1. Introduction

The Data Protection Agreement (hereinafter the “Agreement”) is intended to govern the use of the Personal Data of the customers (hereinafter the “Customer”) of Synneo SAS (hereinafter the “Processor” or “Synneo”) when they use the services provided by Synneo (hereinafter the “Service”).

2. Definitions

The terms "adequacy decision", "technical and organisational measures", "data subjects", "data protection by design", "data protection by default", "record", "joint controller(s)", "controller", "processor", "processing" and "personal data breach" used in the Agreement have the meanings set out in Articles 4 et seq. of the GDPR.

The other terms are defined below:

●        "Agreement": means the appendix to the Contract governing the use of the Customer's Personal Data in accordance with the provisions of Article 28 of the GDPR, also referred to as the "Data Processing Addendum" ("DPA")

●        "DPIA": means a data protection impact assessment used to verify the proportionality of the processing of Personal Data and to prevent the risks associated with the processing of Personal Data

●        "Anonymisation": means processing intended to make it impossible, irreversibly, to identify the data subjects concerned by the processing carried out as part of the Service

●        "Supervisory Authority": means the supervisory authority competent under the GDPR for the Service provided by the Processor

●        "Customer": means the entity that has subscribed to the Service provided by the Processor

●        "Contract": means the contract entered into between the Processor and the Customer for the use of the Service, to which this Agreement is appended

●        "Rights Request(s)": means the fundamental right(s) created by the GDPR in Articles 15 et seq. (e.g. right of access, right to erasure, etc.).

●        "Customer's Personal Data": means any data relating to an identified or identifiable natural person that is transmitted to the Processor and processed by it on behalf of the Customer as part of the Service, the detailed list of which is set out in the appendix

●        "Party(ies)": means the Customer and the Processor jointly

●        "GDPR": means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, also known as the "General Data Protection Regulation"

●        "Applicable Personal Data Protection Regulations": means, together, French Law No. 78-17 of 6 January 1978 on information technology, data files and civil liberties, and the GDPR

●        "Reversibility": means the operation intended to enable the transfer and integration, in a usable and recognised format, of the Customer's Personal Data from the Processor's Service to an equivalent service offered by another provider

●        "SaaS Service": means software hosted by the Processor that can be used simultaneously by an unlimited number of customers

●        "Sub-processor": means the processors engaged by the Processor to process the Customer's Personal Data exclusively for the purposes of the Service

●        "End Users": means the persons whose Personal Data is processed by the Processor on behalf of the Customer

3. Contractual relationship and term

The Agreement is an indivisible appendix to the Contract signed between the Customer and the Processor for the use of the Service.

In the event of a conflict between the Contract entered into for the use of the Service and the Agreement, the obligations set out in the Agreement shall prevail over the Contract in respect of all GDPR matters.

The Agreement applies for the entire term of the Contract entered into for the use of the Service and may continue beyond it for as long as all the obligations set out herein remain applicable.

4. Role of the Parties and scope

Under the Agreement, the Customer acts as controller and Synneo acts as processor within the meaning of Article 28 of the GDPR.

Under no circumstances may the Parties be regarded as joint controllers in connection with the Service. However, the Parties agree that, in the event of an error in or a change to their classification, they shall meet as soon as possible to amend the Agreement and take all measures required by such a situation in order to comply with the requirements of the Applicable Personal Data Protection Regulations.

The Agreement exclusively governs the processing of the Customer's Personal Data carried out as part of the Service by Synneo as Processor within the meaning of Article 28 of the GDPR, to the exclusion of processing carried out by Synneo as controller, which is governed by the Contract.

5. Instructions and undertakings

The Processor undertakes to use the Customer's Personal Data in connection with the use of the Service only on the documented instructions set out in the appendix to the Agreement. The Processor shall immediately inform the Customer if it considers that an instruction given by the Customer is unlawful under the Applicable Personal Data Protection Regulations. The Processor shall not be held liable where, despite the Processor's notification that the instruction is unlawful, the Customer maintains and applies that instruction through the Service.

The Processor undertakes to comply with the provisions of the GDPR and, in particular, to keep a record of processing activities specific to the Service and to develop its Service in accordance with the rules of "Data protection by design" and "Data protection by default".

The Processor undertakes never to transfer the Customer's Personal Data for reasons other than the provision of the Service, and undertakes never to use the Customer's Personal Data for its own benefit as controller.

The Processor declares that all internal or external personnel required to process the Customer's Personal Data are bound by one or more binding legal instruments and regularly receive training and awareness-raising.

The Processor undertakes to ensure the security of the Customer's Personal Data and to implement all the technical and organisational measures necessary for its Service, details of which are set out in the appendix to the Agreement.

However, the Processor is never liable for the Customer's failures to comply with the Applicable Personal Data Protection Regulations when the Customer uses the Service as controller.

6. Assistance with carrying out DPIAs

DPIAs must be carried out by the Customer, in accordance with the provisions of the GDPR. Nevertheless, the Processor undertakes to provide, at the Customer's written request, all the information necessary and required for the Customer to carry out a DPIA.

The Processor is not, however, required to carry out DPIAs in place of and on behalf of the Customer. Any request going beyond the provision of information may be refused.

7. Assistance with Rights Requests

Rights Requests sent by End Users are forwarded to the Customer as soon as possible. The Processor is not required to keep an inventory of Rights Requests on behalf of the Customer and is not liable for the Customer's failures in handling Rights Requests.

At the Customer's written request, the Processor shall carry out the technical actions required for the Customer to fulfil its obligation to respond to data subjects' requests.

The Customer accepts and understands that the Processor is not required to handle Rights Requests made by individuals in connection with the Service in place of and on behalf of the Customer. Any additional request for such handling will be refused.

Rights Requests sent to the Processor as controller are handled exclusively by the Processor and are not forwarded to the Customer.

8. Assistance with security measures

The Processor undertakes to provide all necessary and required information on the technical and organisational security measures to be implemented to ensure the security of the Customer's Personal Data in connection with the provision of the Service.

9. Personal Data breaches

The Processor undertakes to notify the Customer, as soon as possible and no later than 48 working hours after becoming aware of it, of any personal data breach relating to the Service that is likely to concern the Customer's Personal Data, together with all the necessary and required information in its possession to mitigate the effects of the personal data breach. The Customer accepts and acknowledges that the 72-hour period applicable to it only starts to run from the time it becomes aware of the personal data breach and that, accordingly, the period of 48 working hours complies with the GDPR.

The Processor is not authorised to handle notifications of personal data breaches to the Supervisory Authority or to inform End Users on behalf of the Customer. Any request to that effect from the Customer will be refused.

10. Sub-processors

The Customer grants the Processor general authorisation to engage Sub-processors, provided that the Customer is informed of any change concerning those Sub-processors as soon as possible so that it is able to raise objections. The Customer accepts and acknowledges that specific authorisation is not workable for a SaaS tool and could result in the Service being blocked.  

If the Customer raises no objections within eight (8) days of the notification, the new Sub-processor is definitively engaged and the Customer may not object, claim damages or request termination of the Contract. If an objection raised within that period is considered admissible by the Processor, the Processor may offer the Customer one of the following solutions: i) removal of the Sub-processor, ii) implementation of additional measures to ensure the security of the Customer's Personal Data, iii) discontinuation of the Service, without the Customer being entitled to claim damages.

To be considered admissible by the Processor, objections must be objective and serious and must be duly substantiated. The Parties agree that the following situations are, by default, considered admissible: i) the proposed Sub-processor is a direct competitor of the Customer, ii) the Sub-processor is in a dispute with the Customer, iii) the Sub-processor has been sanctioned by a Supervisory Authority in the 12 months preceding its engagement, and iv) the Sub-processor does not comply, where applicable, with the rules governing transfers outside the European Union.

The Processor undertakes to engage only Sub-processors which, after verification, offer the necessary and sufficient guarantees to ensure the security and confidentiality of the Customer's Personal Data. The relationship between the Processor and the Sub-processor must be governed by an agreement containing obligations similar to those of this Agreement.

The Processor remains liable, within the limits of liability set out in the Contract, for any breaches of the GDPR committed by its Sub-processors in connection with the Service.

11. Hosting and transfers outside the European Union

a) Data hosting

The Processor undertakes to do what is necessary to host the Customer's Personal Data exclusively within a Member State of the European Union. The Customer authorises the Processor to select the Member State of the European Union of its choice. If Personal Data is hosted in a country outside the European Union, the Processor undertakes to obtain the Customer's prior authorisation and to implement all the mechanisms required to govern that transfer, such as entering into Standard Contractual Clauses and, where appropriate, to implement additional technical measures to strengthen the security of the Customer's Personal Data.

b) Data transfers

The Customer grants the Processor general authorisation for transfers outside the European Union if, cumulatively, i) the transfers are made exclusively to GDPR-compliant Sub-processors and ii) the transfers are made exclusively to a country covered by an adequacy decision or are governed by appropriate safeguards such as, in particular, Standard Contractual Clauses. If these conditions are not met, transfers outside the European Union are permitted only with the Customer's prior consent. Additional technical security measures to strengthen the security of the Customer's Personal Data must be implemented where Personal Data is transferred to a non-democratic country.

12. Retention periods and fate of the Customer's Personal Data

The Processor undertakes to retain the Customer's Personal Data only for the duration of the use of the Service, in accordance with the instructions detailed in the appendix, and to delete it at the end of the Contract. On written request, the Processor shall certify the deletion of the Personal Data and of all existing copies.

The Customer is informed that it must retrieve its Personal Data before the end of the Agreement. Failing this, the Customer will no longer be able to retrieve its Personal Data, as the deletion of personal data is irreversible and permanent. The Processor cannot be held liable for any loss of Personal Data after its deletion, the Customer bearing full responsibility for this. The Customer agrees that the complete, irreversible and permanent anonymisation of the Customer's Personal Data may be used as a means of deletion and that the Processor may retain the anonymised data to improve the Service, as accepted by the Supervisory Authorities.

The Processor informs the Customer that the return of Personal Data provided for in the GDPR does not constitute Reversibility of the data to a new processor and that any request to that effect will always be refused by the Processor.

13. Audits

The Customer has the right to carry out an audit in the form of a written questionnaire once a year to verify compliance with this Agreement. The questionnaire has the force of a sworn statement binding on the Processor. The questionnaire may be sent in any form to the Processor, which undertakes to respond as soon as possible after receiving it.

The Customer also has the right to carry out, once a year and at its own expense, an on-site audit, where applicable at the Processor's premises, in the event of a data breach caused by a proven and demonstrated failure by the Processor that has resulted in duly substantiated harm to the Customer. An audit at the Processor's premises may be conducted either by the Customer or by an independent third party appointed by the Customer, and must be notified in writing to the Processor at least thirty (30) days before the audit takes place. The Processor has the right to reject the choice of independent third party if the latter is i) a direct or indirect competitor of the Processor, ii) in a conflict of interest with the Processor (e.g. an adviser to a competitor of the Processor) or iii) in a pre-litigation or litigation situation with the Processor. In that case, the Customer undertakes to choose a new independent third party to carry out the audit. The Processor may refuse access to certain areas for reasons of confidentiality or security. In that case, the Processor shall carry out the audit in those areas and communicate the results to the Customer.

If a discrepancy is identified during the audit, the Processor undertakes to implement, without delay and at its own expense, the measures necessary to comply with this Agreement. Discrepancies may relate only to the regulations applicable to the Customer's Personal Data and may not relate to internal procedures or measures specifically implemented by the Customer. Discrepancies must be duly demonstrated, substantiated and documented.

If the Processor disputes the discrepancies identified, the Processor may, at its option and with the Customer's prior written consent, propose i) to meet in order to find an amicable solution and a compromise, ii) to refer the matter to the Supervisory Authority to obtain a ruling on the dispute, or iii) to refer the matter to an independent expert to settle the dispute.

14. Cooperation with authorities

The Processor undertakes to cooperate with the CNIL, the competent Supervisory Authority, in the event of an inspection concerning the processing carried out as part of the Service, and undertakes to notify the Customer as soon as possible of any requests concerning its Personal Data made by the Supervisory Authority or by an administrative, judicial or police authority.

15. Contact

The Customer and the Processor shall each designate a contact person responsible for this Agreement, who will receive the various notifications and communications to be made under the Agreement.

The Processor informs the Customer that it has appointed Dipeeo SAS as its Data Protection Officer, which can be contacted using the following details:

●        Email address: dpo@synneo.fr

●        Postal address: Société Dipeeo SAS, 95 avenue du Président Wilson, 93100 Montreuil, France

●        Telephone number: +33 1 59 06 81 85

16. Revisions

The Processor reserves the right to amend this Agreement in the event of changes to the rules applicable to the protection of Personal Data or in the event of a change to the Service that would have the effect of modifying any of its provisions.