This document is a data processing agreement within the meaning of Article 28 GDPR. It is concluded together with the terms of service, at the same moment, and applies for as long as we run your application.
In short
- You are the controller of the data in your application. We are the processor.
- We process it solely on your documented instructions and to run the application.
- The subprocessor list is public and we give notice before changing it.
- After the contract ends the data is deleted within 30 days, backups included.
01Parties and subject matter
This agreement covers personal data you place in the NEXAENVISION application, or that reaches it through use by your staff and business partners.
Controller
You. You decide what data enters the application, for what purpose and how long it stays there.
Processor
REDOC Sp. z o.o. We process that data solely to keep the application running and to deliver the changes you order.
02Duration
Processing lasts as long as the main contract. It ends with it, and the obligations concerning deletion apply after it ends as well.
03Nature, purpose and scope of processing
The scope follows from how you use the application. The entries below describe the typical case - if you intend to put special category data into the application, tell us before we start.
- Nature
- Storage, organisation, disclosure to authorised users, backup, deletion
- Purpose
- Running your application instance and delivering the changes you order in it
- Types of data
- Identification and contact data, billing data, the content of documents and requests entered into the application
- Categories of people
- Your staff and contractors, your customers and business partners, and anyone whose data you enter into the application
The application is not intended for special category data under Article 9 GDPR or data under Article 10. If such data is to be held in it, that requires a separate arrangement before the instance starts.
04The controller's instructions
We process the data solely on your documented instructions. Your configuration of the application and the content of the requests you submit constitute those instructions. If we believe an instruction infringes data protection law, we tell you before carrying it out.
We do not process this data for our own purposes. In particular, customer data and content processed in NEXAENVISION is never used to train AI models - ours or anyone else's.
05Confidentiality
Only people who need it to run the service are given access to the data, and they are bound by confidentiality obligations. Every access to a customer database is logged.
06Security of processing
We apply technical and organisational measures matching Article 32 GDPR. The main ones:
- A separate application instance and a separate database for every customer. Nothing is shared.
- Encryption in transit and at rest.
- Daily backups, verified by restoring them.
- Role and permission based access, with a change log inside the application.
- Work on changes is done on the description written by our administrator and on source code - not on the text of requests and not on production data.
07Subprocessors
We use subprocessors only where necessary to provide the service, and we bind them by obligations no lighter than our own. The current list is public and forms part of this agreement.
We notify you by e-mail at least 30 days before adding or changing a subprocessor. You may object during that period, and if we cannot find a solution you may end the contract without consequences.
08Help with your obligations
We help you meet the obligations GDPR places on a controller:
- Answering data subject requests - access, rectification, erasure, portability. A full export is available in the application at all times.
- Breach notification: we inform you without undue delay after becoming aware of a breach, so that you can notify the authority within 72 hours.
- Data protection impact assessments and prior consultation - we provide the information available to us.
09Deletion or return of data
After the contract ends you have 30 days to export your data. After that we delete it together with the backups, unless the law requires us to keep it.
The same period applies to trials, counted from the moment the trial expires.
10Information, audit and data transfers
At your request we provide the information needed to demonstrate that we comply with this agreement, and we allow an audit - carried out by you or an auditor you appoint, at a time agreed in advance.
Your application, its database and its backups run in one agreed region, the European Union by default. Today no subprocessor processes your data outside the European Economic Area. Should that change, we will state the basis for the transfer next to it on the subprocessor list and give you notice in advance.