Personal-data processor addendum
Contractual framework describing how FYGR (through its OKIMIA tool) processes personal data on behalf of its clients, in accordance with the GDPR.
Introduction
The purpose of this Addendum is to define the conditions under which FYGR SAS (through its OKIMIA tool), acting as a processor and within the scope of the services defined in the document, undertakes to carry out, on behalf of its users, personal-data processing operations in accordance with the applicable provisions on personal-data protection, in particular the amended French Act of 6 January 1978 on information technology, data files and civil liberties, as well as Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, applicable since 25 May 2018 (hereinafter the "GDPR").
For the purposes hereof, FYGR SAS (through its OKIMIA tool) therefore acts as a "processor" in the following cases: when the client stores or gives access to personal information relating to third parties through the use of the Powens, Bridge API or Fintecture service.
The user, for their part, is presumed to act as a "controller" within the meaning of the definitions given by the GDPR.
Within the framework of their contractual relations, the parties each undertake, as regards their own role, to comply with the regulations in force applicable to the processing of personal data.
Article 1. Definitions
Within the framework of their contractual relations, the parties each undertake, as regards their own role, to comply with the regulations in force applicable to the processing of personal data.
Personal data: any information relating to an identified or identifiable natural person (hereinafter referred to as the "data subject"); an "identifiable natural person" is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
Sensitive data or special categories of data: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation. (Article 9 of the GDPR).
Processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing. Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Recipient: the natural or legal person, public authority, agency or any other body to which personal data are disclosed, whether or not a third party. However, public authorities that may receive personal data within the framework of a particular inquiry in accordance with Union or User-State law are not regarded as recipients; the processing of those data by the public authorities in question complies with the applicable data-protection rules according to the purposes of the processing.
Article 2. Description of the processing subject to subcontracting
FYGR (through its OKIMIA tool) is authorized, as a Processor acting on the user's instructions, to process the Controller's Personal Data to the extent necessary to provide the services.
The nature of the operations carried out by FYGR (through its OKIMIA tool) regarding Personal Data may be the storage of information and/or any other service as described in the Terms of Use. The type of Personal Data and the categories of data subjects are determined and controlled by the user, at their sole discretion. The processing activities are carried out by FYGR (through its OKIMIA tool) for the duration set out in the Terms of Use.
Article 3. FYGR's obligations as a processor
As a processor, FYGR (through its OKIMIA tool) undertakes to:
1. Process Personal Data solely for the purpose of carrying out the services;
2. Not access or use Personal Data for purposes other than those necessary to perform the services;
3. Process Personal Data in accordance with the user's documented instructions;
4. Inform the user if, in its opinion and given the information available to it, one of the instructions constitutes a breach of the GDPR or of any other Union or User-State law provision on data protection;
5. Guarantee the confidentiality of the Personal Data processed in the course of carrying out its tasks;
6. Where applicable, ensure that the members of its staff authorized to process Personal Data:
- undertake to respect confidentiality or are subject to an appropriate statutory obligation of confidentiality;
- receive the necessary training in personal-data protection;
7. Take into account, with regard to its tools, products, applications or services, the principles of data protection by design and data protection by default;
8. Sub-processors:
FYGR may engage another processor to process Personal Data in the performance of the services (a "Sub-processor"). The user expressly authorizes FYGR to engage these companies as Sub-processors.
In any event, the Sub-processor is required to comply with the obligations of this contract on behalf of and according to FYGR's instructions. It is FYGR's responsibility to ensure that the Sub-processor provides the same sufficient guarantees as to the implementation of appropriate technical and organizational measures so that the processing meets the requirements of the European data-protection regulation. If the Sub-processor fails to fulfil its data-protection obligations, FYGR remains fully liable to the user for the other processor's performance of its obligations.
9. Data subjects' right to information:
The user, as Controller, is fully responsible for informing data subjects about their rights and for upholding those rights, including the rights of access, rectification, erasure, restriction and portability.
10. Exercise of individuals' rights:
FYGR (through its OKIMIA tool) provides cooperation and assistance, to the extent reasonably necessary, to respond to data subjects' requests. This reasonable cooperation and assistance may consist of (a) communicating to the user any request received directly from the data subject and (b) enabling the Controller to design and deploy the technical and organizational measures necessary to respond to data subjects' requests.
The user, as Controller, is solely responsible for responding to such requests.
The user acknowledges and agrees that, in the event such cooperation and assistance require significant resources from FYGR, this may be billed to the user, provided that the user is notified and gives prior consent.
11. Notification of personal-data breaches:
FYGR (through its OKIMIA tool) undertakes to notify the user by any means of any personal-data breach within a maximum of 72 (seventy-two) hours after becoming aware of it. This notification is accompanied by any relevant documentation to enable the user, if necessary, to notify this breach to the competent supervisory authority (CNIL — the French data-protection authority).
12. FYGR's assistance in the user's compliance with its obligations:
FYGR undertakes, where possible and if necessary, to assist the user in carrying out data-protection impact assessments.
FYGR also undertakes, if necessary, to assist the user in carrying out the prior consultation of the supervisory authority (CNIL).
13. Security measures:
FYGR (through its OKIMIA tool) implements appropriate technical and organizational measures to ensure the security, confidentiality and integrity of data processing and to protect data against destruction, loss, alteration, unauthorized disclosure of personal data transmitted, stored or otherwise processed, or unauthorized access to such data.
14. Fate of the data:
At the end of the service (in particular upon termination of the Terms of Use), FYGR undertakes to delete all content (in particular data, files, etc.) reproduced, stored, hosted or otherwise used by the user within the framework of the services, unless a request issued by a competent legal or judicial authority, or the applicable law of the European Union or of an EU Member State, requires otherwise.
The user is solely responsible for ensuring that the operations necessary (such as backup, transfer to a third-party solution, etc.) to preserve the Personal Data are carried out, in particular before the termination or expiry of the services, and before carrying out any deletion, update or reinstallation of the services.
In this respect, the user is informed that the termination and expiry of the service for any reason whatsoever, as well as certain update or reinstallation operations of the services, may automatically result in the irreversible deletion of any content reproduced, stored, hosted or otherwise used by the user within the framework of the services, including any potential backup.
15. Record of categories of processing activities:
FYGR declares that it keeps a written record of all the categories of processing activities carried out on behalf of the user, comprising:
- the name and contact details of the user on whose behalf it acts, of any sub-processors and, where applicable, of the data protection officer;
- the categories of processing carried out on behalf of the user;
- where applicable, transfers of personal data to a third country or to an international organization, including the identification of that third country or international organization and, in the case of transfers referred to in the second subparagraph of Article 49(1) of the GDPR, the documents attesting to the existence of appropriate safeguards;
- as far as possible, a general description of the technical and organizational security measures.
16. Documentation:
FYGR (through its OKIMIA tool) makes available to its users the documentation necessary to demonstrate compliance with all its obligations and to allow audits, including inspections, by the user or another auditor mandated by them, and to contribute to these audits.
In the context of such audits, the user or the auditor mandated by them will not, however, be authorized to access FYGR's trade secrets, its strategic information, or information that FYGR has undertaken to keep confidential towards its other clients and/or partners. FYGR may object to any control measure by the user or the auditor mandated by them that would be likely to give them access to such data or information. FYGR will furthermore ensure, in any event, that the auditor and, more generally, the staff carrying out the audit are subject to appropriate confidentiality obligations.
Article 4. The user's obligations as controller vis-à-vis FYGR
The user undertakes to comply with the obligations incumbent upon them as controller under the GDPR. In this respect, it is in particular their responsibility to ensure that:
- the processing of personal data has an appropriate legal basis (for example, the data subject's consent, the controller's legitimate interest, or a legal provision, etc.);
- the data-processing records are kept up to date;
- all required formalities and procedures (such as an impact assessment, a notification or a request for authorization to the supervisory authority or any other body) have, where applicable, been carried out;
- data subjects are informed about the processing of personal data in a concise, transparent, intelligible and easily accessible manner;
- data subjects have the opportunity to exercise their rights, as provided for by the GDPR;
- technical and organizational measures are implemented within their own systems and operations that fall outside the scope of the services, in order to ensure the security of personal-data processing.
In addition, the user undertakes to:
- document in writing any instruction concerning the processing of data;
- ensure, beforehand and throughout the duration of the processing, FYGR's compliance with the obligations provided for by the GDPR;
- supervise the processing, including carrying out audits and inspections of FYGR, under the conditions described above.
Questions?
Our team is available to clarify any legal point.