CompuGraphics Data Processing Addendum

Effective from 27/02/2024

1. TOEPASSING AREA This Data Processing Agreement (“DPA”) governs the processing of personal data by CompuGraphics (“we,” “us,” “our”) on behalf of you (“you,” “Customer”) under one or more agreements between you and CompuGraphics (collectively, the “Agreement”) under which we provide certain services (“Services”). This DPA is governed by the terms of the Agreement. All capitalized terms used but not defined herein have the meanings given to them in the Agreement. This DPA does not apply if we are a controller of personal data.

2. PROCESSING

2.1. We will implement appropriate technical and organizational measures to ensure that processing meets the requirements of relevant data protection legislation and guarantees the protection of the rights of the data subject. The standard of protection will be at least comparable to that required under relevant data protection legislation. We will protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

2.2. Our processing falls under this DPA. Specifically, we will:

  • Process personal data only according to your documented instructions, including with regard to the transfer of personal data to a third country or an international organization, unless this is required by applicable law. In such a case, we will inform you of this legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3. SUB-EDITING

3.1. You hereby grant us general consent to engage other processors to process personal data in accordance with this DPA. We maintain a list of subprocessors (there are currently no subprocessors to list), which we may update from time to time. We will update the list on our website at least 14 days before authorizing a new processor to process personal data. You may object to the change free of charge by notifying us within 14 days of the website being updated, setting out your reasons for the objection. Without prejudice to any applicable refund or termination rights under the Agreement, we will do our best to avoid processing personal data to which you reasonably object by such a new processor.

4. RIGHTS OF THE DATA SUBJECT

4.1. To the extent legally permitted, we will promptly notify you of any data subject requests we receive and cooperate with you in fulfilling your obligations under data protection law in relation to such requests. You are responsible for all reasonable costs incurred in assisting us in fulfilling such obligations.

5. TRANSFER

5.1. CompuGraphics will ensure that, to the extent personal data originating from the UK, Switzerland or the European Economic Area (“EEA”) is transferred to a country or territory outside the UK, Switzerland or the EEA that has not received a binding adequacy decision from the European Commission or a competent national data protection authority, such transfer will be subject to appropriate safeguards in accordance with data protection legislation (including Article 46 of the General Data Protection Regulation (“GDPR”)).

6. SECURITY OF THE PROCESSING

6.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, CompuGraphics will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. This includes, as applicable:

  • The pseudonymization and encryption of personal data;
  • The ability to ensure the continued confidentiality, integrity, availability and resilience of processing systems and services;
  • The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  • A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

6.2. When assessing the appropriate level of security, CompuGraphics takes into account the risks presented by the processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

6.3. CompuGraphics will take reasonable steps to ensure that a natural person acting under our authority who has access to personal data does not process the data except on your instructions, unless they are legally required to do so.

7. PERSONAL DATA BREACH

7.1. CompuGraphics will notify you without undue delay after becoming aware of a personal data breach. We will promptly investigate the breach if it has occurred on our infrastructure or in another area for which we are responsible. We will respond reasonably to your requests for further information to assist you in complying with your obligations under data protection law.

8. RECORDING OF PROCESSING ACTIVITIES

8.1. CompuGraphics will maintain all data required by data protection legislation and, to the extent applicable to the processing of personal data on your behalf, make it available to you as needed.

9. CONTROL

Upon your written request, CompuGraphics will provide you with our most recent certifications and/or summary audit reports to regularly test, assess, and evaluate the effectiveness of our technical and organizational measures. Audits must:

  • Subject to the execution of appropriate confidentiality or non-disclosure agreements;
  • Not to be performed more than once per year unless there is a demonstrated reasonable suspicion of non-compliance with the Agreement, after thirty (30) days prior written notice and after a plan for such assessment has been provided; And
  • Performed at a mutually agreed time, place and manner.

10. CONFLICTS

10.1. If there is any conflict or inconsistency between the terms of this DPA and the Agreement, the terms of this DPA shall govern to the extent required by law.