Exhibit n. 7 - Data Process Agreement
The purpose of this Data processing Agreement (DPA) is to lay down the terms and conditions under which EXALOGIC undertakes, as a ‘Processor’ within the meaning of the Regulation (as the term Is defined below), to carry out on behalf of IFLEX, who is the ‘Controller’ within the meaning of the Regulation, the personal data processing operations defined in appendix 1.
EXALOGIC will have to process personal data (hereafter ‘Personal Data’) as defined by the General Data Protection Reguletlon (‘GDPR’) no. 2016 679 of 27 April 2018, hereafter referred to as the ‘Regulation’.
EXALOGIC is fully informed of the GDPR’ requirement and acknowledges that the compliance of its services (Including its platforms, software and services) with the Regulation determines the compliance of IFLEX’s services and, consequently, underpins the IFLEX’s approval of the Agreement.
In accordance with the Regulation, IFLEX is the ‘Controller’ and EXALOGIC is the ‘Processor’.
For the purposes of Article 28(3) of Regulation 2016/679 (the GDPR) between IFLEX (the data controller) and EXALOGIC (the data processor) HAVE AGREED on the following Data Processing Agreement in order to meet the requirements of the GDPR and to ensure the protection of the rights of the data subject.
Obligations of EXALOGIC
General provisions
EXALOGIC, as Processor within the meaning of the Regulation, undertakes to:
1. | Process Personal Data only for the purposes of the subcontracting operation and in accordance with the instructions of the Controller; EXALOGIC shall |
not reproduce, exploit or use this data for Its own purposes or on behalf of a third party.
If the Processor considers that a set of instructions from IFLEX may be in breach of the Regulation, it will immediately notify IFLEX.
Furthermore, if EXALOGIC has to transfer data to a third country (outside of the EU) or to an international organisation, In light of European Union law or the laws of a Member State to which it is bound, it must notify IFLEX of this legal obligation before the processing operation, except if providing such Information is forbidden by law for reasons of public interest;
2. | Guarantee the confidentiality of the Personal Data processed under the current Agreement. |
3. | Make sure that those people who are authorized to process Personal Data abide by the Agreement’s confidentiality obligations. |
Specific provisions
Security measures
EXALOGIC will take appropriate technical and organisational security measures to ensure a level of security during the processing of the Personal Data in question that is appropriate to the risk posed by the processing operation by implementing the following security measures in particular the data controller shall evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. Depending on their relevance, the measures may include the following:
Notification of Personal Data breaches
EXALOGIC undertakes to implement and maintain all access restriction, monitoring and alert systems in the event of a breach or the unauthorised disclosure of the Personal Data.