Pocket Receptionist

Data processing addendum

DATA PROCESSING ADDENDUM

1. Definitions

2. Term

3. Processing of Customer Personal Data

  • (i) For internal use by the Provider to build or improve the quality of its services, provided that the use does not include building or modifying Data Subject profiles to use in providing services to another business, or correcting or augmenting Personal Data acquired from another source;
  • (ii) To detect Security Incidents or protect against fraudulent or illegal activity;
  • (iii) To comply with applicable law;
  • (iv) To comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities;
  • (v) To cooperate with law enforcement agencies concerning conduct or activity that the Customer, Provider, or Sub-processor(s) reasonably and in good faith believe may violate federal, state, or local law; and
  • (vi) To exercise or defend legal claims.

4. Provider Personnel

5. Sub-processors

6. Security

7. Cross-Border Transfers

  • (a) Module Two applies;
  • (b) In Clause 7, the optional docking clause applies;
  • (c) In Clause 9(a), Option 2 applies, and the time period for prior notice of Subprocessors is seven (7) days;
  • (d) In Clause 11(a), the optional language does not apply;
  • (e) In Clause 13(a), the exporter is established in an EU Member State;
  • (f) In Clause 17, Option 1 applies with the governing law being English Law;
  • (g) In Clause 18(b), disputes will be resolve before the courts in England;
  • (h) Annex I of the EU SCCs is completed with the information in Exhibit A and Exhibit C to this DPA; and
  • (i) Annex II of the EU SCCs is completed with the information in Exhibit B to this DPA.
  • (a) The UK Transfer Addendum is completed with the information in Section 7.1 and Exhibit A, Exhibit B, and Exhibit C to this DPA;
  • (b) Both “Importer” and “Exporter” are selected in Table 4;
  • (c) In Table 2, the selected Addendum EU SCCs are the version of the Approved EU SCCs, which the UK Transfer Addendum is appended to, dated 4 June 2021, including the Appendix Information;

8. Data Subject Rights

9. Security Incident Response

10. Data Protection Impact Assessment and Prior Consultation

11. Return or Destruction of Personal Data

12. Audit

13. Severance

EXHIBIT A: DETAILS OF PROCESSING

  • Subject matter and duration of the Processing: The subject matter of the Processing to be conducted under the Agreement is the Personal Data that Processor Processes on behalf of Provider in connection with the execution of the Agreement. The duration of the Processing is determined by the contractual agreement between the Processor and the Provider.
  • Nature and purpose of the Processing: The nature and purpose of the Processing to be conducted under the Agreement is secure processing of Personal Data to facilitate the business services provided by the Provider.
  • Types of Customer Personal Data: The Personal Data to be Processed under the Agreement include the following types of Personal Data: Full Name, Phone number, email, physical address, social security number, and date of birth.
  • Categories of Data Subjects: The Processing of Personal Data will be conducted under the Agreement for the following Categories of Data Subjects: Provider’s customers, Provider’s customer’s customers, Provider’s employees.

EXHIBIT B: TECHNICAL, ORGANISATIONAL, AND PHYSICAL SECURITY MEASURES

I. Confidentiality

  • i. Security perimeter controls, such as fences, solid buildings, true floor-to-ceiling walls, locked doors, turnstiles, alarm systems.
  • ii. Dedicated secure areas (e.g. data centers, server rooms) with a limited number of authorized personnel who have access.
  • iii. Electronic access cards (ID cards, badges), keys and door locks.
  • iv. Video surveillance systems.
  • v. Facility security services and/or entrance security staff for data centers and research and development office.
  • vi. Proper authorization and escorting of visitors when needed.
  • i. Unique identifier (user ID) for all authorized users, for their personal use only and authentication technique to substantiate the claimed identity of a user.
  • ii. Password protection for computer systems and strong password policy: 1) A strong and unique password (at least 8 characters long).
  • 2) The password contains characters belonging to at least three of the following five categories: upper case letters.
  • lower case letters.
  • numerical symbols.
  • special symbols.
  • Unicode alphabet characters that do not have upper and lower cases (e.g. Asian languages).
  • 3) Storing passwords in an encrypted format using one-way hashing.
  • 4) Periodical testing of passwords.
  • iii. Automatic account locking after 5 failed log-on attempts.
  • iv. New accounts are forced to change passwords on initial log-on.
  • v. Systems are automatically timed out / password locked after 15 minutes of inactivity and require authentication to continue.
  • vi. Inactive accounts are locked during quarterly audits.
  • vii. Multifactor authentication for remote access to corporate services and privileged operations.
  • viii. Encryption of data at rest using hard drive built-in tools and Microsoft technologies, like Bitlocker or Azure encryption.
  • ix. Anonymization is used where required and possible, according to the nature of processed data.
  • x. Secure disposal of old equipment.
  • i. Secure access connections and technologies used for authentication control.
  • ii. Unique login names, strong passwords and periodic examinations of the access lists are existent to guarantee the appropriate use of user accounts.
  • iii. The granting of access rights is a formal process, based on the job responsibilities (role) of the user and on a need-to-know basis and must be authorized by the corresponding resource owner and/or supervisor of the person who makes an application for it.
  • iv. Identity management tool used to manage access according to defined and approved rules, to process access requests, and to keep tracks of access changes.
  • v. The access to productive systems is only granted to users who are periodically trained and authorized for the corresponding action. The access to productive systems is also immediately withdrawn in case of a termination of the contract of employment or in case of an assignment of a different task.
  • vi. System access events are logged and stored securely with restricted access only for authorized users.
  • vii. Isolation Control. Data is processed according to the purpose of processing. Data of different customers are separated logically in storages, using access rules and/or using separation of environments or logical Identifiers.

II. Integrity

  • i. Encryption of data in transit by using HTTPS (TLS 1.2), IPsec.
  • ii. Laptops’ hard drives and mobile devices storages are encrypted.
  • iii. VPN is used to connect separate locations and for remote access.
  • iv. The perimeter network devices are appropriately configurated to secure internal network from unauthorized external connections and to secure that computer connections and data flow do not breach the logical access adjustment control.
  • v. Electronic signatures are used where applicable.
  • i. Logging of user access to systems.
  • ii. Documents changes are tracked.
  • iii. Requirements for ensuring authenticity and protecting message integrity in applications are identified, where necessary, and appropriate controls are implemented.

III. Availability and Resilience

  • i. Reasonable physical protection against environmental risks (e.g., fire, flood, earthquake), such as: 1) Climate control systems.
  • 2) Temperature sensors.
  • 3) Smoke/heat detectors.
  • 4) Water sensors.
  • 5) Fire suppression systems.
  • 6) Alarm / Monitoring systems.
  • ii. Physical protection from power failures and other disruptions caused by failures in supporting utilities, such as: 1) Uninterruptible Power Supply (UPS) for servers and network equipment.
  • 2) Multiple power feeds and generators with onsite fuel capacity for datacenters
  • iii. Backup strategy and procedures, such as regular backups, on-site/off-site storage of backups, backups monitoring and checks.
  • iv. Antimalware protection and firewalls installed on endpoints and on gateway level (e.g. web-proxy, email gateway). It is managed centrally by IT, virus signatures are updated at least once a day, full scan is scheduled weekly.
  • v. Workstations centralized management (automatic locking, patch management, configuration, physical security, etc.) to reduce the possibility to exploit software properties (operating systems, business applications etc.).
  • vi. Network security: 1) Firewalls on endpoints and gateways.
  • 2) Intrusion detection and prevention systems.
  • 3) Network segmentation.
  • 4) Secure network configuration and protocols use.
  • vii. Restriction of physical and logical access to diagnostic and configuration ports of infrastructure equipment.
  • viii. Using advanced threat analytics solution to detect suspicious user/device activity.

IV. Rapid Recovery

  • Redundant architectures, such as clusters, RAID, network load balancing.
  • Use of geo-redundancy in cloud services and redundant data centers.
  • Business continuity and disaster recovery planning and regular testing.

V. Procedures for Regular Testing, Assessment and Evaluation of the Effectiveness of Technical and Organizational Measures for Ensuring the Security

  • At least annual risk assessment and security policy review.
  • Regular security tests, such as scanning for vulnerabilities (endpoints, products, services etc.), penetration tests by specialized providers (services, corporate network).
  • Periodical internal security audits and tests.
  • Annual certification audits for several services.
  • Processing incidents according to Incident Response Plan, reviewing results during root cause analysis and improving security management system.

VI. Order or Contract Control

  • Clear and unambiguous contractual arrangements in line with GDPR requirements.
  • Procurement procedure, legal review and vendor management procedure to check the security state of new vendor before selecting it.
  • Information security state of vendors is reviewed annually or in case of security incidents.

VII. Organizational Control

  • Data Protection Officer is responsible of data protection laws and regulations (contact e-mail: [email protected]). In-house lawyers working on data protection are responsible for legal aspects of data processing.
  • Privacy Policy and internal guidelines on privacy include the description of risks, key principles to be followed, target objectives, rules to be applied and are available for different stakeholders, e.g. users, IT department, HR department, policymakers etc. via corporate portal.
  • Security Policies and guidelines on many security topics are implemented in processes and systems, reviewed annually, approved by management, and communicated to users.
  • When developing, designing, selecting and using applications, services and products that are based on the processing of personal data or process personal data to fulfil their task, the strictest privacy settings apply by default, without any manual input from the end user. For any data processing that are not covered by legitimate interest data subject is asked for consent.
  • Privacy by design, i.e. measures to ensure that when processing of personal data privacy is built into a system during the whole life cycle of that system or process. This consist, inter alia, of minimizing the processing of personal data, pseudonymizing personal data as soon as possible, transparency regarding the functions and processing of personal data, enabling the data subject to monitor the data processing, enabling the controller to create and improve security features.
  • Data Protection Impact Assessment describes processes to control the risks that processing operations performed by the organization pose on data protection and the privacy of data subjects.
  • Processing of personal data is minimized during Data Protection Impact Assessment.