As of 1 November 2023 we will be changing the PERSONAL DATA PROCESSING AGREEMENT. The current wording, in
effect until 31 October 2023, follows.
At the end of the wording of the current terms and conditions, the
new wording of the PERSONAL DATA PROCESSING AGREEMENT effective from 1 November 2023 follows.
Dear Users, if you collect and process Personal Data of other
persons as their Controller when using Services in connection with
the use of Cloud JABLOTRON
(e.g., if you use storage of photo or video recordings in Cloud
JABLOTRON, allow other Users of Cloud JABLOTRON access your
devices not only during exclusively personal or domestic
activities, or if you are an Installation Partner using the
MyCOMPANY module or a Partner using the JA PARTNER module,
including ARC)), you are subject to an obligation arising from Regulation (EU)
of the European Parliament and of the Council No 2016/679, on the
protection of natural persons with regard to the processing of
personal data and on the free movement of such data
(GDPR) to have, in processing such data when you are using
another person (processor) for processing, a processing
agreement in place. As a Cloud JABLOTRON provider, JABLOTRON
CLOUD Services is such a person with respect to you. .
For this purpose, the text of the Processing Agreement follows,
which you, by providing your consent, enter into with our company
for the processing of the Personal Data in question in Cloud
JABLOTRON. Should you have any reservations to the content of the
Agreement, contact us at
support@jablotron.cz.
If you authorise another User to access your Device and thereby
allow them access the Personal Data recorded by such Device or
if you provide another person with the login credentials to your
Account and thereby allow them access the Personal Data stored
in Cloud JABLOTRON under your Account, you are obliged to inform
that person, at the latest at the time you provide them with
your login credentials, of the obligations relating to the
protection of Personal Data arising from the TCU, the Processing
Agreement and the Applicable Regulations
USERS WHO NOT PROCESS PERSONAL DATA OF OTHER PERSONS IN USING
SERVICES IN CONNECTION WITH THE USE OF CLOUD JABLOTRON OR DO SO
DURING EXCLUSIVELY PERSONAL OR DOMESTIC ACTIVITIES DO NOT ENTER
INTO ANY DATA PROCESSING AGREEMENT WITH OUR COMPANY.
PERSONAL DATA PROCESSING AGREEMENT
entered into in accordance with Art. 28 of Regulation (EU) 28 of the
European Parliament and of the Council 2016/679 of 27 April 2016 on
the protection of natural persons with regard to the processing of
personal data and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation), as amended
(hereinafter also referred to as “GDPR”), this Agreement
hereinafter also referred to as the “Agreement”
-
PARTIES AND THEIR STATUS
-
The Parties are JABLOTRON CLOUD Services s.r.o., .,
reg. No.: 047 86 645, with its registered office at U Přehrady
3204/61, Mšeno nad Nisou, 466 02 Jablonec nad Nisou, Czech
Republic, registered in the Commercial Register administered
by the Regional Court in Ústí nad Labem, section C, file No.
36983, as the data processor (“Processor”), and a User
under the General Terms and Conditions for the Use of Cloud
JABLOTRON (“TCU”) in the position of Personal Data controller
“Controller”).
-
PURPOSE AND SUBJECT-MATTER OF THE AGREEMENT
-
The purpose of this Agreement is to ensure proper and lawful
processing of Personal Data by the Processor for the
Controller and especially to ensure processing in principle on
the basis of documented instructions of the Controller.
-
The Controller collects or otherwise processes Personal Data
when using its Account or using the Services or in connection
with these activities. The subject-matter of this Agreement is
the obligation of the Processor to carry out, under the
conditions and according to the instructions of the
Controller, processing of the Personal Data specified for the
Controller, and the corresponding obligation of the Controller
to provide the Processor with all necessary instructions in a
proper and timely manner. This Agreement is concluded as free
of charge.
-
The Personal Data in question are captured by Software,
Modules and Applications used by the Controller in Cloud
JABLOTRON when using specific Services and when using the
Devices associated with the Services.
-
The scope and type of Personal Data subject to processing as
well as the categories of Data Subjects whose personal data
are processed, and the purpose of processing are specified
below in this Agreement.
-
Purpose of processing. The Processor processes the disclosed
Personal Data only for the purpose of providing the Services
used by the Controller on the basis of a special contractual
arrangement between the Parties, the content of which is set
out in the General Terms and Conditions for the Use of Cloud
JABLOTRON, to which the Controller has consented together with
the conclusion of this Agreement, as well as in the relevant
terms and conditions of provision of each Service. The purpose
of the processing is thus determined by the Controller’s
decision on the use of each Service. Where capitalized terms
in this Agreement are not defined in the Agreement, they have
the meaning specified in the TCU or in the relevant terms and
conditions for the provision of each Service.
-
Scope of processing. The scope of processing is determined by
the technical capabilities of Cloud JABLOTRON, the
functionalities and settings of the relevant Service used by
the Controller. Cloud JABLOTRON includes a database for the
collection and processing of Personal Data necessary for the
provision of individual Services by the Processor to the
Controller in accordance with the TCU.
-
Nature of processing. Processing consists in automatically
storing data containing Personal Data in Cloud JABLOTRON,
backing them up, restoring them and ensuring access to such
data by authorised persons in accordance with the TCU and the
technical set-up of Cloud JABLOTRON.
-
PROCESSING OF PERSONAL DATA IN CONNECTION WITH THE MYJABLOTRON
SERVICE
-
The purpose of Personal Data Processing for the Controller in
the MyJABLOTRON Service is:
-
technical support of the Controller’s ability to grant
access to its Devices to other Users;
-
processing of photographic records taken by the
Controller’s Devices according to the set-up of each
Device; and
-
processing of events received to Cloud JABLOTRON from
individual Devices.
-
Furthermore, in the use of the MyCOMPANY Module, the Purpose
of Personal Data Processing is:
- management of End Users’ Devices;
- management of customer portfolio;
-
communication or conduct of the Controller towards the
Processor or Related Parties;
-
access to technical support resources of the Provider and
Related parties, including technical materials and
software tools for setting up and servicing Devices;
- management of offers for Device installation;
-
use of bonus offers, ordering Devices and services from
the Controller or Related Parties.
-
Furthermore, in the use of the JA PARTNER Module, the Purpose
of Personal Data Processing is:
-
setting up, activation, configuration and, where
applicable, deactivation and cancellation of Accounts of
Installation Partners, Installers and, in some cases, End
Users;
-
registration of Devices to Cloud JABLOTRON and their
decommissioning;
-
setting up or terminating communication of registered
Devices to Cloud JABLOTRON;
- remote configuration of Devices;
-
remote execution of tasks for Installation Partners and
their cooperating Installers and End Users;
-
granting other Users the authority to set up Account of
End Users and other persons and where the Processor has
agreed with the Controller:
- operation of the Alarm Receiving Center (ARC);
-
enabling access to technical support resources of the
Provider and Related parties;
-
provision of information about the availability of
individual Cloud JABLOTRON services.
-
In providing the MyJABLOTRON Service to the Controller, the
Processor processes, depending on the settings of the
Controller’s Account and the manner and extent of the
Controller’s use of the Service:
-
the following types of Personal Data:
-
ID of another User to whom the Controller has granted
permission to access the Device;
-
email address of another User to whom the Controller
has granted permission to access the Device; and
-
photographic records from the Device (the appearance
of a natural person);
- records of events detected by the Device,
-
the following Data Subjects:
-
another User to whom the Controller has granted
permission to access the Device;
- a natural person recorded by the Device;
- a natural person handling the Device.
-
In the event that the Controller also uses the MyCOMPANY
Module as part of the MyJABLOTRON Service, the Processor also
processes, in providing the MyJABLOTRON Service based on the
setup of the Controller’s Account and on the way the
Controller uses the Service:
-
the following types of Personal Data:
- name and surname;
- date of birth;
- phone number;
- address;
- email address;
- Reg. No.;
- VAT reg. No.;
- phone number of the Device;
- registration code of the Device;
- IP address;
- User ID;
-
photos of the premises, including the physical
appearance of persons depicted in them;
- GPS of the guarded premises;
- address of the guarded premises;
- description of the guarded premises:
- vehicle registration number,
-
the following Data Subjects:
-
natural person – a potential customer of the
Controller;
- natural person – a customer of the Controller;
- natural person – an employee of the Controller;
-
In the event that the Controller also uses the JA PARTNER
Module as part of the MyJABLOTRON Service, the Processor also
processes, in providing the MyJABLOTRON Service based on the
setup of the Controller’s Account and on the way the
Controller uses the Service:
-
the following types of Personal Data:
- name and surname;
- date of birth;
- phone number;
- address;
- email address;
- Reg. No.;
- VAT reg. No.;
- phone number of the Device;
- registration code of the Device;
- IP address;
- User ID;
- GPS of the guarded premises;
- address of the guarded premises;
- description of the guarded premises:
- vehicle registration number,
- physical appearance of persons;
- video recordings made by the Device;
-
physical appearance of persons depicted in them; and
-
if the ARC Service is also used, photos of the
premises, including the physical appearance of the
people depicted in them,
-
the following Data Subjects:
-
natural person – a potential customer of the
Controller;
- natural person – a customer of the Controller;
- natural person – an employee of the Controller;
-
PROCESSING OF PERSONAL DATA IN CONNECTION WITH VIDEO
SERVICES
-
The purpose of the processing of Personal Data in the context
of the acquisition of Video Sequences and other recordings in
the context of the Video Services (currently LIVE, LIVE+,
RECORD3 and RECORD7) is to use the information and recordings
to identify individuals in connection with certain actions
captured by the Camera based on the activation of the
recording system according to the Controller’s settings.
-
In providing the Video Services, the Processor processes,
depending on the settings of the Controller’s Account and the
manner of the Controller’s use of the Service:
-
the following types of Personal Data:
-
video recordings showing the physical appearance of
persons in the monitored areas;
-
information on the movement and location of persons;
- vehicle registration numbers;
- User ID;
- Device location;
- MAC address of the Device;
- Device name,
-
the following Data Subjects:
-
a natural person whose physical appearance is captured
by the Controller’s Device.
-
PERSONAL DATA PROCESSING IN CONNECTION WITH THE DRIVER’S LOG
SERVICE
-
The purpose of Personal Data processing in the context of the
Driver’s Log Service is in particular the protection and
management of property and the keeping of records of journeys
in accordance with tax regulations, occupational health
regulations or other generally binding legal regulations.
-
In providing the Driver’s Log Service, the Processor
processes, depending on the settings of the Controller’s
Account and the manner of the Controller’s use of the Service:
-
the following types of Personal Data
- driver’s log data and their history;
- vehicle traffic data, including location data;
-
name and surname of the person to whom the vehicle has
been entrusted,
-
the following Data Subjects:
-
natural person who uses the vehicle for which the
Controller uses the Driver’s Log Service.
-
OBLIGATIONS OF THE CONTROLLER
-
The Controller undertakes to:
-
process only Personal Data for the processing of which the
Controller has a legal basis under the Applicable
Regulations;
-
collect and process only Personal Data that are accurate
and fit for purpose and the scope is necessary to fulfil
the stated purpose;
-
fulfil its obligation to inform all Data Subjects whose
Personal Data are processed and to provide the Data
Subjects with all information in a concise, transparent,
easy to understand and easily accessible manner using
clear and plain language, and to make all communications
required by the GDPR and other Applicable Regulations;
- act as a point of contact for Data Subjects;
-
bear liability for the conduct of persons to whom the
Controller provided permission to the Controller’s Account
and Applications, in particular, for the fact they will
act in accordance with Applicable Regulations, this
Agreement and the TCU.
-
OBLIGATIONS OF THE PROCESSOR
-
The Processor undertakes to:
-
process Personal Data only on the basis of documented
instructions from the Controller in the form of its
settings in the Account, within the technical capabilities
of Cloud JABLOTRON;
-
maintain confidentiality about the Personal Data
processed, in particular not to publish, disseminate or
disclose Personal Data to other persons except persons
employed by the Processor or other authorised persons
entrusted with the processing of Personal Data in
accordance with this Agreement;
-
ensure that all persons involved in the processing are
bound by confidentiality obligations, including
Processor’s employees and other processors;
-
adopt technical and organisational measures taking into
account the nature of the processing in order to enable
the Controller to respect the rights of the Data Subjects
and to achieve security for the Personal Data processed,
in particular to prevent unauthorised or random access to,
alteration, destruction or loss of Personal Data,
unauthorised transfers, other unauthorised processing of
the data as well as other misuse, and to ensure, in terms
of staff and organisational measures, that all obligations
of the Data Processor arising from the Applicable Data
Protection Regulations;
- keep records of the processing;
-
dispose of the results of the processing and all media
containing Personal Data and delete existing copies no
later than one month after the termination of this
Agreement, with the exception of Personal Data contained
in backups not searchable without the data being recovered
and with their own erasure period set, and Personal Data
the Processor is authorised to process by law;
-
notify the Controller without undue delay if the Processor
finds that the Controller is in breach of the Controller’s
obligations as stipulated by the Applicable Data
Protection Regulations;
-
at the request of the Controller, at any time allow an
audit or inspection regarding the processing of Personal
Data, whereby this step will be charged at an hourly rate
according to the Processor’s current price list;
-
assist the Controller in ensuring compliance with the
obligations under Articles 32 to 36 of the GDPR
(especially the security of processing, reporting of data
breaches, Personal Data impact assessment, and previous
consultation);
-
provide the Controller with all the information needed to
show that the obligations set out in Article 28 of the
GDPR have been met, and allow audits, including
inspections, performed by the Controller or by another
auditor commissioned by the Controller, and contribute to
such audits.
-
The Processor will ensure at least the following technical and
organisational measures:
-
protection of access rights to personal data in the Cloud
JABLOTRON so that unauthorised persons do not gain access
to it and cannot use it;
-
regular backup of data related to personal data in Cloud
JABLOTRON;
-
adequate measures against data loss, data unavailability
or malware infection;
-
encryption of data containing Personal Data and, if
encryption is not possible for some data, setting a policy
for access and other rights;
-
adoption and continuous verification (audit) of measures
to ensure confidentiality, integrity, availability and
resilience of Cloud JABLOTRON and the Services provided;
-
adoption and continuous verification (audit) of measures
to ensure timely availability and access to Personal Data
in the event of a physical or technical incident;
-
creation and verification (audit) of processes for regular
testing, evaluation and assessment of the effectiveness of
technical and organizational measures to ensure the
security of processing of Cloud JABLOTRON and the Services
provided;
-
location of all Personal Data media in a locked
environment sufficiently protected against physical access
by unauthorised persons, including premises where the
servers on which the data containing Personal Data are
stored are located;
-
ensuring access to Personal Data stored on electronic
media exclusively to authorised persons and exclusively
through individual login credentials demonstrably issued
to authorised persons, and with division of user roles
according to the rights of persons accessing the Personal
Data;
-
allowing remote access to Personal Data only from secure
end devices via encrypted communication.
-
OTHER PROVISIONS ON THE PROCESSING OF PERSONAL DATA
-
The Parties undertake to notify each other without delay of
any facts known to them which could adversely affect the
proper and timely performance of the obligations arising from
this Agreement.
-
In the event of a security breach of the data processed,
unauthorised or random access to Personal Data, destruction or
loss, unauthorised transmission or other unauthorised
processing or misuse, the Processor is obliged to inform the
Controller without delay and is obliged to take urgent
measures to remedy the defective condition. The Processor is
obliged to inform the Controller immediately in writing, by
email or by text message about the measures taken.
-
The Processor declares that the protection of personal data is
subject to the Processor’s internal security regulations
within its information security management system, which is
substantially based on the security requirements of ISO 27001.
-
Processing of Personal Data by the Processor takes place
exclusively in the territory of the European Union or the
European Economic Area.
-
The Controller authorises the Processor to engage other
processors in processing; their selection is the
responsibility of the Processor and is not dependent on an
additional specific approval by the Controller. The Processor
must ensure that the same obligations the Processor has under
this Agreement also apply to the other processor.
-
At present, the Processor uses the following other
processors:
-
providers of development and servicing services
relating to Cloud JABLOTRON;
-
operators of data centers used by the Processor;
-
providers of data and internet connectivity of the
Processor.
-
The Parties agree that the Processor’s liability for damage
caused in or in connection with the performance of this
Agreement is limited to an amount corresponding to the sum of
payments made by the Processor to the Controller for the
provision of the Services in accordance with the TCU in the
six months from the occurrence of such damage
-
FINAL PROVISIONS
-
This Agreement comes into force and effect on the date of the
Controller’s provision of consent to its electronic version.
-
This Agreement is concluded for the duration of the
contractual relationship between the Parties established by
the acceptance of the TCU by the Controller. Termination of
the contractual relationship between the Parties established
by the Controller’s acceptance of the TCU will also
automatically result in the termination of the contractual
relationship between the Controller and the Processor under
this Agreement. In the event of termination of the contractual
relationship, the Processor’s obligation to process Personal
Data for the Controller on the basis of this Agreement will
cease at the time of disposal of the processed Personal Data
in accordance with this Agreement.
-
In the event of any discrepancies between the TCU and this
Agreement, this Agreement will prevail.
-
This Agreement constitutes a complete agreement between the
Parties in relation to the subjectmatter of this Agreement and
supersedes any prior arrangements regarding the subject-
matter of this Agreement.
-
The legal relations established by this Agreement are governed
by the legal order governing the TCU.
-
The Parties expressly declare that they have been well
acquainted with the contents of the Agreement in its entirety,
the Agreement reflects the Parties' true and free will. In
witness of their agreement, the Parties replace their
signatures with electronic means.
Dear Users, if you collect and process Personal Data of other
persons as their Controller when using Services in connection with
the use of Cloud JABLOTRON
(e.g., if you use storage of photo or video recordings in Cloud
JABLOTRON, allow other Users of Cloud JABLOTRON access your
devices not only during exclusively personal or domestic
activities, or if you are an Installation Partner using the
MyCOMPANY module or a Partner using the JA PARTNER module,
including ARC), you are subject to an obligation arising from Regulation (EU)
of the European Parliament and of the Council No 2016/679, on the
protection of natural persons with regard to the processing of
personal data and on the free movement of such data
(GDPR) to have, in processing such data when you are using
another person (processor) for processing, a processing
agreement in place. As a Cloud JABLOTRON provider, JABLOTRON
CLOUD Services is such a person with respect to you. .
For this purpose, the text of the Processing Agreement follows,
which you, by providing your consent, enter into with our company
for the processing of the Personal Data in question in Cloud
JABLOTRON. Should you have any reservations to the content of the
Agreement, contact us at
support@jablotron.cz.
If you authorise another User to access your Device and thereby
allow them access the Personal Data recorded by such Device or
if you provide another person with the login credentials to your
Account and thereby allow them access the Personal Data stored
in Cloud JABLOTRON under your Account, you are obliged to inform
that person, at the latest at the time you provide them with
your login credentials, of the obligations relating to the
protection of Personal Data arising from the TCU, the Processing
Agreement and the Applicable Regulations
USERS WHO NOT PROCESS PERSONAL DATA OF OTHER PERSONS IN USING
SERVICES IN CONNECTION WITH THE USE OF CLOUD JABLOTRON OR DO SO
DURING EXCLUSIVELY PERSONAL OR DOMESTIC ACTIVITIES DO NOT ENTER
INTO ANY DATA PROCESSING AGREEMENT WITH OUR COMPANY.
PERSONAL DATA PROCESSING AGREEMENT
entered into in accordance with Art. 28 of Regulation (EU) 28 of the
European Parliament and of the Council 2016/679 of 27 April 2016 on
the protection of natural persons with regard to the processing of
personal data and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation), as amended
(hereinafter also referred to as “GDPR”), this Agreement
hereinafter also referred to as the “Agreement”
-
PARTIES AND THEIR STATUS
-
The Parties are JABLOTRON CLOUD Services s.r.o., .,
reg. No.: 047 86 645, with its registered office at U Přehrady
3204/61, Mšeno nad Nisou, 466 02 Jablonec nad Nisou, Czech
Republic, registered in the Commercial Register administered
by the Regional Court in Ústí nad Labem, section C, file No.
36983, as the data processor (“Processor”), and a User
under the General Terms and Conditions for the Use of Cloud
JABLOTRON (“TCU”) in the position of Personal Data controller
“Controller”).
-
PURPOSE AND SUBJECT-MATTER OF THE AGREEMENT
-
The purpose of this Agreement is to ensure proper and lawful
processing of Personal Data by the Processor for the
Controller and especially to ensure processing in principle on
the basis of documented instructions of the Controller.
-
The Controller collects or otherwise processes Personal Data
when using its Account or using the Services or in connection
with these activities. The subject-matter of this Agreement is
the obligation of the Processor to carry out, under the
conditions and according to the instructions of the
Controller, processing of the Personal Data specified for the
Controller, and the corresponding obligation of the Controller
to provide the Processor with all necessary instructions in a
proper and timely manner. This Agreement is concluded as free
of charge.
-
The Personal Data in question are captured by Software,
Modules and Applications used by the Controller in Cloud
JABLOTRON when using specific Services and when using the
Devices associated with the Services.
-
The scope and type of Personal Data subject to processing as
well as the categories of Data Subjects whose personal data
are processed, and the purpose of processing are specified
below in this Agreement.
-
Purpose of processing. The Processor processes the disclosed
Personal Data only for the purpose of providing the Services
used by the Controller on the basis of a special contractual
arrangement between the Parties, the content of which is set
out in the General Terms and Conditions for the Use of Cloud
JABLOTRON, to which the Controller has consented together with
the conclusion of this Agreement, as well as in the relevant
terms and conditions of provision of each Service. The purpose
of the processing is thus determined by the Controller’s
decision on the use of each Service. Where capitalized terms
in this Agreement are not defined in the Agreement, they have
the meaning specified in the TCU or in the relevant terms and
conditions for the provision of each Service.
-
Scope of processing. The scope of processing is determined by
the technical capabilities of Cloud JABLOTRON, the
functionalities and settings of the relevant Service used by
the Controller. Cloud JABLOTRON includes a database for the
collection and processing of Personal Data necessary for the
provision of individual Services by the Processor to the
Controller in accordance with the TCU.
-
Nature of processing. Processing consists in automatically
storing data containing Personal Data in Cloud JABLOTRON,
backing them up, restoring them and ensuring access to such
data by authorised persons in accordance with the TCU and the
technical set-up of Cloud JABLOTRON.
-
PROCESSING OF PERSONAL DATA IN CONNECTION WITH THE MYJABLOTRON
SERVICE
-
The purpose of Personal Data Processing for the Controller in
the MyJABLOTRON Service is:
-
technical support of the Controller’s ability to grant
access to its Devices to other Users;
-
processing of photographic records taken by the
Controller’s Devices according to the set-up of each
Device; and
-
processing of events received to Cloud JABLOTRON from
individual Devices.
-
Furthermore, in the use of the MyCOMPANY Module, the Purpose
of Personal Data Processing is:
- management of End Users’ Devices;
- management of customer portfolio;
-
communication or conduct of the Controller towards the
Processor or Related Parties;
-
access to technical support resources of the Provider and
Related parties, including technical materials and
software tools for setting up and servicing Devices;
- management of offers for Device installation;
-
use of bonus offers, ordering Devices and services from
the Controller or Related Parties.
-
Furthermore, in the use of the JA PARTNER Module, the Purpose
of Personal Data Processing is:
-
setting up, activation, configuration and, where
applicable, deactivation and cancellation of Accounts of
Installation Partners, Installers and, in some cases, End
Users;
-
registration of Devices to Cloud JABLOTRON and their
decommissioning;
-
setting up or terminating communication of registered
Devices to Cloud JABLOTRON;
- remote configuration of Devices;
-
remote execution of tasks for Installation Partners and
their cooperating Installers and End Users;
-
granting other Users the authority to set up Account of
End Users and other persons and where the Processor has
agreed with the Controller:
- operation of the Alarm Receiving Center (ARC);
-
enabling access to technical support resources of the
Provider and Related parties;
-
provision of information about the availability of
individual Cloud JABLOTRON services.
-
In providing the MyJABLOTRON Service to the Controller, the
Processor processes, depending on the settings of the
Controller’s Account and the manner and extent of the
Controller’s use of the Service:
-
the following types of Personal Data:
-
ID of another User to whom the Controller has granted
permission to access the Device;
-
email address of another User to whom the Controller
has granted permission to access the Device; and
-
photographic records from the Device (the appearance
of a natural person);
- records of events detected by the Device,
-
the following Data Subjects:
-
another User to whom the Controller has granted
permission to access the Device;
- a natural person recorded by the Device;
- a natural person handling the Device.
-
In the event that the Controller also uses the MyCOMPANY
Module as part of the MyJABLOTRON Service, the Processor also
processes, in providing the MyJABLOTRON Service based on the
setup of the Controller’s Account and on the way the
Controller uses the Service:
-
the following types of Personal Data:
- name and surname;
- date of birth;
- phone number;
- address;
- email address;
- Reg. No.;
- VAT reg. No.;
- phone number of the Device;
- registration code of the Device;
- IP address;
- User ID;
-
photos of the premises, including the physical
appearance of persons depicted in them;
- GPS of the guarded premises;
- address of the guarded premises;
- description of the guarded premises:
- vehicle registration number,
-
the following Data Subjects:
-
natural person – a potential customer of the
Controller;
- natural person – a customer of the Controller;
- natural person – an employee of the Controller;
-
In the event that the Controller also uses the JA PARTNER
Module as part of the MyJABLOTRON Service, the Processor also
processes, in providing the MyJABLOTRON Service based on the
setup of the Controller’s Account and on the way the
Controller uses the Service:
-
the following types of Personal Data:
- name and surname;
- date of birth;
- phone number;
- address;
- email address;
- Reg. No.;
- VAT reg. No.;
- phone number of the Device;
- registration code of the Device;
- IP address;
- User ID;
- GPS of the guarded premises;
- address of the guarded premises;
- description of the guarded premises:
- vehicle registration number,
- physical appearance of persons;
- video recordings made by the Device;
-
physical appearance of persons depicted in them; and
-
if the ARC Service is also used, photos of the
premises, including the physical appearance of the
people depicted in them,
-
the following Data Subjects:
-
natural person – a potential customer of the
Controller;
- natural person – a customer of the Controller;
- natural person – an employee of the Controller;
-
PROCESSING OF PERSONAL DATA IN CONNECTION WITH VIDEO
SERVICES
-
The purpose of the processing of Personal Data in the context
of the acquisition of Video Sequences and other recordings in
the context of the Video Services (currently LIVE, LIVE+,
RECORD3 and RECORD7) is to use the information and recordings
to identify individuals in connection with certain actions
captured by the Camera based on the activation of the
recording system according to the Controller’s settings.
-
In providing the Video Services, the Processor processes,
depending on the settings of the Controller’s Account and the
manner of the Controller’s use of the Service:
-
the following types of Personal Data:
-
video recordings showing the physical appearance of
persons in the monitored areas;
-
information on the movement and location of persons;
- vehicle registration numbers;
- User ID;
- Device location;
- MAC address of the Device;
- Device name,
-
the following Data Subjects:
-
a natural person whose physical appearance is captured
by the Controller’s Device.
-
PERSONAL DATA PROCESSING IN CONNECTION WITH THE DRIVER’S LOG
SERVICE
-
The purpose of Personal Data processing in the context of the
Driver’s Log Service is in particular the protection and
management of property and the keeping of records of journeys
in accordance with tax regulations, occupational health
regulations or other generally binding legal regulations.
-
In providing the Driver’s Log Service, the Processor
processes, depending on the settings of the Controller’s
Account and the manner of the Controller’s use of the Service:
-
the following types of Personal Data
- driver’s log data and their history;
- vehicle traffic data, including location data;
-
name and surname of the person to whom the vehicle has
been entrusted,
-
the following Data Subjects:
-
natural person who uses the vehicle for which the
Controller uses the Driver’s Log Service.
-
PERSONAL DATA PROCESSING IN THE NOTIFICATION SERVICE
-
The purpose of Personal Data processing in the Notification
Service is to inform the User and other natural persons
selected by the User of events registered by the Device using
a Notification in the form of an SMS, voice notification, push
notification or Email.
-
In providing the Notification Service, the Processor
processes, based on the settings of the Controller’s Account
and on the manner of use of the Service by the Controller:
-
the following types of Personal Data:
- phone number;
- email;
-
of the following Data Subjects:
-
a natural person whose contact information was
provided by the Controller for the sending of the
Notification.
-
OBLIGATIONS OF THE CONTROLLER
-
The Controller undertakes to:
-
process only Personal Data for the processing of which the
Controller has a legal basis under the Applicable
Regulations;
-
collect and process only Personal Data that are accurate
and fit for purpose and the scope is necessary to fulfil
the stated purpose;
-
fulfil its obligation to inform all Data Subjects whose
Personal Data are processed and to provide the Data
Subjects with all information in a concise, transparent,
easy to understand and easily accessible manner using
clear and plain language, and to make all communications
required by the GDPR and other Applicable Regulations;
- act as a point of contact for Data Subjects;
-
bear liability for the conduct of persons to whom the
Controller provided permission to the Controller’s Account
and Applications, in particular, for the fact they will
act in accordance with Applicable Regulations, this
Agreement and the TCU.
-
OBLIGATIONS OF THE PROCESSOR
-
The Processor undertakes to:
-
process Personal Data only on the basis of documented
instructions from the Controller in the form of its
settings in the Account, within the technical capabilities
of Cloud JABLOTRON;
-
maintain confidentiality about the Personal Data
processed, in particular not to publish, disseminate or
disclose Personal Data to other persons except persons
employed by the Processor or other authorised persons
entrusted with the processing of Personal Data in
accordance with this Agreement;
-
ensure that all persons involved in the processing are
bound by confidentiality obligations, including
Processor’s employees and other processors;
-
adopt technical and organisational measures taking into
account the nature of the processing in order to enable
the Controller to respect the rights of the Data Subjects
and to achieve security for the Personal Data processed,
in particular to prevent unauthorised or random access to,
alteration, destruction or loss of Personal Data,
unauthorised transfers, other unauthorised processing of
the data as well as other misuse, and to ensure, in terms
of staff and organisational measures, that all obligations
of the Data Processor arising from the Applicable Data
Protection Regulations;
- keep records of the processing;
-
dispose of the results of the processing and all media
containing Personal Data and delete existing copies no
later than one month after the termination of this
Agreement, with the exception of Personal Data contained
in backups not searchable without the data being recovered
and with their own erasure period set, and Personal Data
the Processor is authorised to process by law;
-
notify the Controller without undue delay if the Processor
finds that the Controller is in breach of the Controller’s
obligations as stipulated by the Applicable Data
Protection Regulations;
-
at the request of the Controller, at any time allow an
audit or inspection regarding the processing of Personal
Data, whereby this step will be charged at an hourly rate
according to the Processor’s current price list;
-
assist the Controller in ensuring compliance with the
obligations under Articles 32 to 36 of the GDPR
(especially the security of processing, reporting of data
breaches, Personal Data impact assessment, and previous
consultation);
-
provide the Controller with all the information needed to
show that the obligations set out in Article 28 of the
GDPR have been met, and allow audits, including
inspections, performed by the Controller or by another
auditor commissioned by the Controller, and contribute to
such audits.
-
The Processor will ensure at least the following technical and
organisational measures:
-
protection of access rights to personal data in the Cloud
JABLOTRON so that unauthorised persons do not gain access
to it and cannot use it;
-
regular backup of data related to personal data in Cloud
JABLOTRON;
-
adequate measures against data loss, data unavailability
or malware infection;
-
encryption of data containing Personal Data and, if
encryption is not possible for some data, setting a policy
for access and other rights;
-
adoption and continuous verification (audit) of measures
to ensure confidentiality, integrity, availability and
resilience of Cloud JABLOTRON and the Services provided;
-
adoption and continuous verification (audit) of measures
to ensure timely availability and access to Personal Data
in the event of a physical or technical incident;
-
creation and verification (audit) of processes for regular
testing, evaluation and assessment of the effectiveness of
technical and organizational measures to ensure the
security of processing of Cloud JABLOTRON and the Services
provided;
-
location of all Personal Data media in a locked
environment sufficiently protected against physical access
by unauthorised persons, including premises where the
servers on which the data containing Personal Data are
stored are located;
-
ensuring access to Personal Data stored on electronic
media exclusively to authorised persons and exclusively
through individual login credentials demonstrably issued
to authorised persons, and with division of user roles
according to the rights of persons accessing the Personal
Data;
-
allowing remote access to Personal Data only from secure
end devices via encrypted communication.
-
OTHER PROVISIONS ON THE PROCESSING OF PERSONAL DATA
-
The Parties undertake to notify each other without delay of
any facts known to them which could adversely affect the
proper and timely performance of the obligations arising from
this Agreement.
-
In the event of a security breach of the data processed,
unauthorised or random access to Personal Data, destruction or
loss, unauthorised transmission or other unauthorised
processing or misuse, the Processor is obliged to inform the
Controller without delay and is obliged to take urgent
measures to remedy the defective condition. The Processor is
obliged to inform the Controller immediately in writing, by
email or by text message about the measures taken.
-
The Processor declares that the protection of personal data is
subject to the Processor’s internal security regulations
within its information security management system, which is
substantially based on the security requirements of ISO 27001.
-
Processing of Personal Data by the Processor takes place
exclusively in the territory of the European Union or the
European Economic Area.
-
The Controller authorises the Processor to engage other
processors in processing; their selection is the
responsibility of the Processor and is not dependent on an
additional specific approval by the Controller. The Processor
must ensure that the same obligations the Processor has under
this Agreement also apply to the other processor.
-
At present, the Processor uses the following other
processors:
-
providers of development and servicing services
relating to Cloud JABLOTRON;
-
operators of data centers used by the Processor;
-
providers of data and internet connectivity of the
Processor.
-
The Parties agree that the Processor’s liability for damage
caused in or in connection with the performance of this
Agreement is limited to an amount corresponding to the sum of
payments made by the Processor to the Controller for the
provision of the Services in accordance with the TCU in the
six months from the occurrence of such damage
-
FINAL PROVISIONS
-
This Agreement comes into force and effect on the date of the
Controller’s provision of consent to its electronic version.
-
This Agreement is concluded for the duration of the
contractual relationship between the Parties established by
the acceptance of the TCU by the Controller. Termination of
the contractual relationship between the Parties established
by the Controller’s acceptance of the TCU will also
automatically result in the termination of the contractual
relationship between the Controller and the Processor under
this Agreement. In the event of termination of the contractual
relationship, the Processor’s obligation to process Personal
Data for the Controller on the basis of this Agreement will
cease at the time of disposal of the processed Personal Data
in accordance with this Agreement.
-
In the event of any discrepancies between the TCU and this
Agreement, this Agreement will prevail.
-
This Agreement constitutes a complete agreement between the
Parties in relation to the subjectmatter of this Agreement and
supersedes any prior arrangements regarding the subject-
matter of this Agreement.
-
The legal relations established by this Agreement are governed
by the legal order governing the TCU.
-
The Parties expressly declare that they have been well
acquainted with the contents of the Agreement in its entirety,
the Agreement reflects the Parties' true and free will. In
witness of their agreement, the Parties replace their
signatures with electronic means.