said services, all of which shall be in conformity with the data protection regulations.
- once the Service contract term is over, or should the Contracting party cease to use the programme CRM_imaweb_VO for any reason, Imaweb 2000, S.L. shall return the Contracting party at no cost a copy of the personal data and related information belonging to the Contracting party.
- communicate to the Contracting party, on a daily basis, the requests received by any means, concerning the exercise of the rights of access, rectification, cancellation, opposition, rights to be forgotten, portability and processing restrictions.
- Imaweb's data centre is located in Madrid, at Calle Albasanz, 71, and does not make international data transfers. Should Imaweb 2000, S.L. decide to locate its data centre in a country that does not provide a protection level comparable to the Spanish legislation concerning personal data protection, it shall communicate the change of location in writing, at least three months before the change of location of the data centre actually takes place.
- The Data processor shall notify the Data controller, without undue delay, and within 72 hours at most, of the breaches to the security of the Personal data he/she is in charge of and acquainted with, along with all the pertinent information for the documentation and communication of the issue.
- Such notification shall not be necessary when it is unlikely that said security breach constitutes a risk to the rights and freedoms of natural persons.
- The non-compliance by Imaweb 2000, S.L. of any of the obligations provided for in the present agreement shall entitle the Contracting party to receive compensation for the damages caused to the latter.
- The confidentiality obligations set forth in the present agreement shall remain in force for ten (10) years following termination, by any cause, of the relationship between Imaweb 2000, S.L. and the Contracting party.
Imaweb 2000 S.L.