Data processing

Data processing agreement

The processor terms that apply whenever Pertento handles personal data on a customer’s behalf. The client is the data controller and Pertento is the data processor.

Effective 29 September 2023


1Definitions

  • "Client Data" refers to personal data processed by Provider on behalf of the Client.
  • "Provider" refers to Pertento AB.
  • "Data Controller" refers to the Client.
  • "Data Processor" refers to Pertento AI.
  • "Data Protection Officer" refers to the designated data protection officer of Pertento AB,
  • "Data Location" refers to the geographical location where Client Data is stored.
  • "Personal Data Breach" refers to a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to Client Data.
  • "Data Subject" refers to the individual to whom Personal Data relates.

2Data processing

During the provision of services to the Client, Provider may process Client Data. This DPA applies to such processing.

3Client data

The categories of Personal Data processed by Provider are specified in this DPA, Section 1. Any other Personal Data processed by Provider on behalf of the Client shall also be subject to this DPA.

4Data controller and data processor

The Client is the Data Controller, and Provider is the Data Processor.

5Data location

During the term of the Agreement, the Provider shall store Client Data in the EEA unless with Client’s prior written consent. Client Data cannot be accessed from outside of the EEA without Client’s prior written consent.

6Security

Throughout the term of the Agreement, the Provider shall take and implement adequate Technical And Organisational Security Measures to protect Client Data against Personal Data Breaches.

7Personal data breach notification

The Provider shall promptly, and in no case later than 24 hours of having become aware, notify Client of any Personal Data Breach it becomes aware it has sustained, and provide Client with all available information pertaining to such Personal Data Breach, including correction and other remedies taken or planned to be taken by Provider. Provider shall thereafter implement all necessary measures to limit and remedy the incident as soon as possible, shall keep Client properly informed on developments and shall provide any and all cooperation requested by Client.

8Data subject rights

The Provider shall promptly notify Client of: (i) any Data Subject requests or complaints regarding the Processing of their Personal Data; or (ii) any third party (including organizations or associations) requests or complaints regarding the Processing of Personal Data by Provider on behalf of Client; or (iii) any government requests for access to or information about the Processing of Personal Data undertaken by Provider in the context of the Agreement. In the event Provider directly receives such a request or complaint, the Provider shall immediately notify Client and shall in no event respond directly, unless with Client’s prior written instruction.

9Correction, deletion, or blocking of personal data

Where Client notifies Provider that a Data Subject has exerted the right to rectification, erasure, restriction of Processing, or objection to Processing, the Provider shall ensure that this is promptly implemented as instructed by the Client, and in any event within 15 days from the Client’s instruction. Moreover, Provider shall ensure that this is communicated to each recipient to whom it has disclosed the Personal Data in question (e.g. its Subprocessors).

10Contractor personnel

The Provider is under the obligation to implement measures to limit access to Client Data only to those employees of Provider which need access to such data in order to fulfill their work attributions to the benefit of Client, based on the “need to know” and “least privileged access” principles.

11Subcontractor

The Provider may use Subcontractors to provide limited services on its behalf in accordance with the terms of the Agreement and this DPA. Any such Subcontractor will be permitted to Process Client Data only to deliver the services the Provider has retained them to provide, and Provider shall procure the Subcontractor does not Process Client Data for any other purpose.

12Deletion of personal data and restriction of use

Save for other instructions from Client, Provider shall delete or return the Client Data to Client no later than 90 days after termination of the Contract (or, if applicable, after a project within the Contract is finalized), and delete all records of such data from its systems (including backups).

13Liability

The Provider shall not be liable to any damages incurred by the use of its services.

14Term and termination

This DPA shall come into effect on the effective date of the Agreement OR the signing date and continue for as long as the Agreement is in force. Termination of the Agreement due to any reason will automatically lead to the termination of this DPA. The termination of the DPA shall not affect the provisions hereof or the legal obligations meant to produce effects after termination.

15Miscellaneous

  • The provisions of the Agreement referring to confidentiality, dispute resolution shall apply mutatis mutandis.
  • The provisions referring to Technical and Organisational Security Measures, as well as Client’s audit rights, shall remain valid and enforceable for the duration of this DPA as well as an additional period of three calendar years.
  • With regard to the subject matter of this DPA, the terms herein shall prevail on the Agreement.
  • This DPA shall be governed by Swedish law. Any disputes between the Parties shall be resolved pursuant to the terms of the Agreement.
  • This DPA shall be subject to the confidentiality provisions of the Agreement. However, Client may share this DPA with the data protection supervisory authority and with the client without Provider’s consent.
  • In the event one or more of the provisions contained in this DPA shall be held, for any reason, to be invalid, void, illegal and/or unenforceable in any respect, the validity, legality and enforceability of the remaining provisions of this DPA shall not be in any way affected and, if necessary for this purpose, such provision(s) shall be deemed to be omitted from this DPA.
  • No amendment of this DPA shall be effective unless in writing and signed by a person duly authorized on behalf of each of the Parties.
  • In case of conflict between the two language versions of this DPA, the English version shall prevail.

16Processing on documented instructions

Provider shall process Client Data only on the Client’s documented instructions, including as regards transfers of Client Data to a third country, unless required to do otherwise by Union or Member State law to which Provider is subject. In that case Provider shall inform the Client of that legal requirement before processing, unless the law prohibits it from doing so on important grounds of public interest.

The Agreement, this DPA, and the Client’s use of the configuration available to it in the platform, together constitute the Client’s documented instructions.

Provider shall inform the Client if, in its opinion, an instruction infringes applicable data protection law.

17Confidentiality of personnel

Provider shall ensure that persons authorised to process Client Data have committed themselves to confidentiality, or are under an appropriate statutory obligation of confidentiality, and that the obligation survives the end of their engagement.

18Assistance to the Client

Taking into account the nature of the processing, Provider shall assist the Client by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Client’s obligation to respond to requests to exercise a Data Subject’s rights.

Taking into account the nature of the processing and the information available to it, Provider shall assist the Client in ensuring compliance with its obligations as to the security of processing, the notification of a Personal Data Breach to the supervisory authority and to affected Data Subjects, data protection impact assessments, and prior consultation of the supervisory authority.

19Authorisation, notice and objection for Subcontractors

The Client gives Provider general written authorisation to engage Subcontractors, on the terms of the Subcontractor section above and this one.

Provider shall maintain a list of the Subcontractors that process Client Data and shall make it available to the Client on request.

Provider shall give the Client notice before adding or replacing a Subcontractor. The Client may object on reasonable grounds relating to data protection within 30 days of that notice, and the parties shall discuss the objection in good faith. Where it cannot be resolved, the Client may terminate the affected services without penalty.

Provider shall impose on each Subcontractor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Client for the performance of that Subcontractor’s obligations.

20Audit and information

Provider shall make available to the Client all information necessary to demonstrate compliance with its obligations as a processor, and shall allow for and contribute to audits, including inspections, conducted by the Client or by another auditor the Client mandates.

An audit shall take place on at least 30 days’ written notice, during business hours, without unreasonable disruption to Provider’s operations, and no more than once in any twelve month period — except following a Personal Data Breach, or where a supervisory authority requires it, when it may take place as often as is necessary.

21International transfers

Provider shall not transfer Client Data outside the EEA except as the Data Location section above permits. Where such a transfer takes place with the Client’s prior written consent, the parties shall put in place a transfer mechanism valid under Chapter V of the GDPR before the transfer begins, and Provider shall carry out any assessment of the destination country that the mechanism requires.

22Minimum security measures

Authentication and access control

  • Unauthorized persons shall not be allowed access to the equipment by which personal data are processed or in which personal data are stored.
  • The use of data-processing systems by unauthorized persons shall be strictly prohibited.
  • All reasonable measures shall be taken to ensure that any persons authorized to use the data-processing system have access only to the data they have been authorized to access, and that personal