<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1579425466404534&amp;ev=PageView&amp;noscript=1"/>

DATA PROCESSING AGREEMENT (DPA)

Part of the Agreement between Usere B.V. and the Customer

ARTICLE 1. SCOPE AND APPLICABILITY
This Data Processing Agreement applies to all processing of personal data carried out by Usere B.V. (hereinafter: the Processor) on behalf of and for the benefit of the Client (hereinafter: the Data Controller)
the context of the use of The Tool and The Services. Definitions in this Data Processing Agreement have the same meaning as in Usere General Terms and Conditions and the General Data Protection Regulation (GDPR).

ARTICLE 2. PURPOSE AND NATURE OF THE PROCESSING
The Processor undertakes to process personal data on behalf of the Data Controller in accordance with the terms of this Data Processing Agreement. The processing shall take place exclusively for the purposes of performing the Agreement (such as facilitating email marketing, managing contact lists and social media planning via The Tool). The categories of data subjects and the types of personal data are specified in Annex 1 to this agreement. The Processor shall not process the personal data for any purpose other than as instructed by the Controller, unless there is a legal obligation to do so.

ARTICLE 3. SECURITY AND CONFIDENTIALITY
The Processor shall take appropriate technical and organisational measures to protect the personal data against loss or any form of unlawful processing. These measures shall ensure an
appropriate level of security, taking into account the risks. All persons acting under the authority of the Processor and having access to the personal data are bound by a duty of confidentiality.

ARTICLE 4. DATA BREACHES
In the event of a detected data breach (a breach of security leading to a substantial risk of, or the actual destruction, loss, alteration or unauthorised disclosure of personal data),
the Processor shall inform the Controller of this without undue delay, but no later than 48 hours after discovery.
The Processor shall provide all necessary information required by the Controller to fulfil its statutory reporting obligation (to the Dutch Data Protection Authority and, where applicable, to data subjects).

ARTICLE 5. RIGHTS OF DATA SUBJECTS
If a datasubject submits a request to the Processor to exercise his or her rights (such as the right to access, rectify or erase data), the Processor shall forward the request to the Controller without delay. The Processor shall, to the extent technically and operationally possible, assist the Data Controller in responding to such requests.

ARTICLE 6. ENGAGEMENT OF SUB-PROCESSORS
The Data Controller hereby grants the Processor general authorisation to engage third parties (sub-processors) for the performance of the Agreement (such as hosting providers, mail servers and
IT infrastructure providers). The Processor shall impose on these sub-processors at least the same obligations as those set out in this
Data Processing Agreement. The Processor shall process and store all data on servers located within the European Economic Area (EEA)
. Transfers to countries outside the EEA are permitted only if the conditions set out in Chapter V of the GDPR are met.

ARTICLE 7. AUDITS
The Data Controller shall be entitled, at its own expense, to have an audit carried out by an independent expert no more than once a year to verify compliance with this Data Processing Agreement
. The Processor shall cooperate with this audit and make the necessary information available. Notice of an audit shall be given in writing at least 30 days in advance.

ARTICLE 8. TERM AND TERMINATION
This Data Processing Agreement shall remain in force for as long as the main agreement between the parties remains in force. Upon termination of the Agreement, the Processor shall, at the Data Controller’s discretion, either permanently delete or transfer all personal data held on behalf of the Data Controller, unless a legal obligation requires the data to be retained.