Version 20210601
Data Processing Agreement
English
The undersigned, hereinafter jointly referred to as the “Parties”;
Whereas:
- The Parties have entered into an agreement concerning the provision, use and support of software for business planning and time administration of employees and business resources, commencing on , hereinafter referred to as the “Agreement”. In performance of the Agreement, Bedrijfsrooster processes personal data on behalf of Customer;
- The Parties wish to handle carefully and in accordance with the General Data Protection Regulation and other applicable laws and regulations concerning the processing of personal data the personal data that is or will be processed in performance of the Agreement;
- The Parties wish to record in writing, in accordance with the General Data Protection Regulation and other applicable laws and regulations concerning the processing of personal data, their rights and obligations regarding the processing of data subjects’ personal data in this Data Processing Agreement.
- Customer alone determines the purposes and means of processing personal data, and Bedrijfsrooster has no influence over them.
- Customer purchases a standard package of services and software from Bedrijfsrooster, in the same standardised form, at a comparable volume-discounted rate and through largely automated processes, as Bedrijfsrooster provides to multiple customers. Anything that deviates from this shall be agreed in a “Customisation Agreement” at a rate to be determined by Bedrijfsrooster.
Have agreed as follows:
1. Definitions
- Additional Measures: optional, future privacy and security measures and tools offered by Bedrijfsrooster, which the User may use or deploy on their own initiative as they wish or consider necessary, including the Delete Action functionality and settings made available through the Application.
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Data Subject: the person to whom Personal Data relates.
- EEA: European Economic Area.
- Personal Data Breach: a breach of Bedrijfsrooster’s security leading, accidentally or unlawfully, to the destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
- Notification Email Address: the email address provided by Customer when entering into the Agreement or through the Application, to which Bedrijfsrooster sends certain notifications and written communications.
- Transfer Period: the period of 30 days after termination of the Agreement during which Customer may request the transfer of Personal Data or carry it out independently.
- Personnel: the natural persons engaged by Bedrijfsrooster and/or Customer to perform this Data Processing Agreement, who are under their authority or in a hierarchical relationship with Bedrijfsrooster and/or Customer.
- Personal Data: any information relating to an identified or identifiable natural person.
- Sub-processor: a third party engaged by Bedrijfsrooster to process Personal Data on behalf of Bedrijfsrooster, which is not subject to Bedrijfsrooster’s direct authority and is not in a hierarchical relationship with Bedrijfsrooster.
- Processor/Bedrijfsrooster: the party that processes Personal Data on behalf of Customer without being subject to Customer’s direct authority, referred to in this agreement as “Bedrijfsrooster”.
- Data Processing Agreement: this agreement, including its recitals and appendices.
- Processing: an operation or set of operations performed in connection with the Agreement on Personal Data, or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Controller/Customer: the controller of the Processing within the meaning of the GDPR who determines its purposes and means, referred to in this agreement as “Customer”.
- Delete Action: an instruction given by a User through the Application to delete Personal Data, without the option to restore or recover it.
2. Subject matter
- This Data Processing Agreement sets out arrangements concerning the Processing of Personal Data by Bedrijfsrooster in connection with the Agreement.
- The nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are described in Appendix 1 (Processing Specification).
3. Entry into force and term
- This Data Processing Agreement enters into force when Customer has clicked “accept” in the Application, or the Parties have otherwise entered into this Data Processing Agreement, but never before 25 May 2018.
- The provisions on the term and termination of the Agreement shall apply as provisions on the term and termination of the Data Processing Agreement. If the Agreement ends for any reason, the Data Processing Agreement shall also end after expiry of the Transfer Period and once Bedrijfsrooster has destroyed all Personal Data.
- Obligations which by their nature are intended to continue after termination of the Data Processing Agreement shall remain in force after termination. These include, among others, provisions concerning confidentiality, destruction, liability and applicable law.
4. Obligations of the Controller
- Customer warrants that the instruction to Process the Personal Data is lawful and does not infringe third-party rights, and warrants that the purposes and categories of Data Subjects and Personal Data described in Appendix 1 (Processing Specification) are complete and accurate. Customer indemnifies Bedrijfsrooster against any defects and claims resulting from an incomplete specification.
- Where applicable, Customer shall notify Bedrijfsrooster in writing of any desired changes concerning the Processing of Personal Data and allow Bedrijfsrooster 10 days to respond or object. If Bedrijfsrooster objects, Customer may terminate the Agreement with immediate effect.
- Bedrijfsrooster applies a level of security appropriate to the risk relating to the Processing of Personal Data (taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing of Personal Data, as well as the risks to individuals) by means of Measures implemented and maintained by Bedrijfsrooster as set out in Article 8 (Data Security).
5. Obligations of the Processor
- Bedrijfsrooster shall Process Personal Data only if and insofar as necessary to perform the Agreement, and shall follow all reasonable instructions from Customer, subject to any contrary statutory requirements applicable to Bedrijfsrooster.
- Bedrijfsrooster shall provide Customer with reasonable assistance so that Data Subjects can obtain access to their personal data, have it erased or corrected, and/or demonstrate that it has been erased or corrected.
- Bedrijfsrooster shall take adequate internal control measures to comply with its obligations under this agreement and document them in a manner that readily enables compliance to be audited.
- Bedrijfsrooster may Process Personal Data at a location outside the EEA or transfer it to countries outside the EEA, and shall do so in compliance with the rules on international data transfers.
- Bedrijfsrooster agrees that Customer may have the Processing of Personal Data audited for compliance with the Data Processing Agreement by an independent auditor no more than once per year.
- In the event of an audit, at Customer’s request Bedrijfsrooster shall make available all information requested by the auditor that is reasonably necessary to demonstrate that Bedrijfsrooster complies with its obligations under this Data Processing Agreement. The auditor shall be bound by confidentiality. The auditor shall report to Customer in general terms, but shall not disclose details of the security measures, systems and software used. Customer shall bear the costs of the audit unless it shows that Bedrijfsrooster is not complying with its obligations under this Data Processing Agreement. In that case, the limitation of liability set out in the Agreement shall apply to the amount of the costs.
- Before an audit, Bedrijfsrooster shall consult with Customer and agree in advance on a reasonable notice period and measures for security and confidentiality oversight. Bedrijfsrooster may object to an auditor appointed by Customer if, judged objectively, the auditor is not independent, is a competitor of Bedrijfsrooster or is otherwise unsuitable. In that event, Customer and Bedrijfsrooster shall consult on the appointment of an independent auditor, or Customer may conduct the audit itself with Bedrijfsrooster’s written consent.
- The content and scope of the Processing instruction and the fee payable for it shall be as set out in the Agreement. Bedrijfsrooster shall Process Personal Data solely on the basis of Customer’s written instructions as set out in this Data Processing Agreement.
6. Sub-processors
- Customer gives general authorisation to use Sub-processors to provide (parts of) the Application and Service, which, where applicable, are listed in Appendix 4 (List of Sub-processors). Before engaging a new Sub-processor to Process Personal Data, Bedrijfsrooster shall notify the Notification Email Address and give Customer 14 days to object in writing. If Customer objects, the Parties shall enter into a Customisation Agreement within 14 days, or Customer may terminate the Agreement with immediate effect.
- If Bedrijfsrooster outsources all or part of the performance of the Data Processing Agreement to a Sub-processor, Bedrijfsrooster shall remain Customer’s point of contact and responsible for the Sub-processor’s compliance with provisions corresponding to this Data Processing Agreement.
- To the extent that Sub-processors engaged by Bedrijfsrooster Process Personal Data outside the EEA, Bedrijfsrooster shall take reasonable steps to ensure that such Processing complies with the statutory rules on international data transfers.
- Bedrijfsrooster shall impose on the Sub-processor the same obligations as those arising for Bedrijfsrooster under this Data Processing Agreement, record them in writing in a data processing agreement, and monitor the Sub-processor’s compliance. If the Sub-processor fails to meet its data protection obligations, Bedrijfsrooster shall remain liable to the Controller for the Sub-processor’s performance of its obligations.
7. Requests and disclosure of Personal Data
- If Data Subjects make requests to Bedrijfsrooster concerning Personal Data during the term of the Agreement or the Transfer Period, Bedrijfsrooster shall ask them to submit the request to Customer. Customer is responsible for responding and, where necessary, using the Application or Service to fulfil the request insofar as possible.
- For a request as referred to in clause 7.1, and taking into account the nature of the Processing of Personal Data, Bedrijfsrooster shall assist Customer insofar as reasonably possible in meeting its statutory obligations under the GDPR by implementing Additional Measures, providing the Service or otherwise offering support.
- Bedrijfsrooster may not disclose Personal Data to anyone other than Customer and the User, except where required by law or with Customer’s written consent. Bedrijfsrooster shall confirm any disclosure to a third party to Customer in writing, identifying all parties and/or persons involved, except where prohibited by law.
- If Bedrijfsrooster is required by law to disclose Personal Data, it shall verify the legal basis for the request and the identity of the requester and, before making the disclosure, inform Customer, except where prohibited by law. It shall limit the disclosure to what is legally required and enable Customer to exercise its own rights and those of Data Subjects and to defend their interests.
- Bedrijfsrooster shall provide Personal Data in a structured, commonly used and machine-readable format, as enabled by Additional Measures or provided through the Service.
8. Security of Personal Data
- Bedrijfsrooster shall take appropriate technical and organisational measures, taking into account the state of the art and the costs of implementation and operation, to ensure a level of security appropriate to the risk, so that the Processing meets the requirements of the GDPR and other applicable laws and regulations concerning the Processing of Personal Data and the rights of Data Subjects are protected. To this end, Bedrijfsrooster shall, where appropriate, take at least the measures referred to in Article 32 of the GDPR.
- Bedrijfsrooster shall protect Personal Data against intruders and external threats, as well as careless Processing, unlawful or unauthorised disclosure, and loss, destruction or damage.
- Bedrijfsrooster shall ensure that the systems used for Processing continue to meet adequate requirements for security, confidentiality, integrity and availability, and for prompt recovery after temporary failures.
- If Customer so requests in writing, Bedrijfsrooster shall take special (additional) measures to secure and/or maintain the confidentiality of the specified (categories of) Personal Data. If this results in costs for Bedrijfsrooster, Customer shall reimburse them.
- Bedrijfsrooster shall document and implement a security policy concerning the Processing of Customer’s Personal Data. The policy shall identify vulnerabilities in the relevant systems and describe measures to monitor them and to prevent, resolve and mitigate risks. Bedrijfsrooster shall report on this to Customer annually.
9. Personal Data Breach
- Bedrijfsrooster shall inform Customer immediately, and in any event within 24 hours after becoming aware of a Personal Data Breach, in accordance with the arrangements set out in Appendix 3 (Personal Data Breach Procedure).
- Bedrijfsrooster shall take all measures reasonably required to end, prevent or limit the Personal Data Breach and any further unlawful Processing.
- After notifying Customer of a Personal Data Breach, Bedrijfsrooster shall keep Customer informed of any developments concerning the breach and the measures Bedrijfsrooster takes to limit its effects and prevent recurrence. Bedrijfsrooster shall provide Customer with all reasonable assistance in meeting the notification obligation under Article 33 of the GDPR to the Dutch Data Protection Authority and the Data Subjects. Arrangements for notification to Customer are set out in Appendix 3 (Personal Data Breach Procedure).
- Bedrijfsrooster shall not inspect or assess the content of Personal Data to determine Customer’s legal or other obligations. Customer is itself responsible for complying with its statutory obligations concerning a Personal Data Breach and any related notification to third parties.
10. Data transfer
- A Data Subject may, in whole or in part, view, update, transfer or export, and erase Personal Data through the Application, using forms, overviews, exports and Additional Measures made available by Customer in the Application.
- At a Data Subject’s request, Customer shall prepare and export Personal Data for transfer through the Application and mark it for erasure and eventual complete destruction by means of a Delete Action or instruction. Bedrijfsrooster shall assist Customer through the Service if necessary.
11. Data destruction and termination
- The retention period for Personal Data is determined solely by Customer and shall never exceed the term of the Agreement, as further explained in Appendix 1 (Processing Specification).
- By means of a Delete Action or an instruction to delete Personal Data without the option to restore it, as made possible through the Application, Service or Additional Measures, Customer or the User instructs Bedrijfsrooster to destroy the Personal Data permanently and immediately.
- Bedrijfsrooster shall carry out instructions to destroy Personal Data as soon as reasonably possible, subject to statutory requirements and taking account of backup rotation and other delaying Measures or physical storage mechanisms, but always fully within 194 days.
- If Customer wishes or needs to have Personal Data transferred upon termination, Customer alone is responsible for ensuring its timely and correct export or transfer before termination of the Data Processing Agreement. When the Agreement ends and the Transfer Period begins, Bedrijfsrooster shall send written notice to the Notification Email Address.
- Where applicable and insofar as reasonably possible, Bedrijfsrooster shall offer Customer assistance and possible Additional Measures to facilitate the editing, transfer or destruction of Data Subjects’ Personal Data.
- After termination of the Agreement, Customer may during the Transfer Period export data through the Application or request its transfer, in either case in consultation with Bedrijfsrooster.
- After termination of this Data Processing Agreement and expiry of the Transfer Period, Bedrijfsrooster shall permanently destroy all Personal Data, subject to statutory requirements.
- At Customer’s instruction, Bedrijfsrooster shall assist, insofar as reasonably possible, with a proper and lawful transfer or ensure the destruction of Personal Data, copies and Processing thereof, as well as all data carriers on which the Personal Data, copies or derivatives have been or will be recorded.
12. Confidentiality
- Personal Data is confidential and shall be treated as such by Bedrijfsrooster, which is therefore obliged to keep all Personal Data it Processes confidential.
- Bedrijfsrooster shall impose a contractual confidentiality obligation on its Personnel.
- Confidentiality shall not apply to information whose disclosure is required by any statutory provision or court order, provided that Bedrijfsrooster gives Customer prior written notice.
- This article and the confidentiality obligation set out in it shall remain in force after termination of this Data Processing Agreement.
13. Liability
- Bedrijfsrooster shall be liable for losses suffered by Customer and fines imposed on Customer as a result of Bedrijfsrooster’s failure to comply with, or act contrary to, requirements under or pursuant to the GDPR and guidelines concerning the protection of personal data and/or other relevant laws and regulations and/or this Data Processing Agreement.
- Customer shall indemnify Bedrijfsrooster against third-party claims (in particular, claims by Data Subjects) and any resulting losses, based on Customer’s failure to comply with requirements under or pursuant to the GDPR and guidelines concerning the protection of personal data and/or other relevant laws and regulations and/or this Data Processing Agreement.
- Bedrijfsrooster shall indemnify Customer against third-party claims (in particular, claims by Data Subjects) and any resulting losses, based on Bedrijfsrooster’s failure to comply with requirements under or pursuant to the GDPR and guidelines concerning the protection of personal data and/or other relevant laws and regulations and/or this Data Processing Agreement.
- Customer shall indemnify Bedrijfsrooster against any loss arising from Customer’s Processing of Personal Data using software or hardware developed or manufactured by third parties which Customer itself connects to the Application, including those of API integration partners, time-registration terminals, tablets and smartphones.
- The limitation of liability set out in the Agreement shall apply in full to Bedrijfsrooster’s liability under this Data Processing Agreement and to its indemnification obligations under this agreement. This limitation of liability shall not apply if and insofar as the loss results from wilful misconduct or gross negligence (conscious recklessness) by Bedrijfsrooster.
14. Termination for breach
- Either Party may terminate the Agreement in whole or in part if the other Party is in breach of its obligations under the Data Processing Agreement and fails to remedy that breach after being given notice of default, without prejudice to the right to compensation for loss.
15. Miscellaneous
- Amendments to or supplements of this Data Processing Agreement shall be agreed in writing or through the Application between Bedrijfsrooster and Customer. Amendments and supplements shall be recorded in an addendum to this agreement and shall be binding if signed by both Parties or if Customer has clicked “accept” for it in the Application.
- Any disputes arising from this Data Processing Agreement shall, after an unsuccessful attempt to resolve the dispute by mutual consultation, be settled as provided in the Agreement.
- If and insofar as the Parties have previously made arrangements concerning the Processing of Personal Data in connection with the Agreement (including, but not limited to, a Data Processing Agreement), those earlier arrangements shall lapse upon execution of this agreement and be replaced by this Data Processing Agreement.
Appendix 1. Processing Specification
Subject matter of the Processing
The provision of the Application and Service by Bedrijfsrooster on Customer’s instructions under the Agreement.
Purposes of the Processing
Bedrijfsrooster shall Process Personal Data solely for the purpose of providing the Application and Service to Customer as set out in the Agreement, to support business planning concerning individuals and the compilation and connection of records relating to working hours, availability, leave, absence, mileage, labour costs and expense claims, and to prepare personal time-registration overviews and generate human- and machine-readable export files thereof.
Categories of Data Subjects
Data Subjects are employees of Customer or persons temporarily engaged by Customer, Customer’s customers or other business relations of Customer who, for business operations, manage schedules or need to be scheduled.
Categories of Personal Data
Personal Data that may be Processed is limited to the following categories:
- Name, address and place of residence, telephone number and email address
- Gender and date of birth
- Contractual terms relating to scheduling
- Financial data: hourly wage and allowances
- Health data: start and end time of absence
- Biometric data: profile photograph
- GPS location, IP address and device UniqueID
- Working hours and time administration
Any change to the categories of Personal Data or the Personal Data to be Processed shall take place only following written notice from Customer to Bedrijfsrooster and confirmation by the Parties.
Retention period for Personal Data
Personal Data remains available and is retained until a Delete Action by Customer or the User, or for as long as the Agreement applies plus the Transfer Period and until Bedrijfsrooster has deleted all Personal Data in accordance with this Data Processing Agreement.
Sub-processors involved in the Processing of Personal Data
Customer gives Bedrijfsrooster general authorisation to engage Sub-processors in the Processing of Personal Data as set out in Article 6 (Sub-processors) and further specified in Appendix 4 (List of Sub-processors) to this Data Processing Agreement.
Appendix 2. Measures
For the security of Personal Data as set out in Article 8 (Security of Personal Data), and where appropriate taking into account the state of the art and the time and costs involved in implementation and operation, Bedrijfsrooster shall take the following technical and organisational measures:
- Use of ISO 27001 (information security) certified data centres for the physical storage and hosting of, and access to, critical systems and networks for the Application, thereby ensuring physical protection of environments, required authorisation and high quality.
- Firewalls, redundant storage, pseudonymisation, SSL encryption, regular backups and software updates, and other facilities to ensure on an ongoing basis the confidentiality, integrity, availability and resilience of the Application and, where necessary, timely recovery.
- A procedure for periodically testing, assessing and evaluating the effectiveness of the security policy and the Measures set out in this appendix.
- Personnel involved in the Processing of personal data shall be bound by a confidentiality obligation, must familiarise themselves with, agree to and comply with internal policies on security, privacy and the Processing of Personal Data, and shall be screened before commencing employment, so that Customer may require Bedrijfsrooster to confirm that a Certificate of Conduct (VOG) has been checked for these employees.
- Sub-processors shall be reviewed by means of an internal audit and, by written agreement, required to act in accordance with the Agreement and the GDPR and to ensure that security and privacy measures are sufficient to maintain the level reasonably expected or legally required in view of the nature of the Processing.
- Various optional Additional Measures, tools and procedures made available to Customer through the Application to enhance security in relation to the Processing of Personal Data, including password-policy settings, Two-Factor-Authentication (2FA), IP address access restrictions, automatic logout after inactivity, role allocation and interface restrictions.
Each year, Bedrijfsrooster shall provide Customer with a detailed written report of the security measures it has implemented (including administrative, technical, physical or organisational safeguards), so that Customer can reasonably determine whether all Personal Data is Processed, used and disclosed in accordance with applicable laws and the Agreement.
Appendix 3. Personal Data Breach Procedure
In the event of a Personal Data Breach, Bedrijfsrooster follows the procedure below, enabling Customer independently to determine whether it must fulfil any statutory obligations to notify authorities or Data Subjects.
Except where required by law, Bedrijfsrooster shall never itself notify Data Subjects or authorities of a Personal Data Breach.
Notification
Without undue delay and, where reasonably possible, within 24 hours after becoming aware of the Personal Data Breach, Bedrijfsrooster shall notify Customer of at least the following:
- The (suspected) cause of the Personal Data Breach
- The consequences (known and/or expected at that time)
- The (proposed) solution and the timeframe for implementing it
- Contact details and a contact person for follow-up on the notification
- The date and time, or the period during which, the incident occurred
- The category of Personal Data, insofar as Bedrijfsrooster can reasonably determine it in a timely manner
- An estimate of the number of people affected by the breach
- The name of the Sub-processor if the breach occurred at a Sub-processor
- Where possible, a timeline of the incident, procedure and measures taken
If and insofar as it is not possible to provide all information at the same time, Bedrijfsrooster may provide it to Customer in phases without undue delay.
The notification shall be sent to Customer’s Notification Email Address and may optionally be explained by telephone. Customer alone is responsible for the accuracy and accessibility of the Notification Email Address.
Measures
After becoming aware of a Personal Data Breach, Bedrijfsrooster shall:
- Take measures to limit or end the breach
- Begin preparing a report and make it available to Customer (periodically if necessary)
- Notify Customer when the breach has ended
Assistance
Bedrijfsrooster shall provide Customer with all reasonable assistance and information reasonably required to adequately inform the Dutch Data Protection Authority or the Data Subject, as applicable, about the cause and scope of the Personal Data Breach.
Appendix 4. List of Sub-processors
Bedrijfsrooster may use the services of the following Sub-processors to perform the Agreement and meet the obligations set out in the Data Processing Agreement.
Data centres involved in storage and performance of critical processes and related data
- The Datacenter Group Amsterdam BV
Physical location for and storage of: Backups, databases & webservers
Data centre location: NL Amsterdam, Delft - Google Cloud Europe - Google, LLC
Physical location for and storage of: Backups, databases & webservers
Data centre location: NL, BE, DE - Google Cloud Europe - Google, LLC
Physical location for and storage of: File uploads by Customer
Data centre location: NL, BE - Google Cloud Europe - Google, LLC
Physical location for and storage of: General operational infrastructure
Data centre location: NL, BE, DE, FI (Europe Location)
Organisations within the EEA
- Mobile Tulip BV
Service: SMS facilities
Business location: Amsterdam, Netherlands - Park Two BV
Service: Technical management & support
Business location: Haarlem, Netherlands - Thingo Internet BV
Service: Technical management & support
Business location: Haarlem, Netherlands - TransIP BV
Service: Technical management & support
Business location: Amsterdam, Netherlands - TeamViewer GmbH
Service: Customer Support
Business location: Goppingen, Germany - Voys BV
Service: VoIP facilities & Customer Support
Business location: Groningen, Netherlands
Organisations outside the EEA
- Amazon Web Services, Inc
Service: Technical management & operations
Business location: Seattle, WA, USA - Apple, Inc
Service: App push notifications & analytics
Business location: Cupertino, CF, USA - DocuSign
Service: Electronic signatures
Business location: San Francisco, CA, USA - Firebase APIs & Services - Google, LLC
Service: App push notifications & analytics
Business location: Mountain View, CA, USA - Google Analytics - Google, LLC
Service: App, web & system analytics
Business location: Mountain View, CA, USA - Google Cloud Platform - Google, LLC
Service: Technical management & operations
Business location: Mountain View, CA, USA - Google Maps Platform - Google, LLC
Service: GPS & address facilities
Business location: Mountain View, CA, USA - Google GSuite - Google, LLC
Service: Customer Support
Business location: Mountain View, CA, USA - Hubspot, Inc
Service: Customer Support
Business location: Cambridge, MA, USA - Intercom R&D Unlimited Company
Service: Customer Support
Business location: San Francisco, CA, USA - Microsoft Corp.
Service: Customer Support
Business location: Redmond, WA, USA - SendGrid, Inc
Service: Email facilities
Business location: Denver, CO, USA - The Rocket Science Group, LLC
Service: Email facilities
Business location: Atlanta, GA, USA - Zendesk, Inc
Service: Customer Support
Business location: San Francisco, CA, USA