Data Processing Agreement
Infinity DPA
This DATA PROCESSING AGREEMENT (”DPA”) are made by and between the party on whose behalf they are accepted (“Customer”, “Controller”) and Loop54 (“Loop54”, “Processor”) and are effective as of the date they are accepted by the Customer.
“Loop54” means either (i) The Loop54 Group AB, Company no: 556815-0451, with offices at Barnhusgatan 20, SE-111 23 Stockholm, Sweden or (ii) Loop54 Ltd, Company no: 10446599, with the legal address St James House, 13 Kensington Square, London, W8 5 HD, United Kingdom, depending on what is specified in the Service Order. The parties are hereinafter each referred to as a “Party” and jointly as the “Parties”.
Last updated: 2024-11-01
Effective date: 2024-11-01
- BACKGROUND
- The Parties have entered into an agreement under which the Processor shall provide certain services to the Controller (“the Service Order”). This DPA shall be deemed to be part of the Service Order.
- This DPA regulates the Controller’s rights and obligations in its capacity of data controller as well as the Processor’s rights and obligations in its capacity of data processor when the Processor processes personal data on behalf of the Controller.
- DEFINITIONS
- Concepts, terms and expressions in this DPA shall be interpreted in accordance with applicable data protection legislation.
- Definitions used in this DPA that are not defined in this DPA shall be defined in accordance with the Service Order.
- LIST OF APPENDICES
- Specification of the data processing: Appendix 1
- Pre-approved sub-processors: Appendix 2
- PROCESSING OF PERSONAL DATA
- The Processor undertakes to only process personal data in accordance with written instructions communicated to the Processor by the Controller, unless otherwise required by European Union law or national legislation applicable to the Data Processor, in which case the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- The Controller’s initial instructions to the Processor regarding the subject-matter and duration of the processing, the nature and purpose of the processing, categories of personal data and categories of data subjects are set forth in this DPA and Appendix 1.
- The Controller confirms that the obligations of the Processor as set out in this DPA, including Appendix 1, constitute the complete instructions for the Processor to comply with. All amendments to the Controller’s instructions shall be negotiated separately and shall, in order to be valid, be documented in writing and duly signed by both Parties. The Controller is obliged to not, unless agreed in writing, let the Processor process other categories of personal data, or process personal data regarding other categories of data subjects, than those specified in Appendix 1.
- The Processor shall, to the extent required under applicable data protection legislation and in accordance with the Controller’s written instructions in each case, assist the Controller in fulfilling the Controller’s legal obligations under applicable data protection legislation.
- The Processor shall immediately inform the Controller if the Processor deems that an instruction provided by the Controller infringes applicable data protection legislation.
- DISCLOSURE OF PERSONAL DATA
- The Processor undertakes to not, without the Controller’s prior written consent, disclose or otherwise make personal data processed under this DPA available to any third party, unless otherwise required by Swedish or European Union legislation.
- If a data subject requests information from the Processor regarding the processing of its personal data, the Processor shall refer such request to the Controller without any undue delay.
- If a competent authority requests information from the Processor regarding the processing of personal data, the Processor shall refer such request to the Controller without any undue delay. The Processor may not in any way act on behalf of, or as a representative of, the Controller and may not, without prior consent from the Controller, transfer or in any other way disclose personal data or any other information relating to the processing of personal data to any third party, unless otherwise required by Swedish or European Union legislation.
- In the event that the Processor, in accordance with applicable Swedish or European Union legislation, is required to disclose personal data that the Processor process on behalf of the Controller, the Processor is obliged to without undue delay inform the Controller thereof, unless otherwise follows said legislation, and in conjunction with the disclosure of the requested information, request that the information shall be processed with confidentiality.
- SUB-PROCESSORS AND TRANSFERS TO THIRD COUNTRIES
- The Controller confirms that the Processor may engage sub-processors to perform the Service. The Processor shall ensure that the sub-processors are bound by written agreements that require them to comply with data processing obligations that correspond to those contained in this DPA. Appendix 2 contains a list of sub-processors as of the day this DPA enters into force. The Processor shall not be obliged to oblige sub-processors that are public cloud service providers to allow physical audits under clause 9 below, provided that such sub-processors offer another way of auditing which fulfills the requirements of applicable data protection legislation.
- The Processor shall be entitled to use sub-processors outside the EEA. The Processor shall ensure that legal grounds under applicable data protection legislation for transfers to such sub-processors exist, such as the EU model clauses. The Controller mandates the Processor to enter into the EU model clauses with sub-processors on the Controller’s behalf.
- If the Processor intends to engage a new, or replace a current, sub-processor to process personal data covered by this DPA, the Processor shall, prior to such engagement, inform the Controller thereof and enable the Controller to object to the engagement. Such objections shall be made by the Controller in writing within five business days as from the time the Controller receives the information. The Processor shall provide the Controller with any information reasonably requested by the Controller to enable the Controller to assess whether the use of the proposed sub-processor will ensure the Controller’s compliance with this DPA and applicable data protection legislation. If such compliance, in the Controller’s legitimate opinion, will not be enabled through the engagement of the proposed new sub-processor and the Processor, despite the objections of the Controller, want to engage the proposed sub-processor, the Controller shall have the right to terminate the Service Order without additional costs. If the objection is not legitimate, the Controller shall not have the right to terminate the Service Order.
- INFORMATION SECURITY AND CONFIDENTIALITY
- The Processor is obliged to fulfill its legal obligations regarding information security under applicable data protection legislation and shall in all cases take appropriate technical and organizational measures to protect the personal data that is being processed.
- The Processor is obliged to ensure that only such personnel that directly require access to personal data in order to fulfill the Processor’s obligations in accordance with this DPA have access to such information. The Processor shall ensure that such personnel are bound by an adequate confidentiality agreement.
- DATA BREACH NOTIFICATIONS
- The Processor shall without any undue delay inform the Controller after becoming aware of any personal data breach.
- The Processor shall assist the Controller with any information reasonably required to fulfill the Controller’s data breach notification requirements.
- AUDIT RIGHTS
- The Processor undertakes to make available to the Controller all information and all assistance that are necessary to demonstrate compliance with the obligations stipulated in this DPA and enable and contribute to audits, including inspections, conducted by the Controller or an auditor appointed by the Controller, provided that the individuals performing the audit enter into adequate confidentiality agreements.
- TERM OF AGREEMENT
- The provisions of this DPA shall apply as long as the Processor processes personal data for which the Controller is data controller.
- MEASURES UPON COMPLETION OF PROCESSING OF PERSONAL DATA
- Upon expiration of the Main Agreement, the Processor shall, at the choice of the Controller, delete or return all personal data that has been processed under this DPA within thirty (30) days after the expiration of the Service Order, unless Swedish or European Union legislation requires the Processor to store the personal data.
- Upon the Controller’s request, the Processor shall provide a written confirmation of the measures that the Processor has taken regarding the personal data following the termination of the processing as set out in clause 11.1 above.
- COMPENSATION
- The Processor shall be entitled to compensation for its processing of personal data under clause 4.4, 5, 8.2, 9 and 11 of this DPA in accordance with the Processor’s list of rates that applies from time to time.
Appendix 1
Data processing instructions
|
Purposes
Please specify all purposes for which the personal data shall be processed by the Processor
|
- Fulfill the Processors rights and obligations under the Service Order. Delivering and developing the services specified therein.
|
|
Categories of data
Please specify the personal data that shall be processed by the Processor
|
- User Id
- IP adress
- Search terms
- Click, add to cart and purchase interactions
|
|
Categories of data subjects
Please specify the categories of data subjects whose personal data shall be Processed by the Processor
|
- Users of the Controller’s website
|
|
Processing activities
Please specify all processing activities to be conducted by the Processor
|
- Processing of api-calls to supply the service
- Analysis of end user interactions of the website
- Storage of personal data
|
|
Location of Processing activities
Please specify all locations where the personal data shall be processed by the Processor
|
- Sweden
- United Kingdom
- Germany
|
Appendix 2
Pre-approved sub-processors
If the Processor, in accordance with clause 6.3 of this DPA, intends to engage a new or replace a current sub-processor to process personal data covered by this DPA, the Processor will inform the Controller thereof at the Processor’s website, https://www.fact-finder.com/media/loop54_subcontractors.pdf.