Acordo de Tratamento de Dados (DPA)
Aplicável a todos os Clientes da bood.be®
Data Processing Agreement (DPA)
Scope of application
This Data Processing Agreement ("Agreement" or "DPA") applies to all clients ("Client") who contract, with bood.be®, software development services, website hosting, email hosting, database services, multimedia content production and/or video/audio editing (the "Services").
This Agreement forms an integral part of the service provision contract, accepted commercial proposal, or terms of service entered into between bood.be® and the Client (the "Main Agreement"), applying automatically whenever, in the course of providing the Services, bood.be® processes personal data on behalf of the Client, pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR).
By contracting the Services, the Client accepts the terms of this Agreement, thereby dispensing with the need to sign a separate document, without prejudice to the Client's ability to request formalization of a signed copy, if desired.
Parties
Processor: bood.be®, Lda., with registered office at Quinta da Barca - Rua N. Sra. de Guadalupe, Nº 113, Ed. 69 / 42 - 4740-473 Esposende - PORTUGAL, Tax ID PT 509 149 197, hereinafter "bood.be®".
Controller: the Client identified in the Main Agreement entered into with bood.be®, hereinafter "Client".
Hereinafter jointly referred to as the "Parties".
1. Definitions
For the purposes of this Agreement, the terms "personal data", "processing", "controller", "processor", "personal data breach" and "data subject" have the meaning assigned to them in Article 4 of the GDPR.
2. Subject matter and scope
This Agreement governs the processing of personal data carried out by bood.be®, as processor, on behalf of each Client, as controller, in the course of performing the contracted Services. General processing instructions are set out in Annex I, which may be supplemented or specified in the Main Agreement or in a service sheet/proposal specific to each Client, depending on the Services actually contracted.
3. Duration
This Agreement remains in effect for the entire term of the Main Agreement entered into between bood.be® and each Client, automatically terminating upon its expiry, without prejudice to the obligations which, by their nature, must survive termination (namely those set out in clause 10).
4. Nature and purpose of processing
bood.be® processes personal data on behalf of the Client exclusively for the purpose of providing the contracted Services (website hosting, email, databases, multimedia content hosting and/or software development), as detailed in Annex I, and may not use it for any other purpose.
5. Types of personal data and categories of data subjects
The types of personal data and categories of data subjects covered by this Agreement are set out in Annex I, which may include identification data, contact data, authentication data, content hosted by the Client, and any other data the Client chooses to process through the contracted Services. The specific nature of the data varies depending on the Services actually contracted by each Client.
6. Obligations of bood.be® as processor
bood.be® undertakes to:
a) Process personal data only on documented instructions from the Client, including with regard to international transfers, unless required to do so by European Union or Member State law to which it is subject, in which case it shall inform the Client of that legal requirement in advance, unless that law prohibits such information on important grounds of public interest;
b) Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
c) Adopt appropriate technical and organizational measures as required by Article 32 of the GDPR, as described in Annex II;
d) Comply with the conditions set out in this Agreement regarding the engagement of other processors (clause 7);
e) Assist the Client, through appropriate technical and organizational measures, insofar as possible, to fulfil its obligation to respond to requests for exercising data subjects' rights;
f) Assist the Client in ensuring compliance with the obligations set out in Articles 32 to 36 of the GDPR (security, breach notification, impact assessments and prior consultation), taking into account the nature of the processing and the information available to bood.be®;
g) Depending on the Client's choice, delete or return all personal data after the end of the provision of Services, deleting existing copies, unless retention is required by European Union or Member State law;
h) Make available to the Client all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by the Client or another auditor mandated by it, subject to reasonable prior notice and at times and conditions to be agreed between the Parties.
7. Sub-processing
Each Client generally authorizes bood.be® to engage other processors (sub-processors) for the processing of personal data in connection with the provision of the Services, namely data center infrastructure providers, protection against cyberattacks, content distribution (CDN) providers, and DNS management services.
The list of sub-processors authorized as of the date of this Agreement is set out in Annex III, available to any Client upon request and/or published on bood.be®'s website. bood.be® will inform Clients of any intended changes to that list (addition or replacement of sub-processors), with reasonable advance notice, giving the Client the opportunity to object to such changes on reasonable grounds related to data protection.
bood.be® imposes on all sub-processors data protection obligations equivalent to those set out in this Agreement, remaining fully liable to the Client for the fulfilment of the obligations of those sub-processors.
8. International transfers
Whenever the provision of the Services involves the transfer of personal data outside the European Economic Area, bood.be® ensures that such transfer is covered by an adequacy decision of the European Commission or subject to appropriate safeguards, namely Standard Contractual Clauses approved by the European Commission, informing the Client of such transfers upon request.
9. Personal data breaches
bood.be® will notify the affected Client without undue delay, and no later than 48 (forty-eight) hours after becoming aware of it, of any personal data breach affecting the data processed under this Agreement, providing sufficient information to allow the Client to comply with its notification obligations to the supervisory authority and, where applicable, to data subjects, pursuant to Articles 33 and 34 of the GDPR.
10. Effects of termination
Upon termination of the Main Agreement, and unless otherwise instructed by the Client, bood.be® will delete all personal data processed on its behalf within a reasonable period, except where there is a legal obligation of retention, in which case the data will be retained only for the period and purpose required by law, and then deleted.
11. Liability
Each Party is liable for damages caused by the processing of personal data resulting from non-compliance with the obligations specifically addressed to it under the GDPR, or resulting from non-compliance with lawful instructions from the Client, without prejudice to the joint and several liability regime set out in Article 82 of the GDPR.
12. Final provisions
This Agreement is governed by Portuguese law and applies uniformly to all bood.be® Clients, without prejudice to specific conditions that may be agreed in writing in an individual contract. In the event of a conflict between this Agreement and the Main Agreement regarding personal data protection matters, the provisions of this Agreement shall prevail. For the resolution of any disputes arising from this Agreement, the Parties elect the courts of the jurisdiction where bood.be®'s registered office is located, expressly waiving any other jurisdiction.
Annex I — General Description of Processing
| Subject matter | Provision of website hosting, email, database, multimedia content and/or software development services, depending on the Services contracted by each Client |
| Duration | Coinciding with the term of the Main Agreement of each Client |
| Nature of processing | Hosting, storage, backup, and technical availability of data |
| Purpose | Performance of the Services contracted by the Client |
| Categories of data subjects | Employees, clients, and end users of each Client, as applicable |
| Categories of personal data | Identification and contact data, access credentials, content hosted by the Client (including any data contained in databases or mailboxes managed by the Client) |
Annex II — Technical and Organizational Security Measures
- Access control through individual credentials and minimum necessary privileges;
- Encryption of credentials and sensitive communications;
- Network segmentation and firewalls;
- Regular backups of hosted data;
- Monitoring and logging of system access;
- Regularly applied security updates and patches;
- Internal security incident response procedures;
Annex III — Authorized Sub-processors
| Sub-processor | Service provided | Location |
|---|---|---|
| OVH | Physical server hosting | Gravelines (GRA) - France / EU |
| CLOUDFLARE | Protection against cyberattacks: DDoS attack mitigation, filtering of malicious traffic through a Web Application Firewall (WAF), and concealment of the origin server's IP address through a CDN/reverse proxy service (Cloudflare), with DNS management and domain registration centralized on the same platform. | United States of America (global distribution network — CDN); international data transfer under Standard Contractual Clauses (SCC) |
| VIMEO | Video content hosting with "Private (embed only)" privacy setting, preventing direct access to or public search of the videos, which are made available exclusively via embedding on the client's pages. | United States of America; international data transfer under Standard Contractual Clauses (SCC) |
| SMTP2GO | Transactional email delivery service (SMTP relay) for delivering automated communications from the website and applications (e.g., quote requests, notifications, contact forms). Service provided by Sand Dune Mail Ltd. | European Union (Amsterdam, Netherlands data center) — data sent, stored, and processed within the EU |
Se necessita mais informação relativa ao Acordo de Tratamento de Dados, por favor contacte-nos pelo email support@bood.be.
bood.be®