Personal data processing agreement

 

MYGRACE, licensed under the company S.C. GODDESS INTERNATIONAL S.R.L., including all its subdomains and related links, processes personal data in accordance with Romanian legislation and adapted to the company's field of activity.

1. DEFINITIONS

  • "Controller" means the provider of personal data, specifically the client, and the only one competent to update, modify, or request the modification of personal data associated with their client account.
  • "Client Data" means any data that MYGRACE processes on behalf of the Client in the course of providing services in accordance with the Agreement.
  • "Data Protection Laws" means all data protection and privacy laws and regulations applicable to the processing of personal data under the agreement, including, where applicable, EU personal data protection law (GDPR).
  • "EU Personal Data Protection Law" means (1) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); and (2) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector.
  • "Personal Data" means any client data relating to an identified or identifiable natural person insofar as such information is classified as personal data under applicable data protection law.
  • "Processor" means an entity that processes personal data on behalf of the controller.
  • "Security Incident" means any unauthorized or unlawful breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
  • "Services" means any product or service provided by MYGRACE to the Client in accordance with and as specifically described in the Agreement.
  • "Third-Party Company" means any processor engaged by MYGRACE to provide services on its behalf, to facilitate the operation of current services, or to provide complementary services.

2. APPLICABILITY

This Agreement applies if and only to the extent that MYGRACE processes the Client's personal data in the course of providing the services, and such personal data is subject to the data protection laws of the European Union, the European Economic Area and/or their member states, Switzerland and/or the United Kingdom. The parties agree to comply with the terms and conditions of this Personal Data Processing Agreement.

The Client is the controller of the personal data, and MYGRACE will process the personal data only as a processor.

The Client agrees that (1) it will comply with its obligations as a controller under the data protection laws with regard to the processing of personal data and any processing instructions it issues to MYGRACE; and (2) MYGRACE undertakes to provide notice and has obtained (or will obtain) all necessary consents and rights under the Data Protection Law to process personal data and provide the services in accordance with this Agreement.

As a processor, MYGRACE will process personal data only for the following purposes: (1) processing to perform the services in accordance with the agreement; (2) processing to perform any necessary stage for the fulfillment of the agreement; and (3) to comply with other reasonable instructions provided by the Client to the extent they are consistent with the terms of this Agreement.

Such client data may contain special categories of data, depending on how the Services are used by the Client. Client data may be subject to the following processing activities: (1) storage and other processing necessary for the provision, maintenance, and improvement of the Services provided to the client; (2) to provide the client with technical support; and (3) disclosures as required by law, state regulations, or other objects provided in the agreement.

3. SUB-PROCESSING

The Client agrees that MYGRACE may engage sub-processors to process personal data on behalf of MYGRACE only to provide, improve, and update client services, or only if the transmission of personal data to third-party companies is necessary.

MYGRACE is not obliged to inform the client that data is sent to a third party, with MYGRACE being responsible for the processing of client data. MYGRACE will enter into personal data protection agreements with the contracted third parties.

MYGRACE must: (1) enter into a written agreement with the sub-processor imposing data protection terms that require the sub-processor to protect personal data to the standard required by data protection laws; and (2) remain responsible for compliance with the obligations of this Agreement.

4. SECURITY

MYGRACE must implement and maintain appropriate technical and organizational security measures to protect personal data from security incidents and to preserve the security and confidentiality of personal data, in accordance with the security standards of applicable laws.

MYGRACE ensures that any person authorized by MYGRACE to process personal data (including its personnel, partners, and subcontractors) will be under an appropriate obligation of confidentiality (whether a contractual or legal obligation).

Upon becoming aware of a security incident, MYGRACE will notify the Client without undue delay and will promptly provide information relating to the security incident, as it becomes known or as reasonably requested by the Client.

The Client acknowledges that security measures are subject to technical progress and development, and that MYGRACE may update or modify security measures periodically, provided that such updates and modifications do not result in a degradation of the overall security of the services purchased by the client.

5. SECURITY REPORTS

MYGRACE will further provide written (confidential) responses to all reasonable requests for information made by the Client, including responses to information security and audit questionnaires, which the Client (acting reasonably) deems necessary to confirm MYGRACE's compliance with this Agreement, provided that the Client does not exercise this right more than once per year.

To the extent that the Standard Contractual Clauses apply and the Client reasonably argues and establishes that the above documentation and/or other third-party audit reports are insufficient to demonstrate compliance with the obligations set forth in this agreement, the Client may conduct an audit, provided that, in such a case, the parties agree: (a) the Client is responsible for all costs and fees associated with that audit (including for the time, costs, and materials expended by MYGRACE); (b) a third-party auditor must be mutually agreed upon by the parties to follow standard and appropriate industry audit procedures; (c) such an audit must not unreasonably interfere with MYGRACE's business activities and must be reasonable in time and scope; and (d) the parties must agree on a specific audit plan before such an audit, which must be negotiated in good faith between the parties.

For the avoidance of doubt, nothing in this section modifies or varies the standard contractual clauses, and to the extent that a competent authority determines otherwise or any other part of the section is otherwise prohibited, unenforceable, or inappropriate, given the standard contractual clauses, the sub-section will be removed and its remaining provisions will not be affected.

6. INTERNATIONAL DATA TRANSFERS

MYGRACE may transfer and process client data anywhere in the world where MYGRACE and its sub-processors carry out data processing operations. MYGRACE must implement appropriate methods to protect personal data, whenever processed, in accordance with the requirements of data protection laws.

7. DATA DELETION OR ARCHIVING

Upon termination of services, all personal data will be deleted, except when current legislation obliges MYGRACE to retain clients' personal data for a certain period.

In the case of archiving personal data, MYGRACE undertakes to ensure advanced and updated personal data protection methods to prevent data breaches or losses.

8. CONTACT

MYGRACE, legally represented by S.C. GODDESS INTERNATIONAL S.R.L. can be contacted via:

  • Mail: Bucharest, District 3, Splaiul Unirii, no. 313, ICPE building, M wing, 2nd floor, MYGRACE
  • Contact phone number: 0746 166 732
  • Contact email address: contact@mygrace.ro
  • DPO contact: protectia.datelor@mygrace.ro

In the case of archiving personal data, MYGRACE undertakes to ensure advanced and updated personal data protection methods to prevent data breaches or losses.