Appendix — Outsourcing of Personal Data
This appendix applies to the data you collect through your website. It is part of the general terms and conditions of sale.
Roles of the Parties
For data collected through your website, you are the data controller, and we act as a data processor, as defined by the General Data Protection Regulation.
We process this data only in accordance with your documented instructions, which are derived from your use of the service and these terms and conditions.
We will notify you if we believe an instruction constitutes a violation of applicable regulations.
Processing Activities
The processing activities carried out on your behalf are as follows, depending on the modules you activate.
- Contact forms: Receiving messages sent from your website and forwarding them to your email address.
- Store: recording of orders, items ordered, and the contact information necessary to process them.
- Reservations: recording of reservations, the relevant time periods, and the contact information of those making the reservations.
Data Subjects: visitors to your website, your customers, and individuals who contact you.
Data Categories: identification and contact information, message content, order or reservation data. We do not request any sensitive data, and the service is not designed to process such data.
Duration: the duration of your subscription, plus the retention period specified in the terms and conditions.
Our Commitments
- Confidentiality: Individuals authorized to process this data are subject to a confidentiality obligation.
- Security: We implement appropriate technical and organizational measures, including encryption of communications, segregation between clients, and access restrictions.
- Support: We assist you in responding to requests from data subjects to exercise their rights, to the extent that the service allows.
- Notification: We will notify you without undue delay of any data breach affecting the data processed on your behalf.
- Deletion: Upon termination of the contract, we delete this data after the retention period has expired, unless there is a legal obligation to retain it.
Subsequent Processors
You generally authorize the use of sub-processors that provide sufficient safeguards. An up-to-date, dated list of these sub-processors is available for review at any time through your account.
You will be notified of any additions or replacements before they are implemented, so that you may object to them. In the event of a legitimate objection that we are unable to address, you may terminate the contract at no cost.
Audit
We provide you with the information necessary to demonstrate compliance with our obligations, in the form of documented written responses to your questions. This communication fulfills our audit obligation.
An on-site or remote inspection remains possible in the event of a confirmed security incident affecting you. It will then be conducted with reasonable notice, no more than once a year, and without compromising the security or confidentiality of other customers’ data.
Any costs incurred by an audit request, including those of an auditor you may appoint, are your responsibility.
Requests under this appendix should be directed to contact@intuisphere.com.
A question about this document? Write to us, we answer.