Data Processing Agreement

How TaxSync processes personal data on behalf of customers, in accordance with Article 28 GDPR. Version 1.0.

TaxSync Data Processing Agreement (DPA)

Version 1.0

TD Marvel d.o.o., Beogradska 9, Belgrade, Serbia ("Processor") processes personal data on behalf of the customer and its Affiliates (collectively referred to as "Controller"). Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name.

This agreement contains the written contract within the meaning of Article 28 of the General Data Protection Regulation ("GDPR") and regulates the rights and obligations of the Parties in connection with the processing of personal data on behalf of Controller.

1. Subject Matter and Duration

1.1 Subject Matter

Personal data are processed within the provision of the following services:

Processor provides Controller with a software platform for packaging compliance, Declaration of Conformity (DoC) generation, Extended Producer Responsibility (EPR) reporting, and related services ("Platform"). Processor manages the hosting, maintenance, and operations of the Platform.

1.2 Duration

The duration of this agreement corresponds to the duration of the services provided to Controller.

1.3 Early Termination by Controller

Controller may terminate this agreement at any time without notice if:

  • Processor is in serious breach of the provisions of this agreement;
  • Processor is unable or unwilling to carry out instructions from Controller; or
  • Processor refuses to comply with contractual or statutory control measures of Controller.

2. Specification of Processing

2.1 Geographic Location of Processing

The processing of personal data shall be carried out exclusively within a member state of the European Union (EU) or within a member state of the European Economic Area (EEA). Any transfer of personal data to a state which is not a member state of either the EU or the EEA requires the prior written approval of Controller and shall only occur if the specific conditions of Article 44 et seq. GDPR are met.

2.2 Data Types/Categories

The following data types/categories are subject to the processing of personal data:

  • Personal master data (e.g., name, surname, company name)
  • Communication data (e.g., email address, phone number)
  • Location data (e.g., country, city)
  • Contract master data (e.g., subscription data, billing information)
  • Logging data (e.g., access logs, usage logs)

2.3 Data Subjects

The following data subjects are subject to the processing of personal data:

  • Users of the Platform (including administrators, compliance managers, and other authorized personnel)

3. Technical and Organisational Measures

3.1 General Security Obligations

Processor shall establish security in accordance with Articles 28(3)(c) and 32 GDPR. The measures to be taken include measures of data security and measures that guarantee a protection level appropriate to the risk concerning confidentiality, integrity, availability, and resilience of the systems.

The following factors must be taken into account:

  • The state of the art;
  • Implementation costs;
  • The nature, scope, and purposes of processing; and
  • The probability of occurrence and the severity of the risk to the rights and freedoms of natural persons within the meaning of Article 32(1) GDPR.

Processor's technical and organizational measures are set out in Appendix 1 to this agreement.

3.2 Updates and Improvements

The technical and organizational measures are subject to technical progress and further development. Processor may implement alternative adequate measures that do not reduce the overall security level. Substantial changes must be documented and, where appropriate, communicated to Controller.

4. Quality Assurance and Other Duties of Processor

4.1 Compliance with Statutory Requirements

Processor shall comply with the statutory requirements referred to in Articles 28 to 33 GDPR. Accordingly, Processor ensures, in particular, compliance with the following requirements:

  • Data Protection Officer: If required by applicable law, Processor shall appoint a data protection officer and publish their contact details (publication on Processor's website is sufficient).
  • Employee Confidentiality: Processor entrusts only such employees with the data processing outlined in this agreement who have been bound to confidentiality.
  • Processing on Instructions: Processor and any person acting under its authority who has access to personal data shall not process that data unless on instructions from Controller (including the powers granted in this agreement), unless required to do so by law.
  • Record of Processing Activities: Processor shall cooperate in an appropriate manner in the preparation of the record of processing activities (Article 30(1) GDPR) by Controller by providing relevant information. Processor must maintain its own list in accordance with Article 30(2) GDPR for all categories of processing activities carried out on behalf of Controller.
  • Cooperation with Supervisory Authorities: Controller and Processor shall cooperate, on request, with the supervisory authority in performance of its tasks. Controller shall be informed immediately of any inspections and measures conducted by a supervisory authority, as far as they relate to this agreement.

4.2 Rectification, Erasure, and Restriction

Processor may not on its own authority rectify, erase, or restrict the processing of personal data that is being processed on behalf of Controller, but only on documented instructions of Controller.

In case a data subject contacts Processor directly concerning rectification, erasure, or restriction of processing, Processor will immediately forward the request to Controller.

5. Subprocessing

5.1 Definition and Scope

Subprocessing for the purpose of executing this agreement means services which relate directly to the provision of the main service. This does not include ancillary services, such as:

  • Telecommunication services;
  • Postal/transport services;
  • Maintenance and user support services;
  • Disposal of data carriers; or
  • Other measures to ensure confidentiality, availability, integrity, and resilience of hardware and software.

Notwithstanding the above, Processor shall be obliged to make appropriate and legally binding contractual arrangements and take appropriate measures to ensure compliance with data protection requirements.

5.2 Authorised Subprocessors

Processor may commission subprocessors. Controller agrees to the following subprocessors:

SubprocessorAddressService
Hetzner Online GmbHIndustriestr. 25, 91710 Gunzenhausen, GermanyHosting and operation of the Platform infrastructure (data center Falkenstein, Germany)

5.3 Changes to Subprocessors

Processor shall inform Controller of any intended change with regard to subprocessors or the replacement of existing subprocessors in writing or in text form with appropriate advance notice, which will enable Controller the possibility to object to such changes for legitimate reasons.

If Processor is unable to perform the contract without the indicated change, Processor may terminate the agreement for cause following an objection by Controller.

5.4 Selection and Compliance

Processor shall carefully select subprocessors and ensure compliance with the provisions set out in this agreement. Further outsourcing by subprocessors requires that the terms of this agreement are complied with.

6. Supervisory Powers of Controller

6.1 Right to Inspect

Controller has the right, after consultation with Processor, to carry out inspections or to have them carried out by a competent third party.

6.2 Verification of Compliance

Processor shall ensure that Controller is able to verify compliance with the obligations of Processor in accordance with Article 28 GDPR.

7. Communication in the Case of Infringements

7.1 Assistance Obligations

Processor shall assist Controller in complying with the obligations concerning:

  • Security of personal data (Article 32);
  • Reporting requirements for data breaches (Article 33);
  • Data protection impact assessments (Article 35); and
  • Prior consultations (Article 36).

These include:

  • Ensuring an appropriate level of protection through technical and organizational measures that take into account the circumstances and purposes of the processing as well as the projected probability and severity of a possible infringement of the law as a result of security vulnerabilities;
  • Enabling immediate detection of relevant infringement events;
  • The obligation to report a personal data breach immediately to Controller;
  • The duty to assist Controller with regard to Controller's obligation to provide information to data subjects;
  • Immediately providing Controller with all relevant information in this regard;
  • Supporting Controller, if necessary, with its data protection impact assessment; and
  • Supporting Controller, if necessary, with regard to prior consultation of the supervisory authority.

8. Authority of Controller to Issue Instructions

8.1 General Instructions

Controller reserves the right to issue comprehensive instructions on the type, scope, and procedure of data processing, which can be specified by means of individual instructions.

Changes to the subject of processing and procedural changes shall be made in accordance with the instructions of Controller and shall be documented. If changes to the processing are implemented, Processor must be informed immediately.

8.2 Confirmation of Oral Instructions

Controller shall immediately confirm oral instructions (at minimum in text form).

8.3 Objection to Instructions

Processor shall inform Controller immediately if an instruction is considered to violate any applicable data protection regulations. Processor shall then be entitled to suspend the execution of the relevant instructions until Controller confirms or changes them.

9. Deletion, Return, and Further Use of Personal Data

9.1 Prohibition on Unauthorised Copies

Copies or duplicates of the data shall never be created without the knowledge of Controller, with the exception of:

  • Back-up copies as far as they are necessary to ensure orderly data processing; and
  • Data required to meet regulatory requirements to retain data.

9.2 Return or Destruction Upon Termination

After conclusion of the data processing governed by this agreement, or earlier upon request by Controller, at the latest upon termination of the agreement, Processor shall hand over to Controller or, subject to prior consent, destroy all documents, processing and utilization results, and data sets related to the processing.

9.3 Retention of Documentation

Documentation which is used to demonstrate orderly data processing shall be stored beyond the contract duration by Processor in accordance with the respective retention periods.

Appendix 1: Technical and Organisational Measures

1. Electronic Access Control

Measures and protocols to prevent unauthorised persons from using data processing systems:

  • Assignment of user rights
  • Creation of user profiles
  • Password assignment
  • Assignment of user profiles within IT system
  • Authentication by username/password
  • Encryption of data carriers within laptops/notebooks
  • Use of software firewall

2. Internal Access Control

Measures and protocols to ensure that access to data processing systems of any person granted user rights under the authority of Processor is limited to the granted rights, and that personal data cannot be read, copied, changed, or deleted within the system when processed, used, or after storage:

  • Number of administrators limited to the minimum
  • Recording of access to systems, especially when entering, changing, or deleting data
  • Management of rights by system administrator
  • Password policy including length and change of password

3. Separation Rule

Measures and protocols to ensure that data which have been collected for different purposes can be processed separately:

  • Logical client separation (by software)
  • Separation of productive systems from test systems

4. Data Entry Control

Measures and protocols to ensure subsequent verification and determination whether and by whom data is entered, changed, or deleted in a data processing system:

  • Recording of entry, change, and deletion
  • Control by logfile system of data
  • Assignment of rights to enter, change, or delete data based on authorization concept

5. Order Control

Measures and protocols to ensure personal data processed in order and on behalf of Controller will only be processed for the performance of the contract and according to the instructions of Controller:

  • Written instructions by Controller (e.g., through this Data Processing Agreement)

6. Availability Control

Measures and protocols to prevent personal data from accidental destruction or loss:

  • Regular backup copies

7. Procedures for Regular Testing, Assessment, and Evaluation (Article 32(1)(d) GDPR; Article 25(1) GDPR)

The adopted measures and protocols shall undergo regular assessment. The measures shall undergo technology upgrading and are to be kept up to date. Within the company, the control and evaluation concept will be implemented as follows:

  • Regular monitoring of technical components of the backup and recovery concept
  • Regular installation of patches and software updates

Contact Information

Processor:

TD Marvel d.o.o.
Beogradska 9
Belgrade, Serbia

Contact: dpa@taxsync-app.eu

TaxSync: Your Partner for PPWR Compliance.