All rights reserved. © Re:Shark, part of The Ocean B.V.
VAT Number: NL864519886B01
Chamber of Commerce Number: 88152081
VAT Number: NL864519886B01
Chamber of Commerce Number: 88152081
Terms and conditions
Re:Shark Processing Agreement
Generally
1.
This Appendix is a Part of the agreement between Re:Shark (hereinafter referred to as the “Supplier” or “Processor”) and the “Controller” are closed.
2.
This Annex contains requirements relating to the General Data Protection Regulation (AVG).
Introduction
3.
The controller is to be identified as a controller within the meaning of the General Data Protection Regulation (GDPR) (hereinafter: Controller), Supplier and/or Subcontractors are defined as (sub)processors within the meaning of the GDPR (hereinafter: the processor);
4.
As Personal Data: the personal data within the meaning of Article 4 GDPR that Responsible under an Agreement concluded between the parties Provides to Processor(s)
5.
Processor processes within the framework of this Agreement whose processor agreement a part of is for the purpose of Responsible personal data;
6.
The processor shall have access to the Personal Data of and responsible;
7.
The parties have agreed to the processing of Personal Data by the Processor to for the controller to comply with the requirements set out in this Annex by the GDPR to lay.
Subject is
8.
The controller gives an order to the Processor for the processing of Personal Data.
9.
The controller is fully responsible for determining the purpose and means. for the processing of personal data.
Services provided by the processor
10.
A description of the service(s) provided by the Processor: The Controller uses personal data of employers to communicate with employers to come in contact. The purpose of this contact is to see if there is an interest in these employers.
Providing the services and products of the Responsible
11.
A description of the type of Personal Data processed by the Processor: - All personal data that is relevant for the implementation of the scheme thus: data, email address, telephone number.
12.
Description of the categories of stakeholders: The categories of data subjects whose personal data are processed are directors HR and/or Marketing and / or Sales officers of the companies with which Responsible person wants to get in touch. It can also involve other officials. the company, such as CFO or positions in the Finance column or CTO in the IT/ICT column.
13.
A description of the (groups) employees of the Processor who need access: All Re:Shark employees who are required to have access to this service of personal data.
Reliability requirements and security
14.
A representation of the reliability requirements applicable to the processing of the Personal data, differentiated according to the sensitivity of the Personal Data: The processor gives the controller an insight into the level of reliability which are used by the processor.
15.
The Data Processor shall in any case take adequate technical and organizational security measures. Meet to : protect the Personal Data from loss and/or damage by fire, water, radiation, air pollution and/or other disasters; protect the IT facilities and equipment physically and softwarewise against access by unauthorized, damages and disruptions caused by, for example, hacks, malware infections and and viruses. These systems are kept up-to-date. restrict access to the locations where the Personal Data is processed to persons who need the Personal Data for the performance of their duties; to ensure that recovery of the Personal Data in case of loss and/or damage of the Personal data can be processed as much and as quickly as possible; in the event of destruction of the Personal Data, to make it impossible to recover the original to recover personal data; activities that employees carry out with Personal Data and other relevant events relating to the Personal Data (such as attempts to gain unauthorized access to Personal data or disturbances that may lead to corruption or loss of Personal data) to be recorded in log files; Apply encryption (according to the most common state of the art) when sending of Personal Data via the Internet, when storing Personal Data on portable equipment and on removable media, such as USB sticks and in other situations where Personal data is vulnerable to unauthorized access.
Obligations of Processor
16.
The processing of the Personal Data by the Processor will take place in accordance with the provisions as set out in this Agreement and other Annexes to this in accordance with the written instructions of the Responsible.
17.
The processor undertakes:
17.1.
all instructions of the Controller in the context of the processing of Tracking of personal data;
17.2.
process the Personal Data solely for the benefit of the Controller and within the framework of and for the implementation of the Agreement and this Annex and the not to use or use personal data for any other purpose;
17.3.
to comply with all applicable laws and regulations and codes of conduct regarding protection of Personal Data, including at least the GDPR; and,
17.4.
at the first request of the Controller, free of charge to the controller access to provide the Personal Data, or to make the Personal data available to the Controller on a durable data carrier, in the manner and in the format that the controller wishes.
18.
It is not permitted for the Processor to modify, supplement, change the Personal Data. Third-party information, third party information, and third party access. personal data or otherwise make available to third parties and/or copy, unless (i) is necessary for the implementation of the Agreement or this Annex, (ii) is explicitly otherwise specified in the Agreement or this Annex, or (iii) after the Controller has given express written consent.
19.
The processor guarantees that the security measures specified have a level of security. provide that meets the level of protection required by law, required by by AVG. The processor shall, on its own initiative and free of charge, take the security measures modify that during the duration of the Agreement or as long as the Processor has access to the Personal Data, always has an adequate level of protection and guaranteed. At the first request of the Controller, the Processor shall informing the responsible persons of the technical and organizational measures taken by the Processor at that time has implemented and handles.
20.
If the reliability requirements to the Personal Data change in such a way that new arrangements regarding the security of these Personal Data are necessary, Processor and Controller adapt the security standards and the Annex Specific Provisions on the processing of Personal Data may be amended accordingly.
21.
The processor may only engage sub-processors for the processing of Personal data, if and to the extent that the Controller has given written consent has granted. The Controller is entitled to this consent conditions and connect. The processor shall with all sub-processors to whom the processing of Personal data subcontractors conclude a written processor agreement in which all the obligations imposed on the processor in this Annex also on the subprocessor are imposed. In any case, the Controller gives permission for the subprocessors listed in the Annex.
Requests for information
22.
The Processor shall inform the Controller without delay if an authorized a public authority has a request for provision of or access to the Personal Data done, unless it has been prohibited to the Processor by the relevant public authority such Providing information to the responsible.
23.
The Processor is obliged to inform the Controller when a the data subject has directed a question or request to the Processor for access, improvement, supplementation, removal or blocking of the related to him/her of personal data.
24.
The Processor is not entitled to ask questions and requests from public authorities and/or data subjects. in respect of the Personal Data, directed to the Processor, to respond and/or to inform the data subjects in response to a question or request about the processing of his/her Personal Data, unless the Processor has previously written has obtained the consent of the Controller or if the Processor is legally required to do so and compulsory.
25.
If and to the extent that the Processor is legally obliged to answer a question or request from a to respond to a public authority and/or the data subject, the Processor will only provide the Personal Data that is necessary to comply with the relevant legal obligation.
26.
The Processor shall provide full cooperation free of charge to the Controller for the answering a question or request from a public authority or person concerned concerning personal data within the specified time limits.
27.
The Processor shall, at the first request of the Controller, immediately and no later than within five business days after the Data Controller has made the request, to the Data controller in writing provide all information and all Personal Data that the Controller requests.
28.
The Processor shall, at the first request of the Controller, immediately and no later than within five business days after the Controller has made this request, the stored Personal Data improve, supplement, remove or shield according to the instructions of the and responsible.
Processing of Personal Data within the European Economic Area and transfer of Personal data
29.
Any processing of Personal Data for the Controller will take place in the European Economic Area (EEA), unless the Controller has given prior consent to the processing outside the EEA (laten) to take place. The Controller is entitled to this consent conditions and connect.
30.
The Processor guarantees that any processing of the Personal Data that, taking into account the the provisions of the preceding paragraph, taking place outside the EEA, is demonstrably in conformity with the requirements that the GDPR imposes on a transfer of personal data to a country outside the EEA.
secrecy
31.
The Processor shall recognize the persons employed by the Processor and the performing work on behalf of or on the order of the Processor, obliging to confidentiality with regard to the Personal Data, except to the extent that any legal obligation to notify them. The Processor shall also ensure that access the Personal Data is only open to persons involved in the execution of the Agreement and access to the Personal Data are required for this and that consultation This is not possible for other persons. This obligation of the processor continues after termination of the agreement.
Monitoring of compliance and evaluation
32.
The Controller has the right to periodically check whether the Processor is obligations arising from this Annex and applicable laws and regulations in the field processing and protection of personal data, complies. The processor will free of charge all cooperation and will at the first request of the Responsible or provide an independent third party designated by the Controller with access to its offices, work spaces, processes and systems. The Processor shall provide all cooperation to carrying out the audit and the Controller or the independent person designated by it provide free assistance to third parties, answer questions and, at the first request of the Information requested by the controller or independent third parties designated by it to provide.
33.
The Controller shall inform the Processor in a timely manner of the wish to carry out control and the Controller and the Processor shall jointly determine a date on which such inspection will take place.
34.
The cost of such a control (for example, the cost of engaging a independent third parties) are on behalf of the Controller, unless from the results of the verification shows that the Processor fulfils its obligations arising from this Annex and/or applicable laws and regulations in the field of processing and protection of personal data is violated. The costs of an audit shall be borne entirely by the Processor.
35.
The processor shall, following a control carried out pursuant to this Annex, deficiencies within a reasonable framework to be determined for this purpose by the Controller fix the deadline at their own expense. If the processor does not within this period defects have been corrected, the Controller has the right to Part of the agreement shall be terminated with immediate effect by written Notification to the Processor, without any compensation owed to the processor.
Responsibility
36.
The Controller, its managers and employees are users of the data provided by the Processor. processes (and software applications) and are therefore mainly responsible for the use of this. Possible liability arising from use as referred to in this The agreement will be with the principal responsible (“the Responsible”). The processor is responsible for the security of the data within the system, but not the use of of this.
36.1
If the Administrator is liable for any damage, the liability of the Administrator is limited to a maximum of twice the invoice value of the order, at least to that part of the order to which the liability relates.
Violations of security - reporting obligation
37.
The Processor shall report all (investigations into) violations of the security of the Personal Data (including any data leakage and any possible data breach) immediately and in any case within 24 hours after discovery of this through the Contact Person of the Responsible. It also serves (a investigation of a breach of the security of personal data without delay and in any the case within 24 hours to be to the known contact person as indicated in the The agreement. The Processor shall inform the Controller upon notification as referred to in this provide the following information: (i) the nature of the infringement; (ii) the Personal data (possibly) affected by the breach; (iii) the consequences and expected consequences of the infringement; (iv) the measures that the Processor has taken and will take to limit the consequences of the infringement (as far as possible); and (v) the measures The processor proposes to limit the consequences of the infringement (as far as possible).
38.
If and to the extent that the Processor has not made the decision within the aforementioned period has about the information mentioned in that paragraph, the Processor shall immediately provide this information. collect and immediately provide to the Responsible.
39.
The Processor shall keep the designated contact person of the Controller informed of the developments surrounding the breach of the security of personal data and involves Responsible for the measures taken by the Processor to remedy the consequences of the infringement Reduce and prevent repetition.
40.
The Processor will take all necessary measures to prevent (possible) damage resulting from a limit the breach of the security of personal data. If the necessary measures have a direct impact on the Personal Data or the execution of the Agreement or these Appendix, the Processor will take those measures only after the Controller has given permission. The Processor shall also take all reasonable measures where the Responsible for request. The costs of the measures to be taken shall be borne by The Processor
41.
The controller shall determine whether and in what manner the breach of security to the Authority Personal data and/or to the person concerned is. The parties give each other full cooperation in the notification to the Personal Data Authority and to the persons concerned.
42.
If the Processor fails to violate the security of personal data or does not promptly to the Controller, so that the controller does not or does not respond to its legal (notification) obligations may be fulfilled, then the Processor shall pay the penalty The Responsible shall be obliged to reimburse the Responsible in full.
Creation, duration and interim termination
43.
This Appendix shall remain in force for the duration of the Agreement and shall automatically terminate on termination of the Agreement for any reason, provided that a notice period of at least 30 days from (monthly) billing date. This is only different if the processor termination of the Agreement still has disposal of Personal Data and/or if Processor on other grounds than the Agreement for the benefit of the Controller Personal data is processed.
Return, destruction of Personal Data and transfer
44.
The Processor undertakes to, after termination of the Agreement, the Personal Data and all copies thereof (on paper, electronically or otherwise) and all processing of the Personal data to the responsible (of aan een door Verantwoordelijke aan te wijzen derde) to be provided, in a manner indicated by the Responsible and by the Data controllers to be specified or, if the Controller so chooses, all To destroy personal data and to declare to the Controller that he has done so.
45.
The Processor undertakes to do so after termination of this Agreement and after the Processor its obligations under the preceding article, the use of the Personal Data and the access to cease to do so and to stop, unless the Controller requests otherwise in writing.
46.
Even after termination of the Agreement, the obligations for the Processor that result from this Annex without prejudice to the effect as long as the Processor Personal Data is at his disposal.
47.
The Processor will, at the first request of the Controller, provide all cooperation to an orderly transfer of the work relating to the processing of the Personal data to the Controller or to a third party designated by the controller in such a way that the continuity of the processing of Personal Data is maximized guaranteed, at least not hindered by actions or omissions of the Processor. De costs related to these efforts of the Processor are deemed to have been included in the agreed prices and fees of the Processor arising from the Agreement, unless explicitly agreed otherwise by the Parties in writing.
Automatic Direct Debit (through Mollie)
48.
For recurring payments, the Client may choose to enable the automatic direct debit service provided by Mollie B.V. ("Mollie"), a third-party payment processor. By choosing this option, the Client agrees to the terms and conditions of Mollie, which can be found on the Mollie website.
49.
By enabling the automatic direct debit, the Client authorizes the Company and Mollie to automatically charge the Client's bank account for the amounts due under the Agreement. The Client will be notified in advance about the upcoming charge.
50.
The Client is responsible for ensuring that the bank account details provided to the Company and Mollie are accurate and up to date. The Client must notify the Company of any changes to these details as soon as possible.
51.
In the event that an automatic direct debit payment fails due to insufficient funds, the Company will notify the Client. The Client is obliged to immediately pay the outstanding amount. If the Client fails to do this, the Company may suspend the provision of the Services until the Client has fulfilled their payment obligations.
52.
The Client has the right to cancel the automatic direct debit at any time. However, this does not exempt the Client from any obligation to pay the amounts due under the Agreement.
Final provisions
53.
All provisions of this Annex are intended by their nature to continue to apply after the end of the Agreement. to remain in force between the parties. Such obligations include, inter alia, provisions on the obligation to report, confidentiality, liability and return, destruction and Transfer of Personal Data.
54.
The Controller reserves the right to unilaterally amend this Annex in the event amendment of applicable laws and regulations.
Google and Microsoft OAuth and Connected Email Services
55.
Re:Shark uses OAuth to authenticate users and, when a user chooses to connect a mailbox, to obtain the permissions required for connected email functionality. OAuth access is granted by the user through Google or Microsoft and remains subject to the permissions granted by that user.
56.
For Gmail, Re:Shark uses the gmail.send permission to send prospect emails through the user's connected Gmail account and the gmail.readonly permission to identify and process replies and conversation data relating to prospect communications initiated or managed through Re:Shark.
57.
For Microsoft Outlook and Microsoft 365, Re:Shark uses delegated Mail.Send permission to send prospect emails through the user's connected account and delegated Mail.Read permission to identify and process replies and conversation data relating to prospect communications initiated or managed through Re:Shark.
58.
The read permissions granted by Google and Microsoft are technically broader than Re:Shark's intended product use. Re:Shark limits its actual use of mailbox read access to messages, replies, identifiers, headers, thread information and message content that relate to prospect communications initiated or managed through Re:Shark. Re:Shark does not intentionally browse, monitor, analyse, profile, retrieve or use unrelated personal, internal or general mailbox communications that users send or receive outside Re:Shark.
59.
Re:Shark is not designed or intended for bulk email distribution through connected Gmail or Microsoft accounts. Outbound activity through these connected accounts is limited to a maximum of ten (10) prospect emails per user per day. Messages are initiated and controlled by the user and are sent as individual business communications through the user's connected mailbox. Re:Shark does not use connected accounts to circumvent provider sending limits, spam controls, abuse-prevention mechanisms, filters or other platform restrictions.
60.
Google and Microsoft user data obtained through connected accounts is used only to provide or improve the user-facing Re:Shark functionality selected by the user. Re:Shark does not sell or rent connected-mailbox data and does not use it for advertising, retargeting, unrelated profiling, surveillance, creditworthiness or lending decisions. Google user data obtained through Google Workspace APIs is not transferred, sold or used to create, train or improve a general-purpose or shared machine-learning or artificial-intelligence model.
61.
Re:Shark personnel do not read connected-mailbox content except where the user explicitly requests support or affirmatively authorizes access to specific data, access is strictly necessary to investigate security, abuse or a technical incident, or access is required by applicable law. Any such access is limited to what is reasonably necessary for that purpose.
62.
OAuth tokens and connected-account data are protected using appropriate technical and organizational security measures. A user may disconnect a connected mailbox or revoke Re:Shark's authorization through the relevant Google or Microsoft account settings. Once authorization is revoked or the mailbox is disconnected, Re:Shark will cease future API access to that account. OAuth tokens that are no longer required will be revoked where applicable and deleted. Requests concerning retained connected-account data may be submitted to support@reshark.io.
63.
Re:Shark's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including applicable Limited Use requirements.