Annex on Data Processing

Data Processing Annex

This Annex forms an integral part of the Contract and is entered into by and between : 

  1. (i) The Client (« Data Exporter ») ; and
  2. (ii) IQUALIF (« Data Importer »),

each being a « Party » and together the « Parties ».

Preamble

WHEREAS the Data Importer provides professional software services, IT and related services (such as Browsers with advanced search functions) ;

WHEREAS, under the Contract, the Data Importer has agreed to provide the Data Exporter with the services specified in the Contract (the « Services ») ;

WHEREAS, in providing the Services, the Data Importer receives or has access to the Data Exporter’s information or information about other persons who have a (potential) relationship with the Data Exporter, which information may qualify as personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (« GDPR ») and other applicable data protection laws ;

WHEREAS this Annex contains the general terms applicable to the collection, processing and use of such personal data by the Data Importer as an authorized data processor of the Data Exporter, in order to ensure that the parties comply with applicable data protection law.

NOW, and in order to allow the Parties to continue their relationship in a law-compliant manner, the Parties have agreed this Annex as follows :

Part 1

1. Document structure and definitions

1.1 Structure

This Annex consists of different parts, as follows :

Part 1 :

contains the general provisions, for example regarding the definitions used in this Annex, compliance with local laws, term and termination ;

Part 2 :

contains the unamended body of the Standard Contractual Clauses ;

Annex 1.1 and following Part 2 :

contains the details of the processing operations provided by the Data Importer to the Data Exporter as an authorized data processor (including the subject matter of the processing, the nature and purpose of the processing, the types of personal data and categories of data subjects) under this Annex ;

Annex 2 of Part 2 :

contains a description of the technical and organizational security measures of the Data Importer, which are applied consistently in relation to all processing activities described in Annex 1.1 and following Part 2 ;

Part 3 :

contains the signatures of the Parties who declare themselves bound by this Annex and identifies each Data Importer.

1.2 Terminology and definitions

For the purposes of this Annex, the terminology and definitions used by the GDPR apply (also in the body of the Standard Contractual Clauses in Part 2, where defined terms are not capitalized). In addition to that, 

« Member State"

means a country belonging to the European Union or the European Economic Area ;

« Special categories of data (personal) »

relates to personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data where processed for the purpose of uniquely identifying a natural person, data concerning health or data concerning a person’s sex life or sexual orientation ;

« Standard Contractual Clauses »

means the Standard Contractual Clauses for the transfer of personal data by processors established in third countries, pursuant to Commission Decision 2010/87/EU of 5 February 2010, as amended by Commission Implementing Decision (EU) 2016/2297 of 16 December 2016 ;

« Sub-processor »

means any processor, located inside or outside the EU/EEA, who agrees to receive from the Data Importer or from any other sub-processor of the Data Importer, personal data for the exclusive purpose of carrying out processing activities on behalf of the Data Exporter after the transfer in accordance with the Data Exporter’s instructions, subject to the terms of this Annex and the Contract with the Data Importer.

2. Obligations of the Data Exporter

2.1 The Data Exporter shall ensure compliance with all obligations applicable under the GDPR and any other applicable data protection law that applies to the Data Exporter, and to demonstrate such compliance as required by Art. 5 (2) of the GDPR. The Data Exporter warrants to the Data Importer that it has obtained in advance the consent of the data subjects in accordance with Article 6 (a) of the GDPR and has complied with its obligation to inform data subjects in accordance with Articles 13 and 14 of the GDPR.

2.2 The Data Exporter shall provide the Data Importer with the respective records of processing activities pursuant to Art. 30 (1) of the GDPR related to the Services under this Annex, to the extent necessary for the Data Importer to comply with the obligation under Art. 30 (2) of the GDPR. 

2.3 The Data Exporter shall appoint a data protection officer or representative, to the extent required by applicable data protection law. The Data Exporter shall provide the contact details of the data protection officer or representative, if any, to the Data Importer. 

2.4. Prior to the performance of the processing, the Data Exporter confirms by accepting this Annex that the technical and organizational security measures of the Data Importer, as set out in Annex 2 to Part 2, are appropriate and sufficient to protect the rights of data subjects and confirms that the Data Importer provides sufficient guarantees in this regard.

3. Compliance with local law

In order to meet the requirements for processors under Art. 28 of the GDPR, the following amendments apply :

3.1 Instructions

  1. (i) The Data Exporter gives the Data Importer the instruction to process personal data only on behalf of the Data Exporter. The Data Exporter’s instructions are provided in this Annex and in the Contract. The Data Exporter must ensure that all instructions given to the Data Importer comply with applicable data protection laws. The Data Importer shall process personal data only in accordance with the instructions provided by the Data Exporter, unless required otherwise by European Union law or the law of a Member State (in the latter case, Part 1 Clause 3.2 (iv) (c) applies).
  2. (ii) Any other instructions beyond those contained in this Annex or in the Contract shall be included within the subject matter of this Annex and the Contract. If implementation of such additional instruction causes costs for the Data Importer, the Data Importer will inform the Data Exporter of such costs and provide an explanation before implementing the instruction. Only after the Data Exporter has confirmed acceptance of those fees for implementing the instruction shall the Data Importer implement such additional instruction. The Data Exporter should give additional instructions generally in writing, unless urgency or other specific circumstances require another form (e.g., oral, electronic). Instructions in a form other than writing must be confirmed in writing without delay by the Data Exporter.
  1. 1. Unless the Data Exporter cannot effect correction, erasure or restriction of personal data by itself, the instructions may also relate to the correction, erasure and/or restriction of personal data as set out in Part 1 Clause 3.3. 
  2. 2. The Data Importer must immediately inform the Data Exporter if, in its opinion, an instruction violates the GDPR or other applicable data protection provisions of the European Union or a Member State (« Contested Instruction »). If the Data Importer considers that an instruction violates the GDPR or other applicable data protection provisions of the European Union or a Member State, the Data Importer is not obliged to follow the Contested Instruction. If the Data Exporter confirms the Contested Instruction upon receipt of the information from the Data Importer and acknowledges its responsibility for the Contested Instruction, the Data Importer will implement the Contested Instruction, unless it relates to (i) the implementation of technical and organizational measures, (ii) the rights of data subjects, or (iii) the engagement of Sub-processors. In cases (i) to (iii), the Data Importer may contact a competent supervisory authority to have the Contested Instruction legally assessed by it. If the supervisory authority declares that the Contested Instruction is lawful, the Data Importer must apply the Contested Instruction. Part 1 Clause 3.1 (ii) remains applicable.

3.2 Obligations of the Data Importer

  1. (i) The Data Importer is obliged to ensure that persons authorized by the Data Importer to process personal data on behalf of the Data Exporter, in particular the Data Importer’s employees as well as the employees of any Sub-processor, have committed to confidentiality or are subject to an appropriate statutory duty of confidentiality, and that those persons who have access to personal data process it in accordance with the Data Exporter’s instructions.
  2. (ii) The Data Importer is obliged to implement the technical and organizational security measures as set out in Annex 2 to Part 2 prior to processing the Data Exporter’s personal data. The Data Importer may change the technical and organizational security measures from time to time, provided they do not offer a lower level of protection than those set out in Annex 2 to Part 2.
  3. (iii) The Data Importer shall provide the Data Exporter, upon request, with information to demonstrate compliance with the Data Importer’s obligations under this Annex. The parties agree that this information obligation is satisfied by providing the Data Exporter with an audit report (covering security of principles, system availability and confidentiality) (« Audit Report »). If additional audit activities are legally required, the Data Exporter may request that inspections be carried out by the Data Exporter or another auditor appointed by the Data Exporter, subject to such auditor entering into a confidentiality agreement with the Data Importer to its reasonable satisfaction (« Audit »). Such Audit is subject to the following conditions: (i) the Data Importer’s prior formal written consent; and (ii) the Data Exporter shall bear all costs arising from or in connection with the on-site Audit for the Data Exporter and the Data Importer. The Data Exporter is obliged to create an audit report summarizing the results and findings of the on-site Audit (« On-site Audit Report »). On-site Audit Reports, as well as Audit Reports, are confidential information of the Data Importer and must not be disclosed to third parties, unless required by applicable data protection law or with the Data Importer’s consent. 
  4. (iv) The Data Importer is obliged to notify the Data Exporter without undue delay :
    1. a. of any legally binding request for disclosure of personal data by a law enforcement authority, unless otherwise prohibited, such as a prohibition under criminal law to protect the confidentiality of a law enforcement investigation ;
    2. b. of any complaint and request received directly from a data subject (e.g., concerning access, rectification, erasure, restriction of processing, data portability, objection to processing, automated decision-making) without responding to that request, unless the Data Importer has been authorized to do so ;
    3. c. if it is obliged, under the law of the European Union or of a Member State to which the Data Importer or the Sub-processor is subject, to process personal data beyond the instructions of the Data Exporter, prior to carrying out that processing beyond the instruction, unless that law of the European Union or Member State prohibits such information on important grounds of public interest, in which case the notification to the Data Exporter shall specify the legal requirement under that law of the European Union or Member State; or
    4. d. if the Data Importer becomes aware of a personal data breach, solely attributable to itself or its sub-processor, which would affect the personal data of the Data Exporter covered by this contract, in which case the Data Importer will assist the Data Exporter in its obligation, under applicable data protection law, to inform the data subjects and, if applicable, the supervisory authorities by providing the information it holds, in accordance with Art. 33 (3) of the GDPR. 
    5. (v) At the Data Exporter’s request, the Data Importer shall assist it in carrying out a data protection impact assessment which may be required by Art. 35 of the GDPR and with any prior consultation that may be required by Art. 36 of the GDPR regarding the services provided by the Data Importer to the Data Exporter under this Annex, by providing the information necessary and available to the Data Exporter. The Data Importer shall only be required to provide such assistance to the extent that the Data Exporter is unable to fulfil its obligation by other means. The Data Importer will notify the Data Exporter of the cost of such assistance. Once the Data Exporter has confirmed that it can bear such cost, the Data Importer will provide that assistance.
    6. (vi) At the end of the provision of the services, the Data Exporter may request the return of the personal data processed by the Data Importer under this Annex within one month after the end of the services. Unless the law of the Member State or of the European Union requires the Data Importer to store or retain such personal data, the Data Importer shall delete all such personal or non-personal data after the one month period, whether or not it has returned them to the Data Exporter at its request.

3.3 Data subject rights

    1. (i) The Data Exporter is primarily responsible for handling requests submitted by data subjects and for responding to them. The Data Importer is not obliged to respond directly to data subjects. 
    2. (ii) If the Data Exporter needs the Data Importer’s assistance to handle requests submitted by data subjects and to provide responses, it will issue an additional instruction, in accordance with Clause 3.1 (ii) of Part 1. The Data Importer will assist the Data Exporter by means of appropriate and feasible technical and organizational measures as follows in order to respond to requests to exercise the data subject rights set out in Chapter III of the GDPR : 
    3. a. Regarding information requests, the Data Importer will provide the Data Exporter with the information required by Arts. 13 and 14 of the GDPR that it may hold only if the Data Exporter is unable to find it itself.
    4. b. Regarding access requests (Art. 15 of the GDPR), the Data Importer will provide the Data Exporter with the information that should be provided to a data subject for such access request, that it may hold, only if the Data Exporter is unable to find it itself.
    5. c. Regarding rectification requests (Art. 16 of the GDPR), erasure requests (Art. 17 of the GDPR), restrictions on processing requests (Art. 18 of the GDPR), or portability requests (Art. 20 of the GDPR), and only if the Data Exporter cannot itself rectify or, as the case may be, erase, restrict or transmit the personal data to another third party, the Data Importer will offer the Data Exporter the ability to rectify or, as the case may be, erase, restrict or transmit the relevant personal data to the other third party, or if that is not possible, it will provide the necessary assistance to rectify or, as the case may be, erase, restrict or transmit the relevant personal data to the other third party.
    6. d. Regarding notification of rectification, erasure or restriction of processing (Art. 19 of the GDPR), the Data Importer will assist the Data Exporter by notifying all recipients of personal data engaged by the Data Importer as sub-processors if the Data Exporter requests this and if the Data Exporter is unable to address it itself. 
    7. e. Regarding the right to object exercised by a data subject (Arts. 21 and 22 of the GDPR) the Data Exporter will determine whether the objection is legitimate and how to handle it.
    8. (iii) The Data Importer’s assistance obligations are limited to personal data processed within its infrastructures (e.g., databases, systems, applications owned or provided by the Data Importer).  
    9. (iv) The Data Exporter must determine whether a data subject has the right to exercise the data subject rights set out in Clause 3.1 of this Part 1 and must indicate to the Data Importer to what extent the assistance specified in Clauses 3.3 (ii), (iii) of Part 1 is necessary.
    10. (v) If the Data Exporter requests, in order to respond to data subject rights, additional or modified technical and organizational measures beyond the assistance provided by the Data Importer under Clause 3.3 (ii), (iii) of Part 1, the Data Importer must inform the Data Exporter of the costs of implementing such additional or modified technical and organizational measures.  Once the Data Exporter has confirmed that it can bear those costs, the Data Importer will implement those additional or modified technical and organizational measures to assist the Data Exporter in responding to data subject requests.
    11. (vi) Without limiting the scope of Clause 3.3 (v) of Part 1, the Data Exporter shall reimburse the Data Importer for its reasonable expenses incurred by data subject requests.

3.4 Sub-processing

    1. (i) The Data Exporter authorizes the use of sub-processors by the Data Importer for the provision of services under this Annex. The Data Importer will select such sub-processors with care. The Data Exporter approves the sub-processors listed in Annex 1.1 at the end of Part 2.
    2. (ii) The Data Importer will pass on to sub-processors its obligations under this Annex to the extent applicable to the subcontracted services. 
    3. (iii) The Data Importer may dismiss, replace or appoint at its discretion other appropriate and reliable sub-processors. If the Data Exporter requests it in writing, the Data Importer is obliged to follow the procedure set out below :
    1. a. The Data Importer will inform the Data Exporter in advance of any changes to the list of sub-processors referenced under Clause 3.4 (i) of Part 1. If the Data Exporter does not object pursuant to Clause 3.4. (b) of Part 1 within thirty days of receiving the Data Importer’s notification, the additional sub-processors will be deemed accepted.
    2. b. If the Data Exporter has a legitimate reason to object to an additional sub-processor, it will notify the Data Importer in writing within thirty days of receipt of the Data Importer’s notification and, in any event, before the commencement of the service provided by the Data Importer. If the Data Exporter objects to the use of an additional sub-processor, the Data Importer shall be entitled to remove the objection by means of one of the following options (to be chosen at its discretion): (A) the Data Importer will cancel its plans to use the additional sub-processor with respect to the Data Exporter’s personal data; (B) the Data Importer will take the corrective measures required by the Data Exporter in its objection (thereby voiding such objection) and will use the additional sub-processor with respect to the Data Exporter’s personal data; (C) the Data Importer may cease to provide or the Data Exporter may agree not to use (temporarily or permanently) a particular aspect of the service that would involve the use of the additional sub-processor with respect to the Data Exporter’s personal data.
    1. (iv) Where the sub-processor is located outside the EU-EEA in a country that is not recognized as providing an adequate level of data protection pursuant to a decision of the European Commission, the Data Importer will take measures to ensure an adequate level of data protection in accordance with the GDPR (such measures may include – among others and as applicable - the use of data processing agreements based on the EU Model Clauses, transfer to self-certified sub-processors under the EU-US Privacy Shield, or a similar program).

3.5 Term

The term of this Annex is identical to the term of the corresponding Contract. Unless otherwise provided in this Annex, the rights and duties related to termination shall be identical to those set out in the Contract.

4. Limitation of liability

4.1 Each party is responsible for its obligations arising from this Annex and from applicable data protection legislation.

4.2 Any liability arising from or in connection with a breach of the obligations under this Annex or applicable data protection law shall be subject to the liability provisions set out in the Contract, or applicable to that contract, and governed by it, unless otherwise provided in this Annex. If liability is governed by the liability provisions set out in the Contract or applicable to that contract, for the purposes of calculating liability caps or determining the application of other limitations of liability, liability arising under this Annex shall be treated as liability arising under the Contract.

5. General provisions

5.1 To the extent there are contradictions or inconsistencies between Parts 1 and 2 of this Annex, the provisions of Part 2 shall prevail. More specifically, even in that case, the provisions of Part 1 that simply go beyond Part 2 (i.e., conditions of the Standard Clause) without contradicting it shall remain valid.

5.2 In case of inconsistencies between the provisions of this Annex and those of other agreements binding the parties, the provisions of this Annex shall prevail regarding the parties’ obligations related to data protection. In case of doubt as to whether clauses of other agreements concern the parties’ obligations related to data protection, this Annex shall prevail.

5.3 If any provision of this Annex is found to be invalid or unenforceable, the remainder of this Annex shall remain fully valid. The invalid or unenforceable provision shall (i) be amended as necessary to ensure its validity and enforceability, while preserving as much as possible the parties’ intent, or – if that is not possible – (ii) be interpreted as if the invalid or unenforceable part had never been part of the agreement.  The foregoing shall also apply if this Annex contains an omission.

5.5 As necessary, the Parties are entitled to request amendments to Part 1, Clause 3 (Compliance with local law)  or other parts of the Annex, in order to comply with interpretations, directives or orders issued by competent Union or Member State authorities, national implementation provisions, or any other legal developments concerning the GDPR or other delegation conditions for any entities involved in data processing generally, and specifically regarding the use of the Standard Contractual Clauses under the GDPR. The terms of the Standard Contractual Clauses may not be modified or replaced unless expressly approved by the European Commission (for example by new adequate and standard data protection clauses).

5.6 Any reference in this Annex to the «Clauses» shall be understood to refer to all provisions of this Annex, unless otherwise provided. 

5.7 The choice of law in Part 2, clause 9, applies to the entire Contract.

6. Personal data transferred and processed by the parties for their own purposes (controller to controller transfer)

6.1 The Parties are fully aware that certain personal data will be transferred from the Data Exporter to the Data Importer and vice versa, and that such data are processed by each party for its own purposes. With respect to such personal data, the other provisions of this Annex do not apply (except for this clause 6).

6.2 The Data Exporter may transfer personal data relating to the Data Importer’s personnel to that same Data Importer, including information on security incidents, or any other documents or files created or compiled by the Data Exporter in connection with the Services provided by the Data Importer’s personnel. The Data Importer may process such personal data for its own purposes, including in the context of its professional relations with the Data Importer’s personnel, for quality control and training, or for commercial purposes.

6.3. The Data Importer may transfer personal data to the Data Exporter, including names and contact details relating to the Data Importer’s personnel. The Data Exporter may process such personal data for its own purposes.

6.4 Both parties shall comply with any applicable data protection law, including the GDPR, when collecting, processing and using such personal data received from the other party under this clause 1 of Part 1. In particular, both parties shall take adequate security measures, providing a level of protection similar to the security measures set out in Annex 2 of Part 2. Any access to such personal data shall be limited to a need-to-know basis.

6.5 Both parties are required to delete such personal data as soon as possible once the purposes have been achieved.

Part 2

 COMMISSION DECISION 

of 5 February 2010

on standard contractual clauses for the transfer of personal data to processors established in third countries under Directive 95/46/EC of the European Parliament and of the Council

Clause 1 

Definitions 

For the purposes of the clauses: 

a) “personal data”, “special categories of data”, “process/processing”, “data controller”, “processor”, “data subject” and “supervisory authority” have the same meaning as in Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data ( 1 ); 

b) the “data exporter” is the data controller who transfers the personal data; 

c) the “data importer” is the processor who agrees to receive from the data exporter personal data intended to be processed on behalf of the data exporter after the transfer in accordance with its instructions and the terms of these clauses and who is not subject to a third country mechanism providing adequate protection within the meaning of Article 25(1) of Directive 95/46/EC; d) the “sub-processor” is the processor engaged by the data importer or by any other subsequent processor of the data importer, who agrees to receive from the data importer or from any other subsequent processor of the data importer personal data exclusively intended for processing activities on behalf of the data exporter after the transfer in accordance with the instructions of the latter, under the conditions set out in these clauses and under the terms of the written subcontract; 

e) the “applicable data protection law” is the legislation protecting the fundamental freedoms and rights of individuals, in particular the right to privacy with respect to the processing of personal data, and applying to a data controller in the Member State in which the data exporter is established; 

f) the “technical and organizational security measures” are the measures intended to protect personal data against accidental or unlawful destruction, accidental loss, alteration, disclosure or unauthorized access, in particular where processing involves the transmission of data over a network, and against all other forms of unlawful processing. 

Clause 2 

Details of the transfer 

The details of the transfer and, in particular, where applicable, the special categories of personal data, are specified in Appendix 1 which forms an integral part of these clauses. 

Clause 3 

Third-party beneficiary clause 

1. The data subject may enforce against the data exporter this clause, as well as clause 4, points b) to i), clause 5, points a) to e) and points g) to j), clause 6, paragraphs 1 and 2, clause 7, clause 8, paragraph 2, and clauses 9 to 12 as a third-party beneficiary. 

2. The data subject may enforce against the data importer this clause, as well as clause 5, points a) to e) and g), clause 6, clause 7, clause 8, paragraph 2, and clauses 9 to 12 in cases where the data exporter has materially disappeared or ceased to exist in law, unless all of its legal obligations have been transferred, by contract or by operation of law, to the entity which succeeds it, to which the rights and obligations of the data exporter therefore pass, and against which the data subject may therefore enforce such clauses. 

3. The data subject may enforce against the subsequent processor this clause, as well as clause 5, points a) to e) and g), clause 6, clause 7, clause 8, paragraph 2, and clauses 9 to 12, but only in cases where the data exporter and the data importer have materially disappeared, ceased to exist in law or become insolvent, unless all of the data exporter’s legal obligations have been transferred, by contract or by operation of law, to the legal successor, to which the rights and obligations of the data exporter therefore pass, and against which the data subject may therefore enforce such clauses. The civil liability of the subsequent processor shall be limited to its own processing activities under these clauses. 4. The parties do not object to the data subject being represented by an association or other body if it so wishes and if national law allows. 

Clause 4 

Obligations of the data exporter 

The data exporter accepts and warrants the following: 

a) the processing, including the transfer itself of the personal data, has been and will continue to be carried out in accordance with the relevant provisions of the applicable data protection law (and, where appropriate, has been notified to the competent authorities of the Member State in which the data exporter is established) and does not infringe the relevant provisions of that State; 

b) it has appointed, and will during the term of the personal data processing services appoint, the data importer to process the personal data transferred on behalf of the data exporter and in accordance with the applicable data protection law and these clauses; 

c) the data importer will provide sufficient guarantees in respect of the technical and organizational security measures specified in Appendix 2 to this contract; 

d) after assessing the requirements of the applicable data protection law, the security measures are adequate to protect personal data against accidental or unlawful destruction, accidental loss, alteration, disclosure or unauthorized access, in particular where processing involves the transmission of data over a network, and against all other forms of unlawful processing and provide a level of security appropriate to the risks associated with the processing and the nature of the data to be protected, taking into account the state of the art and the cost of implementation; 

e) it will ensure compliance with the security measures; 

f) if the transfer concerns special categories of data, the data subject has been informed or will be informed before the transfer or as soon as possible after the transfer that their data could be transferred to a third country not offering an adequate level of protection within the meaning of Directive 95/46/EC; 

g) it will forward any notice received from the data importer or any subsequent processor pursuant to clause 5, point b), and clause 8, paragraph 3), to the supervisory authority if it decides to continue the transfer or to lift its suspension; 

h) it will make available to the data subjects, if they so request, a copy of these clauses, except Appendix 2, and a summary description of the security measures, as well as a copy of any subsequent subcontract concluded under these clauses, unless those clauses or the contract contain business information, in which case it may redact such information; 

i) in the event of subsequent sub-processing, the processing activity is carried out in accordance with clause 11 by a subsequent processor providing at least the same level of protection for personal data and the rights of the data subject as the data importer under these clauses; and 

j) it will ensure compliance with clause 4, points a) to i). 

Clause 5 

Obligations of the data importer  

The data importer accepts and warrants the following: 

a) it will process the personal data exclusively on behalf of the data exporter and in accordance with the latter’s instructions and these clauses; if it is unable to comply for any reason, it agrees to inform the data exporter without delay, in which case the latter has the right to suspend the transfer of data and/or terminate the contract; 

b) it has no reason to believe that the legislation applicable to it prevents it from fulfilling the instructions given by the data exporter and the obligations incumbent upon it under the contract, and if such legislation is subject to a change likely to have a substantial adverse effect on the guarantees and obligations offered by the clauses, it will notify the data exporter of the change without delay after becoming aware of it, in which case the latter has the right to suspend the transfer of data and/or terminate the contract; c) it has implemented the technical and organizational security measures specified in Appendix 2 prior to processing the personal data transferred;

d) it will notify the data exporter without delay: 

i) any legally binding request for disclosure of personal data from a law enforcement authority, unless otherwise provided, such as a criminal prohibition intended to preserve the secrecy of a police investigation; 

ii) any accidental or unauthorized access; and 

iii) any request received directly from data subjects without responding to that request, unless it has been authorized to do so; 

e) it will promptly and properly deal with all enquiries from the data exporter relating to its processing of the personal data subject to the transfer and will follow the advice of the supervisory authority with regard to the processing of transferred data; 

f) at the data exporter’s request, it will submit its data processing facilities to an audit of the processing activities covered by these clauses to be carried out by the data exporter or by an independent auditing body composed of members with the required professional qualifications, subject to an obligation of confidentiality and chosen by the data exporter, where appropriate with the agreement of the supervisory authority; 

g) it will make available to the data subject, if they so request, a copy of these clauses, or any subsequent subcontract concluded, unless the clauses or the contract contain business information, in which case it may redact such information, except Appendix 2, which shall be replaced by a summary description of the security measures, where the data subject is unable to obtain a copy from the data exporter; 

h) in the event of subsequent sub-processing, it will obtain the data exporter’s prior written authorization; 

i) the processing services provided by the subsequent processor will comply with clause 11; 

j) it will send a copy of any subsequent subcontract concluded by it under these clauses to the data exporter without delay. 

Clause 6 

Liability 

1. The parties agree that any data subject who has suffered damage as a result of an infringement of the obligations referred to in clause 3 or clause 11 by one of the parties or by a subsequent processor shall be entitled to receive compensation from the data exporter for the damage suffered. 

2. If a data subject is prevented from bringing an action for compensation referred to in paragraph 1 against the data exporter because the data exporter has materially disappeared, ceased to exist in law or become insolvent, the data importer agrees that the data subject may bring a claim against it as if it were the data exporter, unless all the data exporter’s legal obligations have been transferred, by contract or by operation of law, to the entity which succeeds it, against which the data subject may then bring action. The data importer cannot rely on a breach by a subsequent processor to avoid its own liabilities. 

3. If a data subject is prevented from bringing the action referred to in paragraphs 1 and 2 against the data exporter or the data importer for a breach by the subsequent processor of any of its obligations referred to in clause 3 or clause 11, because the data exporter and the data importer have materially disappeared, ceased to exist in law or become insolvent, the subsequent processor agrees that the data subject may bring a claim against it in respect of its own processing activities under these clauses as if it were the data exporter or the data importer, unless all of the data exporter’s or the data importer’s legal obligations have been transferred, by contract or by operation of law, to a legal successor, against which the data subject may then bring action. The liability of the subsequent processor shall be limited to its own processing activities under these clauses. 

Clause 7 

Mediation and jurisdiction 

1. The data importer agrees that if, under the clauses, the data subject invokes against it the third-party beneficiary right and/or requests compensation for the damage suffered, it will accept the data subject’s choice: 

a) to refer the dispute to mediation by an independent person or, where appropriate, the supervisory authority; 

b) to bring the dispute before the courts of the Member State where the data exporter is established. 

2. The parties agree that the choice made by the data subject shall not affect the data subject’s procedural or substantive right to obtain compensation under other provisions of national or international law. 

Clause 8 

Cooperation with supervisory authorities 

1. The data exporter agrees to lodge a copy of this contract with the supervisory authority if the latter so requires or if such lodging is provided for by applicable data protection law. 

2. The parties agree that the supervisory authority has the power to carry out checks at the data importer and at any subsequent processor to the same extent and under the same conditions as checks carried out at the data exporter under the applicable data protection law. 

3. The data importer shall inform the data exporter, without delay, of the existence of any legislation applicable to it or to any subsequent processor that prevents checks being carried out at its premises or at the premises of any subsequent processor in accordance with paragraph 2. In that case, the data exporter shall be entitled to take the measures provided for in clause 5, point b). 

Clause 9 

Applicable law 

The clauses shall be governed by the law of the Member State in which the data exporter is established., 

Clause 10 

Variation of the contract 

The parties undertake not to vary these clauses. The parties remain free to include other commercial clauses they deem necessary, provided they do not contradict these clauses. 

Clause 11 

Sub-processing 

1. The data importer shall not subcontract any of its processing activities carried out on behalf of the data exporter pursuant to these clauses without the data exporter’s prior written authorisation. The data importer shall subcontract the obligations incumbent on it pursuant to these clauses, with the data exporter’s authorisation, only by way of a written contract with the subsequent processor, imposing on the latter the same obligations as those incumbent on the data importer pursuant to these clauses ). In the event of a breach by the subsequent processor of the data protection obligations incumbent on it under that written contract, the data importer shall remain fully liable to the data exporter for the performance of those obligations. 

2. The prior written contract between the data importer and the subsequent processor shall also contain a third-party beneficiary clause as set out in clause 3 for the cases where the data subject is prevented from bringing the action for compensation referred to in clause 6, paragraph 1, against the data exporter or the data importer because they have materially disappeared, ceased to exist in law or become insolvent, and where all the data exporter’s or the data importer’s legal obligations have not been transferred, by contract or by operation of law, to another entity which has assumed them. The civil liability of the subsequent processor shall be limited to its own processing activities under these clauses. 

3. The provisions governing the data protection related aspects of sub-processing of the contract referred to in paragraph 1 shall be governed by the law of the Member State in which the data exporter is established. 

4. The data exporter shall maintain a list of the sub-processing contracts concluded pursuant to these clauses and notified by the data importer under clause 5, point j), which shall be updated at least once a year. This list shall be made available to the data exporter’s supervisory authority. 

Clause 12 

Obligation after the termination of the personal data processing services 

1. The parties agree that, at the end of the processing services, the data importer and the subsequent processor will return to the data exporter, at the choice of the latter, all the personal data transferred as well as all copies thereof, or will destroy all such data and certify to the data exporter that they have done so, unless legislation imposed on the data importer prevents it from returning or destroying all or part of the personal data transferred. In that case, the data importer warrants that it will ensure the confidentiality of the personal data transferred and will not actively process the data anymore. 

2. The data importer and the subsequent processor warrant that if the data exporter and/or the supervisory authority so request, they will submit their data processing facilities to an audit of the measures referred to in paragraph 1. 

Annex 1.1 of Part 2

Details of the transfer

Data Exporter

Data Importer

The Data Importer is IQUALIF and is assigned to process the data, providing services to the Data Exporter.

Data subjects

The personal data transferred concern the following categories of data subjects :

☒ telephone subscribers listed in the universal directory

Others, in particular :

Categories of data

The personal data transferred concern the following categories of data :

Categories of personal data of the Data Exporter’s data subjects, in particular,

☒ Full name

☒ Postal address

☒ Contact details (email, telephone, IP address, etc.)

☒ Details about marketing activities concerning the telephone subscriber

☒ Others, in particular : type of housing, average income and ages by city rendered anonymous

Special categories of data (if any)

The personal data transferred concern the following special categories of data :

☒ The transfer of special categories of data is not envisaged

Race or ethnic origin

Religious or philosophical beliefs

Trade union membership

Political opinions

Genetic information 

Biometric information

Information about sexual orientation or sex life

Health data

Processing activities

The personal data transferred will be subject to the following basic processing activities :

    • Subject matter of the processing

The processing carried out on behalf of the Data Exporter revolves around the following subjects, in particular :

☒ Support for products or services offered by the Data Exporter

☒ Offering a product or service that the called person may request

☒ Orders taken from called persons and further processing of those orders

☒ Surveys and analyses

☒ Telemarketing

Others, in particular :

    • Nature and purpose of the processing

The Data Importer processes the personal data of the data subjects on behalf of the Data Exporter in order to provide the following services, in particular :

☒ Sales and marketing

☒ Others, in particular : updating municipal and political party databases

    • Provision of services and use of service providers

IQUALIF combines, centralizes and mainly provides services to the Data Exporter. The services provided by the named service provider may include (among others and as applicable) the following ancillary services: (i) provision of applications, tools, systems and IT infrastructure in relation to the data centers used, in order to provide and support the services, including the processing of the personal data of the data subjects as described above, via such applications, tools and systems; (ii) provision of IT support, maintenance and other services related to those applications, tools, systems and IT infrastructure, including potential access to personal data stored in those applications, tools and systems; and (iii) provision of data protection services, monitoring and incident response services, including potential access to personal data when providing such protection services. IQUALIF may engage sub-processors as indicated below in order to provide the services, including the ancillary services.

    • External third party service providers as sub-entities assigned to data processing

IQUALIF engages external third-party service providers, which are not IQUALIF subsidiaries, in order to support the provision of services to the Data Exporter. The Data Exporter approves such external third-party service providers as sub-entities assigned to data processing

If a sub-entity assigned to data processing is located outside the EU / EEA, in a country considered not to provide an adequate level of data protection pursuant to a decision of the European Commission, the Data Importer will take measures to obtain an adequate level of data protection in accordance with the GDPR, as well as section 3.4 (iv) of Part 1.

Annex 2, Part 2

Technical and organizational security measures

The Data Importer shall take the following technical and organizational security measures, as applicable and confirmed by the Data Exporter where appropriate, in order to ensure an appropriate level of security of the rights and freedoms of individuals, according to the risks. When assessing the relevant level of protection, the Data Exporter has taken into account in particular the risks related to the processing, including accidental or unlawful destruction, alteration, unauthorized disclosure or access to personal data transmitted, stored or otherwise processed. For clarification: These technical and organizational security measures do not concern applications, tools, systems and/or IT infrastructures provided by the Data Exporter.

1 General technical and organizational security measures

1.1 General information and data protection strategies

The following measures should be taken to follow the general information and data protection strategies :

  • a) take measures to assess those technical and organizational protection measures ;
  • b) provide training to raise employee awareness ;
  • c) maintain a description of the systems concerned and grant access to employees ;
  • d) implement an official documentation process whenever systems are implemented or changed ;
  • e) documentation of the organizational structure, processes, responsibilities and respective assessments ;

1.2 Organization of information protection

The following measures should be taken to coordinate data and information protection activities :

  • a) defined responsibilities for information and data protection (for example, via a data protection management policy) ;
  • b) necessary competencies in information and data protection remain available ;
  • c) all employees have committed to keeping personal data confidential, and have been informed of the potential consequences in case of breach of that commitment.

1.3 Control of access to processing areas 

The following measures should be taken to prevent unauthorized persons from accessing data processing systems (including software and hardware) when personal data are processed, stored or transmitted : 

  • a) establish secure zones ;
  • b) protect and restrict access to data processing systems ; 
  • c) establish access authorizations for employees and third parties, including the respective documents ;
  • d) all access to the data centers hosting personal data will be logged.

1.4 Control of access to data processing systems 

The following measures should be taken to prevent unauthorized access to data processing systems: 

  • a) user authentication policies and procedures ; 
  • b) use passwords on all computer systems ;
  • c) remote access to the network requires multi-factor authentication, and is granted to relevant personnel based on responsibilities and authorization ;
  • d) access to specific functions is based on job functions and/or attributes assigned individually to a user account ;
  • e) access rights related to personal data are reviewed regularly ;
  • f) keep records up to date of changes made to access rights.

1.4 Control of access to specific areas of use of data processing systems 

The following measures should be taken so that authorized persons with the right to use the data processing system can only access the data relevant to their responsibilities and respective access authorizations, and so that personal data cannot be read, copied, altered or deleted without authorization: 

    1. a) policies, instructions and employee training regarding each person’s obligations concerning confidentiality, access rights to personal data and the scope of personal data processing; 
  • b) disciplinary measures against persons accessing personal data without authorization ; 
  • c) access to personal data will only be granted to authorized persons, and only based on their need to know ; 
  • d) keep a list of system administrators, and take appropriate measures to monitor system administrators ;
  • e) do not copy or reproduce personal data on all storage systems, in order to prevent unauthorized persons from deleting information from its author ;
  • f) controlled and documented deletion or destruction of data ; 
  • g) securely store all personal data that must be retained for legal or regulatory reasons (for example, data retention obligations), and only for as long as required by law.

1.6 Control of transmissions 

The following measures should be taken to prevent personal data from being read, copied, altered or deleted by unauthorized third parties during transmission or transport of data storage devices (depending on the processing carried out of the personal data) : 

    1. a) use of firewalls ; 
  • b) avoid storing personal data on mobile storage devices for transport purposes, or encrypt the devices
  • c) Only use them on laptops and other mobile devices once encryption protection is enabled ;
  • d) logging of transmissions of personal data.

1.7 Input control 

The following measures should be taken to ensure that it is possible to verify and establish whether personal data have been entered into the data processing systems or deleted, and by whom : 

    1. a) a policy for authorization to read, alter and delete stored data ;
  • b) protective measures regarding reading, alteration and deletion of stored data.

1.8 Job control 

In the case of outsourced processing of personal data, the following measures should be taken to ensure that such data is processed in accordance with the controller’s instructions:

    1. a) entities or sub-entities assigned to data processing, selected with diligence (service providers processing personal data on behalf of the controller);
  • b) instructions concerning the scope of any processing of personal data to employees, entities or sub-entities assigned to data processing ;
  • c) agreed audit rights with the entities or sub-entities assigned to data processing
  • d) agreements in place with the entities or sub-entities assigned to data processing.

1,9 Separation of processing for other purposes 

The following measures should be taken to ensure that data collected for other purposes can be processed separately : 

    1. a) separate access to personal data in accordance with users’ rights in force ; 
  • b) interfaces, batch processing and reports are aimed at other objectives and functions, so that data collected for other purposes can be processed separately.

1.10 Pseudonymisation 

The following measures should be taken regarding pseudonymisation of personal data :

    1. a) If the Data Exporter orders a specific processing or if it is considered appropriate by the data importer, and in accordance with applicable data protection laws regarding certain processing activities, the processing of personal data shall be carried out in such a way that the data can no longer be attributed to a specific person without the use of additional information. Such additional information shall be kept separately ;
  • b) use of pseudonymisation techniques, including list allocation randomization; creation of hash-like values.

1,11 Encryption

The following measures should be taken in order to encrypt personal data in applications and transmissions that support encryption :

    1. a) use of encryption techniques ;
  • b) establish encryption management to support the authorized encryption techniques to be used ;
  • c) support the use of cryptography through procedures and protocols for the generation, modification, revocation, destruction, distribution, certification, storage, entry, use and archiving of cryptographic keys as protection against unauthorized alteration and disclosure.

1.12 Integrity of data processing systems and services 

The following measures should be taken to ensure the integrity of data processing systems and services :

  1. a) protect data processing systems against tampering or destruction, by appropriate means (e.g., anti-virus software, data loss prevention software and anti-malware software, software patches, firewalls and managed desktop protection) ;
  • b) prohibit the installation of any service or software harmful to data processing systems, services or the manipulation of personal data ;
  • c) use a network intrusion detection and prevention system within the network structure itself.

1,14 Availability of data processing systems and services, and ability to restore access to and use of personal data in the event of a physical or technical incident

The following measures should be taken to ensure the availability of data processing systems and to be able to quickly restore availability of and access to personal data in the event of a physical or technical incident (including ensuring that personal data are protected against any accidental destruction or loss):

  • a) have controls to maintain backup copies, and to restore lost or erased data ;
  • b) infrastructure redundancy and operational tests ;
  • c) physical protection of IT resources ;
  • d) use of tools to monitor the health and availability of the internal network ;
  • e) incident reporting and response policies governing the incident management procedure, and reiteration of adherence to these policies as part of regular training ;
  • f) backups (sometimes off-site) enabling the system to be restored and thus perform its functions again ;
  • g) business continuity / disaster recovery plans.

1.12 Resilience of data processing systems and services 

The following measures should be taken to ensure the resilience of data processing systems and services :

  • a) systems configured consistently, using approved security settings ;
  • b) network redundancy ;
  • c) containment protection for critical systems.

1,16 Procedure to regularly test, assess and evaluate the effectiveness of technical and organizational measures to ensure the security of data processing

Procedure to regularly test, assess and evaluate the effectiveness of technical and organizational measures to protect data processing

  • a) take necessary measures to assess risks and mitigation strategies ;
  • b) IT department service review meetings to address current issues ;
  • c) business continuity / disaster recovery plans are regularly updated.

Part 3

Signatures of the parties and list of Data Importers

At the time of completing your the online order form and validating it, by ticking the box accepting the terms of use, the contract governing the relations between the Client and IQUALIF is formed. 

Sending the payment to IQUALIF shall be sufficient to consider the contract formed. 

FAQ

How to install the software

Software Installation

To install IQUALIF, simply click on this download link and install the trial version.

📥 Step 1: Download

After downloading, your browser or Chrome may display a warning message.

This can happen for recent or less widely distributed software.

In this case:

  • Right-click on the downloaded file
  • Click on "Keep" or "Keep Anyway"

⚙️ Step 2: Installation

When launching the program (double-click), Windows may display a security alert (Windows Defender).

This simply occurs because the software has not been downloaded many times yet and does not have a large history volume on Microsoft servers.

If this message appears:

  • Click on "More info" or on the three dots "..."
  • Then select "Run Anyway" or "Open Anyway"

✅ Why can you install with confidence?

IQUALIF is a professional software developed since 2013.

We develop solutions used daily by professionals.

These security messages are automatic and solely related to the number of downloads, not the content of the software.

What is the difference between the trial version and the paid version?

The trial version and the paid version offer exactly the same features.

The difference is simple:

  • The trial version is limited to 3 days.
  • The paid version operates twice as fast, providing optimal time savings in daily use.

You can freely test all features and then fully enjoy maximum performance with the full version.

What is included in the Plan

Plans give you full access to all IQUALIF software for the entire duration of their validity.

As soon as your order is confirmed, you will receive your activation key by email within just 5 minutes.

If you can't find it, be sure to check your SPAM or junk mail folder.

Automatic renewal is without commitment: you can cancel it at any time from your customer account.

Your login credentials will be sent to you by email after your order.

And of course, we are available via chat, email, or phone if you have any questions.

What is speed

A speed tailored to your needs

IQUALIF allows you to retrieve data at your own pace, depending on the volume you require.

Trial Version

Up to 400 contacts per hour

(ideal for discovering and testing all features)

Paid Version

  • Standard speed: up to 800 contacts per hour
  • Speed 5x: up to 4,000 contacts per hour
  • Speed 10x: up to 8,000 contacts per hour

You choose the speed that suits your activity and can upgrade at any time.

Speed may vary depending on the selected source.

Are there any discounts?

Occasional promotions are offered throughout the year, with no fixed schedule.

Discounts are also granted to our loyal customers, with decreasing rates based on seniority.

To learn more, do not hesitate to contact us by email or phone

I need assistance or a remote demonstration

You can contact us via chat, email, or phone: our team will be happy to assist you.

If needed, we can also directly access your computer through a secure remote support tool to help you quickly and efficiently.

I just placed an order, how do I activate my product?

  1. Open IQUALIF.
  2. Click on the ? menu at the top left, then select License.
  3. In the window that opens, copy the key received by email and click on OK.

A confirmation message will appear to indicate that your product has been successfully activated.