Data Processing Agreement (DPA)
Effective Date:
23/09/2024
Serviks LTD (trading as ServX)
Company Registration Number: 15556128
Address: 167-169 Great Portland Street, London, England, W1W
5PF
This Data Processing Agreement ("DPA") is entered into by and between Serviks LTD (trading as ServX) and the User (referred to as the "Data Processor") and governs the processing of personal data on behalf of ServX in compliance with GDPR (General Data Protection Regulation).
-
Definitions
- Personal Data: Any information relating to an identified or identifiable natural person, as defined under GDPR.
- Processing: Any operation performed on personal data, such as collection, storage, retrieval, or deletion.
- Controller: ServX, the entity that determines the purposes and means of processing personal data.
- Processor: The User, who processes personal data on behalf of ServX.
- Data Subject: Any natural person whose personal data is processed under this DPA.
-
Roles and Responsibilities
- ServX as Controller: ServX acts as the Data Controller and determines the purposes and means of processing personal data through the app or services provided.
- User as Processor: The User acts as the Data Processor, responsible for processing data according to ServX’s instructions under this DPA and GDPR.
-
Data Processing Instructions
- Processing Scope: The Processor agrees to process personal data only for purposes outlined by ServX and as necessary to fulfill obligations in the License Agreement.
-
Data Types Processed: The
User may process the following types of personal data:
- Device information (e.g., device model, operating system)
- IP addresses
- User activity logs
- Account and payment data
- Duration of Processing: The Processor shall process the data for the duration of the service agreement or until this DPA is terminated.
-
Data Subject Rights
- Access Requests: The User agrees to assist ServX in responding to requests from Data Subjects, including requests to access, correct, or delete personal data.
- Rectification and Deletion: If a Data Subject requests rectification or deletion, the Processor must act promptly and inform ServX.
-
Security Measures
- Confidentiality: The Processor agrees to implement and maintain technical and organizational measures to ensure the confidentiality and security of personal data, including encryption, access control, and regular penetration tests.
- Data Breaches: The Processor agrees to notify ServX within 48 hours of becoming aware of any data breach affecting personal data.
-
Subprocessing
- Subprocessor Engagement: The Processor shall not engage third parties for data processing without the prior written consent of ServX.
- Subprocessor Obligations: The Processor ensures that all subprocessors comply with GDPR, including confidentiality, security measures, and audit cooperation.
- Responsibilities: The Processor remains liable for any acts or omissions of the subprocessor.
-
International Data Transfers
- Data Transfers: Personal data shall not be transferred outside of the European Economic Area (EEA) unless appropriate safeguards (e.g., Standard Contractual Clauses) are in place, as approved by ServX.
-
Audit Rights
- Audit: ServX reserves the right to conduct audits, including penetration testing and security assessments, to verify compliance with this DPA and GDPR. The Processor agrees to cooperate fully with any such audits.
-
Notification of Legal Requests
- Legal Requests: If the Processor receives any legal request or court order regarding data processing, it must notify ServX before responding, unless prohibited by law.
-
Data Protection Officer
- Appointment of DPO: ServX shall appoint a Data Protection Officer (DPO) who is responsible for overseeing compliance with GDPR and coordinating with the Processor as needed.
-
Term and Termination
- Term: This DPA will remain in force for the duration of the User’s relationship with ServX.
- Termination: Upon termination of the License Agreement, the Processor must delete or return all personal data to ServX unless legally required to retain it.
-
Liability
- Breach of GDPR: In the event of a breach of GDPR, the Processor agrees to indemnify ServX for any damages, fines, or penalties resulting from such a breach.
-
Miscellaneous
- Amendments: Any amendments to this DPA must be in writing and agreed upon by both parties.
- Governing Law: This DPA is governed by the laws of England and Wales, and any disputes shall be resolved under the exclusive jurisdiction of the courts of London.
Serviks LTD
Company Registration Number: 15556128
167-169 Great Portland Street, London, England, W1W 5PF