This Data Processing Agreement is incorporated in Prewave’s Terms of Service – Free Basic Account and forms an integral part of the Contract concluded with the User.
The DPA is concluded to govern the relation between the User and Prewave, when User acts as a Data Controller and Prewave acts as a Data Processor. The User wishes to contract certain Services according to the Terms of Service, which imply the Processing of Personal Data, to the Data Processor. The nature and purpose of the proposed Processing of Personal Data and the nature of the data and the categories of Data Subjects are set out in Appendix 1 to this Agreement.
This Data Processing Agreement is implemented in order to comply with the requirements of the current legal framework in relation to Data Processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:
The terms, “Commission”, “Controller”, “Processor”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.
a. Harald Nitschinger
b. Managing Director of Prewave
c. +436641337894
d. privacy@prewave.ai
a. promptly notify the User if it receives a request from a Data Subject under any Data Protection Law in respect to User Personal Data; and
b. ensure that it does not respond to that request except on the documented instructions of the User or as required by Applicable Laws to which the Data Processor is subject, in which case the Data Processor shall to the extent permitted by Applicable Laws inform the User of that legal requirement before the Data Processor responds to the request.
Data Processing Agreement – User
Prewave GmbH, April 2024 (V 1)
Contracted Services | Software-as-a-Service solution for “Supply Chain Risk and Sustainability Monitoring” within the scope agreed with the Data Processor, in accordance with the Contract. - Registration of User’s employees on the Prewave Platform - User’s employees’ interaction on/usage of Prewave Platform (statement requests, Alert status updates, uploading/sending out questionnaires to User’s Sites, planning/initiating measures and actions, exporting reports from the Prewave Platform etc.) |
Categories of Data Subjects whose Personal Data are processed | - User/User’s employees - User’s Sites and contact persons |
Categories of Personal Data | User/User’s employees: - Personal master data (name, title, position, form of address, UID-number, password encrypted, etc.) - role of the User's employee on Prewave Platform - objects related to the User’s employee (follows, collections, labels, etc. on Prewave Platform) - Contact data (e-mail) - activities of User’s employees in Prewave Network (usage, features, logins, etc.) - Communication data (IP address, etc.) - Personal data when entering content into the Prewave Platform, as e.g. through Information Requests (name, User, e-mail, potentially content etc.) |
User’s Sites: - Personal master data (name, address, spend, internal Site ID, homepage (URL), DUNS Number, etc.) - Contact data (telephone/e-mail of User’s Site/of User’s contact person at User’s Site) | |
Extent, type, and purpose of the Processing of data | Extent: As far as necessary to provide contracted Services; continuous processing during the contract term outlined in the Contract + 90 days back-up. Type: Collection, storage, adaptation, use, destruction/erasure, disclosure, and other processing necessary to provide, maintain and improve the Services, all in accordance with the Contract. Purpose: Allowing access to the Prewave Platform in order to provide contracted Services, including the purposes listed under Appendix 2 |
Purpose of Processing | Subprocessor/ Contracting Entity | Categories of Personal Data | Location of Processing | Agreement/ Mechanism for Transfer outside EU (Concluded SCCs, DPF certified) |
---|---|---|---|---|
Communication | Mailgun Technologies, Inc. | - User correspondence | EU | // |
Server hosting; Portal for usage of Prewave Services; Master data management | Google Cloud Platform - Google Cloud EMEA Limited | User/User’s employees: - Personal master data (name, title, position, form of address, UID-number, password encrypted, etc.) - Role of User’s employee on Prewave Platform - Objects related to User’s employees (follows, collections, labels, etc. on Prewave Platform) - Contact data (e-mail) - Activities of User’s employees in Prewave Network (usage, features, logins, etc.) - Communication data (IP address, etc.) | EU | // |
User’s Sites: - Personal master data (name, address, spend, internal Site ID, homepage (URL), DUNS Number, etc.) - Contact data (telephone/e-mail of User’s Site/of User’s contact person at User’s Site) |
Prewave is hosting its Services and data on the Google Cloud Platform (Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland). We are using datacenters located within the EU.
Stay ahead of supply chain disruptions with our latest research, case studies, exclusive webinars, and other value packed content.
© 2024 Prewave GmbH | All Rights Reserved