Welcome to EHA Soft Solutions
SERVICE LEVEL AGREEMENT (SLA)
This Service Level Agreement (“Agreement“),
between:
and
Company (“Processor/ Customer/Controller”) acting on its own behalf
The terms used in this Agreement shall have the meanings set forth in this Agreement. Capitalised terms not otherwise defined herein shall have the meaning given to them in the Principal Agreement. Except as modified below, the terms of the Principal Agreement shall remain in full force and effect.
In consideration of the mutual obligations set out herein, the parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the Principal Agreement. Except where the context requires otherwise, references in this Addendum to the Principal Agreement are to the Principal Agreement as amended by, and including, this Addendum.
This Service Level Agreement (SLA) remains valid until mutually endorsed by the stakeholders. This SLA supplement the EHA SOFT SOLUTIONS LTD. General Terms and Conditions of Business which is attached in Appendix 1 of this document. In the case of any conflict between the SLA, the General Terms and Conditions, and the Data Processing Agreement at Appendix 2, the order of priority shall be (1) the Data Processing Agreement, (2) the SLA, and (3) the General Terms and Conditions.
The goal of this Agreement is to obtain mutual agreement between the Service Provider(s) and Customer(s).
The objectives of this Agreement are to:
(a)Provide a thorough understanding of service ownership and the roles and responsibilities.
(b)This Agreement represents a concise description of the services provided by the Service Provider.
(c)Match perceptions of expected service provision with actual service support & delivery.
The following Service Provider(s) and Customer(s) will be used as the basis of the Agreement and represent the primary stakeholders associated with this SLA:
Service Provider(s): EHA SOFT SOLUTIONS LTD. (“Controller/Provider”)
Customer(s): COMPANY (“Processor/Customer”)
The terms stated in the Agreement shall be valid from the Effective Date. The revisions to this agreement shall be carried out every fiscal year, however, during the revision, the current Agreement shall be considered valid.
Review Period: Annually
Previous Review Date: 26th January 2021
EHA SOFT SOLUTIONS LTD. has implemented ISO 27001 and maintains the required protocols in order to ensure that clients’ requirements are being met to the highest standards.
EHA SOFT SOLUTIONS LTD. will maintain confidentiality and will adhere to all requirements of the Data Protection legislation. Any breach of this obligation shall entitle the CLIENT to terminate this SLA with immediate effect and EHA SOFT SOLUTIONS LTD. will indemnify CLIENT against all liabilities, costs, expenses, damages and losses (including but not limited to any direct, indirect or consequential losses, loss of profit, loss of reputation and all interest, penalties and legal costs (calculated on a full indemnity basis) and all other reasonable professional costs and expenses) suffered or incurred by CLIENT arising out of or in connection with such breach.
The following are the responsibility of the Service Provider in the ongoing support of this Agreement.
(a) Service Scope
The following Services are covered by this Agreement (for more information please go to Appendixes 1 and 2):
I. Contractor Portal
II. mai™ Management System Software
(b) Customer Requirements
Customer responsibilities and/or requirements in support of this Agreement include:
I. Payment for all support costs at the agreed interval.
(c) Service Provider Requirements
Service Provider responsibilities and/or requirements in support of this Agreement include:
I. Adhering to appropriate response times associated with service-related incidents.
II. Advance notification to the Customer for all maintenance.
(d) Service Assumptions
Assumptions related to in-scope services and/or components include:
I. Changes to services will be communicated and documented to all stakeholders.
For maintaining adequate customer-support levels, this Agreement lists the available scope of services/solutions provided by the Service Provider. This lists details regarding availability, monitoring, and other relevant factors.
(a) Service Availability
I. Coverage parameters specific to the service(s) covered in this Agreement are as follows:
Telephone support: 0900 A.M. to 1700. Monday – Friday
II. Calls received out of office hours will be forwarded to a mobile phone and best efforts will be made to answer / action the call, however, there will be a backup answer phone service:
Email support: Monitored 0800 to 1800 Monday – Friday
III. Emails received outside of office hours will be collected, however, no action can be guaranteed until the next working day.
(b) Service Requests
In support of services outlined in this Agreement, the Service Provider will respond to service-related incidents and/or requests submitted by the Customer within the following time frames:
I. 0-8 hours (during business hours) for issues classified as High priority.
II. Within 48 hours for issues classified as Medium priority.
III. Within 5 working days for issues classified as Low priority.
Remote assistance will be provided in-line with the above timescales dependent on the priority of the support request.
Any amendments and/or variations to this SLA can only be made with agreement from both parties and must be written with both parties’ signatures. Please also refer to the General Terms and Conditions of Business.
APPENDIX 1 – GENERAL TERMS AND CONDITIONS OF BUSINESS
By using this website and related products (APPs etc.), you signify your consent to these terms of use and conditions. If you do not agree to these Terms of Use and Conditions, please do not use the website or related products (APP’s etc.).
These Terms of Use and Conditions may be revised from time to time by updating this posting. You are bound by any such revisions and should therefore periodically visit this page to review the then current Terms of Use and Conditions to which you are bound.
APPENDIX 2 – DATA PROCESSING AGREEMENT
This Data Processing Agreement (“Agreement“),
between:
(i) EHA SOFT SOLUTIONS LTD. (“Controller/Provider/ Processor / Joint Processor “) acting on its own behalf; and
(ii) CLIENT (“Processor/Customer“) acting on its own behalf and as agent for each Company Affiliate.
WHEREAS:
(a) Under an agreement between the Data Controller and the Data Processor – Service Level Agreement (SLA) / Data Processing Agreement (DPA) – the Data Processor provides to the Data Controller the Services described in Appendix 3.
(b) The provision of the Services by the Data Processor involves it in processing the Personal Data on behalf of the Data Controller – please refer to our Privacy and Personal Data Protection Policy, provided as an attachment to this SLA.
(c) Under EU Regulation 2016/679 General Data Protection Regulation (“the GDPR”) (Article 28, paragraph 3), the Data Controller is required to put in place an agreement in writing between the Data Controller and any organisation which processes personal data on its behalf governing the processing of that data.
(d) The Parties have agreed to enter into this Agreement to ensure compliance with the said provisions of the GDPR in relation to all processing of the Personal Data by the Data Processor for the Data Controller.
(e) The terms of this Agreement are to apply to all processing of Personal Data carried out for the Data Controller by the Data Processor and to all Personal Data held by the Data Processor in relation to all such processing.
1. Definitions
1.1 Data Protection Legislation: The General Data Protection Regulation ((EU) 2016/679) (GDPR) and any national implementing laws, regulations, and secondary legislation, as amended or updated from time to time.
1.2 Data Controller, Data Processor, processing, and data subject: shall have the meanings given to the terms “controller”, “processor”, “processing”, and “data subject” respectively in Article 4 of the GDPR.
1.3 DCO: means the Irish supervisory authority, the Data Commissioner’s Office.
1.4 Personal Data: means all such “personal data”, as defined in Article 4 of the GDPR, as is, or is to be, processed by the Data Processor on behalf of the Data Controller.
1.5 Services: means those services AND/OR solutions described in Appendix 1 which are provided by the Data Processor to the Data Controller and which the Data Controller uses for the purpose[s] described in Appendix 1;
1.6 Standard Contractual Clauses: means the European Commission’s Standard Contractual Clauses for the transfer of Personal Data from the European Union to data processors established in third countries (controller-to-processor transfers), as set out in the Annex to Commission Decision 2010/87/EU.
1.7 Sub-Processor: means a sub-contractor appointed by the Data Processor to process the Personal Data.
1.8 Sub-Processor Agreement: means an agreement between the Data Processor and a Sub-Processor governing the Personal Data processing carried out by the Sub-Processor, as described in Clause 10.
1.9 Term: means the term of this Agreement, as set out in sub-Clause 14.1.
All terms used herein with capital letters and not otherwise defined shall have the meaning set forth in the GDPR.
2. Scope and Application of this Agreement
2.1 The provisions of this Agreement shall apply to the processing of the Personal Data described in Appendix 2, carried out for the Data Controller by the Data Processor, and to all Personal Data held by the Data Processor in relation to all such processing whether such Personal Data is held at the date of this Agreement or received afterwards.
2.2 In the event of any conflict or ambiguity, the following shall apply:
2.2.1 Where there is any conflict or ambiguity between a provision contained in the body of this Agreement and any provision contained in a Schedule to this Agreement, the provision in the body of this Agreement shall prevail.
2.2.2 Where there is any conflict or ambiguity between the terms of any invoice or other document annexed to this Agreement and any provision contained in a Schedule to this Agreement, the provision contained in the Schedule shall prevail.
2.2.3 Where there is any conflict or ambiguity between a provision of this Agreement and a provision of the Service Agreement, the provision in this Agreement shall prevail; and
2.2.4 Where there is any conflict or ambiguity between a provision of this Agreement and any executed Standard Contractual Clauses, the provisions of the executed Standard Contractual Clauses shall prevail.
3. Provision of the Services and Processing Personal Data
3.1 The Data Processor is only to carry out the Services, and only to process the Personal Data received from the Data Controller:
3.1.1 for the purposes of those Services and not for any other purpose;
3.1.2 to the extent and in such a manner as is necessary for those purposes; and
3.1.3 strictly in accordance with the express written authorization and instructions of the Data Controller (which may be specific instructions or instructions of a general nature or as otherwise notified by the Data Controller to the Data Processor).
3.2 The Data Controller shall retain control of the Personal Data and shall remain responsible for its compliance obligations under the Data Protection Legislation including, but not limited to, providing the required notices, and obtaining any required consents, and for any and all processing instructions it gives to the Data Processor.
4. Rights and Obligations of the Parties
4.1 Both parties will comply with all applicable requirements of the Data Protection Legislation. This DPA is in addition to, and does not relieve, remove, or replace, a party’s obligations under the Data Protection Legislation.
4.2 The parties acknowledge that for the purposes of the Data Protection Legislation, the Customer is the Data Controller, and the Provider is the Data Processor (where Data Controller and Data Processor have the meanings as defined in the Data Protection Legislation). Appendix 2 to this DPA sets out the scope, nature, and purpose of processing by the Provider, the duration of the processing and the types of personal data (as defined in the Data Protection Legislation, Personal Data) and categories of data subjects.
4.3 Without prejudice to the generality of clause 1.1, the Customer will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of the Personal Data to the Provider for the duration and purposes of this agreement.
4.4 Without prejudice to the generality of clause 1.1, the Provider shall, in relation to any Personal Data processed in connection with the performance by the Provider of its obligations under this agreement:
(a) process any Personal Data only in accordance with Customer’s written instructions and for the purpose of carrying out its obligations under the Principal Agreement unless the Provider is required by the laws of any member of the European Union or by the laws of the European Union applicable to the Provider to process Personal Data (Applicable Laws). Where the Provider is relying on Applicable Laws as the basis for processing Personal Data, the Provider shall promptly notify the Customer of this before processing any data as required by the Applicable Laws unless the Applicable Laws prohibit the Provider from notifying the Customer;
(b) ensure that Provider shall structure Provider’s internal corporate organisation to ensure compliance with the specific requirements of the protection of Personal Data. Provider shall take the appropriate technical and organisational measures to adequately protect Customer’s Personal Data against misuse and loss in accordance with the applicable Data Protection Legislation and Description of the Technical and Organizational Security Measures (attachment to Appendix 4). The technical and organizational measures shall be set in relation to how sensitive the Personal Data is, the risks of varying likelihood and severity for the rights and freedoms of natural persons that are associated with the processing as well as the nature, scope, context and purposes of the processing. In assessing the appropriate level of security, the Provider shall particularly take into account the risks that are presented by processing, especially the risks for accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Personal Data. The appropriate level of security shall be further set taking into account the technical possibilities available and the costs associated with implementing the measurements. The Personal Data shall be protected against any accidental or unlawful processing, such as accidental, unauthorized or unlawful destruction, loss, alteration, unauthorized disclosure or access.
(c) The Provider shall maintain, in electronic form, accurate and up-to-date records of all processing of Personal data, such as which persons have access to the Personal Data and in which locations the Personal Data are being Processed pursuant to this Agreement and the Principal Agreement, as well as all other information as set forth in the provisions concerning records of processing activities of the GDPR.
(d) ensure that all personnel who have access to and/or process Personal Data are obliged to keep the Personal Data confidential; and
(e) assist the Customer in responding to any request from a Data Subject and in ensuring compliance with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
(f) notify the Customer without undue delay but not later than 24 hours upon discovery of any completed or attempted case of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to of the Personal Data;
(g) consents that the Customer, or an independent third-party auditor mandated by the Customer, has a right to control and audit that the Processor complies with its obligations stated in this DPA and with the instructions issued by Controller. The Processor agrees to contribute to such audits and to cooperate with the Controller in this regard and upon request provide any relevant documentation needed in order to carry out such audit.
(h) at the written direction of the Customer, delete or return Personal Data and copies thereof to the Customer on termination of the agreement unless required by Applicable Laws to store the Personal Data; and
(i) maintain complete and accurate records and information to demonstrate its compliance with this DPA and allow for audits by the Customer or the Customer’s designated auditor.
5. Data Protection Compliance, Transfer of Personal Data and Third-Party Processor
5.1 All instructions given by the Data Controller to the Data Processor shall be made in writing and shall at all times be in compliance with the Data Protection Legislation and other applicable laws. The Data Processor shall act only on such written instructions from the Data Controller unless the Data Processor is required by law to do otherwise.
5.2 The Data Processor shall promptly comply with any request from the Data Controller requiring the Data Processor to amend, transfer, delete, or otherwise dispose of the Personal Data, or to cease, mitigate, or remedy any authorised processing.
5.3 The Data Processor shall transfer all Personal Data to the Data Controller on the Data Controller’s request in the formats, at the times, and in compliance with the Data Controller’s written instructions.
5.4 Both Parties shall comply at all times with the Data Protection Legislation and shall not perform their obligations under this Agreement or any other agreement or arrangement between themselves in such way as to cause either Party to breach any of its applicable obligations under the Data Protection Legislation.
5.5 The Data Controller hereby warrants, represents, and undertakes that the Personal Data and its use with respect to the Service Agreement and this Agreement shall comply with the Data Protection Legislation in all respects including, but not limited to, its collection, holding, and processing.
5.6 Provider shall not transfer any Personal Data outside of the European Economic Area unless the prior written consent of the Customer has been obtained and is carried out in accordance with the conditions stipulated in chapter V of the GDPR and this DPA.
5.7 Provider may only instruct a third party (Third-Party Processor) to process Customer’s Personal Data on Provider’s behalf with Customer’s prior written consent. If such consent is received the Processor may only engage a Third-Party Processor in compliance with the provisions concerning Processors in the GDPR and always provided that such engagement will be under a written agreement with the sub-processor under which the sub-processor is imposed the substantially same obligations as the Processor is under this DPA. The Customer consents to the Provider appointing the companies referred to in Appendix 2 (“Approved Third Party Processors”) as a third-party processor of Personal Data under this agreement. The Processor shall inform the Controller of any and all newly engaged sub-processors processing Personal Data.
5.8 In case the Third-Party Processor is located outside of the European Economic Area Provider shall ensure that the requirements according to clause 2.1 of this DPA are met. As between the Customer and the Provider, the Provider shall remain fully liable for all acts or omissions of any Third-Party Processor appointed by Provider.
6. Data Processor’s Personnel
6.1 The Data Processor shall ensure that all personnel who are to access and/or process any of the Personal Data:
6.1.1 are aware both of the Data Processor’s duties and obligations, and of their own individual duties and obligations under this Agreement and the Data Protection Legislation;
6.1.2 have been given suitable training on the Data Protection Legislation with respect to the handling of Personal Data and how the Data Protection Legislation applies to their particular duties; and
6.1.3 are contractually obliged to keep the Personal Data confidential.
6.2 The Data Processor shall take reasonable steps to ensure the reliability, integrity, and trustworthiness of all personnel who are to access and/or process any of the Personal Data (carrying out background checks permissible by law where appropriate).
7. Security
The Data Processor shall implement suitable technical and organisational security measures in order to protect the Personal Data against unauthorised or unlawful access, processing, disclosure, copying, alteration, storage, reproduction, display, or distribution; and against loss, destruction, or damage, whether accidental or otherwise. Such measures shall include, but not be limited to, those set out in Appendix 4. Such measures shall be fully documented in writing by the Data Processor and be reviewed at least annually to ensure that they remain up-to-date, complete, and appropriate. The Data Processor shall inform the Data Controller in advance of any changes to such measures.
8. Appointment of Sub-Processors
8.1 The Data Processor shall not sub-contract any of its obligations or rights under this Agreement without the prior written consent of the Data Controller.
8.2 In the event that the Data Processor appoints a Sub-Processor (with the written consent of the Data Controller), the Data Processor shall:
8.2.1 enter into a Sub-Processing Agreement with the Sub-Processor which shall impose upon the Sub-Processor the same obligations as are imposed upon the Data Processor by this Agreement and which shall permit both the Data Processor and the Data Controller to enforce those obligations;
8.2.2 provide copies of any and all Sub-Processing Agreements entered into to the Data Controller;
8.2.3 ensure that the Sub-Processor complies fully with its obligations under the Sub-Processing Agreement and the Data Protection Legislation and does not process any of the Personal Data except on the instructions from the Data Controller.
8.3 The Data Processor shall maintain control over all Personal Data transferred to any Sub-Processor.
8.4 In the event that a Sub-Processor fails to meet its obligations under any Sub-Processing Agreement, the Data Processor shall remain fully liable to the Data Controller for failing to meet its obligations under this Agreement.
8.5 Any and all Sub-Processing Agreements entered into shall terminate automatically on termination of this Agreement for any reason.
8.6 The Data Processor shall, on the Data Controller’s written request, audit the compliance of any Sub-Processor with its obligations with respect to the Personal Data and shall provide the Data Controller with the results of such audits.
9. Cross-Border Transfers of Personal Data
9.1 The Data Processor shall not transfer or otherwise process any of the Personal Data outside of the European Economic Area (“EEA”) without the prior written consent of the Data Controller.
9.2 In the event that the Data Controller consents to such a transfer or processing, the Data Processor may only process (or permit the processing) of the Personal Data outside of the EEA if one or more of the following conditions are satisfied:
9.2.1 the Data Processor is processing the Personal Data in a territory that is subject to a current finding by the European Commission under the Data Protection Legislation that said territory provides adequate protection for the privacy rights of individuals; or
9.2.2 the Data Processor participates in a valid cross-border transfer mechanism under the Data Protection Legislation under which the Data Processor (and the Data Controller, where appropriate) can ensure that appropriate safeguards are in place to ensure an adequate level of data protection with respect to the privacy rights of individuals as required by Article 46 of the GDPR. The Data Processor shall immediately inform the Data Controller of any changes thereto; or
9.2.3 the transfer of the Personal Data otherwise complies with the Data Protection.
9.3 In the event that any transfer of Personal Data between the Data Controller and the Data Processor requires execution of Standard Contractual Clauses in order to comply with the Data Protection Legislation (that is, where the Data Controller is exporting the Personal Data to the Data Processor, which is located outside of the EEA.
9.4 In the event that the Data Controller consents to the Data Processor (that is located within the EEA) appointing a Sub-Processor, in accordance with the provisions of Clause 10, and the Sub-Processor is located outside of the EEA, the Data Controller hereby authorises the Data Processor to enter into Standard Contractual Clauses, with the Sub-Processor in the Data Controller’s name and on the Data Controller’s behalf. The Data Processor shall make said executed Standard Contractual Clauses available to the Data Controller on request.
10. Appointment of a Data Protection Officer
10.1 The Data Controller has appointed a Data Protection Officer in accordance with Article 37 of the GDPR and details shall be provided to Data Processor at request.
10.2 The Data Processor shall appoint a Data Protection Officer in accordance with Article 37 of the GDPR and shall supply the details of the Data Protection Officer if/when requested.
11. Liability and Indemnity
11.1 The Data Controller shall be liable for, and shall indemnify (and keep indemnified) the Data Processor in respect of any and all action, proceeding, liability, cost, claim, loss, expense (including reasonable legal fees and payments on a solicitor and client basis), or demand suffered or incurred by, awarded against, or agreed to be paid by, the Data Processor [and any Sub-Processor] arising directly or in connection with
11.1.1 any non-compliance by the Data Controller with the GDPR or other applicable legislation;
11.1.2 any Personal Data processing carried out by the Data Processor [or Sub-Processor] in accordance with instructions given by the Data Controller that infringe the GDPR or other applicable legislation; or
11.1.3 any breach by the Data Controller of its obligations under this Agreement, except to the extent that the Data Processor (or Sub-Processor) is liable under sub-Clause 4.2.
11.2 The Data Processor shall be liable for, and shall indemnify (and keep indemnified) the Data Controller in respect of any and all action, proceeding, liability, cost, claim, loss, expense (including reasonable legal fees and payments on a solicitor and client basis), or demand suffered or incurred by, awarded against, or agreed to be paid by, the Data controller arising directly or in connection with the Data Processor’s Personal Data processing activities that are subject to this Agreement:
11.2.1 only to the extent that the same results from the Data Processor’s [or a Sub-Processor’s] breach of this Agreement; and
11.2.2 not to the extent that the same is or are contributed to by any breach of this Agreement by the Data Controller.
11.3 The Data Controller shall not be entitled to claim back from the Data Processor [or Sub-Processor] any sums paid in compensation by the Data Controller in respect of any damage to the extent that the Data Controller is liable to indemnify the Data Processor [or Sub-Processor] under sub-Clause 4.1.
11.4 Nothing in this Agreement (and in particular, this Clause) shall relieve either Party of, or otherwise affect, the liability of either Party to any data subject, or for any other breach of that Party’s direct obligations under the GDPR. Furthermore, the Data Processor hereby acknowledges that it shall remain subject to the authority of the DCO and shall co-operate fully therewith, as required, and that failure to comply with its obligations as a Data Processor under the GDPR may render it subject to the fines, penalties, and compensation requirements set out in the GDPR.
12. Intellectual Property Rights
All copyright, database rights, and other intellectual property rights subsisting in the Personal Data (including but not limited to any updates, amendments, or adaptations to the Personal Data made by either the Data Controller or the Data Processor) shall belong to the Data Controller or to any other applicable third party from whom the Data Controller has obtained the Personal Data under licence (including, but not limited to, data subjects, where applicable). The Data Processor is licensed to use such Personal Data under such rights only [for the term of the Service Agreement,] for the purposes of the Services, and in accordance with this Agreement.
13. Confidentiality
13.1 The Data Processor shall maintain the Personal Data in confidence, and in particular, unless the Data Controller has given written consent for the Data Processor to do so, the Data Processor shall not disclose any Personal Data supplied to the Data Processor by, for, or on behalf of, the Data Controller to any third party. The Data Processor shall not process or make any use of any Personal Data supplied to it by the Data Controller otherwise than in connection with the provision of the Services to the Data Controller.
13.2 The Data Processor shall ensure that all personnel who are to access and/or process any of the Personal Data are contractually obliged to keep the Personal Data confidential.
13.3 The obligations set out in in this Clause shall continue for a period of 2 months after the cessation of the provision of Services by the Data Processor to the Data Controller.
13.4 Nothing in this Agreement shall prevent either Party from complying with any requirement to disclose Personal Data where such disclosure is required by law. In such cases, the Party required to disclose shall notify the other Party of the disclosure requirements prior to disclosure, unless such notification is prohibited by law.
14. Deletion and/or Disposal of Personal Data
14.1 The Data Processor shall, at the written request of the Data Controller, delete (or otherwise dispose of) the Personal Data or return it to the Data Controller in the format(s) reasonably requested by the Data Controller within a reasonable time after the earlier of the following:
14.1.1 the end of the provision of the Services (under the Service Level Agreement);
14.1.2 the termination of the Service Level Agreement; or
14.1.3 the processing of that Personal Data by the Data Processor is no longer required for the performance of the Data Processor’s obligations under this Agreement AND/OR the Service Level Agreement.
14.2 If the Data Processor is required by law, government, or other regulatory body to retain any documents or materials that the Data Processor would otherwise be required to return, delete, or otherwise dispose of under this Agreement, the Data Processor shall notify the Data Controller in writing of the requirement. Such notice shall give details of all documents or materials that the Data Processor is required to retain, the legal basis for that retention, and the timeline for deletion and/or disposal at the end of the retention period.
14.3 All Personal Data to be deleted or disposed of under this Agreement shall be deleted or disposed.
14.4 The Data Processor shall certify in writing that the Personal Data has been deleted or otherwise disposed of within 30 days of such deletion or disposal.
15. Record Keeping
15.1 The Data Processor shall keep suitably detailed, accurate, and up-to-date written records of any and all processing of the Personal Data carried out for the Data Controller. Such records shall include, but not be limited to, access, control, security, sub-contractors, affiliates, the purpose(s) for which the Personal Data is processed, the category or categories of processing, transfers of the Personal Data to non-EEA territories and related safeguards, and details of the technical and organisational security measures referred to in Clause 9.
15.2 The Data Processor shall ensure that such records are sufficient to enable the Data Controller to verify the Data Processor’s compliance with the provisions of this Agreement and with the Data Protection Legislation. The Data Processor shall provide the Data Controller with copies of such records on request.
15.3 The Data Processor shall review the information contained in the Appendixes to this Agreement in order to ensure that it remains accurate and up-to-date with current practices.
16. Auditing
16.1 The Data Processor shall permit the Data Controller and any third-party representatives that the Data Controller may from time to time appoint to audit its compliance with its obligations under this Agreement, on a reasonable prior notice during the Term of this Agreement.
16.2 The Data Processor shall provide to the Data Controller and any third-party representatives all necessary assistance in conducting such audits including, but not limited to:
16.2.1 physical and electronic access to, and copies of, records kept under Clause 16 and any other information pertaining to the processing of the Personal Data;
16.2.2 access to (and meetings with) any of the Data Processor’s personnel that are reasonably necessary to audit the Data Processor’s compliance with this Agreement; and
16.2.3 inspection of any and all infrastructure, systems, facilities, equipment, electronic data, and software used for the storage, transfer, and processing of the Personal Data.
16.3 Prior to commencing the processing of the Personal Data and thereafter on an annual basis, the Data Processor shall:
16.3.1 carry out an information security audit in order to identify any security deficiencies;
16.3.2 produce a written report of its audit which shall include plans to remedy any such deficiencies;
16.3.3 provide the Data Controller with a copy of the report; and
16.3.4 remedy any defects identified in its audit within 30 days.
16.4 The notice requirement set out in sub-Clause 17.1 shall not apply if the Data Controller has reason to believe that a personal data breach has taken place or is taking place, or that the Data Processor is in breach of any of its obligations under this Agreement or the Data Protection Legislation.
16.5 In the event of a personal data breach (including if the Data Processor becomes aware of any breach of its obligations under this Agreement or the Data Protection Legislation), the Data Processor shall:
16.5.1 conduct its own audit to determine the cause of said breach within 24 hours of the triggering event;
16.5.2 produce a written report of its audit which shall include plans to remedy any deficiencies identified thereby;
16.5.3 provide the Data Controller with a copy of the report; and
16.5.4 remedy any defects identified in its audit within 72 hours.
17. Term and Termination
17.1 This Agreement shall remain in full force and effect:
17.1 .1 for as long as the Service Agreement remains in effect; or
17.1 .2 for as long as the Data Processor retains any Personal Data relating to the Service Agreement in its possession or control,
17.1 .3 whichever period is longer.
17.2 Where any provision of this Agreement, whether expressly or by implication, either comes into force, or continues in force on or after the termination of the Service Agreement in order to protect the Personal Data, that provision shall remain in full force and effect.
17.3 Any failure by the Data Processor to comply with the terms of this Agreement shall be deemed to be a material breach of the Service Agreement. In the event of such a breach, the Data Controller shall have the right to terminate the Service Agreement OR any part of the Service Agreement under which Data Processor processes the Personal Data, such termination to be effective immediately on written notice to the Data Processor, without further liability or obligation.
17.4 If any change to the Data Protection Legislation prevents either Party from fulfilling any of its obligations under the Service Agreement, the processing of the Personal Data shall be suspended until such processing can be made to comply with the Data Protection Legislation, as amended. If such processing cannot be made to comply within 30 days, the Parties may terminate the Service Agreement on written notice to one another.
18. Miscellaneous
18.1 The appendices 3 and 4 form an essential part of this DPA.
18.2 Either party may, at any time on not less than 30 days’ notice, request to replace this DPA with any applicable controller to processor standard clauses or similar terms forming party of an applicable certification scheme (which shall apply when replaced by attachment to this agreement).
18.3 The parties hereby submit to the place of jurisdiction stipulated in the Principal Agreement with respect to any disputes or claims howsoever arising under this DPA, including disputes regarding its existence, validity or termination or the consequences of its nullity; and this DPA and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Principal Agreement.
18.4 Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
18.5 This DPA is the entire agreement between the parties relating to its subject matter.
19. Law and Jurisdiction
19.1 This Agreement (including any non-contractual matters and obligations arising therefrom or associated therewith) shall be governed by, and construed in accordance with, the laws of Ireland.
19.2 Any dispute, controversy, proceedings or claim between the Parties relating to this Agreement (including any non-contractual matters and obligations arising therefrom or associated therewith) shall fall within the jurisdiction of the courts of Ireland.
APPENDIX 2 – SERVICES / SOLUTIONS PROVIDED by EHA SOFT SOLUTIONS LTD.
EHA SOFT SOLUTIONS LTD. a business solutions provider, a company that provides applications/software’s to businesses to help them measure, analysis and improve their operations and management system.
DISPLAY SCREEN EQUIPMENT (DSE) TOOL:
The maiTM Contractor Portal provides real, clear time visibility of all Contractor companies details (insurances, risk assessments, licences and permits etc) and their employees (training records, back ground checks etc). It enables the Client to manage every aspect of their contractor workforce easily using a user-friendly but compliance focused tool. The maiTM Contractor Portal has two different types of users; the Client (any organisation that must maintain information about a non-employee for site security, insurance and safety) and the Contractor (any employee of the Contractor company that is going to be working or visiting the Client site). The functionality of the maiTM Contractor Portal is to collect information about the Contractor and its employees in order to determine if they can be on site. This information may include; contact details, insurance held, training certifications, and any induction training that the Client may require. The Portal presents this information to the Client and enables the Client to manage the information in one place.
APPENDIX 3 – PERSONAL DATA
Type of Personal Data |
Category of Data Subject |
Nature of Processing Carried Out |
Purpose(s) of Processing |
Duration of Processing |
Registering you on Our Site. |
End-users of the site. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Contract |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Collect self-assessment answers on the DSE Checklist |
End-users of the DSE tool. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Contract |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Collect photos of Workstation in use |
End-users of the Display Screen Equipment tool. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Contract |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Collect videos of Manual Handling movements being performed |
End-users of the Manual Handling tool. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Contract |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Collect photos of Manual Handling Item being lifted. |
End-users of the Display Screen Equipment tool. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Contract |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Personalising and tailoring your experience on Our Site. |
End-users of the site. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Legitimate Interests – providing you with the best experience on our website. |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller. |
Administering Our Site |
End-users of the site. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Legitimate Interests – providing you with the best experience on our website. |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Administering Our business |
End-users of our tools. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Legitimate Interests – providing you with the best experience on our website. |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Supplying Our products AND/OR services to you |
End-users of our tools. |
Collecting, sorting, saving, transferring, restricting, and deleting data |
Legitimate Interests – Consent given |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Communicating with you |
End-users of our tools. |
Collecting, sorting, saving, transferring, restricting and deleting data |
Legitimate Interests – Consent given |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
Supplying you with information by email AND/OR post that you have opted-in-to (you may opt-out at any time by clicking the unsubscribe button at the end of the email |
End-users of our tools. |
Collecting, sorting, saving, transferring, restricting and deleting data |
Legitimate Interests – Consent given |
Processing shall begin on the date of account creation and be carried out for an unspecified period until the account is deleted by the data controller or until 7 years post-employment. |
APPENDIX 4 – TECHNICAL AND ORGANISATIONAL DATA PROTECTION MEASURES
Description of the technical and organisational security measures provided in this document apply to all services provided by Provider to Client, except where the parties agree on different security measures (the defined measures are derived from ISO 27001 Standard).
HA SOFT SOLUTIONS LTD’s personnel will not process Customer Data without authorization. Personnel are obligated to maintain the confidentiality of any Customer Data and this obligation continues even after their engagement ends.
Organization of Information Security.
Asset Management.
Asset Handling.
Human Resources Security:
Security Training.
Physical and Environmental Security.
Communications and Operations Management.
Data Recovery Procedures.
Data Encryption.
Event Logging
Access Control.
Access Authorization.
Least Privilege.
Integrity and Confidentiality.
Authentication.
Network Design.
Information Security Incident Management.
Business Continuity Management.