Data Protection Agreement
THE FOLLOWING PARTIES:
EMPRESAS PROCESSOR, headquartered at Av. Severo Dullius, nº 410, Bairro São João, Porto Alegre – RS, hereinafter referred to as the “CONTRACTOR”;
And the individual and/or legal entity that enters into an agreement with Grupo Processor, duly identified in the Commercial Proposal or Ancillary Agreement completed and duly signed by the Parties, which forms an integral part of this agreement, hereinafter referred to as the “CLIENT”;
They enter into this DATA PROTECTION AGREEMENT, which shall be governed by the clauses set forth below:
PURPOSE:
The purpose of this term is to establish the agreement between the Parties regarding data protection in accordance with the guidelines of the LGPD (Law No. 13,709/2018). The Parties undertake, on their own behalf and through their representatives, employees and third parties who, at their direction, participate in providing the contracted services, to act in strict compliance with data protection laws and to fully comply with the rules established in this instrument.
OF THE PARTIES’ COMMITMENT:
The Parties irrevocably and unconditionally undertake to:
I. Act in a manner that protects and ensures the proper processing of the data to which they have access during and as a result of the contractual relationship, with each Party being solely and individually responsible for complying with its obligations under the LGPD, as well as for any sanction imposed on it by data protection law in the event of a violation of legal requirements;
II. Adopt reasonable measures to ensure that the use of data to which they gain access as a result of the contractual relationship remains within the limits established by the LGPD, exclusively for the specific purposes set out in the service agreement entered into between the Parties or for the purposes indicated in the CONTRACTOR's privacy policy, available at https://www.processor.com.br/politica-de-privacidade;
III. Maintain confidentiality regarding personal data, information, or documents of a confidential nature to which they gain access as a result of providing the services, being, under the law, responsible for the consequences of improper disclosure or incorrect use thereof;
IV. Do not alter, delete, add to or manipulate the other Party’s systems and/or information and/or data except for the purposes set forth in the contract or the purposes indicated in the privacy policy available at https://www.processor.com.br/politica-de-privacidade, with each Party being responsible for control and monitoring as provided by law;
V. Take reasonable measures to ensure that the data provided to the other Party was obtained in accordance with the rules set forth in the LGPD, where applicable;
VI. In compliance with article 6, item VII, of the LGPD, adopt security, technical and administrative measures capable of protecting personal data from unauthorized access and accidental or unlawful destruction, loss, alteration, communication or dissemination, taking into account the nature of the data processed and the contracted service;
VII. Keep the personal data and confidential information to which they have access as a result of the relationship between the Parties under security programs (including the adoption and application of internal policies and procedures) designed to protect personal data against accidental or unlawful loss, access or disclosure, identify likely and reasonable risks, and prevent unauthorized access to their infrastructure.
VIII. Take reasonable measures to ensure the reliability of employees and/or service providers who may have access to personal data or confidential information arising from the existing agreement between the Parties, as necessary for the purposes of the contractual relationship, ensuring that such individuals are bound by confidentiality commitments;
IX. Notify the other Party, within a reasonable and duly justified period:
(a) if they know or suspect that personal data and/or confidential information related to the agreement has been compromised, disclosed to unauthorized persons or used without authorization;
(b) if complaints have been submitted regarding data processing practices related to the contract/provision of services;
(c) if there has been a significant or substantial breach of the requirements contained in this document;
(d) unless legally required or compelled by a subpoena, court order, or similar document issued by a court or regulatory authority, the Parties agree not to disclose the Security Incident to third parties without first reaching a prior written agreement.
X. Monitor and track compliance of your practices with the personal data protection obligations set out in this instrument.
CLIENT RESPONSIBILITIES:
In relationships where the CLIENT acts as Controller, it will be responsible for obtaining and managing the authorizations and/or consents required from data subjects. Accordingly, it is acknowledged that:
I. The CLIENT, as Controller, is responsible for obtaining the data subject’s prior consent for the processing of submitted data, in writing or by any other means that demonstrates the data subject’s expression of intent, pursuant to Articles 7, item I, and 8 of the LGPD;
II. As Controller, the CLIENT is responsible for obtaining the data subject’s specific consent when personal data must be communicated or shared with other controllers, as provided for in § 5 of Article 7 of the LGPD;
III. Pursuant to Article 8, § 2, of the LGPD, the CLIENT is responsible for proving, whenever necessary, that the consent provided by the data subject complies with the provisions of the LGPD.
IV. The CUSTOMER, in its capacity as Controller, shall maintain a data protection impact report describing personal data processing activities with the potential to pose risks, indicating the respective measures, safeguards and mitigation mechanisms, as provided for in Article 5, item XVII, of the LGPD.
CONTRACTOR’S RESPONSIBILITIES:
I. Under the contracts entered into between the CLIENT and the CONTRACTOR, due to the nature/type of the contractual relationship, the CONTRACTOR does not process data belonging to the CLIENT or third parties related to it. Accordingly, the CLIENT hereby acknowledges and agrees that the CONTRACTOR, pursuant to Article 43, item I, of the LGPD, shall be exempt from the duty to compensate referred to in Article 42, caput, of the LGPD and shall therefore not be liable for damage of any kind arising from a violation of data protection legislation. Such liability shall rest exclusively with the CLIENT and/or a related third party that may be responsible for processing the data;
II. In cases where the contractual relationship between the CLIENT and the CONTRACTED PARTY concerns services related to “Mérito,” “Max Outsource (BPO),” or “LiveCloud BizApps,” and/or where the CONTRACTED PARTY acts under the contract as a service provider entrusted explicitly with a database containing sensitive data, such as a CRM, ERP, or BI system, the CONTRACTED PARTY’s responsibility for data processing and protection will comply strictly with the guidelines of the LGPD. In this case, the following provisions will apply:
(a) As provided in Article 39 of the LGPD, the CONTRACTOR, as Processor, will process data in accordance with the instructions provided by the CLIENT, as Controller, who will verify compliance with its own instructions and the applicable rules;
(b) Under all circumstances, the instructions must be lawful, feasible and compatible with the purpose of the contractual relationship entered into between the CLIENT and the CONTRACTOR. They must be provided in writing and addressed to a single representative of the CONTRACTOR, previously designated by the Parties as the focal point and person responsible for the contract, who must, in all cases, provide written consent to the instruction issued by the CLIENT as proof that the CONTRACTOR is aware of the directive received;
(c) If implementing the instruction provided by the CLIENT is not previously and expressly indicated in the scope of the commercial proposal and included in the investment amount agreed at the time of contracting, the costs of its implementation and operation will be added to the contract value, according to the tools required to meet these requirements. The CONTRACTOR will automatically be released from complying with the instruction if the CLIENT does not agree to and/or pay the related financial impacts arising from its specific requirements;
(d) If necessary for the proper performance of its contractual obligations, the CONTRACTED PARTY may transfer data outside Brazilian territory, undertaking to observe and comply with the rules set forth in the LGPD, and to carry out the transfer only to countries that provide a reasonable level of data protection and/or upon entering into a data protection agreement with the partner, in accordance with the CONTRACTED PARTY’s Privacy Policy, available at https://www.processor.com.br/politica-de-privacidade.
FINAL PROVISIONS:
I. The CUSTOMER agrees that the CONTRACTOR may collect the CUSTOMER’s data, such as registration data required for billing, data collected at events and through surveys, data necessary to maintain the existing commercial relationship between the Parties, as well as solution usage data, which will be used for the specific purposes of:
(a) improve the delivery and maintenance of the CONTRACTED PARTY’s products and services;
(b) create and maintain the CLIENT’s account with the CONTRACTOR;
(c) assess risk, credit, and payments;
(d) provide the CLIENT with services and information related to its account;
(e) assist the CLIENT with service and technical support issues or general questions;
(f) send marketing and promotional communications and targeted advertising with relevant offers, including the customization of content and marketing offers that may be of interest to the CLIENT;
(g) ensure the authenticity of the CLIENT’s access to its account;
(h) detect and prevent fraud;
(i) manage and protect the CONTRACTOR's employees, facilities, communication networks, services, products, and customers;
(j) comply with the CONTRACTOR's legal and regulatory obligations;
(k) conduct research related to the CONTRACTOR’s products and services;
(l) other practices set out in the CONTRACTED PARTY’s Privacy Policy, available at https://www.processor.com.br/politica-de-privacidade;
(m) for the cases described above, where the CONTRACTOR retains the CLIENT’s data, the protection and confidentiality of such data are guaranteed in accordance with this instrument and applicable law;
II. The CLIENT understands and agrees that, when using cloud services, if it does not want its data stored outside the national territory, it must notify the CONTRACTOR in advance, acknowledging that restricting the territory will result in changes to the prices negotiated for the engagement.
III. The parties declare that they are aware of and agree to indemnify each other, up to the annual contract value, excluding taxes and charges, for any damages demonstrably incurred as a result of the exclusive fault of the breaching party with respect to the obligations assumed in this instrument and/or provided for in data protection legislation, the occurrence of which must be proven by a final, non-appealable court decision.
IV. THE RULES SET FORTH HEREIN SHALL APPLY TO ALL CONTRACTS ALREADY IN EXISTENCE OR THAT MAY BE ENTERED INTO BETWEEN GRUPO PROCESSOR AND THE CLIENT and shall replace the data protection and processing guidelines previously agreed between the Parties to the extent that they conflict with these rules.
TERM:
This instrument and its respective updates are registered with the Registry Office and available on the CONTRACTOR’s websites (www.processor.com.br and www.gotobiz.com.br). The context established herein will take effect at the beginning of the commercial relationship between the CLIENT and the CONTRACTOR, after the enactment of the General Data Protection Law, through accession by signing an Ancillary Agreement and/or Commercial Proposal, and shall be accepted by the Parties as a guide for the practices required of both Parties under the LGPD. The provisions agreed herein shall remain in force throughout the entire term of the commercial relationship between the Parties, as well as after the services have ended, as required by applicable law.
JURISDICTION:
To settle any disputes arising from this Term that are not resolved between the Parties, the courts of the District of Porto Alegre are hereby elected, with waiver of any other jurisdiction, however privileged it may be.
Instrument recorded under number 112663, on folio 241f, in book B-367 of the Integral Registry of Deeds and Documents, 1st Registry of Deeds and Documents of Legal Entities of Porto Alegre.In accordance with Article 41, § 1, of Law No. 13.709 of 2018, we inform you that the Data Protection Officer of the Processor Companies (DPO) is: Ana Pochmann.