Close Cookie Popup
Cookie Preferences
By clicking “Accept All”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage and assist in our marketing efforts as outlined in our privacy policy.
Strictly Necessary (Always Active)
Cookies required to enable basic website functionality.
Cookies helping us understand how this website performs, how visitors interact with the site, and whether there may be technical issues.
Cookies used to deliver advertising that is more relevant to you and your interests.
Cookies allowing the website to remember choices you make (such as your user name, language, or the region you are in).

Data Processing Agreement

Parties:

  1. the private limited company AppyBee LTD (hereinafter: “the Processor”),
  2. the natural or legal person with whom the processor has entered into a license agreement for the purpose of AppyBee, (hereinafter: “the Controller’’).

whereas:

  1. The Processor will process personal data on behalf of the Controller within the scope of executing the license agreement between the parties regarding AppyBee;
  2. Parties wish to record their agreements regarding the processing of personal data by the Processor in this data processing agreement;


Definitions

  1. GDPR: the General Data Protection Regulation (Regulation (EU) 2016/679) including the implementing law of this regulation
  2. Data Subject: the person to whom the Personal Data relates, as referred to in Article 4(1) of the GDPR.
  3. Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed as referred to in Article 4(12) of the GDPR.
  4. Main Agreement: the main agreement(s) concluded between Controller and Processor, including appendices, to which this Data Processing Agreement relates.
  5. Employees: Persons working for Controller or Processor, either employed or temporarily hired.
  6. Recipient: a natural or legal person, public authority, agency, or other body, whether a third party or not, to whom Personal Data are disclosed.
  7. Parties: Controller and Processor.
  8. Personal Data: any information relating to an identified or identifiable natural person (the Data Subject) processed within the scope of the Main Agreement as referred to in Article 4(1) of the GDPR; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more elements specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
  9. Sub-processor: another processor engaged by the Processor to process Personal Data on behalf of a Controller.
  10. Processor: the natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Controller as referred to in Article 4(8) of the GDPR.
  11. Processing: an operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of data as referred to in Article 4(2) of the GDPR.
  12. Controller: the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data as referred to in Article 4(7) of the GDPR.
  13. Data Processing Agreement: this Data Processing Agreement for recording agreements as referred to in Article 28(3) of the GDPR.

Applicability


  1. This Data Processing Agreement relates to the Processing of Personal Data by Processor on behalf of Controller within the scope of executing the Main Agreement.
  2. The nature and purpose of the Processing, the type of Personal Data, the categories of Personal Data, the Data Subjects, and Recipients are described in Annex 1.
  3. Processor guarantees compliance with the requirements of applicable laws and regulations regarding the Processing of Personal Data.

Term and termination


  1. This Data Processing Agreement takes effect at the moment the Main Agreement commences, or at a later date to be determined by the parties.
  2. The Data Processing Agreement ends at the moment the Main Agreement ends.
  3. Neither Party may terminate this Data Processing Agreement early independently of the Main Agreement.
  4. Obligations that by their nature are intended to continue even after the termination of this Data Processing Agreement will remain in force after termination. These provisions include, for example, those arising from the clauses regarding confidentiality, liability, dispute resolution, and applicable law.

Processing


  1. Processor processes Personal Data exclusively on behalf of and based on written instructions from Controller, subject to different statutory requirements applicable to Processor. Processor will not process the Personal Data for longer or more extensively than necessary for the performance of the Main Agreement.
  2. If an instruction as referred to in paragraph 1 of this article is, in Processor's opinion, contrary to a statutory data protection provision, Processor will notify Controller thereof prior to Processing, unless a statutory provision prohibits such notification.
  3. If Processor is required to provide Personal Data pursuant to a statutory provision, Processor will inform Controller immediately, and if possible prior to the provision.
  4. Processor ensures that only its Employees have access to the Personal Data. The exception to this is the engagement of Sub-processors in accordance with Article 11 of this Data Processing Agreement. Processor limits access to Employees for whom access is necessary for their work, with access being restricted to Personal Data that these Employees need for their duties. Processor also ensures that Employees with access to Personal Data have received proper and complete instructions regarding the handling of Personal Data and are aware of their responsibilities and statutory obligations.
  5. Controller is legally required to comply with applicable privacy laws and regulations. In particular, Controller must determine whether there is a lawful basis for Processing the Personal Data. Processor ensures compliance with the regulations applicable to it as a Processor in the field of Personal Data Processing and the agreements made in this Data Processing Agreement.
  6. The Processing takes place under Controller's responsibility. Processor has no control over the purpose and means of the Processing and does not make decisions on matters such as the use of Personal Data, the retention period of Personal Data processed for Controller, and the provision of Personal Data to third parties. Controller must ensure that it has clearly defined the purpose and means of Processing the Personal Data.
  7. In the event of chargebacks, AppyBee reserves the right to charge chargeback fees. The cost is €19 excluding VAT per chargeback. These costs are either debited from the Licensee's current balance or invoiced with a payment link. The first chargeback is free of charge.

Security


  1. Processor has implemented the security measures referred to in Appendix 2 attached to this Data Processing Agreement. In adopting these security measures, account was taken of the risks to be mitigated, the state of the art, and the costs of the security measures. These security measures include at least:
    1. the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;

    1. the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
    2. a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of Processing.
  2. Controller has properly informed itself about the security measures taken by Processor and considers that these measures provide a level of security appropriate to the nature of the Personal Data and the scope, context, purposes, and risks of the Processing.
  3. Parties acknowledge that ensuring an appropriate level of security may continuously require taking additional security measures. Processor guarantees a security level tailored to current risks. Processor will notify Controller if any of the security measures change substantially.
  4. Processor provides appropriate safeguards for the application of technical and organizational security measures regarding the Processings to be performed. If Controller wishes to inspect how Processor complies with the security measures, Controller may submit a request to Processor. Processor and Controller will make mutual arrangements for this. The costs of an inspection are borne by Controller. Controller will provide Processor with a copy of the inspection report.
  5. Unless Processor has obtained prior explicit written consent from Controller, Processor will not Process or have Personal Data Processed by itself or third parties in countries outside the European Union ("EU").