Data Processing Agreement
Processing of personal data in accordance with Article 28 GDPR
This Data Processing Agreement forms an integral part of the Agreement between the Client and Qteco and applies insofar as Qteco processes personal data on behalf of the Client in the performance thereof. Terms from the General Data Protection Regulation (GDPR) have the same meaning in this agreement.
Article 1Definitions
- GDPR
- Regulation (EU) 2016/679.
- Personal Data
- all data relating to an identified or identifiable natural person that Qteco processes on behalf of the Client.
- Data Subject
- the person to whom Personal Data relates.
- Processing
- any operation relating to Personal Data.
- Data Breach
- a personal data breach as referred to in Article 4(12) GDPR.
- Sub-processor
- a third party engaged by Qteco that processes Personal Data.
Article 2Roles and Subject Matter
- The Client acts as Controller and Qteco as Processor.
- The subject matter, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex A.
- The duration of the Processing is equal to the term of the Agreement.
Article 3Instructions
- Qteco processes Personal Data solely on the basis of the Client's documented Written instructions, including this agreement, save for deviating statutory obligations.
- Qteco shall inform the Client without delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection legislation.
Article 4Purpose of the Processing
Qteco processes Personal Data exclusively for:
- management of IT systems;
- service desk activities;
- cloud management;
- security monitoring;
- backup services;
- support services.
Article 5Security
Qteco takes appropriate technical and organisational measures as referred to in Article 32 GDPR, taking into account the state of the art, including:
- multi-factor authentication (MFA);
- encryption where possible;
- logging and monitoring;
- network segmentation;
- vulnerability management;
- access control on a least-privilege basis.
Article 6Confidentiality
- Qteco ensures that persons who have access to Personal Data have committed themselves to confidentiality or are bound by an appropriate statutory obligation of confidentiality.
- Access is limited to persons for whom it is necessary for the performance of the Agreement.
Article 7Sub-processors
- The Client grants Qteco general authorisation to engage Sub-processors. The Sub-processors engaged at the time of conclusion are listed in Annex B.
- Qteco shall inform the Client In Writing of intended changes concerning Sub-processors. The Client may raise a reasoned objection within 14 days. In the event of a justified objection, the Parties shall enter into consultation.
- Qteco imposes on each Sub-processor the same data protection obligations as laid down in this agreement.
- Qteco remains responsible towards the Client for compliance by the Sub-processor.
Article 8Transfers outside the EEA
- Transfers of Personal Data to countries outside the European Economic Area take place only where an adequate level of protection is ensured on the basis of an adequacy decision, standard contractual clauses (SCCs) or other appropriate safeguards as referred to in Chapter V GDPR.
- Upon request, Qteco shall inform the Client of the transfer mechanisms applied.
Article 9Data Breaches
- Qteco shall notify the Client of a Data Breach without undue delay and at the latest within 48 hours after becoming aware of it.
- The notification shall at least include the nature of the Data Breach, the categories and (approximate) numbers of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed.
- Qteco shall provide the Client with reasonable assistance in the assessment, the notification to the supervisory authority and any communication to Data Subjects. Notifying the authority and the Data Subjects remains the responsibility of the Client.
Article 10Requests from Data Subjects
Qteco shall provide the Client with reasonable assistance with requests concerning:
- access;
- rectification;
- erasure;
- restriction;
- data portability;
- objection.
Requests that Qteco receives directly from a Data Subject are forwarded to the Client without delay and are not answered by Qteco itself, unless legally required.
Article 11Assistance with DPIAs and Prior Consultation
- Taking into account the nature of the Processing and the information available, Qteco shall provide the Client with reasonable assistance with data protection impact assessments (DPIAs) and prior consultations as referred to in Articles 35 and 36 GDPR.
Article 12Audit
- The Client may carry out (or have carried out) a reasonable audit at most once a year, as well as after a serious security incident or at the request of a supervisory authority, subject to prior Written notice of at least two weeks.
- Qteco may instead provide a current independent statement or certification (such as an ISAE 3402 or ISO 27001 report).
- The reasonable costs of an audit carried out at the Client's request outside an established incident shall be borne by the Client.
Article 13Liability
- The liability arrangement in the General Terms and Conditions applies mutatis mutandis to liability under this Data Processing Agreement.
- The Client indemnifies Qteco against claims arising from Qteco acting in accordance with the Client's instructions, save for intent or deliberate recklessness on the part of Qteco.
Article 14Term and Termination
- This agreement ends simultaneously with the Agreement.
- After termination Qteco shall, at the Client's option, delete or return all Personal Data, unless statutory retention obligations require otherwise.
Article 15Final Provision
- In the event of conflict between this Data Processing Agreement and the other parts of the Agreement, this Data Processing Agreement prevails insofar as the processing of Personal Data is concerned.
Annex ASpecification of the Processing
Annex BSub-processors
At the time of conclusion, Qteco uses, among others, the following Sub-processors. Qteco remains responsible for the management of these relationships.
| Sub-processor | Service | Transfer safeguard |
|---|---|---|
| Microsoft | Cloud / Microsoft 365 / Azure | EU data centres / SCCs |
| Cloud / Workspace | SCCs | |
| Amazon Web Services | Cloud infrastructure | EU regions / SCCs |
| CrowdStrike | Endpoint security | SCCs |
| Datto / Kaseya | Backup / RMM | SCCs |
| ConnectWise | Service management / RMM | SCCs |
| Other suppliers | Insofar as necessary for the services | Appropriate safeguards in accordance with Chapter V GDPR |
§Signature
Thus agreed and signed in duplicate: