Customer Data Processing Terms

1. General Terms

a) To the extent that ENTERSOFTONE processes personal data:

together ENTERSOFTONE Customer Personal Data, each party acknowledges and agrees that for the purpose of Data Protection Laws, the ENTERSOFTONE Customer is the controller of the ENTERSOFTONE Customer Personal Data and ENTERSOFTONE is the processor of the ENTERSOFTONE Customer Personal Data.

b) The ENTERSOFTONE Customer shall comply with its obligations as controller of the ENTERSOFTONE Customer Personal Data (including, without limitation, any obligation under Data Protection Laws to obtain Contributor consent to the processing of ENTERSOFTONE Customer Personal Data) and shall be liable to ENTERSOFTONE for any failure of ENTERSOFTONE Customer to comply with any such obligations.

c) ENTERSOFTONE shall implement appropriate technical and organisational measures to the intent that processing should meet the requirements of Data Protection Laws as to the protection of the rights of the data subject.

d) The subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data, the categories of data subjects and the obligations and rights of the ENTERSOFTONE Customer in relation to the processing are as set out or implied in these ENTERSOFTONE Customer Data Processing Terms, the SocrateXRM Agreement, other ENTERSOFTONE products Agreements and the ENTERSOFTONE Privacy Policy.

e) ENTERSOFTONE shall:

2. Data Subject Rights

ENTERSOFTONE shall:

a) implement technical and organisational measures intended to assist in the fulfilment of the ENTERSOFTONE Customer’s obligation to respond to requests by data subjects to exercise their rights of access, rectification or erasure, to restrict or object to processing of ENTERSOFTONE Customer Personal Data, or to data portability; and

b) if a data subject makes a written request to ENTERSOFTONE to exercise any of the rights referred to in paragraph 2(a) above, forward the request to the ENTERSOFTONE Customer promptly and shall, upon the ENTERSOFTONE Customer’s reasonable written request, provide the ENTERSOFTONE Customer with such co-operation and assistance as is reasonably requested by the ENTERSOFTONE Customer in relation to that request with the object of assisting the ENTERSOFTONE Customer to respond to it.

3. Security Measures

ENTERSOFTONE shall:

a) taking into account the state of the art, the costs of implementation and the nature, scope, context and purpose of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, implement and maintain appropriate technical and organisational measures intended to provide a level of security  appropriate to the risk of unauthorised or unlawful processing of ENTERSOFTONE Customer Personal Data, and of accidental or unlawful loss, alteration, unauthorised disclosure or destruction of, or damage to, ENTERSOFTONE Customer Personal Data; and

b) notify the ENTERSOFTONE Customer without undue delay after becoming aware of a personal data breach, and upon the ENTERSOFTONE Customer’s reasonable written request provide the ENTERSOFTONE Customer at the ENTERSOFTONE Customer’s expense with such co-operation and assistance as is reasonably requested by the ENTERSOFTONE Customer with the object of assisting the ENTERSOFTONE Customer to notify the personal data breach to the relevant supervisory authority and relevant data subject(s) (as applicable).

4. Sharing of ENTERSOFTONE Customer Personal Data

ENTERSOFTONE’s third party processors of ENTERSOFTONE Customer Personal Data (Subprocessors) are identified in the Schedule to these Customer Data Processing Terms.

ENTERSOFTONE shall:

a) inform Customers of the engagement of a new processor at least 30 days prior to the new processor commencing the processing of Personal Data, notifying Customers of its identity and role by publishing and updating it on the website;

b) grant the Customer the right to object to the new processor by terminating the Agreement in accordance with the unilateral termination clause (clause 7c. of the Agreement), this being the Customer’s sole and exclusive remedy if it objects to the engagement of a new processor;

c) enter into a contractual relationship with each processor in compliance with the requirements imposed by Data Protection Laws; and

d) ensure that its employees who have access to Personal Data have committed to confidentiality obligations.

5. Transfers of ENTERSOFTONE Customer Personal Data

a) Save as permitted pursuant to paragraph 4 above, ENTERSOFTONE shall not transfer ENTERSOFTONE Customer Personal Data to, or process ENTERSOFTONE Customer Personal Data in, any country outside the European Economic Area without the prior written consent of the ENTERSOFTONE Customer (such consent not to be unreasonably withheld or delayed) unless (and for so long as):

b) Where any mechanism for cross-border transfers of ENTERSOFTONE Customer Personal Data is found by a supervisory authority, court of competent jurisdiction or other governmental authority to be an invalid means of complying with the restrictions on transferring ENTERSOFTONE Customer Personal Data to a third country or territory as set out in Data Protection Laws, the parties shall act in good faith to agree the implementation of an alternative solution to enable the ENTERSOFTONE Customer to comply with the provisions of Data Protection Laws in respect of any such transfer.

6. Compliance

a) ENTERSOFTONE shall at ENTERSOFTONE Customer’s expense:

b) The ENTERSOFTONE Customer shall:

7. Termination/expiry

a) Unless expressly stated otherwise in these ENTERSOFTONE Customer Data Processing Terms, upon termination of  the ENTERSOFTONE Customer’s participation in the ENTERSOFTONE service, ENTERSOFTONE shall, and shall procure that each processor engaged by ENTERSOFTONE to process ENTERSOFTONE Customer Personal Data shall, cease as soon as is reasonably practicable to use the ENTERSOFTONE Customer Personal Data and delete the ENTERSOFTONE Customer Personal Data unless required or entitled to retain a copy in accordance with any law of the European Union or any member state of the European Union or permitted to retain or continue processing the ENTERSOFTONE Customer Personal Data under any provision of these ENTERSOFTONE Customer Data Processing Terms.

b) On expiry of the ENTERSOFTONE Customer’s participation in the ENTERSOFTONE service these ENTERSOFTONE Customer Data Processing Terms shall survive and continue in full force and effect.

8. Definitions

In these ENTERSOFTONE Customer Data Processing Terms:

a) Data Protection Laws include

b) controller, data subject, personal data, personal data breach, processor and processing shall each bear the meanings given to them in the GDPR;

c) Words and phrases defined in the ENTERSOFTONE Agreement or the ENTERSOFTONE Privacy Policy have the same meaning in these ENTERSOFTONE Customer Data Processing Terms. This category includes SocrateXRM, Socrate Business Services.

d) ENTERSOFTONE Products: products developed by ENTERSOFTONE offered as a service and which have a Cloud service subscription contract or specific contract signed between the Client and ENTERSOFTONE. This category includes SocrateXRM, Socrate Business Services.

9. Schedule: Processors

The Customer confirms that the following general authorisations of processors are authorised for use by ENTERSOFTONE:

Company

Address

Purpose

Amazon Web Services

Amazon Web Services EMEA, Luxembourg

Cloud infrastructure, Storage, Data Processing

MongoDB

MongoDB Ltd, Dublin, Ireland

Storage and Data Processing

Google

Google Ltd Dublin, Ireland

Google Analytics

Intercom

Intercom, San Francisco, CA, USA

Chat and support services

Netopia

Netopia s.r.l., București, România

mobilPay online payment service