Definitions and interpretation
Background
General requirements
Disclosure of Personal Data
Security
Transfer of Personal Data to third countries
Assistance
Sub-processing
Compliance with legislation, etc.
Compliance audits and statements
Duration and termination
Assignment
Entire agreement
Amendments
Notices
Governing law
DESCRIPTION OF PROCESSING OF PERSONAL DATA
This appendix constitutes the Controller’s instruction to the Processor.
Subject-matter and duration of the processing
The Controller hereby instructs the Processor to identify, collect, aggregate, process and host personal data, mentioned in this Data Processing Agreement, received directly from the Controller through technical systems integrations of the codes provided by the Processor or manual import through the Processor’s platform or by using the API’s provided by the Processor and use this data with the purpose of analysing Controller’s users (Data Subjects) behaviour and delivery of the services. Delivery of services include but are not limited to communicate in the name of Data Controller with its users, in accordance to the Controller’s configuration of the Service.
Upon termination of this Agreement, the Personal Data must be deleted irretrievably so that it is no longer possible to uniquely identify natural persons.
Nature and purpose of the processing
The Processor is permitted to collect and process the Personal Data for the following purpose(s):
(i) calculating profit overview as well as similar services as described in the Contract and at Profitmetrics.io’s website,
(ii) delivery of conversion & event data to optimized ads via Facebook, Instagram, Google, Bing ad networks and similar,
(iii) any other purposes instructed by the Controller in writing.
Categories of Personal Data
The processing includes Personal Data of the categories described off below. The security measures put in place by the Processor and any Sub-Processors must provide a level of security appropriate to the risk represented by the sensitivity of the Personal Data.
Categories of data subjects
Location(s) of data processing facilities
Sub-Processors
The Controller consents to the use of the following Sub-Processors:
Sub-Processor Processing location (country)
Hetzner Germany
Amazon AWS Ireland
The Processor will share the Personal Data with ad networks such as Facebook, Instagram, Google, Bing in accordance to the Controller’s configuration of the Service. The Controller is responsible for its own relationship with these ad networks, hence these are not considered Sub-Processors.
Appendix 2 to the Data Processing Agreement
DESCRIPTION OF THE TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
This appendix contains a description of the technical and organisational security measures which the Processor is obliged, under the Data Processing Agreement, to implement, comply with and ensure compliance with by its Sub-Processors.
The Processor must as a minimum implement the following technical and organisational security measures to ensure an adequate level of protection.
In addition to the above, following specific security measures are implemented:
Please note that Profitmetrics.io may use financial data about your business on a pseudonymized level to generate aggregated statistical information. The aggregated statistical information may be shared with third parties (including publicly), but neither your company nor information about your company will be identifiable. Further, as this data concerns company financial data, it falls outside the scope of the Data Processing Agreement mentioned above.