Data processing agreement
An annex to the terms, for business customers: how we process the personal data your company puts into Proofen.
In short
This agreement is part of the terms. It applies from the moment your company accepts the terms, with no separate signature.
Your company is the controller of this data: it decides why and how it is used. We are the processor: we process it only on behalf of your company.
Who runs Proofen
- Company: ClearSecurity Vision S.R.L.
- Company registration number (CUI): 32776248
- Registered office: Feleacu village, Feleacu commune, no. 24/F, Cluj county, Romania
- Trade register: J2014000420120 (old format: J12/420/2014)
- VAT: the company is not registered for VAT. VAT is collected by Paddle, which resells Proofen as the Merchant of Record.
- Contact: contact@proofen.app
“Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor: (a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest; (b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (c) takes all measures required pursuant to Article 32; (d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor; (e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III; (f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor; (g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data; (h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller. With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.”
Regulation (EU) 2016/679 (GDPR), Article 28(3) (eur-lex.europa.eu)
What this means for your company: The law asks for a contract with these elements. You find each of them below, in the same order.
Subject-matter and duration
The subject-matter is providing the Proofen app, under the terms. Duration: as long as the organisation exists in Proofen, plus at most 30 days for backups.
Nature and purpose
We store the data, generate documents from the company profile, keep the evidence log and send account e-mails. We do not use the data for anything else.
What data, about whom
- The company's user accounts: e-mail and sign-in settings.
- Profile data: the contact person (name, e-mail, role) and your technology services provider, if you enter them.
- The evidence log: the action, the time, the account, the IP address and the browser.
- Any other personal data you write in the profile or in documents.
The data subjects are your company's account users, the contact people in the profile and the people you name in documents.
What we commit to
- We process the data only on your documented instructions: the terms, this agreement and what you do in the app. If the law requires something else of us, we tell you first, when the law allows.
- Only people who need access have it, and only after committing to confidentiality.
- We take the security measures in the privacy policy: each company sees only its own data, connections and backups are encrypted, roles with wide rights use two-step sign-in.
- We use the sub-processors in the privacy policy, and by this agreement you approve them. We email you at least 30 days before we add or replace one. During that time you can object; if we go ahead anyway, you can end the contract by closing your account.
- Exception: if we must replace a sub-processor urgently for security reasons, we tell you as soon as possible, and your right to object stays.
- Each sub-processor has a data processing agreement with us, with data protection obligations.
- We help you answer requests from people about their data. Export and deletion are on the Account page; for anything else, write to us.
- We help you with data security, with notifying a breach and with impact assessments. If we learn of a breach affecting your company's data, we tell you without undue delay.
- At the end, you download your data from the app: the Account page, the evidence log export and the documents. Or you ask us for a full export at contact@proofen.app, before closing. Once the organisation is closed, we delete the data from the app at once and from backups within 30 days.
- We give you the information you need to show that we comply with this agreement. We allow audits, including inspections, by you or by an auditor you mandate, after a written request and reasonable notice.
- We tell you at once if, in our view, one of your instructions breaks data protection law.
Your company's rights and obligations
- Your company decides the purpose of the processing and gives us instructions through the terms, this agreement and what it does in the app.
- Your company is responsible for having a lawful basis for the data it puts into Proofen and for informing the people concerned.
- Your company can check compliance through audits, can object to new sub-processors and gets the data back at the end.
Transfers outside the European Union
Some sub-processors are outside the European Union or have access from there. The transfer mechanisms are in the privacy policy.
See the sub-processors and transfers: privacy policy.
Liability
The liability rules in the terms apply to this agreement, with their cap and their exceptions.