Data Processing Agreement

On the date stated below

……… (business name), with its registered office at ………, Company ID: ………, VAT ID: ………, registered ………, represented by ……… (the “Controller”)

and

TCC online s.r.o., with its registered office at Vlkova 46, 130 00 Prague 3, Czech Republic, Company ID: 241 41 089, VAT ID: CZ241 41 089, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 182382, represented by Mgr. Barbora Daňková and Ing. Petr Šik, executive directors (the “Processor”)

hereby conclude this Data Processing Agreement (the “Agreement”).

Preamble

Under the contractual relationships concluded with the Controller (the Service Agreement, the “Main Agreement”), the Processor provides the Controller with services in the course of which personal data are processed. By this Agreement, the Controller, within the meaning of Article 28 of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (the “Regulation” or “GDPR”) and Czech Act No. 110/2019 Coll., on the Processing of Personal Data, entrusts the Processor with processing the personal data of data subjects in accordance with the Controller’s instructions.

I. Subject matter, nature and purpose of the processing, duration

1. The Processor will process for the Controller the personal data of evaluated data subjects (in particular the Controller’s employees and job applicants) to the following extent: name, surname, e-mail address, where applicable other identification and contact details, and answers/outputs from the questionnaires, tests and diagnostic tools made available within the service (the “personal data”).

2. The purpose of the processing is the provision of the service under the Main Agreement – making questionnaires, tests and diagnostic tools available and ensuring their automated evaluation.

3. The processing is both automated and manual (electronic processing and evaluation of questionnaires, manual support where needed). The categories of data subjects are employees, job applicants and other evaluated persons designated by the Controller.

4. This Agreement is concluded for the term of the Main Agreement; processing takes place while the Main Agreement is in effect.

5. The means of processing personal data may be automated, non-automated and manual. The Processor processes only personal data that the Controller has transferred to it or whose processing the Controller has enabled, and only to the extent necessary to perform the Main Agreement.

6. Since the Processor receives the personal data directly from the Controller or from evaluated data subjects at the Controller’s initiative, the Controller confirms that these personal data were obtained in accordance with the Regulation and is responsible for fulfilling the information obligation towards the evaluated data subjects under Articles 13/14 of the Regulation.

7. The parties agree that the diagnostic tools used within the service are work-related psychodiagnostic tools (category A under the classification of psychodiagnostic methods used by the professional community), not clinical psychology tools, and are not intended to collect special categories of personal data under Article 9 of the Regulation (e.g. data concerning health).

II. Rights and obligations of the Processor

1. The Processor undertakes to process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by EU or Czech law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

2. The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.

3. The Processor shall take all measures required pursuant to Article 32 of the Regulation (security of processing), in particular: rules for working with information systems, access by authorised persons only, physical security of premises and equipment, confidentiality undertakings of staff, protection of databases by password or similar means, and protection against unauthorised access from the internet.

4. Sub-processors: The Processor may engage another processor (subcontractor) only with the prior general written authorisation of the Controller. The current list of approved sub-processors forms Annex No. 1 to this Agreement. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Controller the opportunity to object to such changes. The Processor shall impose on the sub-processor the same data protection obligations as are set out in this Agreement and is liable to the Controller for the performance of that sub-processor’s obligations.

5. Assistance with data subjects’ rights: The Processor shall provide the Controller with reasonable assistance by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III of the Regulation (access, rectification, erasure, restriction of processing, portability, objection).

6. Assistance with security and incidents: The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the Regulation, taking into account the nature of processing and the information available to the Processor. The Processor shall notify the Controller of any personal data breach without undue delay after becoming aware of it and shall provide the information necessary for the Controller to fulfil its notification obligations under Articles 33 and 34 of the Regulation.

7. Audit: The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this Agreement and in Article 28 of the Regulation, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. An audit may be carried out at most once a year, with reasonable notice (of at least 14 days) and subject to confidentiality regarding the Processor’s trade secrets, unless there is a reasonable suspicion of a breach of obligations. The costs of the audit shall be borne by the Controller.

8. International transfers: The Processor shall not transfer personal data to a third country or an international organisation outside the European Economic Area other than in accordance with Chapter V of the Regulation; the Controller’s consent to such a transfer is deemed to have been given for the sub-processors listed in Annex No. 1.

9. The Processor undertakes to inform the Controller immediately if, in its opinion, an instruction of the Controller infringes the Regulation or other data protection provisions.

III. Termination of processing

1. After the termination of the Main Agreement, the Controller may, within 30 days, request in writing (including by e-mail) the return or export of the personal data. After their return, or after this period has expired without such a request, the Processor shall without undue delay erase or anonymise the personal data, including existing copies, in accordance with paragraph 2, unless EU or Czech law requires their storage; expiry of the period without a request is deemed to be the Controller’s instruction to proceed in this way. At the Controller’s request, the Processor shall confirm that the erasure or anonymisation has been carried out.

2. The obligation to erase personal data under paragraph 1 is also fulfilled by their anonymisation, i.e. the irreversible removal of all elements enabling the direct or indirect identification of a specific person. The Processor may continue to retain and use data anonymised in this way, which are no longer personal data within the meaning of the Regulation, without time limitation, in particular for statistical purposes, for developing comparative norms (benchmarks) and for developing and improving products.

IV. Compensation for damage

1. The Processor is liable to the Controller for damage caused by a breach of its obligations under the Regulation, Czech Act No. 110/2019 Coll. or this Agreement. If the Controller pays compensation to a data subject for damage for which the Processor is liable, the Controller is entitled to claim from the Processor the part of the compensation corresponding to the Processor’s share of responsibility (Article 82(5) of the Regulation). The total amount of compensation that the Processor is obliged to pay to the Controller under this Agreement is limited to CZK 100,000, including loss of profit; this limitation does not apply to damage caused intentionally or through gross negligence.

V. Contact persons

1. The Processor’s contact (responsible) person for data protection matters: Ing. Petr Šik, e-mail sik@tcconline.cz.

2. The Controller’s contact person: [TO BE COMPLETED BY THE CONTROLLER UPON SIGNATURE].

VI. Final provisions

1. This Agreement is concluded for the term of the Main Agreement; termination of the Main Agreement for any reason results in the automatic termination of this Agreement.

2. Matters not expressly governed by this Agreement are governed by the Regulation, Czech Act No. 110/2019 Coll. and other generally binding legal regulations of the Czech Republic.

3. This Agreement may be amended by written agreement of the parties; where it is concluded as an annex to the provider’s terms and conditions, it may also be amended by the procedure for amending the terms and conditions.

4. This Agreement is executed in two counterparts, each party receiving one.

In Prague on ………

……………………………………                              ……………………………………

Controller                                                              Processor

Annex No. 1 – List of sub-processors (subcontractors)

Purpose: ensuring the operation and provision of the TCC online service (including questionnaires, tests, diagnostic tools and their outputs) for the Controller. List of sub-processors to which the Processor makes personal data available:

  • Hosting and backup: WEDOS a.s., Masarykova 1230, 373 41 Hluboká nad Vltavou, Czech Republic, Company ID 28115694, VAT ID CZ28115694, hosting@wedos.com (data location: Czech Republic).
  • E-mail, shared documents and communication tools (Google Workspace): Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland (data location: EU – Europe data region).

Artificial intelligence tools – the Processor uses or may use them to analyse and summarise answers and results processed within the service; for evaluated persons, direct identifiers (in particular name and e-mail address) are removed before transfer; this does not apply to personal data that a respondent includes in the free text of an answer or comment. The Processor uses the providers’ paid business interfaces and the data transferred are not used to train models. Providers: 

  • Google Gemini (part of Google Workspace): Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland (data location: EU – Europe data region).
  • OpenAI: OpenAI Ireland Limited, Ireland (data location: Europe – European data residency).
  • Mistral AI: Mistral AI, société par actions simplifiée, 15 rue des Halles, 75001 Paris, France (RCS 952 418 325) (data location: EU).