Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between Eazy CRM ("Company") and the customer ("Customer") and is incorporated into the Terms of Service.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person. "Data Protection Laws" means all applicable laws relating to data protection and privacy.
2. Processing of Personal Data
The Company shall process Personal Data only on behalf of the Customer and in accordance with the Customer's instructions. The Company is prohibited from using the Personal Data for any other purpose.
3. Confidentiality
The Company shall ensure that its personnel who are authorized to process Personal Data are subject to a duty of confidentiality.
4. Security
The Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
5. Sub-processing
The Company shall not engage any other processor to process Personal Data without the Customer's prior written consent. Where the Company engages a sub-processor, it shall do so only by way of a written agreement with the sub-processor which imposes the same data protection obligations as set out in this DPA.
6. Data Subject Rights
The Company shall, to the extent legally permitted, promptly notify the Customer if it receives a request from a Data Subject to exercise their rights of access, rectification, erasure, or other rights under Data Protection Laws. The Company shall provide the Customer with reasonable assistance in responding to such requests.
7. Personal Data Breach
The Company shall notify the Customer without undue delay after becoming aware of a Personal Data Breach. The Company shall provide the Customer with sufficient information to allow the Customer to meet any obligations to report or inform Data Subjects of the Personal Data Breach.
8. Data Transfers
The Company shall not transfer any Personal Data to any country or territory outside the European Economic Area (EEA) without the Customer's prior written consent.
9. Deletion or Return of Personal Data
Upon termination of the services, the Company shall, at the Customer's choice, delete or return all Personal Data to the Customer.