This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer") and ALBOSSE EOOD ("Dilmach") for use of the Services, and applies where Dilmach processes personal data on behalf of the Customer as a processor.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given to them under the GDPR. "Customer Personal Data" means personal data contained within Customer Content that Dilmach processes on the Customer's behalf.
2. Roles
For Customer Personal Data, the Customer acts as controller (or processor on behalf of a further controller) and Dilmach acts as processor. Dilmach will process Customer Personal Data only on the Customer's documented instructions, unless required to do otherwise by applicable law.
3. Processing Instructions
The Customer's instructions are set out in the Annex to this DPA, the applicable customer agreement, and the Customer's use of the Services' configurable functionality. Dilmach will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
4. Confidentiality
Dilmach will ensure that persons authorised to process Customer Personal Data are subject to an appropriate obligation of confidentiality.
5. Security
Dilmach will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in our Security page, taking into account Article 32 GDPR.
6. Subprocessors
Dilmach may engage subprocessors to process Customer Personal Data on Dilmach's behalf. Dilmach remains responsible for the processor obligations applicable to its relationship with the Customer and will impose appropriate data protection obligations on subprocessors. Our current subprocessors are listed on our Subprocessors page, which the Customer should review periodically.
7. International Transfers
Where Dilmach or its subprocessors transfer Customer Personal Data outside the European Economic Area, Dilmach will ensure that such transfers are subject to an appropriate lawful transfer mechanism under Chapter V GDPR, which may include an adequacy decision, an applicable certification mechanism, Standard Contractual Clauses, or another legally recognised safeguard.
8. Data Subject Requests
Taking into account the nature of the processing, Dilmach will provide reasonable assistance to the Customer, insofar as possible, to enable the Customer to respond to requests from data subjects seeking to exercise their rights under applicable data protection law.
9. Personal Data Breaches
Dilmach will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to assist the Customer in meeting its own notification obligations under applicable law, including the 72-hour notification period that Article 33 GDPR may impose on the Customer as controller.
10. DPIA and Regulatory Assistance
Dilmach will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, where required under applicable law and taking into account the nature of the processing and information available to Dilmach.
11. Return and Deletion
Following termination of the Services, Dilmach will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, except where applicable law requires retention. Specific retention periods are described on our Data Retention page.
12. Audits and Compliance Information
Dilmach will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable advance notice, confidentiality obligations, and reasonable limits on frequency so as not to unduly disrupt Dilmach's operations. The specific scheduling, scope and cost allocation for a given audit will be agreed between the parties in good faith, and may be addressed in the applicable order form or customer agreement.
13. Personnel
Dilmach limits access to Customer Personal Data to personnel who require such access to perform their job functions and who are bound by confidentiality obligations.
14. Liability
Each party's liability arising out of or in connection with this DPA, including liability of Dilmach and its subprocessors, is subject to the limitations and exclusions of liability set out in the Terms of Service or the applicable customer agreement between the parties. This DPA does not create any additional liability beyond what is set out in that underlying agreement, except to the extent mandatorily required by applicable data protection law.
15. Termination
This DPA remains in effect for as long as Dilmach processes Customer Personal Data on behalf of the Customer under the applicable customer agreement.
16. Order of Precedence
In the event of a conflict between this DPA and the applicable customer agreement regarding the processing of personal data, this DPA will prevail to the extent of the conflict.
17. Governing Law
This DPA is governed by the same governing law as the applicable customer agreement, as described in the Governing Law section of our Terms of Service. This does not override any mandatory data-protection law that applies to the processing of Customer Personal Data regardless of the parties' choice of governing law.
Annex: Processing Description
Subject matter
Processing of personal data as necessary to provide Dilmach's CRM, workspace, task-management and related SaaS services.
Nature of processing
Hosting, storage, organisation, retrieval, transmission, display and other processing necessary to provide and secure the Services.
Duration
For the duration of the applicable customer agreement and the applicable post-termination deletion period.
Categories of data subjects
- Customer employees
- Contractors
- Customers of the Customer
- Prospects
- Business contacts
- Other individuals whose data is lawfully submitted by the Customer
Categories of personal data
- Names
- Business contact information
- Company information
- Job titles
- CRM relationship data
- Notes
- Communications
- Tasks
- Deal information
- Files
- Other Customer Content