Preamble
This Agreement specifies the obligations of the parties in connection with the Maintenance and Support Agreement/ terms ("Main Contract"). It applies to all activities connected with the performance of the Main Contract in which employees of the Processor or subcontractors appointed by the Processor may come in contact with personal data of the Controller connected with the performance of the Main Contract. Personal data are defined as those data within the meaning of the General Data Protection Regulation ("GDPR").
§1 Purpose and Duration of the Agreement
1.1 The purpose of this Agreement is based on the Main Contract referred to here unless otherwise expressed in more specific terms in Paragraph 2 of this Agreement. This Agreement does not cover activities of the Processor within the business premises of the Controller (e.g. on-site support), for which a separate agreement is to be concluded.
1.2 As part of the Main Contract, the Processor will have no access to the personal data of the Controller from the time the Main Contract starts as such access will not be necessary to fulfil the Main Contract. Instead, the Processor will become active when carrying out the Main Contract only if/when requested by the Controller. Neither will any access to personal data be required for purposes of remote diagnosis; instead, the Processor will be informed of technical problems in a related enquiry.
No personal data will be collected, processed or used at any time under the Main Contract, as access to personal data is not essentially necessary but cannot be ruled out. The parties are concluding this Agreement solely because the possibility of access or becoming aware of personal data cannot be ruled out.
The duration of the Agreement corresponds to the term of the Main Contract. This Agreement will end when the Main Contract ends. The provisions of termination of the Main Contract will apply.
§2 Specifying the Content of the Agreement
2.1 As part of the Main Contract, the Controller will notify the Processor of technical problems connected with the use of Intershop standard software (“software”) by telephone, web form and email (maintenance and/or care of IT systems). If required, the Processor will normally perform a remote diagnosis from the maintenance office at the Controller's premises in Jena.
No remote diagnosis will be commenced unless authorized by the Controller. The software used to do this for any such diagnosis will be configured in such a way that activation by the Controller is required prior to commencing diagnosis. Substantive technical remote diagnosis and, where applicable, problem-solving will be carried out by the Controller and Processor as mutually agreed upon. Desktop access may be set up by the Controller for the Processor. The Controller is entitled to follow the remote diagnosis on a control screen for the duration of the remote diagnosis process and may stop the process at any time. If the Processor is required to assist in this, Controller guarantees to comply with the foregoing.
In line with providing services, Intershop Commerce Insight will provide the Controller with log-files and properties files by means of an SSH connection provided by the Processor. Evaluation will be carried out according to the provisions of the Main Contract.
In cases of unpreventable access to personal data, the Controller will, as part of the Main Contract, ensure in all cases that the Processor only receives such data that it absolutely needs in order to fulfil the Main Contract and that, in particular, the Controller will provide the Processor with only anonymised data for test purposes:
However, the possibility that the Processor might obtain access to the following personal data through the following group of people cannot be ruled out.
2.2 Type of Data
Intershop Communications AG, 2018 Page 2 of 8 The personal data to which access cannot be prevented include contact data, usage data, inventory data such as ordering information (content, quantities etc.), log-data, IP addresses, contract master data, communications data.
2.3 Categories of Data Subjects
The data subjects affected are the Controller's employees, contacts and customers: The data affected are personal information of suppliers, business partners and customers/- Controllers of the Controller.
2.4 It will be assumed that unpreventable access to data of the Controller has been obtained exclusively within the territory of the Federal Republic of Germany, in a member state of the European Union or in another contracting state of the Agreement of the European Economic Zone, unless the Controller has selected the option Support Plus (including the additional After-Hours Emergency Support service) or the individual option After-Hours Emergency Support in the Main Contract. By selecting the aforementioned options, the Controller hereby expressly consents that the services, in particular access to the systems, may also be provided by employees of the Intershop Communications Inc. from the United States. The EU standard contractual clauses were agreed between Intershop Group companies. Any other transfer of data to a third-party country will require the prior consent of the Controller and may only be carried out if the special conditions of Art. 44 ff. DS-GVO have been fulfilled, in particular the conclusion of agreements containing the currently applicable standard clauses of EU agreements or acknowledged alternatives for data transmission to third countries.
§3 Technical-Organisational Measures
3.1 The Processor shall design its internal company organization in such a way that it meets the special requirements of data protection. The Processor has to produce the security according to Art. 28 para. 3 lit. c. and Art. 32 GDPR, especially in connection with Art. 5 para. 1, para. 2 GDPR. Overall, the measures to be taken are data security measures and measures to ensure a level of protection appropriate to the risk in terms of confidentiality, integrity, availability and system resilience. The state of the art, implementation costs and the nature, scope and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons within the meaning of Art. 32 para. 1 GDPR shall be taken into account. For this purpose, the Processor shall in particular take the technical and organizational measures defined in Annex 1 to adequately secure the personal data against misuse and loss.
3.2 The Parties are in agreement that any technical and organizational measures are subject to technical progress and further developments. Insofar the Processor shall be permitted to implement adequate alternative measures. Processor shall notify Controller in due time about it and shall ensure that an anticipated measure does not fall below the safety level of the agreed measure. Any major changes shall be discussed and agreed in advance with Controller, and are to be documented by Processor.
3.3 Controller agrees that for the purpose of fulfilling this Agreement data processing may be performed in private apartments of Processor’s employees, or in the context of telework, as far as such is necessary. Processor shall ensure that for any services rendered or work done in private apartments or through telework, exclusively encoded systems of Processor shall be used (VPN encoding etc.).
§4 Correction, Blocking, Deletion of Data
4.1 The rights of the data subjects affected by the handling of data at the Processor’s premises, in particular with regard to correction, restriction and deletion, shall be asserted against the Controller. The Controller is solely responsible for safeguarding these rights. The Processor may not correct, delete or restrict the processing of personal data on its own initiative, but only in accordance with the documented instructions of the Controller. The Processor shall implement the instructions of the Controller without delay, unless the Processor has a legal obligation to store personal data.
4.2 Processor shall be obligated to immediately forward to Controller any requests of data subjects affected or supervisory authorities addressed to Processor in the context of its commissioning in order to ensure proper processing of such requests. Processor shall be under no obligation to independently decide about such requests without having discussed it with Controller.
4.3 Processor shall, at the Controller’s request and to the best of its ability, assist the Controller in fulfilling the rights of the data subjects affected, in particular with regard to the right to be forgotten and the right to data portability. The correction, restriction and deletion of the data concerned during provision of services shall be made by Processor on behalf of Controller.
4.4 The Processor shall be entitled to compensation for assisting the Controller in safeguarding the rights of the data subjects concerned. Unless otherwise agreed, this shall be based on the time required and the remuneration rates of the Processor's current price list.
§5 Processor’s Duties
5.1 In principle, the Processor does not collect, process and use any personal data within the scope of the Main Contract, however, should such data be collected, processed and used in individual cases, the Processor shall collect, process and use such personal data within the scope of the Main Contract and the specific instructions of the Controller.
5.2 In connection with the fulfilment of the obligation to notify the Controller in accordance with Art. 33 and 34 GDPR, the Processor shall immediately report to the Controller in writing in all cases in which the Processor or the persons or sub-contractors employed by the Processor have violated any regulations for the protection of the Controller’s personal data or the stipulations made in this Agreement. This shall also apply in the event of the loss or unlawful transmission or knowledge of personal data and in the event of serious disruptions to the course of business, suspicion of other violations against regulations for the protection of personal data or other irregularities in dealing with Controller’s personal. This also applies to the case of control actions and measures of the supervisory authority pursuant to Art. 58 GDPR. This shall also apply in so far as a competent supervisory authority carries out an investigation at the Processor’s premises in accordance with Art. 82, 83 GDPR.
5.3 If the Processor culpably violates its obligation to cooperate or fails to comply with its statutory obligations as Processor, fails to comply with the Controller’s lawfully issued instructions or acts against these instructions, it shall be obliged to compensate the damage caused to the Controller as well as to indemnify the Controller against any claims of third parties arising therefrom. This shall not apply if the Processor proves that it is in no way responsible for the circumstances which caused the damage.
5.4 The Processor shall inform the Controller without delay of any control actions and measures taken by the supervisory authority insofar as they relate to this Agreement. This shall also apply to the extent that a competent supervisory authority carries out an investigation in the course of administrative offences or criminal proceedings with regard to the processing of personal data during the order processing by the Processor.
5.5 Insofar as the Controller, for its part, is subject to a control by the supervisory authority, an administrative offence or criminal procedure, a liability claim of a data subject affected or a third party or any other claim in connection with order processing by the Processor, it shall support the Controller to the best of its ability.
5.6 Taking into account the nature of the processing and the information at its disposal, the Processor shall assist the Controller in complying with the statutory obligations set out in Art. 32 to 36 GDPR. These include among others
a. ensuring an adequate level of protection by means of technical and organizational measures which take into account the context and purposes of processing as well as the predicted likelihood and severity of a possible breach of the law due to security gaps and which enable an immediate detection of relevant infringement events,
b. the obligation to report any violations of personal data to the Controller without delay,
c. the obligation to support the Controller within the scope of its obligation to inform the data subjects affected and to provide it with all relevant information without delay in this connection,
d. assisting the Controller in its data protection impact assessment,
e. assisting the Controller in the context of prior consultations with the supervisory authority.
For support services that are not due to the Processor’s malpractice, the Processors may claim compensation for such services. Unless otherwise agreed, this shall be based on the time required and the remuneration rates of the Processor's current price list.
5.7 The Controller is entitled at any time to demand correction, deletion and blocking of personal data.
5.8 After termination of data processing, personal data or data carriers which have been handed over to the Contractor for the fulfilment of its obligations under the Main Contract shall be destroyed or returned in accordance with the instructions of the Controller in accordance with data protection regulations. Copies or duplicates of the data will not be made without the knowledge of the Controller. Excluded from this are backup copies, insofar as they are necessary to warrant proper data processing, as well as data which are necessary with regard to compliance with legal storage obligations.
5.9 The Processor documents the data processing and provides the Controller with the documentation on request.
5.10 The Processor undertakes to maintain a record of processing activities in accordance with Art. 30 para. 2 GDPR. The record shall be kept in writing or in an electronic format and shall be presented to the Controller and/or his data protection officer at any time on request.
§6 Confidentiality
6.1 The Processor warrants that the persons authorized to process personal data have undertaken to maintain data secrecy and confidentiality or are subject to an appropriate statutory duty of confidentiality. The Processor has informed the employees employed by it as a precautionary measure about the observance of telecommunications secrecy pursuant to § 88 TKG (German Telecommunications Act). 6.2 It shall be ensured that the obligation to maintain data secrecy and confidentiality shall continue even after termination of this Agreement.
§7. Data Protection Officer
7.1 The Processor has appointed a data protection officer. This is at the time of conclusion of the contract:
datenschutz nord GmbH
e-mail: Datenschutzbeauftragter@Intershop.de
7.2 The Processor shall notify the Controller immediately in writing of any dismissal or reappointment of the Data Protection Officer.
§8. Transfer to non-EEA countries
8.1 The collection, processing and use of personal data by the Processor shall be restricted to a Member State of the European Union or a contracting state of the Agreement on the European Economic Area, unless the Controller has selected the option Support Plus (including the additional After-Hours Emergency Support service) or the individual option After-Hours Emergency Support in the Main Contract. By selecting the aforementioned options, the Controller hereby expressly consents that the services, in particular access to the systems, may also be provided by employees of the Intershop Communications Inc. from the United States. The EU standard contractual clauses were agreed between Intershop Group companies. Every Any other transfer of personal data by the Processor to an entity located outside the EEA, i. e. a company with its registered office outside the EEA, is only possible subject to compliance with the statutory provisions and the separate written consent of the Controller. Exceptions to this are only possible in the cases mentioned in Art. 28 para. 3 lit. a GDPR under the additional conditions mentioned there.
8.2 If, under the applicable law of a Member State or the European Union, the Processor is obliged to transfer data to an entity located outside the EEA, the Processor shall notify the Controller prior to processing in accordance with its obligation under Article 28 para 3 lit. a GDPR, insofar as the applicable law does not prohibit such notification on account of an important public interest.
§9. Sub-Contracting Relationships
9.1 For the purposes of this provision, sub-contracting relationships shall mean those services which relate directly to the provision of the main service. Services which are rendered by third party companies to Processor as additional services in order to support Processor in fulfilling its duties shall not be considered as sub-contracting relationships. These services shall include, e.g. telecommunication services, maintenance and user services, cleaning services, auditors or disposal of data carriers. However, in the event of additional services provided by third parties, Processor shall be obligated to arrange for appropriate and legally sufficient contractual stipulations in order to ensure protection and safety of Controller’s data.
9.2 The Processor may engage sub-contractors (additional processors) to provide certain or supporting services to the Controller.
The Controller agrees that the Processor shall use affiliated companies of the Processor for the fulfilment of its contractually agreed services or sub-contract other third parties with services if the Processor concludes a contractual agreement with the sub-contractor in accordance with Art. 28 para. 2-4 GDPR, the level of protection of which is at least equivalent to that of this Agreement. The aforementioned authorizations constitute the prior general written consent of the Controller to the subcontracting of the processing of Controller´s Customer Data and Personal Data by the Processor, if such general consent is required under the Standard Contractual Clauses or the provisions of the GDPR.
The Processor may occasionally engage new sub-contractors. The Processor shall inform the Controller of any new sub-contractor at least 1 month before the sub-contractor gains access to Controller´s Data (by providing a mechanism to notify the Controller of such update).
Controller may reasonably object to Processor's use of a new sub-contractor (e.g., if providing personal data to the sub-contractor violates applicable data protection laws or weakens the protection of such personal data) by notifying Processor accordingly in writing without undue delay, but no later than 14 calendar days after Controller becomes aware of such change. Such notice shall be sent to the e-mail address Datenschutzbeauftragter@intershop.de, shall include the date on which the Controller became aware of the new sub-contractor and shall set forth the reasonable grounds for the objection. In the event that Controller objects to a new sub-contractor in accordance with the foregoing, Processor shall use commercially reasonable efforts to provide Controller with a modification to Processor's Services or recommend a commercially reasonable modification to Processor's configuration or use of the services to avoid the processing of Personal Data by the objected-to new sub-contractor without cause.
If the Processor is unable to provide such a change within a reasonable period of time, which shall be 14 calendar days from the date on which the Processor has received written notice from the Controller, each party shall only be entitled to terminate the Main Agreement if the services contractually owed under the Main Agreement can no longer be provided in their essential components.
§10. Control Rights of the Controller
10.1 Prior to the start of data processing by the Processor and then regularly, at its own expense, the Controller shall have the right to carry out an order control in consultation with the Processor with regard to the data processing to be carried out by the Processor or to have it carried out by inspectors to be nominated in individual cases by the Controller, provided that the Controller or the nominated inspectors undertake to conclude a non-disclosure agreement with the Processor or its sub-contractors, unless the nominated inspectors are subject to professional confidentiality obligations. If the inspector ordered by the Controller is in competition with the Processor, the Processor has the right to object. After prior notification in good time (usually at least 2 weeks in advance) the Controller shall have the right to verify compliance with this Agreement by the Processor by carrying out random samples in the Processor’s business operations during normal business hours without disrupting the course of operations. In cases where there is a reasonable suspicion of data protection violations or other disruptions, prior notification is not required. The Controller may normally carry out one control per calendar year. This does not affect the Controller’s right to carry out further controls in the event of special occurrences. The Processor undertakes to provide the Controller, on request, with the information necessary to safeguard its obligation to control its commissioning and to make the corresponding evidence available to the extent possible.
10.2 The Processor shall ensure that the Controller can convince itself of the Processor’s compliance with its obligations pursuant to Article 28 GDPR. Upon request, the Processor shall provide evidence of the implementation of the technical and organizational measures taken.
10.3 The Processor undertakes to provide the Controller, on request, with the information and evidence necessary to safeguard the Controller’s obligation to check the commissioning and, if available, to provide evidence. Evidence of the implementation of suitable measures can also be provided by submitting current certificates and reports from independent auditors (accountants, auditors, data protection officers, IT security department, etc.). This shall also apply in so far as the Processor carries out the control of its sub-contractors on behalf of the Controller.
10.4 If the Controller identifies defects in compliance with technical and organizational measures within the scope of the order control, the Processor shall remedy the defects without delay. The Processor shall bear the costs necessary to remedy the defect. 10.5 The Controller shall inform the Processor immediately of any errors or irregularities found in connection with the remote diagnosis.
§11. Supervisory Rights of Controller
11.1 The Processor collects, processes and uses personal data on behalf of and on instructions from the Controller for the fulfilment of its obligations under the Main Contract. Within the scope of this Agreement, the Controller is solely responsible for complying with the statutory provisions of the data protection laws, in particular for the lawfulness of the data transfer to the Processor and for the lawfulness of data processing ("Controller" within the meaning of Art. 4 No. 7 GDPR).
11.2 The handling of the data takes place exclusively within the framework of the agreements made. The Controller is entitled to issue instructions on the type and scope of data processing with regard to the implementation of data protection requirements, even during the assignment (individual instructions). In each case, the instructions must be given in writing and may not contradict the contractually agreed performance by the Processor. Individual instructions which deviate from the stipulations of this Agreement or contain additional requirements require the prior consent of the Processor.
11.3 Instructions of the Controller are to be documented by the Processor.
11.4 If the Processor is of the opinion that any instructions given by the Controller are contrary to GDPR or other data protection provisions of the European Union or the Member States, it shall inform the Controller thereof in writing. In such cases, the Processor shall be entitled to suspend the execution of the instruction until the Controller confirms or modifies the instruction. However, legal advice and/or legal research by the Processor is not owed.
11.5 The Processor shall not use the data for any other purposes and in particular shall not be entitled to pass on data to third parties. Copies and duplicates will not be made without the Controller`s knowledge. Copies are excluded from this, insofar as they are necessary to guarantee the proper performance of services.
§12. Final Provisions
12.1 Should the Controller’s data be endangered by attachment or seizure, by insolvency or composition proceedings or by other events or measures of third parties, the Processor shall inform the Controller thereof without delay. The Processor shall inform all persons responsible in this context without delay that the sovereignty and ownership of the data shall lie exclusively with the Controller as the "Controller" within the meaning of the GDPR.
12.2 Insofar as costs are incurred within the scope of this order, in particular in connection with supporting actions, the surrender or deletion of data, they shall be borne by the Controller.
12.3 In the event of changes to the actual arrangement of the service relationships between the Parties, the Parties shall adapt the annexes accordingly and exchange them by mutual agreement. With the signing of the amended annex by the Parties, it becomes effective and replaces the existing annex.
12.4 Changes or additions to this Agreement must be made in writing. This applies accordingly to the amendment or cancellation of this written form requirement.
12.5 Changes in the person or the competence of the authorized persons must be communicated to the other Party immediately in writing.
12.6 German law applies, the place of jurisdiction is Jena.
12.7 This Agreement has the following elements:
- Text of the present Agreement
- Annex 1 Technical and Organizational Measures pursuant to Art. 32 GDPR
- Main Contract In the event of ambiguities and/or contradictions between the individual documents or parts of the contract, the components shall apply in descending order.
12.8 This Agreement replaces any previous agreements on data processing according to the German Data Protection Act (BDSG). 12.9 Should individual provisions of this Agreement be or become invalid, the validity of the remaining provisions of this agreement shall remain unaffected. The ineffective provision shall be replaced by an effective provision which comes as close as possible to the economic content of the ineffective provision. The same applies in the case of loopholes.