Data processing
We collect and process some of your data to improve your experience, offer you relevant content and keep everything running efficiently. Relax! Your data is in good hands and we treat it in full confidence.
We only use what is needed for you to get the most out of it. If you would like to know more, you can read our Privacy Policy.
This Data Processing Agreement is entered into between Comisionea S.L., a Spanish limited company with registered office at Calle Virués, 4 bajo, 46002 Valencia, Spain (hereinafter, "Feending" or the "Company") and the party that electronically or otherwise accepts, agrees to or opts into this Data Processing Agreement — for example, by signing an order form (the "Customer") — it being specified that use of the Feending solution (hereinafter, the "Feending Solution") constitutes acceptance of this Data Processing Agreement.
PREAMBLE
In the context of European Union Regulation 2016/679 (GDPR), the purpose of this Data Processing Agreement is to set out the rights and obligations of the Parties, as defined by the Data Protection Legislation defined herein.
In this respect, Feending is particularly mindful of the privacy of its Users and of the Customer as regards the protection of their Personal Data, as well as of its obligations as a Data Processor, where applicable, as described in this Data Processing Agreement.
It is expressly understood that this Data Processing Agreement forms an integral part of the main subscription contract applying to the Parties with regard to the provision of the Feending solution (hereinafter, the "Contract").
ARTICLE 1: DEFINITIONS
Terms used in this Data Processing Agreement with an initial capital letter, whether singular or plural, have the following meaning:
"Administrator" means any person, employee, representative or third party duly authorised by the Customer or by one of its Administrators to access the administration panel of the Feending Solution.
"Customer Contact Email" means the Customer's email address communicated to Feending for the purpose of notifying relevant information about the Processing carried out by the Company.
"Data Controller" means the natural or legal person, public authority or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
"Data Processor" means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
"Data Protection Legislation" means the GDPR, together with any legislation and/or regulation implementing or made under the GDPR and the ePrivacy Legislation, or amending, replacing, re-enacting or consolidating any of them, and all other applicable national laws relating to the processing of personal data and privacy that may exist under applicable law.
"Data Subject" means a natural person who is the subject of Personal Data.
"End User" means any User of the Feending Solution, other than an Administrator and the Customer, who can access the Feending Solution with credentials provided by an Administrator and who interacts using the Feending Solution.
"GDPR" (General Data Protection Regulation) means Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC, together with its European and national implementing laws.
"Personal Data" means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"User" means any Administrator or End User.
ARTICLE 2: PROCESSING OF PERSONAL DATA
Personal Data is collected and processed as follows.
2.1 Personal Data of the Customer's staff
In accordance with its subscription to the Contract and the availability of the Feending Solution, the Company collects information identifying the Customer (trade name, legal form, business address, tax or intra-EU VAT number) and contact Personal Data (emails, billing contacts).
For the collection of the Personal Data of the Customer's staff (including the Customer Contact Email), the Company qualifies as Data Controller.
2.2 Personal Data of Users
The Personal Data of Users processed through the use of the Feending Solution is the sole responsibility of the Customer, who collects and processes that Personal Data on its own account, it being understood that the Customer determines the purposes and general means of the processing of Personal Data in accordance with the applicable Data Protection Legislation.
2.3 Processing of Users' Personal Data by the Company
The Customer is informed that the Personal Data of its Users is collected for the sole purpose of performing the Contract and running the Feending Solution the Customer has subscribed to. If the Customer does not provide the required Personal Data, it will not be able to use the full functionality of the services.
The Customer is informed that the Company carries out statistical analyses, as well as measurements of audience, visits and actual use of the Feending Solution, but only after anonymising Users' Personal Data. Moreover, those statistical analyses and measurements of audience, visits and actual use of the Feending Solution are intended for Feending alone, excluding third parties, and for the sole purpose of optimising and improving the features of the Feending Solution.
The Customer guarantees that this information is accurately passed on to the Users of the Feending Solution.
2.4 The Customer's obligations as Data Controller
The Customer, in using the Feending Solution, is to be qualified as the Data Controller of the Users' Personal Data.
As Data Controller, the Customer explicitly undertakes to:
- Have a legal basis for collecting and processing Personal Data before collecting or hosting it. The Customer confirms that it is aware that it may obtain the User's consent through a feature provided by the Company within the Feending Solution.
- Collect Users' Personal Data only for specified, explicit and legitimate purposes and not process it in a manner incompatible with those purposes.
- Keep a record of the processing of Personal Data carried out through the Feending Solution.
- Implement all technical and organisational measures needed to ensure the security of the processing carried out, to guarantee the protection of the rights of the people affected by the processing and to meet the requirements of the Data Protection Legislation.
- Limit access to Users' Personal Data solely to the people authorised to have it, that is, to the Users of the Feending Solution.
- Raise awareness among staff and train them on the processing of Personal Data, the provisions of the Data Protection Legislation and their consequences.
- Never transfer Users' Personal Data to a third party in any way, unless that transfer complies with the Data Protection Legislation.
- Guarantee all rights relating to access, portability, erasure, rectification, objection and restriction of the Users' Personal Data collected during use of the Feending Solution; where the Customer requires the Company's assistance to do so, the Customer undertakes to notify the Company of any request to exercise any of the rights mentioned above without delay.
- Notify the relevant supervisory authority of any security breach posing a serious risk to the rights and freedoms of Users within 72 hours of becoming aware of the breach.
- After termination of the Contract with the Company, and where retention is no longer necessary, proceed to erase the Users' Personal Data within a period compatible with the Data Protection Legislation.
Where the information is collected directly from Users, the Customer, as Data Controller, undertakes to provide Users with the following information, as applicable:
- Information about the identity of the Customer, together with the name of the Data Controller.
- The purpose of the processing of Personal Data.
- The recipient of the Personal Data: the Customer and the Company, together with their subcontractors.
- The retention period of the Personal Data.
- The existence of their rights relating to access, rectification, erasure and portability of the Personal Data, or to any restriction of or objection to the processing of that data.
- Where applicable, the Users' right to withdraw their consent to the processing.
- The Users' right to lodge a complaint with the competent supervisory authority if they consider that their rights have not been respected.
- The Customer informs Users that refusing to provide the data mentioned above will make the Feending Solution unavailable for use.
Under this Data Processing Agreement, the Customer undertakes to complete all declaration formalities and/or authorisation requests and/or impact assessments, if required, and to ensure mandatory compliance with the competent supervisory authority in the light of the processing it carries out in connection with the use of the Feending Solution.
Where the Customer has not yet completed the formalities mentioned above, it explicitly undertakes to do so immediately.
The Customer remains responsible for the Processing of Personal Data carried out under its own responsibility.
The Customer must provide the Customer Contact Email to the Company.
2.5 The Company's obligations as Data Processor
The use of Users' Personal Data in the context of the use of the Feending Solution means that Feending is to be qualified as a Data Processor.
The subject matter, duration, nature and purpose of the processing of the Personal Data, as well as the type of Personal Data processed and the categories of Data Subjects, are listed in Annex 1.
The Contract, its Appendices and this Data Processing Agreement are to be qualified as written instructions from the Customer, qualified as the Data Controller, to Feending, qualified as the Data Processor, without prejudice to any further instructions given in writing.
As Data Processor, and in accordance with the privacy procedures provided for by the Data Protection Legislation, Feending may only use Personal Data on the instructions of the Customer responsible for the processing.
As Data Processor, Feending undertakes to always provide sufficient guarantees to ensure that the necessary security and privacy measures are implemented.
Furthermore, Feending undertakes to:
- Support the Customer in meeting the Customer's obligations to respond to Data Subjects' requests to exercise their rights under the GDPR; where that assistance goes beyond what is commercially reasonable, Feending and the Customer will agree the financial terms applying to its continuation.
- Keep a record of the processing of Personal Data carried out through the Feending Solution.
- Not transfer Users' Personal Data to third parties, other than its subcontractors and as permitted by the Contract, its Appendices and this Data Processing Agreement, and without having given the Customer prior notice.
- Allow the Data Controller to audit the processing carried out by Feending, as well as any appropriate technical and organisational measures ensuring the security of the processing, respect for the rights of data subjects and the requirements of the Data Protection Legislation, it being specified that the Customer must give the Company at least thirty (30) calendar days' written notice. The audit will be carried out at the Customer's expense and may cover only the appropriate technical and organisational measures ensuring the security of the processing, respect for the rights of data subjects and the requirements of the GDPR. The Customer undertakes to appoint an independent auditor, who is not a competitor of the Company in the software-as-a-service (SaaS) field, who is approved in advance by the Company and who accepts a confidentiality agreement. The Company undertakes to co-operate with the auditor in carrying out its work by providing reasonably necessary information and answering its reasonable questions. A copy of the audit report prepared by the auditor will be provided to each Party and discussed jointly by the Parties at a meeting arranged specifically for that purpose.
- The Company undertakes to help the Customer analyse whether a data protection impact assessment is required for the Customer's processing of Personal Data. Where the Customer considers such an assessment necessary, the Company undertakes to assist the Customer in carrying out the data protection impact assessment and, where applicable, in connection with prior consultation of the supervisory authority. This assistance is owed on the same terms as those set out in the first paragraph of this article.
- Restrict access to Personal Data to authorised staff only. In this respect, the Company informs the Customer that, under their employment contracts, its staff are bound by confidentiality clauses that refer explicitly to Personal Data.
2.6 Data breach
The Company will implement all technical measures allowing personal data breaches (as defined by the Data Protection Legislation) to be detected and the Data Controller to be informed of them within a reasonable period of time.
Where a personal data breach occurs or has occurred, the Company will notify the Customer by email without undue delay and, in any event, within 72 hours of becoming aware of the breach, using the Customer Contact Email.
Without prejudice to the Company's legal obligations, the Customer will be responsible for notifying the breach to the competent authority or authorities and/or to the people affected.
Without prejudice to the Company's legal obligations, the Company will assist the Customer to the best of its ability with the notification of the breach to the competent authority or authorities and/or to the people affected.
The Company will in every case treat all of the Customer's questions and requests relating to the breach as a priority.
In the event of a breach, the Company will take all necessary and appropriate measures to restore the Personal Data and/or to limit the negative impact of the breach as far as possible (including, but not limited to, providing forensic assistance to the Customer), it being understood that the Company will, wherever reasonably possible, always consult the Customer on the measures to be taken.
2.7 Appropriate technical and organisational measures implemented by Feending
From the start of the Processing, the Company has implemented appropriate technical and organisational measures to ensure the security of the processing, as well as respect for the rights of the people involved and the requirements of the GDPR.
The code of the Feending Solution and the Personal Data processed are hosted on Amazon and Google Cloud Platform servers, as both offer sufficient guarantees in terms of the technical and organisational measures required under the Data Protection Legislation.
The Customer can read the privacy policies of Amazon AWS and Google Cloud Platform at the following addresses:
https://cloud.google.com/security/privacy/
https://aws.amazon.com/compliance/gdpr-center/
The Company also makes a daily copy of the Personal Data hosted on the Amazon and/or Google Cloud Platform servers. The Personal Data is saved once every hour. The Company keeps the last copy of each day for a period of thirty (30) days.
The Customer is able to export End Users' Personal Data to an Excel spreadsheet from its administration module.
For any further questions, the Company invites its customers to get in touch by email at soporte@feending.com.
2.8 The Data Processor's service providers
For the services offered on Feending to work properly, data has to be transferred outside the European area — for example, it may be transferred to and stored in countries outside the European Economic Area (EEA). This is because we use remote servers to provide our services, which may be located outside the EEA or use servers outside the EEA, which is generally the nature of data stored in the "cloud". It may also be processed by staff operating outside the EEA who work for one of our providers, such as our web server provider (Amazon Web Services and Google Cloud Platform), our payment processing provider (Stripe) or our marketing services provider (Hubspot). These services keep their privacy policies up to date.
This processing of data outside the EEA is covered by legal mechanisms that allow the data to be transferred. If you need further information about international data transfers, get in touch with us at contacto@feending.com.
2.9 Personal Data retention period
A. Personal Data of the Customer's staff
Subject to the mandatory retention period for all data relating to customer files, which is three (3) years from the end of the contractual relationship, the identification data of the Customer's staff (including the Customer Contact Email) will be retained by Feending for a period no longer than the subscription period of the Feending Solution, save for the statutory archiving period.
B. Personal Data of Users
The Company informs the Customer that it will erase Users' Personal Data within thirty (30) to ninety (90) days of termination of the Contract, without prejudice to any direct erasure request from Users.
At the end of the contractual relationship, the Company undertakes to return, free of charge and on the Customer's first request made by registered letter with acknowledgement of receipt, all Personal Data belonging to the Customer that remains in the Company's possession under the terms of this Data Processing Agreement, in a standard format (Microsoft Excel, SQL and CSV), within thirty (30) days of that request.
The Company also undertakes to answer any question raised by the Customer within thirty (30) calendar days of receiving the return request.
2.10 The Customer's liability
The Customer remains solely responsible for the lawfulness of the processing carried out during use of the Feending Solution.
Furthermore, the Customer remains solely responsible for the Personal Data it collects and processes as Data Controller. The Customer undertakes to collect and process Users' Personal Data in accordance with the Data Protection Legislation.
The Customer is informed that certain categories of Personal Data, described as "sensitive" under the Data Protection Legislation, may not be collected or processed without the prior explicit consent of the data subjects, or without any other formality provided for by the applicable Data Protection Legislation (authorisation request, impact assessment and so on). The Customer undertakes never to collect or process sensitive Personal Data, other than as the Legislation allows. The Company declines all liability with regard to the collection or processing of sensitive Personal Data. The Customer acknowledges and accepts that any potential sensitive personal data is subject to the same technical and organisational security measures the Company has implemented for non-sensitive Personal Data.
The Company, acting as Data Processor, declines all liability with regard to the quality, relevance and lawfulness of the Personal Data. Except as provided herein, the Company cannot be held liable in the event of collection or processing of Personal Data that breaches the provisions of the Data Protection Legislation.
The Customer indemnifies the Company, on first request, against any damage incurred as a result of any action by a User or any third party arising from the breach of this clause and/or any breach of any of its obligations as data controller under the Data Protection Legislation.
ANNEX 1. OVERVIEW OF THE PROCESSING
A. Duration of the Processing
For the duration of the contractual relationship between the Parties, including the period covered by the Data Reversibility clause of the Contract.
B. Nature and Purpose of the Processing
The Personal Data will be processed for the purpose of providing the services set out and agreed in the Contract. In this respect, Feending may carry out any kind of processing operation.
C. Type of Personal Data Processed
- Personal identification data (first name, surname, gender, profile photograph, date of birth, language spoken, nationality, email, telephone, address);
- Electronic identification data (IP addresses, cookies);
- Academic record and results;
- Professional experience;
- Current job;
- Professional qualifications and certificates;
- Hobbies and areas of interest;
- Location data;
- In general, any personal information sent or published by a User (payment details and so on).
D. Categories of Data Subjects
Users of the Controller, including but not limited to the members of the Controller's community, employees, collaborators, customers, prospects, suppliers and subcontractors of the Controller.
E. Security Measures
The Data Processor will implement appropriate technical and organisational measures and will monitor compliance with those measures on a regular basis. This includes:
- System access control: the Data Processor will take reasonable measures to prevent unauthorised access to computer systems, such as strong authentication procedures (passwords, two-factor authentication) and documented access approvals.
- Data access control: the Data Processor will take reasonable measures to prevent unauthorised access to Personal Data, such as granting access to personal data only on a need-to-know basis, confidentiality obligations and workstation locking.
- Data transfer control: the Data Processor will take reasonable measures to ensure that personal data cannot be read, copied, modified or deleted without authorisation during electronic transmission, transport or storage, and that it is possible to check and establish to which bodies the transfer of personal data by data transmission facilities is envisaged (data transfer control), such as encryption of data at rest and in transit.
- Input control: the Data Processor will take reasonable measures to make it possible to check retrospectively and establish whether and by whom Personal Data has been entered, modified or deleted in data processing systems, such as logging systems.
- Job control: the Data Processor will take reasonable measures to ensure that personal data is processed in accordance with the Data Controller's instructions, such as entering into appropriate data processing agreements with sub-processors.
- Availability control: the Data Processor will take reasonable measures to prevent the accidental destruction or loss of Personal Data.