Data processing policy

Dernière mise à jour le:

Deze policy is momenteel enkel in het Engels beschikbaar. Wenst u een Nederlandstalige versie van deze policy, gelieve dan contact op te nemen met privacy@accurat.ai.

Cette politique n'est actuellement disponible qu'en anglais. Si vous souhaitez recevoir une version française de cette politique, veuillez contacter privacy@accurat.ai.

Diese Richtlinie ist derzeit nur auf Englisch verfügbar. Wenn Sie eine deutschsprachige Version dieser Richtlinie wünschen, wenden Sie sich bitte an privacy@accurat.ai

1. INTRODUCTION

Accurat BV is a company incorporated and existing under the laws of Belgium, with registered office at BE- Leernsesteenweg 155, 9800 Deinze, with VAT/company number BE-0725.498.434 ( ‘Accurat’, ‘we’ or ‘us’).

When you (‘you’ or the ‘Customer’) rely on the Accurat Solution, Accurat:

  • shall have access to Personal Data; and,

  • will have to Process Personal Data on your behalf.

This Data Processing Policy (the ‘Policy’) applies to the Processing of Personal Data by Accurat for the Customer and determines:

  • how Accurat will manage, secure and process the Personal Data; and,

  • Both parties’ obligation to comply with the Privacy Legislation.

By relying on the Services of Accurat, you acknowledge to have read and accepted this Policy and consequently the way Accurat processes the Personal Data.

2. DEFINITIONS

In this Policy, the following concepts have the meaning described in this article (when written with a capital letter):

Agreement The agreement between Accurat and the Customer.

Controller the entity (being in this case: the Customer), which determines the purposes and means of the Processing of Personal Data;

Data Importer the recipient of personal data/processor of Accurat in a third country, which is not subject to an adequacy decision of the European Commission;

Data Subject the natural person to whom the Personal Data relates, as identified in Annex I;

Data Breach unauthorised disclosure, access, abuse, loss, theft or accidental or unlawful destruction of Personal Data;

End-User the people affiliated with the Customer that are allowed to use the Solution (mainly employees and independent contractors);

Personal Data any information relating to an identified or identifiable natural person (i.e. the Data Subject), as identified in Annex I. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

Privacy Legislation (i) the Belgian Privacy Act of July 30, 2018; (ii) the General Data Protection Regulation 2016/679 of April 27, 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (‘GDPR’); (iii) Directive 2002/58/EC of the European Parliament and Council of 12 July 2002, concerning the processing of personal data and the protection of privacy in the electronic communications sector (‘e-privacy directive’) (including all future legislative changes and amendments/revisions thereof); and/or (iv) all (future) applicable national laws regarding the implementation of the GDPR;

Process/Processing any operation or set of operations which is performed upon Personal Data or sets of Personal Data, whether or not by automated means, including, but not limited to: collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data;

Processor the entity (being in this case: Accurat) which Processes Personal Data on behalf of the Customer as Controller;

Services all services, provided by Accurat to the Customer implying the Processing of Personal Data, including but not limited to: providing a right of access to the Solution and all support related thereto;

Solution the solution developed by Accurat and used by the Customer;

Sub-processor any processor engaged by Accurat.

The Policy includes the following annexes:

Annex I Overview of (i) the Personal Data, which parties expect to be subject of the Processing, (ii) the categories of Data Subjects, which parties expect to be subject of the Processing, the (iii) the nature of the Processing; and (iv) the use (i.e. the way(s) of Processing) of the Personal Data, the purpose and means of such Processing;

3. ROLE OF THE PARTIES

3.1 In accordance with the Privacy Legislation, the Customer shall be considered the ‘Controller’ and Accurat the ‘Processor’.

4. USE OF THE SERVICES

4.1 Parties agree that:

  • Accurat acts as a facilitator of the Services. Therefore, the Customer shall be responsible on how and to what extent it makes use thereof;

  • The Customer is responsible for all acts and omissions of the End-Users (i.e. in case the End-User does (not) take sufficient measures to protect its account on the Solution);

  • Accurat allows the Customer to make adjustments and/or changes to the Personal Data and shall never consult or adjust these Personal Data itself, unless the Customer requests Accurat to do so;

  • The Customer is responsible for the material and/or data provided by the Data Subject. The Customer is, as Controller, thus responsible for complying with the Privacy Legislation and/or any other regulations with regard to aforementioned material and/or data;

  • The Customer shall comply with all laws and regulations (such as but not limited with regard to the retention period or rights of the Data Subject (cf. Article 11)) imposed on it by making use of the Services.

4.2 The Customer shall avoid any misuse of the Services and/or the Solution. In case of misuse by the Customer or the End-Users, the Customer agrees that Accurat can never be held liable in this respect nor for any damage that would occur.

5. OBJECT

5.1 The Customer acknowledges that as a consequence of making use of the Services, Accurat shall Process the Personal Data.

5.2 Accurat shall always Process the Personal Data in a proper and careful way and in accordance with the Privacy Legislation and other applicable rules concerning the Processing of Personal Data.

More specifically, Accurat shall adopt all necessary security measures and provide all its know-how in order to perform the Services in accordance with the rules of art.

5.3 Accurat assures that it shall only Process the Personal Data upon the Customer’s request and in accordance with the latter’s instructions unless any legal obligation states otherwise.

5.4 The Customer keeps full control concerning the following: (i) how Personal Data must be Processed by Accurat, (ii) the types of Personal Data Processed, (iii), the purpose of Processing, and (iv) the fact whether such Processing is proportionate.

6. SECURITY OF PROCESSING

6.1 Accurat takes the security of the Processing activities very seriously. Taking into account the state of the art, Accurat implements appropriate technical and organisational measures for the protection of (i) the Personal Data – including protection against careless, improper, unauthorised or unlawful use and/or Processing and against accidental loss, destruction or damage – (ii) the confidentiality and integrity of Personal Data, as set forth on our website here.

7. SUB-PROCESSORS

7.1 The Customer agrees that Accurat may engage third-party Sub-processors in connection with the performance of the Services. In such case, Accurat shall ensure that the Sub-processors are at least bound by the same obligations by which Accurat is bound under this Policy.

7.2 The current Sub-processor(s) on which we appeal for the performance of the Services are listed on our website (Sub-processors), which includes the identities of those Sub-processors.

Accurat shall update the list whenever a Sub-processor changes (e.g. a new Sub-processor was added, a Sub-processor was substituted, etc.) and will notify the Customer when (significant) changes are made. If you wish to exercise its right to object, please notify Accurat in writing by the latest within thirty (30) days after the list was updated.

7.3 If the objection is well founded, Accurat will use reasonable efforts to (i) make available a change in the Services or (ii) recommend a commercially reasonable change to the Customer’s use of the Services to avoid Processing of Personal Data by the objected new Sub-processor without unreasonably burdening the Customer.

If Accurat is, however, unable to make available such change within a reasonable period of time (which shall not exceed thirty (30) days following your objection), you may terminate the the Services if:

  • You cannot use the Services without appealing on the objected new Sub-processor;

  • Such termination only concerns the Services which cannot be provided by Accurat without appealing to the objected new Sub-processor;

  • You notify Accurat of your wish to terminate the Services to Accurat within a reasonable time.

7.4 Accurat takes responsibility for the acts and omissions of its Sub-processors to the same extent as if it would be performing the Services itself, directly under the terms of this Policy.

8. TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES

8.1 Accurat assures the Customer that a transfer of personal data to a third country or international organisation shall always be subject to (i) an adequacy decision by the Commission or (ii) one of the following safeguards:

  • Closing a data transfer agreement with the third country recipient, which shall contain valid standard contractual clauses (‘SCC’), as adopted by the European Commission. Before the transfer takes place, the Data Importer has to guarantee to Accurat that an adequate level of privacy compliance is ensured in this third party country; and/or;

  • Binding corporate rules. As it is the case for standard contractual clauses, the Data Importer has to guarantee to Accurat that an adequate level of privacy compliance is ensured in the third party country; and/or;

  • Certification mechanisms.

8.2 Every transfer to a third country or international organisation, not recognized by an adequacy decision, is subject to an assessment by Accurat to determine if there is anything in the law and/or practices in force of said third country that may infringe on the effectiveness of the appropriate safeguards in place (as identified above).

Where required on the basis of aforementioned assessment, Accurat shall identify and implement appropriate supplementary measures to govern any data transfer to such international organization or a third country without adequacy decision to ensure the level of data protection as required by EU law.

Furthermore, Accurat shall take all reasonable efforts to oblige the Data Importer to implement sufficient guarantees and measures to protect the Personal Data and ensure the effectiveness of the protection of the SCC’s, binding corporate rules and/or certification mechanisms.

8.3 In case of non-compliance by a Data Importer or where protections in the third country are not adequate, Accurat shall – at its sole discretion - either:

  • Suspend the transfer of Personal Data to the Data Importer / such third country until the issue has been solved; or,

  • Terminate the transfer of Personal Data to the Data Importer / such third country and request the Data Importer to delete the Personal Data in its possession.

8.4 In practice, Accurat performed/added some additional checks to its process:

  • Data mapping: Accurat mapped its data flows (in particular, with regard to data transfers to third parties/countries);

  • Contact with (sub) processors: Accurat contacted the Data Importers to ensure that the processing is carried out in accordance with the agreements made and with the requirements from the Schrems II-decision.

  • Transfer tool identification: Accurat reassessed the transfer tools (e.g. European Commission’s adequacy decisions, Standard Contractual Clauses, etc.) it or its (sub) processor relies on to transfer personal data to (sub) processors located in third countries;

  • Legal assessment of recipient country - Accurat is assessing the privacy laws of all third countries to which personal data is being transferred. Accordingly, Accurat wishes to establish if these third country recipients provide adequate and effective data protection;

  • Adequacy assessment - Accurat is requesting (sub) processors that are transferring data to third countries (in which effective protection equal to the GDPR cannot be guaranteed, such as the United States) to provide an overview of the supplementary measures they have taken or intend to take to ensure the safety and security of the data transfer and processing.

  • EEA alternatives – Prior to each transfer of personal data to a third country (especially where no equivalent level of data protection can be guaranteed) Accurat will assess the necessity of such data transfer by investigating whether there are no alternative options or parties that would ensure that the data is being processed within the European Economic Area (“EEA”);

  • Vendor cooperation assessment - Accurat will terminate the cooperation with (sub) processors transferring data to or located in third countries that are unable to guarantee an equivalent level of data protection.

  • Other procedural & organisational steps - upon finalising the vendor assessment, Accurat will implement the necessary procedural and organisational steps;

  • Periodic monitoring & evaluation - Accurat endeavours to evaluate on an ongoing basis the transfer of personal data to third countries (with regard to necessity, compliance, security…). This includes monitoring developments in such countries that could affect the (earlier) assessments made by Accurat.

9. CONFIDENTIALITY

9.1 Accurat shall maintain the Personal Data confidential and thus not disclose nor transfer any Personal Data to third parties, without your permission, unless when such disclosure and/or transfer is required by law or by a court or other government decision (of any kind). In such case Accurat shall, prior to any disclosure and/or announcement, inform you in full transparency on the scope and manner thereof.

9.2 Accurat ensures that its personnel, engaged in the performance of the Services, is informed of the confidential nature of the Personal Data, are well aware of their responsibilities and are bound by written confidentiality agreements. Accurat ensures that such confidentiality obligations survive the termination of the employment contract.

9.3 Accurat ensures you that the access of its personnel to the Personal Data is limited to such personnel performing the Services in accordance with the Policy.

10. NOTIFICATION

10.1 Accurat will use its best efforts to inform you as soon as reasonably possible when it:

  • Receives a request for information, a subpoena or a request for inspection or audit from a competent public authority in relation to the Processing of Personal Data;

  • Has the intention to disclose Personal Data to a competent public authority;

  • Determines or reasonably suspects a Data Breach has occurred in relation to the Personal Data.

10.2 In case of a Data Breach, Accurat:

  • Notifies you without undue delay (and within 48 hours) after becoming aware of this Data Breach. In the event you wish so, Accurat shall provide – to the extent possible – assistance with respect to your reporting obligation under the Privacy Legislation;

  • Ensures that the notification contains, to the extent available at the time of notification, at least the following information: (i) a description of the nature of the Data Breach, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (ii) the name and contact details of the data protection officer (DPO) or other contact point where more information can be obtained; (iii) a description of the likely consequences of the Data Breach; (iv) a description of the measures taken or proposed to be taken by accurate to address the Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

  • Undertakes – as soon as reasonably possible – to take appropriate remedial actions to make an end to the Data Breach and to prevent and/or limit any future Data Breach.

11. RIGHTS OF DATA SUBJECTS

11.1 Accurat shall notify you no later than five (5) working days after it receives a request from a Data Subject invoking its privacy rights under the Privacy Legislation. Accurat shall not respond to any such data subject request without your prior written consent.

11.2 If a Data Subject requests to exercise his/her rights, you must assist the Data Subject in its request. If you do not have the ability to correct, amend, block or delete the Personal Data (as required by Privacy Legislation), Accurat shall assist you (as long as commercially reasonable).

12. LIABILITY

12.1 Parties are each individually liable towards authorised supervisory authorities and/or Data Subjects for claims and/or fines that are the result of their own breach of or non-compliance with (i) the provisions of this data processing policy, and (ii) the Privacy Legislation or other applicable rules concerning personal data. Accurat and the Customer indemnify each other in this regard.

12.2 The liability of Accurat for a breach of this data processing policy is limited as described in the applicable contractual documentation (i.e. our General Terms and Conditions).

13. RETURN AND DELETION OF PERSONAL DATA

13.1 Upon termination of the Services, the accounts of the Customer will be deactivated and the Personal Data relating hereto will be deleted or anonymised. You can request to receive an export of its data. In any event, Accurat may, at its sole discretion, determine the format of the export.

13.2 Accurat shall retain the Personal Data for three (3) years to ensure export or reactivation request of the Customer can be fulfilled. Accurat shall never access the inactive Personal Data, unless for the purposes as agreed upon. As soon as the three (3) years ends, Accurat will anonymise the Personal Data, which will then solely be used for improvement of the Solution and statistical purposes.

13.3 In case a Data Subject’s information is being removed by the Customer due to the exercise of a Data Subject of any its rights, all Personal Data relating thereto will be deleted or anonymised as well (within 30 days).

13.4 All the foregoing does not apply, and Accurat may therefore continue to retain the Personal Data if – and only to the extent that – it is required to do so pursuant to a legal obligation imposed on Accurat.

14. CONTROL

14.1 Upon Customer’s request, Accurat undertakes to provide the Customer with all information and to the extent as requested by law to allow verification whether Accurat complies with the provisions of this Policy.

14.2 In this respect Accurat shall allow the Customer (or a third party on which the Customer appeals) to undertake inspections no more than once a year – such as but not limited to an audit – and to provide the necessary assistance thereto to the Customer or that third party. The Customer must notify Accurat at least thirty (30) working days in advance. The performance of inspections may in any case not cause any delay in the performance of the Services by Accurat. The scope of the audit shall be limited to Accurat’s processing activities carried out under this Policy

14.3 As to ensure confidentiality of other Accurat customers, the Customer shall impose sufficient confidentiality obligations on its (internal/external) auditors. All information, reports and findings resulting from an audit shall be treated as confidential by both parties and shall not be disclosed to third parties without prior written consent of Accurat, except where disclosure is required by applicable law or by a competent supervisory authority.

14.4 All inspection costs are exclusively borne by the Customer. If (and to the extent that) a severe security incident/personal data breach (at Accurat/under Accurat’s responsibility) or a substantiate violation of this Policy is determined during the inspection, Accurat shall implement an action plan with corrective measures.

15. TERM

15.1 This Policy lasts as long as the Services have not come to an end and as stipulated in our Agreement.

16. UPDATES

16.1 This Policy may be updated from time to time by Accurat, in which case Accurat shall notify you through its website. In any event, the latest version of this Policy can always be accessed on the Accurat website.

17. CONTACT | DPO

17.1 Accurat has appointed a Data Protection Officer (or “DPO”) to ensure its compliance with Privacy Legislation. If you have any questions with regard to this Policy or the manner in which we Process the Personal Data, please contact our DPO via email: dpo@accurat.io.


Annexes:

  • Annex I – Overview of Personal Data

ANNEX I – PROCESSING ACTIVITIES

I. OVERVIEW OF THE PERSONAL DATA, WHICH PARTIES EXPECT TO PROCESS:

DURING THE USE OF OUR SOLUTION

✔ Full name

✔ Employer

✔ E-mail address

✔ Authentication (password / Single Sign On)

✔ Role

COLLECTED THROUGH A DATA PARTNERS’ MOBILE APPLICATION(S)

✔ Precise geolocation data, such as latitude, longitude, altitude, speed, context, method, heading and accuracy of the location;

✔ Granted permissions and consent by the user of the mobile application(s) which allow the collection of the personal data

✔ Unique user identifiers: such as a unique identifier assigned by the mobile application vendor or mobile advertising identifiers such as Apple IDFA for IOS devices and Android Advertising ID for Android devices;

✔ Data on the mobile device: such as manufacturer, make, model, version of the os and app identifiers.

✔ Data on connected networks, such as wifi and mobile phone network SSID’s, name and IP address;

✔ Timestamp of the collected data (time, hour, second, time zone);

✔ Data on the use of the Data Partners’ mobile application by the user: such as in-app activity and interactions

II. OVERVIEW OF THE DATA SUBJECTS:

DURING THE USE OF THE SOLUTION

✔ End-users of the solution

COLLECTED THROUGH A DATA PARTNERS’ MOBILE APPLICATION(S)

✔ Users of the Data Partners’ mobile application(s)

III. NATURE OF THE PROCESSING

✔ Collecting

✔ Consulting

✔ Sorting

✔ Comparing

✔ Structuring

✔ Interconnecting

✔ Modifying

✔ Communicating

✔ Saving

✔ Restricting

✔ Transferring

✔ Deleting

IV. MEANS OF PROCESSING

DURING THE USE OF OUR SOLUTION

✔ Through the Solution

✔ Electronic communication

COLLECTED THROUGH A DATA PARTNERS’ MOBILE APPLICATION(S)

✔ Through the Data Partners’ mobile application(s)

✔ Through the Solution

V. PURPOSE OF THE PROCESSING

✔ Managing the account of the Customer and staff (being the End-Users) on the Solution, from onboarding (creation of the account) on the Solution until offboarding.

✔ Providing the Service by providing aggregated insights in the users of the Customer’s mobile application pursuant to the Agreement.