DECLARATION ON THE SECURITY OF PERSONAL DATA IN ACCORDANCE WITH THE GENERAL REGULATION ON THE PROTECTION OF PERSONAL DATA (EU 679/2016)


OPTISERVER., as the first contractual partner, guarantees




1. Introductory provisions

1.1

By confirming the General Terms and Conditions and paying the pro forma invoice for services with OPTISERVER D.O.O., the other contractual partner ('the Contract Services') entered into a contractual relationship.


1.2

This statement is part of the contractual relationship and provides for the regulation of mutual relations in accordance with the General Regulation on the Protection of Personal Data EU 679/2016 (hereinafter: the Regulation).


1.3

The contractual partner G-server d.o.o. will have the status of a processor (hereinafter: the Processor) in a mutual relationship with each contractual partner and in accordance with the Decree.


1.4

The other contractual partner will have the status of a manager (hereinafter: the Manager) in their mutual relationship and in accordance with the Regulation.


1.5

The terms used in this Declaration have the same meaning as set out in the Regulation.


1.6

The Processor will keep appropriate records of all received personal data necessary for the performance of the Contractual Services.


1.7

The personal data with which the Processor will inadvertently encounter in the performance of the Contractual Services are also considered committed. The processor keeps appropriate records of this personal data.


1.8

The processor will also keep appropriate records of processing, including the purposes of processing (Annex 1).


1.9

The processor will receive the collection or. use the personal data contained therein exclusively for the performance of the Contractual Services.


2. Information security and compliance with the Regulation

2.1

The processor has adopted and consistently implements appropriate technical and organizational measures in its operation to ensure the protection of personal data and the exercise of rights in relation to them in accordance with the Regulation (Articles 28 and 32).


2.2

Minimum technical and organizational measures to prevent the unintentional or intentional unauthorized alteration, destruction, loss or unauthorized processing of personal data include:


physical, technical and logical security of premises, hardware and system software, including ICT input-output units;


technical and logical protection of user software;


technical and logical prevention of unauthorized access to personal data during their transmission, including transmission by telecommunications and networks;


effective means of blocking, destroying, deleting or anonymising personal data when the purpose for which they were collected has been fulfilled;


providing audit trails intended for later determination of the times of entry of individual data into the records of personal data, use, transmission, access or other processing and identification of the performers of these activities (keeping records on the processing and transmission of personal data);


written undertakings by persons authorized to process personal data to protect confidentiality;


other appropriate measures provided for in the Regulation (Article 32).


2.3

The Processor guarantees that in the performance of the Contractual Services it observes and meets all the provisions, requirements and standards defined in connection with the security of personal data by their mutual agreements, the Regulation and good practices in information security.


2.4

The processor also complies with all the provisions of the Regulation and good information security practices in connection with the creation and storage of audit trails.


3. Collection, processing, transmission and storage of personal data

3.1

The controller confirms that all personal and related data that are subject to processing or. the provision of the Contractual Services, lawfully and in a manner consistent with the provisions of Articles 6 (1), 7 (1), 8 and 9 (2) of the Regulation.


3.2

The controller confirms that it informs all individuals clearly, comprehensibly and in writing of the principles of collection, processing, transmission and storage of personal data set out in Article 5 of the Regulation.


4. Rights of individuals

4.1

The controller shall enable all individuals to exercise all the rights set out in Articles 12 to 22 of the Regulation in relation to their personal data.


4.2

In accordance with the provisions of Articles 37, 38 and 39 of the Regulation, the processor appointed the Personal Data Protection Officer and defined his / her powers, obligations and responsibilities.


5. Rights of the Manager

5.1

The Controller may at any time, at its own expense and with the assistance of an independent auditor at the Processor, verify the implementation of Contractual Services and in particular the implementation of appropriate technical and organizational measures to ensure information security and personal data security and compliance with Regulation and good information security practices.


5.2

The Controller may restrict or prohibit the Processor from performing or prohibit cooperation with an individual sub-processor (involving the transfer of data) located in or outside the EU.


6. Obligations of the Manager

6.1

The Operator is obliged to submit all requests and instructions related to the provision of Contractual Services to the Processor in writing.


6.2

The manager, as a careful manager, is obliged to provide protection