Data processing agreement
Data Processing Agreement (DPA)
Rubysoft B.V.
Exa 12
6902 KH Zevenaar
The Netherlands
Dutch Chamber of Commerce (KvK): 30169161
VAT ID: NL810606136B01
Website: www.rubysoft.eu
Email: support@rubysoft.eu
Document Control
| Property | Value |
|---|---|
| Document | Data Processing Agreement |
| Organization | Rubysoft B.V. |
| Version | 2.0 |
| Status | Final |
| Language | English (US) |
| Scope | Business Customers for whom Rubysoft acts as Processor |
| Effective date | Date of publication |
1. Purpose and applicability
This Data Processing Agreement applies where Rubysoft B.V., in performing an agreement, processes Personal Data on behalf of a business Customer.
The Customer acts as Controller and Rubysoft as Processor, unless the nature of a specific processing activity requires otherwise.
This DPA supplements the agreement between Rubysoft and the Customer and Rubysoft's General Terms of Delivery and License. In the event of a conflict concerning processing of Personal Data, this DPA prevails.
This DPA does not apply to Personal Data processed by Rubysoft for its own purposes and under its own responsibility, including customer administration, billing, License management, and Rubysoft's own legal obligations. Rubysoft's Privacy Policy applies to those processing activities.
2. Definitions
Personal Data, Processing, Controller, Processor, Data Subject, Personal Data Breach, and Supervisory Authority have the meanings assigned to them in the General Data Protection Regulation (GDPR).
Subprocessor means a third party engaged by Rubysoft to process Personal Data on behalf of the Customer.
3. Subject matter and duration of processing
Rubysoft processes Personal Data only to the extent necessary to provide the agreed services.
Processing may in particular occur when a Customer provides Personal Data or project files for support, error analysis, troubleshooting, technical investigation, or other agreed assistance.
Processing will not continue longer than necessary for the relevant services unless a statutory retention obligation requires longer storage.
The nature, purpose, and scope of Processing are further described in Appendix 1.
4. Customer instructions
Rubysoft processes Personal Data only on documented instructions from the Customer. The Agreement, this DPA, and specific support or service requests constitute documented instructions.
Rubysoft will not use Personal Data for its own purposes where it processes those data as Processor on behalf of the Customer.
If law requires Rubysoft to process Personal Data other than on the Customer's instructions, Rubysoft will inform the Customer in advance unless prohibited by law.
If Rubysoft believes an instruction infringes applicable data protection law, it will inform the Customer without undue delay.
5. Customer responsibilities
The Customer is responsible for the lawfulness of Personal Data made available to Rubysoft.
The Customer warrants that a valid legal basis exists, Data Subjects are properly informed where required, only necessary data are supplied, and its instructions comply with applicable law.
Where reasonably possible, the Customer will avoid providing more Personal Data for support than necessary.
6. Confidentiality
Rubysoft treats all Personal Data processed on behalf of the Customer as confidential.
Access is limited to personnel and other authorized persons who need the data to perform their duties, and such persons are subject to appropriate confidentiality obligations.
Confidentiality obligations survive termination of the work or this DPA.
7. Security
Rubysoft implements appropriate technical and organizational measures to protect Personal Data against loss, destruction, unauthorized access, unlawful alteration, and unauthorized disclosure.
In determining appropriate measures, Rubysoft considers the state of the art, nature and scope of Processing, sensitivity of the Personal Data, likelihood and severity of risks, and reasonable implementation costs.
Rubysoft applies the principles of data protection by design and by default (Privacy by Design and Privacy by Default). Relevant measures are further described in Appendix 2.
Rubysoft may update security measures in response to technology, risks, or law, provided the overall level of protection is not materially reduced.
8. Personal Data Breaches and security incidents
If Rubysoft becomes aware of a Personal Data Breach affecting Personal Data processed on behalf of the Customer, it will notify the Customer without undue delay.
To the extent available, Rubysoft will provide the nature of the incident, affected categories of Personal Data, likely consequences, measures taken or proposed, and other information reasonably required for assessment. Information may be provided in phases if not yet fully available.
Rubysoft will take reasonable measures to contain the incident and prevent recurrence.
The Customer remains responsible for determining whether notification to a Supervisory Authority or Data Subjects is required, unless applicable law provides otherwise. Rubysoft will provide reasonable assistance.
9. Data Subject requests
If a Data Subject contacts Rubysoft directly concerning Personal Data processed on behalf of the Customer, Rubysoft will forward the request to the Customer unless legally required to handle it itself.
Taking into account the nature of Processing, Rubysoft will provide reasonable assistance with requests for access, rectification, erasure, restriction, portability, and objection.
The Customer remains responsible for the substantive assessment and response.
10. Assistance with GDPR obligations
Taking into account the nature of Processing and information available to it, Rubysoft will provide reasonable assistance with obligations relating to security of Personal Data, Personal Data Breaches, data protection impact assessments (DPIAs), and prior consultation with a Supervisory Authority.
11. Subprocessors
The Customer grants Rubysoft general authorization to engage Subprocessors where necessary for the services.
Rubysoft will use only Subprocessors providing sufficient guarantees for appropriate protection of Personal Data and will impose at least equivalent data protection obligations where applicable.
Rubysoft remains responsible to the Customer for performance of Subprocessor obligations to the extent required by the GDPR.
Rubysoft will inform the Customer of intended additions or replacements of Subprocessors processing Customer Personal Data. The Customer may object within a reasonable period on demonstrable privacy or security grounds.
12. Transfers outside the EEA
Rubysoft seeks to process Personal Data within the European Economic Area (EEA) wherever reasonably possible.
Where Personal Data is processed outside the EEA, this occurs only in accordance with the GDPR, on the basis of a valid transfer mechanism and, where required, appropriate safeguards.
Safeguards may include an adequacy decision of the European Commission, applicable Standard Contractual Clauses, or another legally recognized transfer mechanism.
Rubysoft will provide reasonable information about the transfer mechanism used upon request.
13. Information and audits
Rubysoft will provide information reasonably necessary to demonstrate compliance with this DPA.
If such information is reasonably insufficient, the Customer may arrange an audit. Audits must be announced in writing in advance, take place during normal business hours, minimize disruption, be conducted by an independent expert bound by confidentiality, and be limited to what is necessary to verify compliance.
Rubysoft may first provide relevant independent audit reports, certifications, or comparable documentation in lieu of a separate audit.
Reasonable audit costs are borne by the Customer unless the audit identifies a material breach by Rubysoft.
14. Return and deletion
After termination of the services, Rubysoft will, at the Customer's choice and where reasonably possible, delete or return Personal Data processed on the Customer's behalf.
Rubysoft will delete remaining copies when no longer necessary unless law requires continued storage.
Data may remain in backups during the normal backup cycle; such data will not be processed for other purposes and will be deleted or overwritten in accordance with normal retention periods.
15. Liability
The liability provisions in Rubysoft's General Terms of Delivery and License apply to this DPA to the extent permitted by mandatory law.
16. Term and termination
This DPA takes effect when Rubysoft begins processing Personal Data on behalf of the Customer and remains effective for as long as such Processing continues.
Provisions intended by their nature to survive, including confidentiality and deletion obligations, remain effective after termination.
17. Governing law
This DPA is governed by the laws of the Netherlands.
Disputes are handled in accordance with the dispute provisions in Rubysoft's General Terms of Delivery and License, unless mandatory law provides otherwise.
Appendix 1 – Description of Processing
Subject matter
Processing of Personal Data made available by a business Customer for support, technical analysis, or other agreed services.
Duration
For the period in which the relevant services are performed and for the applicable retention period thereafter.
Nature and purpose
Processing may include receiving, storing, accessing, analyzing, and deleting data for technical support, error analysis, investigation of Software issues, troubleshooting, and performance of agreed services.
Categories of Data Subjects
Depending on Customer-provided content: Customer employees, Software users, employees or contacts of clients and suppliers, and other persons whose data appears in submitted files.
Categories of Personal Data
Depending on Customer-provided content: names, business contact details, user data, project information, data appearing in drawings, models, IFC files or other project files, and technical information necessary for support.
Special categories
Rubysoft does not require special-category or criminal-offence Personal Data for support. The Customer must not provide such data unless necessary and lawful and Rubysoft has been informed in advance.
Appendix 2 – Technical and Organizational Measures
Access security
Access only for authorized personnel.
Individual user accounts where technically possible.
Appropriate password protection.
Access rights limited to what is necessary for the role.
Transmission and storage
Secure connections for data transmission where technically possible.
Appropriate security for systems storing Personal Data.
Storage limited to what is necessary for the services.
Software and systems
Timely security updates.
Appropriate protection against malware and unauthorized access.
Vulnerability and security incident management.
Periodic review of relevant security measures.
Organization
Confidentiality obligations for personnel.
Need-to-know access.
Procedures for security incidents and Personal Data Breaches.
Data protection by design and by default in system development and changes.
Continuity
Reasonable measures to support availability and recoverability of systems used for Processing, appropriate to the risk and nature of the services.