Data Processing Agreement
1. Parties, roles and conclusion
This Data Processing Agreement (the "Agreement") is concluded between the customer who uses Trade Show Companion (the "Customer", acting as controller) and Sandstone Systems F.Z.E, a Free Zone Establishment registered in the Ajman Free Zone, United Arab Emirates, under Licence and Registration No. 55415 (the "Provider", acting as processor).
The Agreement forms part of the Terms of Service and of any individual order for Trade Show Companion (together the "Service Agreement"). It is concluded when the Customer accepts the Terms of Service or places an order, without a separate signature. On request to [email protected] the Provider provides a countersigned copy of this Agreement, including the Standard Contractual Clauses in the Annex, for the Customer's records.
The Customer determines the purposes and means of processing the personal data it enters into Trade Show Companion. The Provider processes that data only on behalf of the Customer and on its documented instructions.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Customer data" means all personal data that the Customer or its users enter into, upload to or generate within Trade Show Companion. "Service" means Trade Show Companion as provided under the Service Agreement. "Standard Contractual Clauses" means the clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
3. Subject matter and duration
The subject matter is the operation of Trade Show Companion as a hosted service: capturing, storing, structuring and managing leads, contacts, companies, customers, notes, voice notes, documents and related records for the Customer's sales work at trade shows and afterwards.
Processing lasts for the term of the Service Agreement, including the free trial and the read-only period after it, and ends with the deletion or return of Customer data under section 13.
4. Nature and purpose of processing
The Provider hosts the Customer's workspace, stores the data the Customer's users enter or upload, runs the AI features the Customer's users trigger (transcription of voice notes, structuring of notes and documents, company research, translation), delivers notifications and emails, creates encrypted backups, and exports data on the Customer's request. Processing consists of collection, storage, structuring, retrieval, consultation, transmission to the Customer's users, erasure and destruction. The purpose is exclusively the provision of the Service to the Customer.
5. Categories of data and data subjects
Data subjects. Trade show visitors and other business contacts of the Customer, employees and representatives of the Customer's prospects and customers, the Customer's own users, and persons mentioned in notes or documents entered by the Customer's users.
Categories of data. Names, job titles, employers, business contact details, badge data, images of business cards, voice notes and their transcripts, notes about conversations, needs, quotes, orders and other records the Customer's users create, plus user account data (name, email address, login and activity records) of the Customer's users.
The Service is not designed for special categories of personal data within the meaning of Article 9 GDPR or for data relating to criminal convictions. The Customer undertakes not to enter such data unless it has a lawful basis for doing so and has informed the Provider in writing.
6. Instructions of the controller
The Provider processes Customer data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which the Provider is subject; in that case the Provider informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Service Agreement, this Agreement and the Customer's use of the Service through its configuration and its users constitute the Customer's complete instructions at the time of conclusion. Further instructions must be given in writing, including by email, and are followed by the Provider within a reasonable time. If following an instruction requires changes beyond the standard functionality of the Service, the parties agree on scope and cost first.
The Provider informs the Customer without delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law. The Provider may suspend the execution of such an instruction until the Customer confirms or changes it.
7. Obligations of the customer
The Customer is responsible for the lawfulness of the processing of Customer data, in particular for having a lawful basis for collecting the data of trade show visitors and business contacts, for informing data subjects in accordance with Articles 13 and 14 GDPR, and for the accuracy of the data it enters. The Customer manages the accounts and roles of its users, keeps its own access credentials confidential and informs the Provider without delay of any suspected unauthorised access to its workspace.
8. Confidentiality
The Provider ensures that every person authorised to process Customer data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and processes Customer data only as instructed. Access to production systems is limited to persons who need it to provide, maintain and secure the Service. The obligation of confidentiality continues after the end of this Agreement.
9. Security measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Provider implements and maintains the following technical and organisational measures in accordance with Article 32 GDPR:
- Location. Production data and backups are stored on servers located in the European Union.
- Encryption. All connections between users and the Service are encrypted in transit using TLS. Backups are encrypted.
- Separation. Customer data is logically separated from the data of other customers. No customer can access another customer's data.
- Access control. Users authenticate by login link and one-time code, optionally with two-factor authentication. Access within the workspace follows the roles the Customer assigns. Administrative access to production systems is restricted to authorised personnel and individually authenticated.
- Integrity and traceability. Changes to records within the workspace are logged with user and time. Public forms are protected against automated abuse.
- Availability. Encrypted backups are created regularly and kept apart from production. A public status page monitors the Service every minute and keeps 90 days of history.
- AI processing. Requests to AI features send only the content needed for the requested output and run under contracts that exclude the use of Customer data for training models.
- Data minimisation and deletion. Trial workspaces and terminated workspaces are deleted on the schedule in section 13. Deleted records are purged from backups within the regular backup rotation.
The Provider may update these measures as technology develops, provided the overall level of protection is not reduced. The current description of the measures is made available to the Customer on request in writing.
10. Sub-processors
The Customer gives the Provider general authorisation to engage the sub-processors listed at tradeshowcompanion.com/subprocessors for the purposes stated there. The Provider imposes on each sub-processor, by way of a contract, data protection obligations that provide at least the same level of protection as this Agreement, in particular sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, the Provider remains fully liable to the Customer for the performance of that sub-processor's obligations.
The Provider informs the Customer in writing, including by email to the workspace administrators, of any intended addition or replacement of a sub-processor at least 30 days before the new sub-processor starts processing Customer data. The Customer may object on reasonable, documented data protection grounds within that period. If the parties cannot resolve the objection in good faith within a further 30 days, the Customer may terminate the Service Agreement with respect to the affected Service with effect from the date the new sub-processor would start processing, without penalty and with a pro rata refund of prepaid fees.
11. Assistance with data subject rights
Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising the rights of data subjects under Chapter III GDPR. The Service allows the Customer to search, correct, export and delete records of individual data subjects itself. Where a data subject contacts the Provider directly, the Provider forwards the request to the Customer without undue delay and does not respond on the Customer's behalf unless instructed to do so.
12. Personal data breaches and assistance
The Provider notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer data. The notification is sent by email to the workspace administrators and describes, as far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Information that is not yet available is provided in phases without undue delay.
The Provider assists the Customer, taking into account the nature of the processing and the information available to the Provider, in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR: security of processing, notification of breaches to supervisory authorities and data subjects, data protection impact assessments and prior consultation, insofar as these concern the Service.
13. Deletion and return of data
The Customer may export all Customer data in CSV and Excel format at any time during the term of the Service Agreement. After the end of the Service Agreement the Customer's workspace remains available in read-only mode for export for 14 days, unless the parties agree otherwise in writing. Trial workspaces follow the deletion schedule in the Terms of Service.
After that period the Provider deletes the workspace including all Customer data and confirms the deletion in writing on request. Copies in backups are deleted within the regular backup rotation. The Provider may retain Customer data beyond that only to the extent that Union or Member State law requires storage, and only for as long as that law requires; such data remains subject to this Agreement.
14. Audits and information
The Provider makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this Agreement, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
The parties agree that written information and documentation are the primary means of demonstrating compliance. An on-site or remote inspection takes place at most once per calendar year, with at least 30 days' written notice, during normal business hours, without disrupting the Provider's operations, and limited to what is necessary to verify compliance with this Agreement. An additional inspection may take place where a personal data breach has occurred or a supervisory authority requires it. The auditor must not be a competitor of the Provider and is bound to confidentiality. Each party bears its own costs of an audit.
15. International transfers
Production data and backups are stored in the European Union. Some sub-processors listed under section 10 are established in the United States. Transfers to them take place on the basis of the Standard Contractual Clauses, an adequacy decision of the European Commission, or another transfer mechanism recognised under Chapter V GDPR, and are limited to the content needed for the respective purpose.
The Provider itself is established in the United Arab Emirates. Access by the Provider to Customer data for the operation, maintenance and support of the Service constitutes a transfer to a third country. For this transfer the parties conclude the Standard Contractual Clauses, Module Two (transfer controller to processor), as set out in the Annex. The Standard Contractual Clauses form an integral part of this Agreement. Where the Customer is not established in the European Economic Area and the GDPR does not apply to the Customer's processing, the Annex does not apply and the remaining provisions of this Agreement remain in force.
16. Liability
Each party is liable to the other for damage caused by its breach of this Agreement in accordance with the limitations of liability in the Service Agreement. Towards data subjects, each party is liable as set out in Article 82 GDPR. Nothing in this Agreement limits or excludes liability that cannot be limited or excluded under applicable law, including the liability of the parties under the Standard Contractual Clauses.
17. Term, changes and precedence
This Agreement enters into force when the Service Agreement is concluded and remains in force for as long as the Provider processes Customer data on behalf of the Customer, including the periods under section 13.
The Provider may update this Agreement to reflect changes in law, in the Service or in the measures under section 9, provided the level of protection for the Customer is not reduced. The Provider informs the Customer of material changes at least 30 days before they take effect by email to the workspace administrators. The version number and effective date are shown at the top of this page; previous versions are available on request.
In case of conflict between this Agreement and the Service Agreement, this Agreement prevails for matters of data protection. In case of conflict between this Agreement and the Standard Contractual Clauses, the Standard Contractual Clauses prevail. This Agreement is governed by the law of the Service Agreement; the Standard Contractual Clauses are governed by the law stated in the Annex. Should any provision be invalid, the remaining provisions remain unaffected and the parties will replace the invalid provision with one that comes closest to its purpose.
Annex: Standard Contractual Clauses
The parties conclude the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, Module Two (transfer controller to processor), with the following selections. The clauses are incorporated by reference in the version published in the Official Journal of the European Union and are provided by the Provider in full on request.
- Clause 7 (docking clause): not included.
- Clause 9 (use of sub-processors): Option 2, general written authorisation, with a notice period of 30 days as set out in section 10 of this Agreement.
- Clause 11 (redress): the optional language on independent dispute resolution is not included.
- Clause 13 (supervision): the competent supervisory authority is the authority of the Member State in which the Customer is established.
- Clause 17 (governing law): Option 1, the laws of the Federal Republic of Germany.
- Clause 18 (choice of forum): the courts of the Federal Republic of Germany.
Annex I.A (list of parties). Data exporter: the Customer, as identified in the Service Agreement, acting as controller. Data importer: Sandstone Systems F.Z.E, Ajman Free Zone, United Arab Emirates, [email protected], acting as processor.
Annex I.B (description of transfer). Categories of data subjects and personal data: section 5 of this Agreement. Sensitive data: none intended, see section 5. Frequency: continuous, for the duration of the Service Agreement. Nature and purpose: sections 3 and 4. Retention: section 13. Transfers to sub-processors: section 10 and the list at tradeshowcompanion.com/subprocessors.
Annex I.C (competent supervisory authority). As determined under Clause 13.
Annex II (technical and organisational measures). Section 9 of this Agreement.
Annex III (list of sub-processors). The list at tradeshowcompanion.com/subprocessors in its version at the time of the transfer.