{"id":2372,"date":"2020-01-20T17:33:01","date_gmt":"2020-01-20T17:33:01","guid":{"rendered":"https:\/\/www.seotesteronline.com\/?page_id=2372"},"modified":"2023-01-18T13:05:06","modified_gmt":"2023-01-18T13:05:06","slug":"data-processing-agreement","status":"publish","type":"page","link":"https:\/\/www.seotesteronline.com\/data-processing-agreement\/","title":{"rendered":"Data Processing Agreement"},"content":{"rendered":"<p><b>DATA PROCESSING AGREEMENT<\/b><\/p>\n<p><span style=\"font-weight: 400;\">This Data Processing Agreement (hereinafter \u201c<\/span><b>Agreement<\/b><span style=\"font-weight: 400;\">\u201d) supplements the terms and conditions of <\/span><i><span style=\"font-weight: 400;\">SEO Tester Online<\/span><\/i><span style=\"font-weight: 400;\"> (hereafter the \u201c<\/span><b>Contract<\/b><span style=\"font-weight: 400;\">\u201d) and the customer agreeing to the following provisions.<\/span><\/p>\n<p><b>Recitals:<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">whereas customer acknowledge that it is the controller (hereinafter \u201c<\/span><b>Controller<\/b><span style=\"font-weight: 400;\">\u201d) of data (hereafter \u201c<\/span><b>Data<\/b><span style=\"font-weight: 400;\">\u201d) processing (hereinafter \u201c<\/span><b>Processing<\/b><span style=\"font-weight: 400;\">\u201d);<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">whereas according to the GDPR Quarzio S.r.l. is qualified as processor (hereinafter \u201c<strong>P<\/strong><\/span><b>rocessor<\/b><span style=\"font-weight: 400;\">\u201d), according to the provision of art. 28 GDPR, on behalf of the Controller;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">whereas the Contract execution requests to process data regarding both individuals (hereinafter \u201c<\/span><b>Subjects<\/b><span style=\"font-weight: 400;\">\u201d) and business related Data;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">whereas Data processed shall be considered confidential information of the Controller and are subjects to confidentiality between Controller and Processor;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">whereas the Controller determines type of Data, the duration of Data processing, the related nature and purposes and the categories of Data;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">whereas Processor guarantees that it can implement adequate technical and organisational measures so that the processing complies both with regards to confidentiality and GDPR;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">whereas Processor commits to process Data related to the Contract in a lawful and accurate way in respect of confidentiality and GDPR and in respect of Controller procedures and further instructions;<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Controller and Processor will be jointly referred as Parties.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><b>Controller and Processor agree as follows:<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><b>Purposes and processed Data<\/b><\/li>\n<\/ol>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Recitals are part of the present Agreement.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processing shall be performed from Processor only for fulfilling duties arising from the Contract and the present Agreement.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processing shall be strictly necessary for executing the Contract itself and shall be performed according to confidentiality and to the GDPR, as well to the duties stated in the present Agreement.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Where it is necessary for the execution of the Contract, the processing is extended to special categories of Data, such as Data stated in the provisions of art. 9 and 10 GDPR.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Data processed are the following:<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Name and surname<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Email address<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Phone number<\/span><\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><b>Security of Processing<\/b>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall adopt the security measures as set forth in art. 32 of GDPR and setting any appropriate technical and organizational measures to guarantee an adequate level of security regarding risks related to destruction, loss, amendment, non-authorised disclosure or access, accidentally or illegally, to processed Data.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Controller acknowledges that Processor guarantees the following security measures:<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<table>\n<tbody>\n<tr>\n<td><b>TYPE<\/b><\/td>\n<td><b>DESCRIPTION<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Physical access control<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Processor implemented measures to avoid non-authorised access to workstations and to work devices where data are processed, both during the working hours and non-working hours. During non-working hours, the office space and the office building are locked.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Virtual access control<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Processor adopts measures to avoid non-authorised access to virtual environments, where Data are processed, through anti-virus, firewall and proxy server.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Processor guarantees that virtual environment can be accessed only by an Authorised Person or a Sub-processor.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Data integrity controls<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Processor adopts measures to avoid that Data are accessed by non-authorised person and that Data are not copied, altered or lost. Employees are legally bound to confidentiality.\u00a0<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Availability Data controls<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Processor adopt measures to avoid unintentional loss or destruction of Data. Processor adopts backups and policies of disaster recovery.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Technical and organisational measures<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Processor regularly updates documents of its organisation and regulates each work relation, both internal and external, with the proper documentation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Processor carries out regular checks of its technical infrastructure to control its compliance to GDPR.<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><b>Data communication and sub-processing<\/b><\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor may communicate Data to third parties as it is necessary for the execution of the Contract and the Agreement and, for the same reason, may transfer Data to countries outside EU.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Given what above, Processor is authorised to commission processors (hereafter \u201c<\/span><b>Sub-processors<\/b><span style=\"font-weight: 400;\">\u201d) if it is necessary for the execution of the Contract.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Controller may request at any time the list of Sub-processors commissioned by the Processor for the execution of the Contract.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall guarantee that commissioned Sub-processors respect confidentiality and the provisions of paragraphs 3, 4 and 5 of art. 28 GDPR.<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li style=\"font-weight: 400;\"><b>Person acting under the authority of Processor<\/b>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor, prior to Processing, shall identify and list any employee that works under its authority and who will process Data (hereinafter \u201c<\/span><b>Authorised Person<\/b><span style=\"font-weight: 400;\">\u201d).<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Regarding each Authorised Person, Processor shall settle related access to Data and provide instructions (written and not) with respect of the Contract and the present Agreement.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Authorised Person shall receive detailed instructions, with special regard to:<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Data confidentiality, Authorised Person shall be bind to keep confidentiality of Data it has access to and process;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">principles set in art. 5 of GDPR about lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation and integrity.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\"><b>DPIA, prior consultation, right of Subjects and Data breach<\/b>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall assist Controller regarding duties of Data Processing Impact Assessment (hereinafter \u201c<\/span><b>DPIA<\/b><span style=\"font-weight: 400;\">\u201d) and prior consultation (hereinafter \u201c<\/span><b>Consultation<\/b><span style=\"font-weight: 400;\">\u201d) according to the provisions of art. 35 and 36 of GDPR.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall not use technologies, tools, modalities or undertake other Data processing that requires DPIA and\/or Consultation without informing the Controller in advance and without receiving previous written authorisation from the latter.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall assist Controller with adequate technical and organisational measures, through the disclosure of proper information, which are necessary for the latter to fulfil Subject requests to exercise their rights within the timeframe provided by GDPR.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In case of a Data breach, Processor shall promptly inform the Controller with the necessary information in order to allow the latter take the mandatory step to limit eventual damages arising from the breach. In particular, Processor shall provide the following information:<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">regarding the leak of Data that breach confidentiality;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">requested by art. 33 and 34 of GDPR, which are necessary for notification to the Controller supervising authority and to the Subjects.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\"><b>Monitoring right of the Controller<\/b>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall control that Data are processed according to the provision set forth in the Contract and in the present Agreement and according to the applicable law to confidentiality and GDPR.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall promptly inform Controller about any situation that may expose the latter to a breach of law or results in an unlawful processing or may breach the confidentiality and integrity of Data or may become a risk regarding Processing.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Controller may, directly or through an appointed person and\/or entity, request to conduct auditing activity on the Processor, only regarding Processing. Auditing activity shall be scheduled between parties and shall be conduct according to rules agreed by both Parties.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall collaborate and will provide the necessary information to demonstrate the respect of the the Contract, the present Agreement, the applicable law to confidentiality and the GDPR.<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li><b>Exclusion of liability<\/b><\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall not be deemed liable for events not depending from its activity and\/or will, including, without limitation, non-availability or disfunction of technical instruments, cables, electronics, hardware, transmissions, phone line, server malfunctioning, omissions or mistakes related to information and images provided during the development.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Processor shall not be deemed liable for delays caused by events not depending from its activity and\/or will.<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\"><b>Termination of Processing and deletion of Data<\/b>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The present Agreement shall be terminated if the Contract is no longer in force between Parties. Termination will have immediate effect on the present Agreement.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In case of termination Quarzio S.r.l. shall not be considered processor any longer. The same principle shall be applied to Sub-processor appointed according to fulfil obligations under the Contract and under the Agreement.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Upon termination of the Agreement the Processor will return all Data to Controller and he will delete all the copies. The same apply in case of explicit request of the Controller.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Data shall not be deleted in case there is a legal duty set forth in national or international provision that forces Processor to keep Data storage.<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li><b>Miscellaneous<\/b><\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The present Agreement shall be considered as the entire expression of the will of the Parties regarding the object of the Agreement.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Each Party shall be intended as independent from the other and, therefore, it has no right to bind the other Party unless agreed in the present Agreement.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Agreement cannot be interpreted as constitutive for any other relationship between Parties that is not stated and agreed in the Agreement itself.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Parties acknowledges that if one of more articles shall breach the law, such articles shall not be effective within the limits of the violation without any prejudice for other articles or the Agreement itself.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Any waiver, express or implied, of any Party to exercise one of its rights shall not be intended as a definitive waiver of such rights and to the possibility of the Party to request performance of what agreed.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Any amendment to the present Agreement shall be previously agreed in written and signed by both Parties.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Parties shall not cede to third Parties the Agreement, nor part of it, without the previous written consent of the other Party.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Controller may communicate to Processor through the following addresses:<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\">privacy@quarzio.com<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li><b>Applicable law and jurisdiction<\/b><\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The present Agreement is governed by Italian law, regarding both substantial and procedural law.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Any dispute arising from or in connection with the present Agreement shall be decided by the Court of Catania which has exclusive jurisdiction.<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-weight: 400;\">Last update date: 17 January 2023.<\/span><\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DATA PROCESSING AGREEMENT This Data Processing Agreement (hereinafter \u201cAgreement\u201d) supplements the terms and conditions of SEO Tester Online (hereafter the \u201cContract\u201d) and the customer agreeing to the following provisions. Recitals: whereas customer acknowledge that it is the controller (hereinafter \u201cController\u201d) of data (hereafter \u201cData\u201d) processing (hereinafter \u201cProcessing\u201d); whereas according to the GDPR Quarzio S.r.l. is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"acf":[],"lang":"en","translations":{"en":2372,"it":2477,"fr":6813,"es":6975,"pl":7214},"pll_sync_post":[],"_links":{"self":[{"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/pages\/2372"}],"collection":[{"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/comments?post=2372"}],"version-history":[{"count":21,"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/pages\/2372\/revisions"}],"predecessor-version":[{"id":7172,"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/pages\/2372\/revisions\/7172"}],"wp:attachment":[{"href":"https:\/\/www.seotesteronline.com\/wp-json\/wp\/v2\/media?parent=2372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}