Skip to main content

Comitas

Contact form

Book a non-binding appointment with

CEO Comitas

Jürgen Astl

/CEO

Contact

We are available between 8:00 and 18:00 and will get back to you as soon as possible. Find answers to your questions!

Order processing (AVV)

Appendix to the General Terms and Conditions for order processing agreement

between
the customer

–Client–

and
Courtesy AG
Wiesenstrasse 10A
8952 Schlieren
Switzerland
–Provider–

about order processing.

Preamble

This annex specifies the data protection obligations of the contracting parties arising from the contract concluded between them (the Provider's General Terms and Conditions). It applies to all activities related to the contract in which employees of the Provider or persons commissioned by the Provider process personal data (hereinafter referred to as "data") of the client.

1. Subject matter, duration and specification of the data processing

1.1. Details relating to the service provided by the provider are governed by the respective contract between the provider and the client (hereinafter referred to as "contract"), which consists of the provider's general terms and conditions.

1.2. The subject matter and duration of the order as well as the type and purpose of the processing shall be set out in the contract, unless otherwise specified in Annex A.

1.3. The term of this annex shall correspond to the term of the contract, unless the provisions of this annex stipulate further obligations.

2 Scope and Responsibility

2.1. The provider processes the data listed in Annex A on behalf of the client for the purpose and to the extent specified therein. This includes activities that are detailed in the contract.

2.2. Within the framework of this contract, the client is solely responsible for compliance with the legal provisions of data protection laws, in particular for the lawfulness of the data transfer to the provider and for the lawfulness of the data processing.

2.3. The instructions are initially defined by the contract and can subsequently be amended, supplemented, or replaced by the client in writing or electronically (text form) by individual instructions to the address designated by the provider (individual instructions). Instructions not provided for in the contract will be treated as a request for a change in services. Verbal instructions must be promptly followed up by the client in writing or text form.

3 Obligations of the provider

3.1. The provider may process data of data subjects only within the scope of the contract and the instructions of the client, unless a legally regulated exception applies. The provider shall inform the client immediately if it believes that an instruction violates applicable laws. The provider may suspend the implementation of the instruction until it has been confirmed or amended by the client.

3.2. Within its area of ​​responsibility, the provider will structure its internal organization in such a way as to meet the specific requirements of data protection. It will implement technical and organizational measures to adequately protect the client's data, in accordance with the applicable legal requirements. The provider must implement technical and organizational measures that ensure the ongoing confidentiality, integrity, availability, and resilience of the systems and services related to the processing. The client is aware of these technical and organizational measures and is responsible for ensuring that they provide an appropriate level of protection for the risks associated with the data being processed.

3.3. The measures taken by the provider are described in more detail in Appendix B. The technical and organizational measures are subject to technological progress and further development. Therefore, the provider is permitted to implement alternative, adequate measures. However, the security level of the specified measures must not be reduced. Significant changes must be documented.

3.4. As agreed, the provider will support the client within its capabilities in fulfilling the requests and claims of data subjects and in complying with data protection obligations.

3.5. The provider guarantees that employees involved in processing the client's data and other persons working for the provider are prohibited from processing the data outside of instructions. Furthermore, the provider guarantees that persons authorized to process personal data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality. The duty of confidentiality/secrecy continues even after the termination of the contract.

3.6. The provider shall inform the client immediately if it becomes aware of any breaches of the client's personal data protection. The provider shall take the necessary measures to secure the data and to mitigate any potential adverse consequences for the data subjects and shall consult with the client immediately in this regard.

3.7. The provider shall provide the client with the following contact person for data protection issues arising within the scope of the contract: The data protection officer of Comitas AG, info@comitas.com

3.8. The provider guarantees compliance with its respective data protection obligations and the implementation of a procedure for regularly reviewing the effectiveness of the technical and organizational measures to ensure the security of processing. The provider will correct any errors or omissions.

or deletes the data covered by the contract if the client so instructs and this is within the scope of the instructions. If data protection-compliant deletion or a corresponding restriction of data processing is not possible, the provider will undertake the data protection-compliant destruction of data carriers and other materials upon individual request from the client or return these data carriers to the client, unless already agreed in the contract. In special cases to be determined by the client, storage or transfer will take place; remuneration and protective measures for this must be agreed separately, unless already agreed in the contract.

3.9. Data, data carriers, and all other materials must be either returned or deleted upon the client's request after completion of the order. Any additional costs incurred due to differing requirements for the return or deletion of the data shall be borne by the client.

3.10. In the event of a claim against the client by a data subject in connection with the order processing, the provider undertakes to support the client in defending against the claim within the scope of its possibilities.

3.11. Services according to clauses 3, 5, 6(2) and 6(3) (e.g. release of data carriers, contacting affected persons, audits) are to be remunerated to the provider according to its current hourly rates or external expenses.

4. Obligations of the client

4.1. The client must inform the provider immediately and completely if he discovers errors or irregularities in the order results with regard to data protection regulations.

4.2. The client shall provide the provider with the contact person for data protection issues arising within the scope of the contract, if this person differs from the contact persons already designated by the client.

4.3 Services according to clauses 3, 5, 6 (2) and 6 (3) (e.g. release of data carriers, contacting affected persons, investigations) shall be remunerated to the provider according to his current hourly rates or external costs.

5 requests from affected persons

5.1. If a data subject contacts the provider with requests for rectification, erasure, or access, the provider will refer the data subject to the client, provided that the data subject's information allows for identification of the client. The provider will support the client within its capabilities and as instructed, to the extent agreed upon. The provider is not liable if the client fails to respond to the data subject's request, responds incorrectly, or fails to respond within the required timeframe.

6 ways to prove

6.1. The provider shall demonstrate to the client compliance with the obligations set out in this appendix by suitable means. This shall be done through a self-audit and/or certification in accordance with ISO 27001.

6.2. Should inspections by the client or an auditor commissioned by the client be necessary in individual cases, these will be carried out during normal business hours without disrupting operations, after prior notification and allowing for a reasonable lead time. The provider may make such inspections contingent upon prior notification with a reasonable lead time and the signing of a confidentiality agreement regarding the data of other customers and the implemented technical and organizational measures. Should the auditor commissioned by the client be in competition with the provider, the provider has the right to object to this auditor.

6.3. Should a data protection supervisory authority or other official supervisory authority of the client conduct an inspection, paragraph 2 shall generally apply accordingly. A confidentiality agreement is not required if this supervisory authority is subject to professional or statutory confidentiality obligations, the violation of which is punishable under the Criminal Code.

7 subcontractors (further data processors)

7.1. The engagement of subcontractors by the provider is permissible, provided that these subcontractors themselves meet the requirements of this annex within the scope of the subcontract.

7.2. The client agrees that the provider may engage subcontractors. The provider will inform the client before engaging or replacing any subcontractors. The provider is obligated to inform the client about the engagement of a subcontractor by updating the aforementioned overview. This overview must be updated at least 14 days in advance. The client will review the overview regularly. The client may object to the change – within these 14 days – for important reasons.

Reason – object to the change with the provider. If no objection is received within the deadline, consent to the change is deemed given. If there is a compelling data protection reason, and if an amicable solution between the parties is not possible, the provider is granted the right to terminate the contract with immediate effect.

7.3. A subcontracting relationship requiring approval exists if the provider engages other providers to perform all or part of the services agreed upon in this appendix. The provider will enter into agreements with these third parties to the necessary extent to ensure appropriate data protection and information security measures. Subcontractors who do not have access to or process customer data are exempt from this section and will therefore not appear in the aforementioned list.

7.4. If the provider places orders with subcontractors, it is the provider's responsibility to transfer its data protection obligations under this annex to the subcontractor.

8 Information obligations

8.1. Should the client's data held by the provider be jeopardized by seizure or confiscation, insolvency or composition proceedings, or other events or actions by third parties, the provider must inform the client immediately. The provider will also immediately inform all parties responsible in this context that the client, as the "controller" within the meaning of the General Data Protection Regulation (GDPR), retains sole control and ownership of the data.

9 liability

9.1 Liability is governed by the contract.

10 Others

10.1. Otherwise, the provisions of the contract shall apply. In the event of any conflict between the provisions of this appendix and the provisions of the contract, this appendix shall prevail. Should individual parts of this appendix be invalid, this shall not affect the validity of the contract or the appendix as a whole.

Version September 2020

Annex A is an integral part of this annex.

Subject of the contract:

Processing of the client's personal data in connection with their use of the provider's services as Software as a Service.

Type and purpose of the intended data processing:

The personal data processed by the client is transferred to the provider within the framework of the Software as a Service (SaaS) offering. The provider processes this data exclusively in accordance with the agreed-upon terms (order management, contact management (CRM), accounting, e-banking, payroll, inventory management, project management).

Type of personal data:

The types of data depend on the data provided by the client. These are (depending on the order):

  • Personal data (name, date of birth, address, employer) including contact details (e.g. telephone, email)
  • Contract data, including billing and payment data
  • History of contract data
 
 Categories of data subjects:

The categories of data subjects depend on the data provided by the client. These are (depending on the contract):

  • Employees (including applicants and former employees) of the client,
  • Client's customers
  • Prospective clients of the client
  • Client's service provider
  • Contact details for contact persons
  • Deletion, blocking and correction of data:
 

Requests for deletion, blocking and correction should be addressed to the client; otherwise, the provisions of the contract apply.