The Data Protection Agreement (hereinafter the "Agreement") aims to govern the use of Personal Data of clients (hereinafter the "Client") of Skillee SAS (hereinafter the "Processor" or "Skillee") when they use the skillee.ai/ service (hereinafter the "Service").
The terms "adequacy decision", "technical and organisational measures", "data subjects", "data protection by design", "data protection by default", "register", "joint controller(s)", "controller", "processor", "processing", "personal data breach" used in the Agreement have the meanings described in Articles 4 et seq. of the GDPR. Other terms are defined below:
The Agreement is an indivisible annex to the Contract signed between the Client and the Processor for the use of the Service.
In case of contradiction between the Contract concluded for the use of the Service and the Agreement, the obligations provided in the Agreement shall prevail over the Contract with regard to the GDPR as a whole.
The Agreement is applicable for the entire duration of the Contract concluded within the framework of the use of the Service and may continue beyond as long as all obligations provided herein remain applicable.
The Client acts, within the framework of the Agreement, as controller and Skillee acts as processor within the meaning of Article 28 of the GDPR.
Under no circumstances may the Parties be considered as joint controllers within the framework of the Service. However, the Parties agree that in case of error or modification of their qualification, the Parties shall meet as soon as possible to amend the Agreement and take all measures relating to such a situation to comply with the requirements of the Applicable Data Protection Legislation.
The Agreement exclusively governs the processing of the Client's Personal Data carried out within the framework of the Service as a Processor within the meaning of Article 28 of the GDPR, excluding processing carried out as a controller by Skillee which is governed by the Contract.
The Processor undertakes to use the Client's Personal Data within the framework of the use of the Service only on documented instructions annexed to the Agreement. The Processor shall immediately inform the Client if it considers that an instruction provided by the Client is unlawful with regard to the Applicable Data Protection Legislation. The Processor's liability shall not be engaged in the event that, despite the Processor's notification regarding the illegality of the instruction, the Client maintains and applies this instruction through the Service.
The Processor undertakes to comply with the provisions of the GDPR and, in particular, to maintain a register of processing activities specific to the Service and to develop its Service in compliance with the rules of "Data Protection by Design" and "Data Protection by Default".
The Processor undertakes never to transfer the Client's Personal Data for reasons other than the provision of the Service and undertakes never to use the Client's Personal Data for its own interest as a controller.
The Processor declares that all internal or external personnel required to process the Client's Personal Data is bound by one or more legally binding instruments and regularly undergoes training and awareness.
The Processor undertakes to guarantee the security of the Client's Personal Data and to implement all necessary technical and organisational measures for its Service, the details of which are presented in the annex to the Agreement.
However, the Processor is never responsible for the Client's failures regarding the Applicable Data Protection Legislation when using the Service as a controller.
DPIAs must be carried out by the Client, in accordance with the provisions of the GDPR. Nevertheless, the Processor undertakes to communicate, upon written request from the Client, all necessary and required information for the Client to carry out a DPIA.
The Processor is, however, not required to carry out DPIAs in place of and on behalf of the Client. Any additional request beyond the communication of information may be refused.
Rights Requests sent by End Users are transferred to the Client as soon as possible. The Processor is not required to maintain an inventory of Rights Requests on behalf of the Client and is not responsible for the Client's failures in managing Rights Requests.
The Processor shall execute, upon written request from the Client, the technical actions to be undertaken so that the Client can fulfil its obligation to respond to data subject requests.
The Client accepts and understands that the Processor is not required to manage Rights Requests from individuals made within the framework of the Service in place of and on behalf of the Client. Any additional request aimed at ensuring such management will be refused.
Rights Requests sent to the Processor as a controller are processed exclusively by the Processor and are not transferred to the Client.
The Processor undertakes to communicate all necessary and required information on technical and organisational security measures to be implemented to guarantee the security of the Client's Personal Data within the framework of the provision of the Service.
The Processor undertakes to notify the Client, as soon as possible and no later than 48 working hours after becoming aware of it, of any personal data breach related to the Service likely to concern the Client's Personal Data as well as all necessary and required information in its possession to reduce the effects of the personal data breach. The Client accepts and acknowledges that the 72-hour period applicable to it only starts from the knowledge of the personal data breach and that, as such, the 48 working hours period complies with the GDPR.
The Processor is not authorised to handle notifications of personal data breaches to the Supervisory Authority and to inform End Users on behalf of the Client. Any request to this effect from the Client will be refused.
The Client grants the Processor general authorisation to recruit Sub-processors provided that the Client is informed of any change regarding these Sub-processors as soon as possible to allow the Client to raise objections. The Client accepts and acknowledges that a specific authorisation, for a SaaS tool, is not applicable and could lead to a blocking of the Service.
Failing objections raised by the Client within eight (8) days of notification, the new Sub-processor is definitively recruited without the Client being able to object, claim damages or request termination of the Contract. If the objection made within the time limit is considered admissible by the Processor, the latter may propose to the Client one of the following solutions: i) withdrawal of the Sub-processor, ii) implementation of additional measures to guarantee the security of the Client's Personal Data, iii) cessation of the Service without the Client being able to claim damages.
To be considered admissible by the Processor, objections must be objective and serious and duly demonstrated. The Parties accept that the following situations shall, by default, be considered admissible: i) the proposed Sub-processor is a direct competitor of the Client, ii) the Sub-processor is in a dispute with the Client, iii) the Sub-processor has been sanctioned by a Supervisory Authority in the 12 months preceding its recruitment and iv) the Sub-processor does not comply, if applicable, with the applicable rules regarding transfers outside the European Union.
The Processor undertakes to recruit only Sub-processors that, after verification, present the necessary and sufficient guarantees to ensure the security and confidentiality of the Client's Personal Data. The relationship between the Processor and the Sub-processor must be governed by an agreement presenting obligations similar to this Agreement.
The Processor remains liable, within the limits of liability provided in the Contract, for GDPR breaches that its Sub-processors may commit within the framework of the Service.
The Processor undertakes to make every effort to host the Client's Personal Data exclusively within a Member State of the European Union. The Client grants the Processor authorisation to choose the Member State of the European Union of its choice. In case of hosting of Personal Data in a country located outside the European Union, the Processor undertakes to obtain the Client's prior authorisation and to implement all required mechanisms to govern this transfer, such as concluding Standard Contractual Clauses and, where applicable, implementing additional technical measures to strengthen the security of the Client's Personal Data.
The Client grants the Processor a general authorisation for transfers outside the European Union if, cumulatively, i) the transfers are made exclusively to Sub-processors compliant with the GDPR and ii) the transfers are made exclusively to a country benefiting from an adequacy decision or are governed by appropriate safeguards such as, in particular, Standard Contractual Clauses. If these conditions are not met, transfers outside the European Union are only authorised with the Client's prior agreement. Additional technical security measures to strengthen the security of the Client's Personal Data must be mandatorily implemented in the event that Personal Data is transferred to a non-democratic country.
The Processor undertakes to retain the Client's Personal Data only for the duration of the use of the Service, in accordance with the instructions detailed in the annex, and to delete them at the end of the Contract. The Processor attests, upon written request, to the deletion of Personal Data and all existing copies.
The Client is informed that it must retrieve its Personal Data before the end of the Agreement. Failing this, the Client can no longer retrieve its Personal Data, as the deletion of personal data is irreversible and final. The Processor cannot be held responsible for any loss of Personal Data after their deletion, the Client assuming full responsibility. The Client accepts that the total, irreversible and final anonymisation of the Client's Personal Data may be used as a means of deletion and that the Processor retains the anonymised data for the improvement of the Service, as accepted by the Supervisory Authorities.
The Processor informs the Client that the restitution of Personal Data provided for in the GDPR does not constitute a Reversibility of data to a new processor and that any request to this effect will always be refused by the Processor.
The Client has the right to carry out an audit in the form of a written questionnaire once a year to verify compliance with this Agreement. The questionnaire has the force of a sworn statement that binds the Processor. The questionnaire may be communicated in any form to the Processor who undertakes to respond to it as soon as possible upon receipt.
The Client also has the right to carry out, once a year and at its expense, an on-site audit, where applicable at the Processor's premises in case of a data breach due to a proven and demonstrated failure of the Processor that has caused duly justified damage to the Client. An audit at the Processor's premises may be conducted either by the Client or by an independent third party designated by the Client and must be notified in writing to the Processor at least thirty (30) days before the audit. The Processor has the right to refuse the choice of the independent third party if the latter is i) a direct or indirect competitor of the Processor, ii) in a situation of conflict of interest with the Processor (e.g.: adviser of a competitor of the Processor) or ii) in pre-litigation or litigation with the Processor. In this case, the Client undertakes to choose a new independent third party to carry out the audit. The Processor may refuse access to certain areas for confidentiality or security reasons. In this case, the Processor carries out the audit in these areas and communicates the results to the Client.
In case of discrepancies found during the audit, the Processor undertakes to implement, without delay and at its expense, the necessary measures to comply with this Agreement. The discrepancies can only concern the Applicable Data Protection Legislation regarding the Client's Personal Data and cannot concern internal procedures or measures implemented by the Client on a specific basis. The discrepancies must be duly demonstrated, justified and documented.
In case of dispute by the Processor of the identified discrepancies, the Processor may, at its choice and upon written and prior acceptance of the Client, propose to i) meet to find an amicable solution and a compromise, ii) refer the matter to the Supervisory Authority to obtain an arbitration on the dispute, and iii) appoint an independent expert to arbitrate the dispute.
The Processor undertakes to cooperate with the CNIL, the competent Supervisory Authority, in case of an inspection concerning the processing carried out within the framework of the Service and undertakes to notify the Client as soon as possible in case of requests concerning its Personal Data made by the Supervisory Authority or by an administrative, judicial or police authority.
The Client and the Processor each designate a contact person responsible for this Agreement who will be the recipient of the various notifications and communications to be made within the framework of the Agreement.
The Processor informs the Client that it has appointed the company Dipeeo SAS as Data Protection Officer who can be contacted at the following details:
Email address: rgpd@skillee.ai
Postal address: Société Dipeeo SAS, 95 avenue du Président Wilson, 93100 Montreuil, France
Phone number: 01 59 06 81 85
The Processor reserves the right to modify this Agreement in case of changes to the applicable rules on the protection of Personal Data or in case of modification of the Service that would have the effect of modifying any of its provisions.