Dpa

Read a brief summary of all the important information here.

Data Processor Agreement* |
Easybox

*This document is machine translated from the original https://www.easybox.com/dpa/
Version: DPA-1.0.4
Publication date: April 21, 2023

This DPA is an integral part of and constitutes an appendix to the Easybox Terms and Conditions entered into between the Customer and Easybox (the “Agreement”). This Easybox Data Processing Agreement (the “DPA”) is entered into by and between the Customer and Breex Easybox, with its registered office at Moutstraat 66/P.O. Box 601, 9000 Ghent, registered in the Crossroads Bank for Enterprises under company number BE 0760.527.015 (“Easybox”). This DPA describes the processing of Personal Data carried out by Easybox on behalf of the Client.

INTRODUCTION

Pursuant to the Agreement, the Customer was granted access to the Easybox platform (the “Platform”). Personal data is collected and processed through the Platform by Easybox on behalf of the Customer.

The Parties wish to enter into a data processing agreement in accordance with the requirements of applicable privacy laws, including the GDPR.

This DPA supersedes any prior provisions in past and current agreements between the Parties that are directly or indirectly related to the processing of personal data, privacy, access to personal data, data transfer, and data security.

1. DEFINITIONS

1.1 Terms not explicitly defined in this DPA have the same meaning as in the Terms of Use. The terms and expressions used herein are defined as follows:
“General Data Protection Regulation, or GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.
“The personconcerned” means any identified or identifiable natural person to whom the Personal Data relates.
“Service” refers to the Platform's online offering as well as related services (support, maintenance, etc.)
“Purposes” mean the specific, explicitly defined, and legitimate purposes of the Processing.
“PersonalDataBreach” means any unauthorized or unlawful access, deletion, alteration, loss, or processing of Personal Data; any other event that results or may result in the unintended or unlawful deletion, loss, alteration, unauthorized disclosure of, or access to Personal Data; any data breach involving Personal Data as defined in the GDPR, or any indication that such a breach will occur or has occurred.
“CustomerData” means all data in any form that is Processed by Easybox on behalf of the Customer for the purpose of providing the Platform, including (to the extent applicable) Personal Data.
“PersonalData” means any information relating to an identified or identifiable natural person as defined in the Agreement. An “identifiable” natural person is a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Platform” refers to the Easybox platform.
“Processor” means the processor as defined in Article 4(8) of the GDPR.
“Data “DataController” means the data controller as defined in Article 4(7) of the GDPR.
“Legislation on dataprotection” means the GDPR and all other local laws within the European Economic Area that may apply to the processing of personal data.
“Processing”or any variant of the verb“Process” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.2. All terms and expressions not expressly defined in this DPA shall have the meanings assigned to them in the Agreement.

2. PROCESSING OF PERSONAL DATA

2.1 The Parties acknowledge that Easybox acts as a Processor with respect to the Personal Data arising from the performance of the Services. The Customer remains the Data Controller with respect to the Personal Data at all times. 2.2 Each Party must comply with its respective obligations regarding the Processing of Personal Data under data protection laws. 2.3 While using the Platform, the Customer may provide certain Personal Data to Easybox for Processing. Easybox will Process this Personal Data only for the duration of the Agreement or for any other agreed-upon period (for example, in the event of early termination), and under no circumstances will it retain the Personal Data longer than is necessary for the purpose for which it is being Processed. 2.4 The nature and purpose of the Processing, the types of Customer Personal Data being Processed, and the categories of Data Subjects covered by this DPA are further specified in Appendix 1. 2.5 Personal Data are processed within the European Economic Area processed. Easybox may transfer Personal Data to countries outside the European Economic Area, provided that such transfer complies with the additional safeguards required by applicable data protection laws.

3. CUSTOMER OBLIGATIONS

3.1 By entering into this DPA, the Customer instructs Easybox to process the Customer’s Personal Data: (a) to provide the Service in accordance with its features and functionalities; (b) to enable the actions initiated by the Customer and the Registered Users on the Service, in accordance with this DPA and/or the Agreement. 3.2 Easybox shall immediately notify the Customer if, in its opinion, an instruction from the Customer constitutes a violation of the GDPR (or other data protection laws). Easybox has the right to suspend the execution of such an instruction and to cease further Processing of the Personal Data in accordance with previously provided instructions following such notification. Such suspension shall not give rise to any right to compensation on the part of the Customer. 3.3 If Easybox is required, pursuant to a provision applicable to it, to process Personal Data or transfer it to a third country or an international organization, Easybox will notify the Customer of that legal requirement, unless such legislation prohibits such notification. 3.4 Under this DPA and in connection with the use of the Service, the Customer is responsible for complying with all obligations to which the Customer is subject under applicable data protection laws, particularly with regard to the Processing of Personal Data. 3.5 Without limiting the foregoing, the Customer specifically agrees that it is solely responsible: (i) for the accuracy, quality, and lawfulness of Personal Data and for the manner in which the Customer obtained such Personal Data; (ii) for complying with all obligations regarding transparency and lawfulness set forth in the applicable data protection laws with respect to the collection and use of the Personal Data; (iii) and that the Customer has the right to provide the Personal Data to Easybox and to grant Easybox access for Processing in accordance with the provisions of the Agreement; and (iv) that the Customer’s instructions to Easybox regarding the Processing of Personal Data comply with applicable law, including data protection laws. The Customer must notify Easybox without undue delay if it is unable to fulfill its obligations arising from this section or from the applicable Data Protection Laws. 3.6 Nothing in this DPA shall entitle the Customer to grant, directly or indirectly, access to the Service to any persons or entities other than the Registered Users and allow them to use the Service, or to use the Service (or allow others to use it) for unlawful purposes or in any manner other than as provided for in the Agreement and/or in this DPA.

4. TECHNICAL AND ORGANIZATIONAL MEASURES

4.1 Easybox has implemented appropriate technical and organizational measures to ensure that the Processing is carried out in accordance with data protection laws and to guarantee an appropriate level of security for the Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons. 4.2 The Customer acknowledges that security requirements are subject to change and that effective security requires regular assessment and improvement of security measures. For this reason, Easybox will continuously evaluate, refine, supplement, or improve the measures taken to comply with its obligations. Easybox may modify and revise the technical and organizational measures at its sole discretion, provided that such modification or revision does not result in a material reduction in the level of protection currently provided by the existing measures. 4.3 Easybox will document all information necessary to demonstrate the aforementioned compliance (including a record of processing activities). Upon simple request by the Customer, Easybox will make these documents available.

5. CONFIDENTIALITY

5.1 Easybox undertakes to ensure the confidentiality of the Processed Personal Data. 5.2 Easybox will inform anyone who has access to the Personal Data (including employees, temporary employees, and independent contractors) of the obligations on behalf of Easybox regarding the Customer’s Personal Data. 5.3 Easybox will ensure that all persons involved in the Processing of the Customer’s Personal Data are bound by professional secrecy or a statutory duty of confidentiality, with the aim of safeguarding the confidentiality and integrity of the Customer’s Personal Data.

6. SUBCONTRACTORS

6.1 The Customer grants its consent to engage (external) subprocessors to process Personal Data (including transfers). 6.2 At this time, Easybox uses the information in Appendix 2 the listed third parties as subprocessors. By signing this Agreement, the Customer grants its written consent to the use of the listed subprocessors for the purpose of Processing Personal Data on behalf of the Customer. 6.3 Easybox will notify the Customer by email and/or via a notice on the Platform of any proposed change regarding the addition or replacement of its current subprocessors prior to such change. The Customer may object to such an addition or replacement within 30 days of the notification, based on valid reasons related to the protection of Personal Data, by sending an email to hello@easybox.com. If the Customer does not object within this period, the Customer is deemed to have waived its right to object and to have authorized Easybox to engage such a subprocessor. 6.4 In the event that the Customer notifies Easybox of such an objection, the Parties shall discuss the objection with the aim of reaching a reasonable solution. If such a solution cannot be reached, Easybox may, at its sole discretion, decide not to appoint the new subprocessor or allow the Customer to suspend or terminate the relevant Service in accordance with the provisions regarding termination of the Agreement without liability toward the other party (however, any fees for the period prior to the suspension or termination of the Agreement remain payable by the Customer). 6.5 Easybox’s subprocessors are bound by the same contractual obligations as set forth in this Agreement, to the extent applicable given the nature of the services provided by such subprocessors. If a subprocessor fails to comply with its data protection obligations, Easybox remains fully liable to the Customer for the subprocessor’s compliance with its obligations.

7. OBLIGATION TO PROVIDE INFORMATION AND ASSISTANCE

7.1 Easybox will assist the Customer in fulfilling its obligation to respond to requests from Data Subjects seeking to exercise their rights:
  • by notifying the Customer of all requests received regarding a Data Subject’s Personal Data, from a supervisory authority and/or any other authority competent under data protection legislation;
  • by providing reasonable cooperation to the Client in responding to requests from the Data Subject in accordance with the GDPR, provided that approval has been obtained from the Client;
  • by ensuring that Easybox has the technical and organizational capabilities to remove the Personal Data of the Data Subject who requests such a right from its system, records, or databases. Personal Data may remain on backup or archival media that are securely isolated and protected from further Processing, and will subsequently be permanently deleted in accordance with the retention policy.
Notwithstanding the foregoing, the Customer remains responsible for handling such requests from Data Subjects properly. 7.2 Taking into account the nature of the Processing and to the extent that Easybox can reasonably obtain the required information, Easybox shall, upon the Customer’s request, provide the Customer with reasonable assistance in carrying out a privacy impact assessment and, if applicable, following prior consultation with the competent supervisory authority. To the extent permitted by applicable data protection laws, the costs of this assistance provided by Easybox shall be borne by the Customer. 7.3 Easybox shall notify the Customer of any breach involving the Customer’s personal data via email without undue delay and, in any event, within 48 hours of becoming aware of such a breach. The Customer must ensure that its contact information remains current and accurate throughout the term of this Agreement. 7.4 Easybox shall provide the Customer with all information necessary, and to the extent required by law, to demonstrate compliance with the obligations set forth in this Agreement, and shall facilitate and cooperate with audits, including inspections, conducted during the term of this Agreement by an external auditor appointed by the Customer to demonstrate compliance with the terms of the Agreement. 7.5 The Customer shall limit its efforts to conduct an audit or inspection to no more than once a year, except in the event that (i) this is required by law, (ii) Easybox has experienced a Personal Data Breach in the preceding twelve (12) months that has affected the Customer’s Personal Data, or (iii) in the event of a mutual agreement, and shall notify Easybox of this request at least 30 business days prior to the audit. 7.6 The Customer warrants that the audit will be conducted in such a way as to minimize any disruption to Easybox. The Customer shall impose an adequate confidentiality obligation on its auditors. In addition, Easybox may require the Customer and its auditors to enter into a confidentiality agreement prior to the start of the audit. 7.7 The scope of an audit shall not give rise to an obligation to grant the auditor access to or provide: (a) information or data pertaining to any other Easybox customer; (b) Easybox’s trade secrets or related information; (c) information that, in Easybox’s reasonable judgment, could compromise the security of Easybox’s systems or premises or that could result in Easybox breaching its obligations under Data Protection Laws or other obligations regarding security, confidentiality, or privacy toward other Easybox customers or third parties; or (d) any information that the auditor wishes to review for reasons other than the good-faith fulfillment of obligations under Data Protection Laws and Easybox’s compliance with the provisions of this DPA.

8. DELETION OR RETURN

8.1 Upon termination or expiration of the Agreement, Easybox shall delete or return all Personal Data Processed under this Agreement (and all existing copies thereof), unless (i) Easybox is required by applicable law to retain the Personal Data, or (ii) the Personal Data has been archived in a backup system that Easybox maintains in a secure, isolated manner, is protected from further Processing, and from which data is deleted in accordance with Easybox’s data retention policy.

9. DURATION

9.1 This DPA automatically terminates upon the expiration of the Term specified in the Order Confirmation, unless this DPA is terminated earlier.

10. LIABILITY

10.1 If it can be proven that Easybox has failed to fulfill its obligations under this Data Processing Agreement or under the GDPR, Easybox shall be liable for the proven direct damages suffered by the Customer. Easybox is not liable for indirect, intangible, and/or consequential damages, including loss of profits, loss of business opportunities, loss of and/or damage to data, loss of reputation, sanctions and/or fines, and unforeseeable damages. Easybox’s liability to the Customer is, in any case, limited to the total amount paid by the Customer to Easybox under the Agreement during the last 12 months. 10.2 Each party is liable for administrative fines imposed by a supervisory authority in connection with its own Processing. 10.3 No provision of this DPA shall limit or exclude any liability or any right to which the Data Subject may be entitled under applicable law in the event of damage resulting from a violation of the GDPR by Easybox in its capacity as a Processor. 10.4 The provisions of this section do not affect any other provision regarding liability contained in the Agreement.

11. GOVERNING LAW AND JURISDICTION

11.1 This DPA is governed by and shall be interpreted in accordance with Belgian data protection law, unless otherwise provided by the applicable data protection law. 11.2 Any disputes arising out of this Agreement shall be submitted to the courts as set forth in the Agreement.

APPENDICES

APPENDIX 1 – Data Processing

  • First Name – Middle Name – Last Name
  • Gender
  • Address(es)
  • Phone number(s)
  • The organization's VAT number
  • Organization logo
  • Job Title
  • Email address
  • An organization's bank account
  • An organization's website
  • Phone number
  • Language

APPENDIX 2 – Easybox's Subprocessors

Easybox engages certain subprocessors to assist it in providing the Services as described in the Agreement. External subprocessors Easybox engages various external subprocessors to perform certain processing operations. These subprocessors may have access to or may process Personal Data in connection with the services they provide to Easybox.

Name of Subprocessor Nature of the processing Country
SendGrid Email service provider United States, in accordance with GDPR regulations
Amazon AWS Cloud service Germany
Cloudflare Cloudflare secures and ensures the reliability of your externally accessible resources, such as websites, APIs, and applications. Headquarters in California, U.S. 100+ countries. Depending on the user's location, in accordance with GDPR regulations.
Deus (in-house software owned by EB) OCR Scanning and AI Germany
FreshWorks Support, ticketing, CRM platform Germany
Make  Data processing, data routing Netherlands (eu-central-1), Germany (eu-central-2)
Mamoto on-premises  To collect and analyze information about your interaction with our applications and to detect and prevent misuse  Germany

Questions or concerns?

Do you have any questions or comments? Please feel free to contact hello@easybox.com.