1. Subject Matter of Data Processing Agreement
1.1 According to the Puttview Mobile App Terms of Service to which this Agreement on Data Processing is attached and the offer (“Main Agreement”), Viewlicity GmbH (hereinafter “PuttView”) makes available services to Customer, which may include the making available of web based services and remote web support. This Agreement on Data Processing (“Data Processing Agreement”) specifies the Parties’ duties regarding data protection laws and applies to both, cases where PuttView is a processor within the meaning of Article 4 (8) GDPR and the Customer is a controller within the meaning of Article 4 (7) GDPR, and cases where Customer is a processor within the meaning of Article 4 (7) GDPR and PuttView acts as the Customer’s sub-processor.
1.2 The Data Processing Agreement applies to all services which relate to the commissioned data processing where PuttView or its personnel may get in contact with Personal Data, which are provided to PuttView by the Customer.
1.3 The type of processed data and categories of data subjects, and the nature and purpose of processing of Personal Data by PuttView on behalf of the Customer and the categories of data subjects are defined in Appendix 1.
2. Technical and Organizational Measures
2.1 PuttView shall establish measures in accordance with Article 28 (3) c, and Article 32 GDPR in particular in conjunction with Article 5 GDPR. The measures to be taken are measures of data security and measures that guarantee an appropriate data protection level taking account of risks for confidentiality, integrity, availability and resilience of systems. The state of the art, implementation costs, the nature, scope and purposes of processing as well as the probability of occurrence and the severity of the risk for the rights and freedoms of natural persons within the meaning of Article 32 (1) GDPR must be taken into account. The measures taken by PuttView are specified in Appendix 2.
2.2 The technical and organizational measures are subject to technical progress and further development. In this respect, PuttView may implement alternative adequate measures. However, the security level of the defined measures shall not be reduced. Substantial changes must be documented.
2.3 PuttView regularly controls the internal processes as well as the technical and organizational measures in order to ensure that the data processing which lies within its responsibility is carried out in accordance with the applicable data protection laws and to ensure the protection of the rights of the data subjects.
3. Rectification, Restriction and Erasure of Data; Rights of Data Subjects
3.1 PuttView may not on its own authority modify or delete the data that is being processed on behalf of the Customer, or restrict the processing of such data, but only on documented instructions from the Customer. In the event that a data subject contacts PuttView directly concerning a modification or deletion of data, or restriction of processing, PuttView shall immediately forward the data subject’s request to the Customer.
3.2 To the extent included in the scope of services, the data deletion policy, ‘right to be forgotten’, rectification, data portability and access shall be ensured by PuttView in accordance with documented instructions from the Customer.
4. Quality Assurance and other Duties of PuttView
4.1 PuttView entrusts only such employees with the data processing outlined in this Data Processing Agreement who have been bound to confidentiality. Unless required by law to process the data, PuttView shall not process the data except as on instructions from the Customer, which includes the processing allowed under this Data Processing Agreement and the Main Agreement.
4.2 PuttView shall assist the Customer in complying with the obligations concerning the security of Personal Data, reporting of data breaches, data protection impact assessments and prior consultations, as stipulated in Articles 32 through 36 GDPR. These include:
4.3 The obligation to report a Personal Data breach immediately to the Customer,
4.4 The duty to assist the Customer with regard to the Customer’s obligation to provide information to the data subject and to immediately provide the Customer with all relevant information in this regard.
4.5 Supporting the Customer with its data protection impact assessment.
4.6 Supporting the Customer regarding prior consultation with the supervisory authority.
5. Subcontracting
5.1 Subcontracting for the purpose of this Data Processing Agreement is to be understood as services which relate directly to the provision of the principal service. This does not include ancillary services, such as telecommunication services, postal / transport services, maintenance and user support services, or the disposal of data carriers, as well as other measures to ensure the confidentiality, availability, integrity and resilience of the hardware and software of data processing equipment. PuttView shall, however, be obliged to make appropriate and legally binding contractual arrangements and take appropriate inspection measures to ensure the data protection and the data security of the Customer’s data, even in the case of outsourced ancillary services.
5.2 The Customer herewith agrees that PuttView may engage sub-processors, provided that PuttView and the sub-processor conclude an agreement according to Article 28 (4) GDPR.
5.3 The Customer herewith agrees that PuttView engages the following sub-contractors:
- Microsoft Ireland Operations Ltd. based in Ireland (“Microsoft Ireland”) as a sub-contractor for the collection, processing and use of data. PuttView may in particular use the infrastructure and platform services of the Windows Azure platform, e.g. for providing server and computing capacities, data storage and database services (collectively “Windows Azure Services”). PuttView uses Windows Azure Services in accordance with Microsoft Ireland’s general terms of use and security measures.
- RevenueCat, Inc. based in the United States (“RevenueCat”) as a sub-contractor for the collection, processing and use of data in connection with the management of in-app purchases, subscriptions and user entitlements within the PuttView Mobile App. PuttView uses RevenueCat’s services in accordance with RevenueCat’s applicable terms of service, data processing agreement and security measures. Transfers of Personal Data to RevenueCat outside the European Economic Area shall be subject to appropriate safeguards pursuant to Chapter V GDPR, including the European Commission’s Standard Contractual Clauses.
5.4 PuttView shall notify the Customer of any intended change with respect to the addition of, or replacement by, any other processors. The Customer may object to such change for good cause by giving notice within one (1) month as of receipt of the notification of change. If the Customer does not oppose within such term, the change shall be deemed approved.
6. Supervisory Rights of the Customer
6.1 The Customer has the right, after consultation with PuttView, to carry out inspections or to have them carried out by an auditor to be designated in each individual case. The Customer has the right to convince itself in the PuttView’s business premises of PuttView’s compliance with this Data Processing Agreement by means of random checks, which are, as a rule, to be announced in good time.
6.2 PuttView shall ensure that the Customer is able to verify compliance with the obligations of PuttView in accordance with Article 28 GDPR. PuttView undertakes to give the Customer the necessary information on request and, in particular, to demonstrate the execution of the technical and organizational measures.
6.3 Evidence of such measures may be provided by
- Compliance with approved codes of conduct pursuant to Article 40 GDPR;
- Certification according to an approved certification procedure in accordance with Article 42 GDPR;
- Current auditor’s certificates, reports or excerpts from reports provided by independent bodies (e.g. auditor, data protection officer, IT security department, data privacy auditor, quality auditor);
- A suitable certification by IT security or data protection auditing (e.g. according to BSI-Grundschutz (IT baseline protection certification developed by the German Federal Office for Security in Information Technology (BSI) or ISO/IEC 27001).
6.4 PuttView may claim remuneration for enabling Customer inspections.
7. Authority of the Customer to issue Instructions
7.1 The Customer shall immediately confirm oral instructions (at the minimum in text form).
7.2 PuttView shall inform the Customer immediately if PuttView considers that an instruction violates data protection laws. PuttView shall then be entitled to suspend the execution of the relevant instructions until the Customer confirms or changes them.
8. Deletion and Return of Personal Data
8.1 Copies or duplicates of the data shall not be created without the knowledge of the Customer, with the exception of (i) backup copies as far as they are necessary to ensure appropriate data processing, and (ii) retention of data required to meet statutory data retention laws.
8.2 After having completed the services owed by PuttView under the Main Agreement, or earlier upon request by the Customer, PuttView shall hand over to the Customer or – subject to prior consent – destroy all documents, processing and utilization results, and data sets related to the Main Agreement that have come into its possession, in a data-protection compliant manner. The log of the destruction or deletion shall be provided on request. PuttView’s obligations under this Section 8.2 do not apply to the extent that Union or EU Member State law requires storage of the Personal Data.
9. Term of Processing; Termination
The duration of this Data Processing Agreement corresponds to the term of the Main Agreement and includes the term after termination of the Main Agreement until full return of deletion of the Personal Data, which have been provided by the Customer to PuttView in connection with the performance of the Main Agreement. This does not affect the right to terminate this Data Processing Agreement with good cause.
10. General Provisions
10.1 This Data Processing Agreement shall be governed by and construed in accordance with German law. Place of performance and jurisdiction is Hamburg, Germany.
10.2 During the term of the agreement, PuttView may amend this Data Processing Agreement in order to (1) adapt the Data Processing Agreement to new statutory requirements or to rulings of higher courts, supreme courts or the Court of Justice of the European Union (CJEU), (2) eliminate doubts as to interpretation or (3) adapt the Terms to changed technological developments, all provided that no amendment pursuant to this Section shall materially diminish the level of protection afforded to Personal Data under this Data Processing Agreement, the GDPR, or any other applicable data protection legislation. PuttView shall inform the Customer of such changes to this Data Processing Agreement in text form at least 4 weeks before the change comes into effect. If the Customer does not object to an amendment within 4 weeks of receipt of the notification, the amendments are deemed to have been effectively agreed. PuttView will inform the Customer separately of the right of objection and the consequences of remaining silent when informing the Customer of the change.
10.3 Should individual provisions of this Data Processing Agreement be invalid or unenforceable for actual or legal reasons, without rendering the continuity of the remaining provisions unreasonable as a whole for a Party, this shall not affect the validity of the remaining provisions. The same shall apply in the event of a contractual gap. In lieu of the invalid or unenforceable provisions or to close any contractual gap, the Parties shall agree to a provision that comes closest to fulfilling the economic purpose intended by the Parties.
Appendix 1: Nature and Purpose of Processing of Personal Data, Type of Data, Categories of Data Subjects
| Categories of data subjects | In particular: Users of App Users Ball Tracking Service The Customer’s employees, personnel, team members, clients, business partners and other contacts |
| Type of data | Contact details of users of the App, which may include: First name, last name, company, email address, phone number, address Account details of users of App, which may include: Sex, Nationality, Right-/lefthanded, Handicap, User type (coach/player), Coach/player pairings, Other pairings such as practice groups Data on the use of software and services (protocol data): Version of privacy policy accepted, Version of terms & conditions accepted, Location Data, Data on hardware Setup, Third party identifiers Data about the putting of users of the App, which may include: Information on tracked and intended putts, Data on the use of service (protocol data, including data on sessions and time stamps), Location Data, Data on hardware Setup Tracking Data of users of the App, which may include: App usage data, Location Data Data processed by Customer on its IT system (to the extent it is subject to support) |
| Recipients | Processor and sub-processor |
| Nature and purpose of processing | Making available of App related web services; rendering IT services, in particular support services |
Appendix 2: Technical and Organizational Measures
Preliminary remark: Within the scope of this Data Processing Agreement PuttView solely processes Personal Data for the purpose of meeting its service obligations under the Main Agreement. All data are processed on the Microsoft Azure platform. The technical and organizational measures undertaken by Microsoft Ireland for these services are specified in the Microsoft Online Services Terms.
The following describes the technical and organizational measures undertaken by PuttView.
1. Confidentiality (Article 32 (1) b GDPR)
Access control
Technical or organizational measures for access control, in particular also for the legitimation of authorized persons: Access control system (electronic / physical keys)
Puttview Indoor Product access control
Technical and organizational measures regarding user identification and authentication: access only through dedicated interface, password procedure, encryption of data transfer, Mac-Adress-Filter, Demand-oriented design of the authorization concept and access rights: Differentiated access authorizations
Separation control
Measures for the separate processing (storage, modification, deletion, transfer) of data for different purposes: Separation of operational data and data for development purposes, separate processing of data for artificial intelligence, user trainings and marketing
2. Integrity (Article 32 (1) b GDPR)
Transfer control
Measures during transport, transfer and transmission or storage on data carriers (manual or electronic) as well as during subsequent verification: Encryption
Input control
Measures for retrospectively examining whether and by whom data have been entered, modified or removed (deleted): Logging and protocol evaluation systems
3. Availability and resilience (Article 32 (1) b GDPR)
Availability control
Measures for data backup (physical / logical): Azure Backup procedures, virus protection / firewall
Timely restorability (Article 32 (1) c GDPR)
Backup procedures
4. Procedures for regular testing, assessing and evaluating (Article 32 (1) d GDPR; Article 25 (1) GDPR)
- Data protection management
- Incident response management
Data protection friendly default settings (Article 25 (2) GDPR)
Automated notifications of any malfunctions
Job control
Clear contract design, formalized order management, strict selection of service provider