Purpose
This Data Processing Agreement (hereinafter the “DPA”) supplements the general terms of sale and the general terms of use, and sets out the respective obligations of BELLUM, acting as processor within the meaning of Article 28 of the GDPR (hereinafter the “Processor”), and of the Customer, acting as controller (hereinafter the “Controller”), with regard to the processing of personal data.
Processing carried out
As part of providing the BellumAI services, the Processor processes, on behalf of the Controller, the following categories of data: identification data of business contacts (surnames, first names, job titles, business contact details); data on target companies (company name, financial data, headcount, business activity); Customer usage data (analyses run, messages generated, actions performed). The data subjects are the business contacts identified in the course of the Customer's B2B sales prospecting. The duration of the processing corresponds to the term of the agreement between the parties.
Processor's obligations
The Processor undertakes to: process the data only on documented instructions from the Controller, including with regard to transfers to third countries or international organisations; ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; implement the technical and organisational security measures described in the Privacy policy; not engage another processor without the prior general or specific written authorisation of the Controller; assist the Controller, through appropriate technical and organisational measures, in fulfilling its obligation to respond to requests to exercise data subjects' rights; assist the Controller in ensuring compliance with the obligations set out in Articles 32 to 36 of the GDPR (security, breach notification, impact assessments); at the Controller's choice, delete or return all personal data at the end of the services; and make available to the Controller all information necessary to demonstrate compliance with its obligations and to allow for audits.
Sub-processors
The Processor is generally authorised by the Controller to engage sub-processors for the performance of specific technical services (hosting, payment processing, infrastructure services). The list of sub-processors is made available to the Customer upon request sent to dpo@bellum-it.com.
The Processor shall inform the Controller in advance of any addition or replacement of a sub-processor. The Controller has thirty days from the notification to raise reasoned objections. Each sub-processor is bound by contractual obligations providing a level of protection equivalent to that set out in this DPA.
Breach notification
In the event of a personal data breach within the meaning of Article 4(12) of the GDPR, the Processor undertakes to notify the Controller without undue delay and, in any event, within a maximum of seventy-two hours after becoming aware of it. The notification shall include the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences of the breach, and the measures taken or proposed to remedy the breach and mitigate its possible adverse effects.
Audits
The Processor undertakes to allow the Controller, or any independent auditor appointed by the Controller and bound by a confidentiality obligation, to carry out audits to verify compliance with the obligations of this DPA, subject to reasonable notice of fifteen days and limited to one audit per calendar year, except in exceptional circumstances justifying an additional audit (in particular in the event of a data breach or a request from the supervisory authority). The costs of the audit are borne by the Controller.
Upon request, the Processor undertakes to cooperate with the competent data protection authorities, in particular in the event of an inspection. In the event of a request from an administrative or judicial authority, the Processor undertakes to inform the Controller as soon as possible.
Term and end of the DPA
This DPA takes effect on the date of subscription to the BellumAI services and remains in force for the entire term of the agreement. At the end of the agreement, the Processor deletes all personal data processed on behalf of the Controller within thirty days, unless a legal retention obligation applies. A certificate of deletion may be issued upon request from the Controller.