This Data Processing Agreement (the "Agreement") is entered into between the Customer and PDFShift.
This Agreement forms an integral part of the Contract for Services under the PDFShift Terms and Conditions (the "Principal Agreement"). This Agreement is entered into for the same term as the Principal Agreement governing the Services provided by PDFShift.
Given the interdependence of this Agreement and the Principal Agreement, termination of the Principal Agreement, for any reason whatsoever, shall result in the termination of this Agreement.
The term of this Agreement shall follow the term of the Principal Agreement. Terms not defined herein shall have the meaning as set forth in the Principal Agreement.
WHEREAS
- (a) The Customer has entered into the Principal Agreement under which PDFShift undertakes to provide the Services.
- (b) The provision of the Services involves the Processing of Company Personal Data by PDFShift on behalf of, and on the documented instructions of, the Customer. In this context, the Customer acts as a Data Controller (the «Controller») and PDFShift acts as a Data Processor (the «Processor»).
- (c) The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing, and in particular with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- (d) As part of their contractual relations, each Party undertakes to comply with applicable Data Protection Laws, and the Parties wish to set out their respective rights and obligations in this Agreement.
IT IS AGREED AS FOLLOWS:
1. Definitions and Interpretation
- 1.1 - Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:
- 1.1.1 - "Company Personal Data" means any Personal Data Processed by a Processor on Controller's behalf pursuant to or in connection with the Principal Agreement;
- 1.1.2 - "Data Protection Laws" means all privacy and data protection legislation applicable to Processor in its provision of the Services, including: (i) Regulation (EU) 2016/679 (the "GDPR") ; (ii) the French Act No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties (as amended) ; (iii) any other applicable data protection laws directly binding on Processor in connection with the performance of the Services.
- 1.1.3 - "EEA" means the European Economic Area;
- 1.1.4 - "GDPR" means EU General Data Protection Regulation 2016/679;
- 1.1.5 - "Services" means the document conversion services provided by PDFShift, as further described in Schedule 1.
- 1.1.6 - "Subprocessor" means any third party appointed by or on behalf of Processor to process Company Personal Data on behalf of Controller in connection with the Agreement.
- 1.2 - The terms, "Commission", "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.
- 1.3 - This Agreement applies solely to Company Personal Data Processed by Processor on behalf of Controller in connection with the Services.
This Agreement does not apply to Personal Data for which Processor acts as an independent Controller, including business contact data, account and user administration data, billing and payment data, fraud-prevention and security data, website analytics data, and service-usage or telemetry data, in each case to the extent Processed by Processor for its own legitimate business purposes and as described in Processor’s Privacy Policy.
For the avoidance of doubt, any Personal Data Processed by Processor on Controller’s behalf remains Company Personal Data and is subject to this Agreement, regardless of the system or service through which it is Processed.
2. Processing of Company Personal Data
- 2.1 - Processor shall comply with all applicable Data Protection Laws in the Processing of Company Personal Data.
- 2.2 - Processor shall process Company Personal Data only on documented instructions from Controller, including with regard to transfers of Company Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which Processor is subject. In such case, Processor shall inform Controller of that legal requirement before Processing, unless such law prohibits such information on important grounds of public interest.
- 2.3 - Controller instructs Processor to process Company Personal Data to provide the Services and related technical support in accordance with the processing details set out in Annex B.
- 2.4 - Controller shall, in its use of the Services and in its instructions to Processor, comply with applicable Data Protection Laws. Controller represents, warrants, and undertakes that: (i) it shall be solely responsible for the accuracy, quality and lawfulness of Company Personal Data; (ii) it has and will maintain a valid legal basis for the Processing of Company Personal Data and for its provision to Processor for collecting, using and providing such Company Personal Data to Processor and its Subprocessors, and for their Processing as contemplated by this Agreement and the Principal Agreement; (iii) it has provided all required notices and obtained all necessary consents and rights under applicable Data Protection Laws to enable such lawful Processing; (iv) its instructions to Processor comply with applicable Data Protection Laws; (v) it shall not submit through the Services any Personal Data that is irrelevant, excessive, or unnecessary in relation to the provision of the Services; (vi) it maintains a record of processing activities carried out under its responsibility in accordance with Article 30 GDPR.
- 2.5 - Processor shall immediately inform Controller if, in Processor's opinion, an instruction from Controller infringes applicable Data Protection Laws. In such case, Processor may suspend the affected Processing until Controller confirms, modifies or withdraws the relevant instruction, without incurring any liability and without giving rise to any refund for the period of suspension. If Controller maintains an instruction that Processor reasonably considers to infringe applicable Data Protection Laws, Processor may terminate this Agreement and the affected Services immediately, without charge or penalty.
- 2.6 - Where Controller submits through the Services any special categories of Personal Data within the meaning of Article 9 GDPR or Personal Data relating to criminal convictions and offences within the meaning of Article 10 GDPR, Controller shall ensure that it has an appropriate legal basis and complies with all additional requirements applicable to such Personal Data, and shall implement any prior information, consent and security measures required. Controller acknowledges that the Services are not specifically designed for the Processing of such categories of Personal Data and that Controller determines, at its sole responsibility, whether to include such Personal Data in content submitted to the Services.
3. Processor Personnel
Processor shall ensure that any person authorised to process Company Personal Data has committed themselves to confidentiality or is under an appropriate statutory obligation of confidentiality, and that access to Company Personal Data is limited to persons who require such access for the provision of the Services.
4. Security
- 4.1 - Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR (including measures to ensure data confidentiality, backup, and the restoration of data availability in the event of a physical or technical incident).
- 4.2 - In assessing the appropriate level of security, Processor shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
- 4.3 - Processor’s technical and organizational security measures as of the effective date of this Agreement are set out in Annex C. Processor may update or modify these measures from time to time, provided that such updates or modifications do not result in a material degradation of the overall level of security provided for Company Personal Data.
5. Subprocessing
- 5.1 - Authorized Subprocessors. Controller agrees that Processor may engage Subprocessors to process Company Personal Data on Controller’s behalf. The Subprocessors currently engaged by Processor and authorized by Controller are listed in Annex A.
- 5.2 - Subprocessor Obligations. Processor shall: (i) enter into a written agreement with the Subprocessor imposing data protection terms that require the Subprocessor to protect the Company Personal Data to the standard required by Data Protection Laws and to provide the same sufficient guarantees regarding the implementation of appropriate technical and organizational measures in such manner that Processing meets the requirements of applicable Data Protection Laws; and (ii) remain responsible for its compliance with the obligations of this Agreement, and for any acts or omissions of the Subprocessor that cause Processor to breach any of its obligations under this Agreement.
- 5.3 – Changes to Subprocessors. Processor shall notify Controller in writing at least 15 days before authorizing any new Subprocessor or replacing an existing Subprocessor. This information must clearly indicate which processing activities are concerned, the name and contact details of the Subprocessor.
- 5.4 – Objection Mechanism and Resolution. Controller may object to the appointment or replacement of a Subprocessor solely on legitimate, documented and justifiable data-protection grounds by submitting its written objections to the Processor within fifteen (15) days from the date of receipt of Processor’s notification. If Controller does not submit a written objection within such fifteen (15) day period, Controller shall be irrevocably deemed to have authorized the appointment and use of the relevant Subprocessor. In the event of Controller’s continuing objections, the Parties shall meet in good faith and use their best efforts to discuss a resolution. Processor may choose to (i) not hire the Subprocessor or (ii) take the corrective action requested by Controller in connection with the objections before hiring the Subprocessor. If neither option is reasonably possible, and if Processor cannot for legitimate reasons hire another Subprocessor for the intended processing, either Party may terminate this Agreement and the Principal Agreement upon a thirty (30) days' written notice, without incurring any liability, fee, or penalty solely from such termination.
6. Data Subject Rights
- 6.1 - Taking into account the nature of the Processing, Processor shall assist Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Controller’s obligations, as reasonably understood by Controller, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
- 6.2 – If Processor receives a request directly from a Data Subject in respect of Company Personal Data, Processor shall:
- 6.2.1 - promptly notify Controller by email sent to Controller’s registered contact email address;
- 6.2.2 - not respond to the Data Subject’s request, except on the documented written instructions of Controller or as required by applicable Data Protection Laws to which the Processor is subject. In this latter case, Processor shall to the extent permitted by Data Protection Laws inform Controller of that legal requirement before responding to the request.
7. Personal Data Breach
- 7.1 - Processor shall notify Controller without undue delay, and in any event within forty-eight (48) hours, upon Processor becoming aware of a Personal Data Breach affecting Company Personal Data, providing Controller with sufficient information to allow Controller to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws. Where, and in so far as, it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay.
- 7.2 - Processor shall co-operate with Controller and take reasonable measures, determined by Processor in light of the circumstances, to investigate, mitigate and remediate any Personal Data Breach affecting Company Personal Data. Processor shall provide reasonable information and assistance to enable Controller to comply with its obligations under applicable Data Protection Laws in relation to such Personal Data Breach.
8. Compliance Assistance
- 8.1 - Processor shall provide reasonable assistance to Controller in ensuring compliance with Controller’s obligations pursuant Articles 32 to 36 of the GPDR (including data protection impact assessments, and prior consultations with Supervisory Authorities or other competent data protection authorities), in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Processor. Where such assistance requires material effort beyond the ordinary provision of the Services, Processor may charge Controller reasonable fees based on the time and resources required, provided that Processor informs Controller of such fees in advance.
9. Deletion or return of Company Personal Data
- 9.1 - Subject to Section 9.2, upon termination or expiration of the Services involving Processing of Company Personal Data, the Controller shall notify the Processor, within 1 month, whether the Company Personal Data is to be returned or securely deleted. The Processor shall give effect to that instruction, and delete all remaining copies, within 30 days of its receipt. Failing such notification within that period, the Processor shall securely delete all Company Personal Data. . Where Company Personal Data has already been returned or deleted through the normal operation of the Services and is no longer retained by Processor as set out in Annex B, the return or deletion obligation shall be considered fulfilled.
- 9.2 - Processor may retain Company Personal Data where required by applicable Data Protection Laws or other statutory legal obligations, provided that Processor continues to protect such Personal Data and limits Processing to the purposes required by such law.
- 9.3 - Upon Controller's reasonable written request, Processor shall confirm completion of the deletion required under this Section.
10. Audit rights
- 10.1 - Subject to this section 10, Processor shall make available to Controller, upon reasonable request, information and documentation necessary to demonstrate compliance with this Agreement and applicable Data Protection Laws. Controller shall first review any existing audit reports, certifications, or documentation provided by Processor before requesting an audit or inspection. Audit requests must be reasonable, proportionate, and limited to information necessary to verify such compliance.
- 10.2 - The Controller may exercise its audit rights under this Agreement no more than once per calendar year, at its own expense, unless: (a) a Personal Data Breach affecting Company Personal Data caused by the Processor has occurred; (b) the Controller has a reasonable and documented basis to suspect a material breach of this Agreement or applicable Data Protection Laws by the Processor; or (c) such audit is explicitly required by applicable Data Protection Laws or a competent Supervisory Authority.
- 10.3 – Any audit shall be conducted by an independent and impartial third-party auditor designated by Controller, provided that Processor may object to the identity of the selected auditor if such auditor is, in Processor’s reasonable opinion, a competitor of Processor or lacks appropriate professional qualifications. The auditor shall be bound by appropriate strict confidentiality obligations.
- 10.4 - Any audits involving on-site inspections or the engagement of third-party auditors shall be subject to at least fifteen (15) days’ prior written notice to Processor. The Parties shall agree in advance on the scope, timing, duration, and operational framework of the audit.
- 10.5 - All costs associated with the audit, including any costs of third-party auditors, shall be borne by the Controller. Notwithstanding the foregoing, if an audit reveals a material breach of this Agreement by the Processor or is conducted following a Personal Data Breach caused by the Processor, the Processor shall reimburse the Controller for the reasonable and documented costs of such audit.
- 10.6 - All audits shall be conducted exclusively during Processor’s normal business hours, and in a manner that minimizes disruption to the Processor’s business operations. The audit shall not threaten or compromise in any way whatsoever: (a) the technical and organizational security measures implemented by Processor ; (b) the trade secrets, proprietary information, and business confidentiality of Processor ; (c) the security, privacy, and confidentiality of the data of Processor’s other customers ; or (d) the proper functioning, continuity, and organization of Processor's operations and business.
- 10.7 - The draft audit report shall be submitted to Processor prior to finalization to allow Processor to make any written comments, which shall be attached to and incorporated into the final version of the audit report. Each audit report and its findings shall be treated as confidential information.
11. International Data Transfers
- 11.1 - The Processor may transfer Company Personal Data outside the EEA where permitted by applicable Data Protection Laws, including where the recipient is located in a country subject to an adequacy decision, participates in an applicable adequacy framework, or where appropriate safeguards such as the European Commission Standard Contractual Clauses are implemented.
- 11.2 - Processor shall ensure that any Subprocessor receiving Company Personal Data in a third country is subject to appropriate contractual and technical safeguards as required by applicable Data Protection Laws.
- 11.3 - Standard Contractual Clauses (SCCs)
Where Processor transfers Company Personal Data to a Subprocessor located outside the EEA and such transfer is subject to Chapter V of the GDPR and cannot rely on an adequacy decision or another valid transfer mechanism, Processor shall ensure that the transfer is subject to appropriate safeguards in accordance with Article 46 GDPR
Where the European Commission Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") are used as the applicable transfer mechanism, Processor shall enter into the EU SCCs with the relevant Subprocessor using the module applicable to the relationship between the parties, including Module Three (Processor to Processor) where Processor transfers Company Personal Data to a Subprocessor.
Processor shall ensure that the information required by the EU SCCs, including the description of the transfer, categories of Personal Data, categories of Data Subjects, frequency and nature of the Processing, applicable retention periods, competent supervisory authority and technical and organisational measures, is completed or otherwise incorporated into the applicable agreement with the relevant Subprocessor.
Where required by applicable Data Protection Laws, Processor shall assess whether the laws and practices of the destination country affect the effectiveness of the safeguards provided by the EU SCCs and shall implement supplementary measures where reasonably necessary.
Controller hereby authorizes Processor to enter into Module Three EU SCCs with Subprocessors in the name and on behalf of Controller. - 11.4 - United Kingdom Transfers
Where Processor transfers Company Personal Data that is subject to the UK GDPR to a recipient outside the United Kingdom and the transfer cannot rely on UK adequacy regulations or another valid transfer mechanism, Processor shall implement an appropriate safeguard recognised under applicable UK Data Protection Laws.
Where the EU SCCs are relied upon for such transfer, the Parties shall apply the then-current
UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office, or any replacement mechanism approved under applicable UK Data Protection Laws.
Processor shall ensure that the information required by the applicable UK transfer mechanism is completed or incorporated by reference into the relevant agreement. - 11.5 - Switzerland Transfers
Where Processor transfers Company Personal Data that is subject to the Swiss Federal Act on Data Protection outside Switzerland and the transfer cannot rely on an adequacy determination or another valid transfer mechanism, Processor shall implement appropriate safeguards as required under Swiss Data Protection Laws.
Where the EU SCCs are used, they shall apply with any adaptations required under Swiss Data Protection Laws, including references to the Swiss Federal Data Protection and Information Commissioner where applicable.
12. General Terms
- 12.1 - Confidentiality. Each Party must keep any information it receives about the other Party and its business in connection with this Agreement ("Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that:
- disclosure is required by law;
- the relevant information is already in the public domain;
- the relevant information was lawfully received from a third party without any obligation of confidentiality;
- the relevant information was independently developed by the receiving Party without use of the other Party’s Confidential Information; or
- disclosure is made to a Party’s employees, advisers, auditors or Subprocessors who are bound by confidentiality obligations, to the extent necessary for the performance of this Agreement.
- 12.2 - Notices. All notices and communications given under this Agreement must be in writing and will be sent by email. Controller shall be notified by email sent to the address related to its use of the Service under the Principal Agreement. Processor shall be notified by email sent to the address: [email protected]
- 12.3 – Liability. The liability caps and exclusions set out in the Principal Agreement shall apply to each Party’s liability arising out of or in connection with this Agreement and applicable Data Protection Laws. The Parties’ total aggregate liability under the Principal Agreement and this Agreement taken together shall not exceed the liability cap set out in the Principal Agreement, and such cap shall not apply separately or cumulatively to this Agreement.
- 12.4 – Order of precedence. In the event of any conflict or inconsistency between this Agreement and the Principal Agreement, this Agreement shall prevail with respect to the subject matter of the Processing of Company Personal Data.
13. Governing Law and Jurisdiction
- 13.1 - This Agreement shall be governed by and construed in accordance with French law.
- 13.2 - Any dispute arising out of or in connection with this Agreement that cannot be resolved amicably shall be subject to the exclusive jurisdiction of the competent courts of Paris, France
- 13.3 - Notwithstanding Sections 13.1 and 13.2, where the EU SCCs, UK International Data Transfer Addendum or another mandatory international data-transfer mechanism applies, any governing-law, supervisory-authority or jurisdiction provisions required by that mechanism shall prevail to the extent of any conflict with this Section 13.
Schedule 1: Service Description
Services means the receipt, loading, rendering and conversion of Controller-provided HTML, including optional header and footer content, URLs and related resources into PDF, JPEG, PNG or WEBP files, together with the transmission, optional temporary storage and delivery of generated files and any optional template or support functionality enabled by Controller.
Parties
Customer (the “Controller”)
| Company Name | __________________________________ |
|---|---|
| Company Address | __________________________________ __________________________________ __________________________________ |
| Registration Number | __________________________________ |
| Represented By | __________________________________ |
| Title | __________________________________ |
| __________________________________ | |
| Date | __________________________________ |
| Signature |
Provider (the “Processor”)
| Company Name | SASU PDFShift |
|---|---|
| Company Address | 128 rue la Boétie 75008 PARIS FRANCE |
| Registration Number | 843 913 807 |
| Represented By | Cyril NICODEME |
| Title | President |
| Date | __________________________________ |
| Signature |
Annex A
List of Processor Subprocessors
The Subprocessors listed below may provide infrastructure hosting and storage, communications, customer support, monitoring, incident management, and other services necessary for the provision of the Services.
Name: Amazon Web Services - https://aws.amazon.com
Purpose: Where Controller provides the filename parameter, PDFShift uses AWS S3 infrastructure located in Paris, France to store the generated output file for up to two (2) days, after which it is automatically deleted. Submitted HTML source, header and footer content are not stored in S3 as part of this functionality.
Location: France
Appropriate safeguards implemented in case of transfer of personal data outside the EU: Non applicable
Name: OVH - https://www.ovhcloud.com/
Purpose: Our servers are managed by OVH in France in two regions: Gravelines and Strasbourg.
Location: France
Appropriate safeguards implemented in case of transfer of personal data outside the EU: Non applicable
Name: Sentry - https://sentry.io
Purpose: PDFShift uses Sentry for application error monitoring and incident diagnostics. HTML source, header/footer content and generated documents are not intentionally transmitted to Sentry. Incidental Company Personal Data, such as IP addresses, request metadata or technical identifiers, may be processed where included in technical error information. Sentry is contractually prohibited from using such Company Personal Data for purposes other than providing its services to PDFShift. Where applicable, transfers are subject to an appropriate mechanism under Chapter V GDPR, including the EU Standard Contractual Clauses.
Location: United-States
Appropriate safeguards implemented in case of transfer of personal data outside the EU: EU-US. Data Privacy Framework / EU SCCs.
Annex B
Details of processing of Company Personal Data
This Annex includes certain details of the Processing of Company Personal Data as required by Article 28(3) GDPR.
Subject matter and duration of the Processing of Company Personal Data
The subject matter of the Processing is the provision of the Services described in Schedule 1.
Company Personal Data submitted for conversion is, by default, Processed only for the duration necessary to perform and return the requested conversion and is not intentionally retained after completion of the request.
Where Controller provides the filename parameter, the generated output file may be retained for up to two (2) days following the conversion and is then automatically deleted.
Any other Processing shall continue only for the duration necessary to provide the Services or as otherwise required by applicable law.
Special categories of Personal Data
Controller acknowledges that, depending solely on the content submitted through the Services, Company Personal Data may include special categories of Personal Data within the meaning of Article 9 GDPR or Personal Data relating to criminal convictions and offences within the meaning of Article 10 GDPR.
Controller is responsible for ensuring that it has an appropriate legal basis for such Processing and complies with any additional requirements applicable to such categories of Personal Data.
The nature and purpose of the Processing of Company Personal Data
Processing Company Personal Data as necessary to receive, render, convert and return content submitted by Controller through the Services, including HTML-to-PDF and other supported document or image conversion operations, and to provide related technical support where requested by Controller.
The types of Company Personal Data to be Processed
Company Personal Data may include any Personal Data contained in HTML source, header or footer content, URLs, remotely loaded resources, or other content submitted by Controller to the Services for conversion, as well as Personal Data contained in the resulting PDF, JPEG, PNG or WEBP file.
Such Personal Data is determined solely by Controller and may include identification data, contact information, financial information, employment information, health information, and any other Personal Data that Controller chooses to include in submitted content, including special categories of Personal Data within the meaning of Article 9 GDPR and Personal Data relating to criminal convictions and offences within the meaning of Article 10 GDPR.
Processor processes such Company Personal Data solely for the purpose of performing the requested conversion and providing related Services.
By default, submitted HTML source, header and footer content and other conversion inputs are processed transiently in volatile memory for the duration of the conversion request and are not intentionally written to persistent storage or retained by Processor following completion of the request.
Where Controller provides the filename parameter, the generated output file may be stored using Amazon S3 infrastructure located in France for up to two (2) days and is then automatically deleted. The submitted HTML source, header and footer content are not stored as part of this optional storage functionality.
The categories of Data Subject to whom the Company Personal Data relates
Any individuals whose Personal Data may be included by Controller in HTML source, header or footer content, URLs, remotely loaded resources or other content submitted to the Services, or whose Personal Data appears in the generated output.
Such Data Subjects may include, without limitation, Controller's customers, prospective customers, employees, contractors, users, suppliers or other individuals.
Processor does not determine or control the categories of Data Subjects whose Personal Data may be included in such content.
The obligations and rights of Controller
The obligations and rights of Controller are set out in the Principal Agreement and this Agreement.
Annex C
Technical and Organisational Security Measures
Processor maintains technical and organisational measures appropriate to the nature of the Processing and the risks presented by the Processing, including where applicable:
1 - Encryption in transit
Communications between Controller and the Services are protected using encrypted HTTPS/TLS connections.
2 - Encryption at rest.
Where Controller enables the optional storage functionality described in Annex B, generated output files stored during the applicable retention period (up to two (2) days) are encrypted at rest using Amazon S3 server-side encryption with AES-256 or another encryption mechanism providing an equivalent or greater level of protection.
3 - Access control
Access to production systems and Company Personal Data is restricted to authorised personnel with a legitimate business need and is granted according to the principle of least privilege. Production access permissions are limited to the minimum level required for the relevant role and are revoked when no longer required.
4 - Authentication
Processor implements appropriate authentication controls for administrative and production access, including multi-factor authentication where appropriate and technically supported.
5 - Confidentiality
Personnel authorised to access Company Personal Data are subject to confidentiality obligations.
6 - Infrastructure and network security
Processor uses network segmentation, firewalls and other technical controls designed to restrict unauthorised access to production systems.
7 - Monitoring and logging
Processor maintains appropriate infrastructure, logging, security and application monitoring designed to detect operational and security incidents.
8 - Backup and recovery
Processor maintains backups of systems and configuration data where appropriate and maintains procedures designed to restore availability following a significant technical or physical incident.
Company Personal Data submitted for conversion, including HTML source and generated conversion output, is not intentionally included in Processor's ordinary backup systems. Generated files stored through the filename functionality remain subject to the two (2) day retention period described in Annex B.
9 - Storage
By default, Company Personal Data submitted for conversion is processed transiently in volatile memory and is not intentionally persisted following completion of the conversion request.
Where Controller provides the filename parameter, the generated output file may be stored using Amazon S3 infrastructure located in France for up to two (2) days and is then automatically deleted.
Stored generated files are encrypted at rest and access is restricted through appropriate technical access controls.
10 - Data isolation
Processor implements logical and/or technical controls designed to prevent unauthorised access between customer environments and Company Personal Data.
11 - Incident response
Processor maintains processes for identifying, investigating, mitigating and responding to security incidents affecting Company Personal Data.
12 - Data minimisation and retention
Processor limits retention of Company Personal Data to the period necessary to provide the Services or comply with applicable legal obligations.
13 - Subprocessors
Processor evaluates Subprocessors that Process Company Personal Data and contractually requires such Subprocessors to implement appropriate data-protection and security measures.
Processor may update these measures from time to time, provided that such updates do not materially decrease the overall level of protection provided to Company Personal Data.