How does AE Van de Vliet BV handle your data?
How does AE Van de Vliet BV handle your data?
AE Van de Vliet BV takes the necessary precautions to ensure the secure storage and processing of personal data belonging to customers and their employees. You can find more information on this in the data processing agreement below.
Data Processing Agreement
Under the terms of the agreement(s) for the services listed in the appendices, AE Van de Vliet BV, with its registered office at Industriedijk 14, 2300 Turnhout (hereinafter referred to as the “Processor” ), processes personal data on behalf of the customer (hereinafter referred to as the “Data Controller” ).
AE Van de Vliet BV undertakes to fulfill its obligations under the General Data Protection Regulation and, as a Data Processor, will comply with the following provisions.
Article 1. Purpose of the Agreement
Under the terms of the service agreement, the Processor processes personal data provided by the Controller.
The Processor processes this personal data solely on the basis of written instructions from the Controller. The nature and purpose of the processing are specified for each legal entity in the various appendices to the agreement.
Article 2. Rights and Obligations of the Processor
-
The Processor processes only the personal data that is strictly necessary for the performance of the service agreement and the achievement of the purpose of the processing.
-
The Processor will not make copies of the personal data unless this is necessary to create a backup or to perform the service agreement between the parties.
-
The Processor will retain the personal data for the duration of the service agreement. After the termination of this agreement, the data will be retained for a period corresponding to the applicable statutory retention period or the statute of limitations relevant to any legal claims.
Upon the expiration of this period, the Processor will, depending on the choice of the Controller, return or delete the personal data, unless its storage is required under Union law or the law of a Member State.
-
The Processor processes personal data within the European Economic Area. Data may be transferred to a third country or an international organization only if there is an adequacy decision, appropriate safeguards, binding corporate rules, or an authorized exception for a specific situation.
-
The Processor expressly undertakes to require its employees to comply with the GDPR.
-
The Processor declares that all persons authorized to process personal data have undertaken to maintain confidentiality or are bound by an appropriate legal duty of confidentiality.
-
The Processor will not disclose personal data to third parties, except to other processors under the conditions set forth in Article 2.10 or when required by or pursuant to law.
-
The Data Controller is aware that the Data Processor engages various subprocessors to fulfill its contractual obligations and provide the contracted services.
This may involve, for example, hosting a digital platform, printing pay stubs and other documents, mail delivery, and creating payment files. Engaging these subprocessors is necessary to provide efficient and effective services. The Data Controller grants its consent for this purpose.
-
The Data Controller grants the Data Processor general authorization to appoint other subprocessors or to replace existing subprocessors.
The Processor shall notify the Controller in advance of the appointment of any other subprocessors. The Controller has the right to object to such appointments for justified reasons.
-
The Processor imposes the same data protection obligations on the engaged subprocessors as those imposed on the Processor under this agreement.
In particular, this includes the obligation to provide sufficient safeguards to ensure that appropriate technical and organizational measures are in place so that the processing complies with the GDPR.
-
The Processor remains fully liable if a subprocessor fails to fulfill its obligations regarding the security of personal data.
-
The Processor shall take appropriate technical and organizational measures to ensure a level of security commensurate with the risk.
This ensures that the processing complies with the requirements of the GDPR and that the rights of the data subjects are protected. Personal data is protected against destruction, loss, alteration, unauthorized disclosure or access, and any other form of unlawful processing.
-
Taking into account the nature of the processing, the Processor shall, to the extent possible, assist the Controller in responding to requests from data subjects who wish to exercise their rights.
-
Taking into account the nature of the processing and the information at its disposal, the Processor shall assist the Controller in complying with the obligations regarding the security of the processing and the reporting of data breaches to the supervisory authority.
-
The Processor shall provide all information necessary to demonstrate compliance with the obligations under the GDPR.
The Processor shall facilitate audits and inspections conducted by the Controller or by an auditor authorized by the Controller and shall cooperate with such audits and inspections.
-
The Processor’s data protection officer is Ms. Marleen Vangeel, whose office is located at Industriedijk 14, 2300 Turnhout. She can be reached at marleen@aevandevliet.be.
Article 3. Rights and Obligations of the Data Controller
-
The Data Controller shall take all appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
-
The Data Controller shall notify the Data Processor of any official request and any inspection by the Data Protection Authority.
-
The Processor does not respond to direct requests from data subjects. The Processor refers data subjects to the Controller. The Controller is responsible for ensuring that all rights of the data subjects are protected.
Article 4. Liability
Except in cases of fraud, gross negligence, or willful misconduct, the Processor shall not be liable for any damages resulting from a breach of this agreement or the GDPR.
In any case, liability is limited to the amounts invoiced to the Data Controller during the twelve (12) months preceding the occurrence of the damage.
Article 5. Term and Termination of the Agreement and the Processing Activities
This agreement is entered into for an indefinite term and terminates upon the expiration of the term specified in Article 2.3.
Article 6. General Provisions
-
All notices under this agreement shall be sent to the addresses specified in the agreement. The parties shall notify each other of any change of address.
-
The invalidity of any provision of this agreement shall not affect the validity of the remaining provisions.
-
This agreement is governed by Belgian law.
-
The parties agree that, in the event of any disputes, they will first seek to reach an amicable settlement in an informal manner and as discreetly as possible.
-
If an amicable settlement cannot be reached, all disputes arising from this agreement shall be submitted exclusively to the courts of the judicial district of Antwerp, Turnhout division.
General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data.
