Data Processing Agreement - previous version
This is an archived page of our April 2024 DPA which is replaced from October 11, 2024
This Data Processing Agreement (hereinafter “DPA”) is applicable between the company RINGO (trading under the name MODJO), a simplified joint stock company with a capital of 38.666,31 euros registered in the trade and companies register of Nanterre under number 879 606 283, and whose registered office is located at 59, avenue Sainte-Foy - 92200 Neuilly-sur-Seine, France (hereinafter “RINGO”) and each of its Client as identified in the Order Form (hereinafter the “Client”).
Preamble:
Im Zusammenhang mit der Erfüllung des/der Auftragsform(en) und der angehängten Allgemeinen Geschäftsbedingungen Modjo (T&Cs), die zwischen RINGO und dem Kunden geschlossen wurden, beauftragt der Kunde als Controller RINGO als Prozessor mit der Verarbeitung von persönlichen Daten.
Diese Datenschutzvereinbarung ist dem Bestellformular und den Allgemeinen Geschäftsbedingungen Modjo beigefügt.
The parties intend to comply with all applicable regulations regarding the Processing of Personal Data, and in particular the French law n°78-17 of 6 January 1978 (known as "Loi Informatique et Libertés") as amended and the EU General Regulation on the Protection of Personal Data n°2016-679 dated 27 April 2016 ("GDPR").
Die Parteien haben sich auf diesen Vertrag geeinigt, um die Einhaltung von Artikel 28(3) und (4) GDPR zu gewährleisten. Dieser Vertrag gilt für die Verarbeitung von personenbezogenen Daten, wie in Artikel 1 beschrieben.
Es wird ausdrücklich vereinbart, dass die in diesem Vertrag verwendeten Begriffe mit Großbuchstaben (z.B. Controller, Personal Data, Service, ...) den Definitionen in GDPR und in den T&Cs entsprechen. Dieser Vertrag ist im Lichte der Bestimmungen von GDPR zu lesen und auszulegen.
1 - Description of processings
The details of the processing operations, in particular the categories of personal data and the purposes of processing for which the personal is processed on behalf of the Client, in its quality of Controller, are :
● Categories of data subjects whose personal data is processed : the Client’s staff and employees using the services provided by RINGO, the Client’s contacts, prospects and clients.
● Categories of personal data processed : data related to the identification of the data subjects (name, surname, contact details and email), data related to the phone call and video conference recordings, data related to the use of the Service such as comments, reviews, translations and intelligent summaries and scoring made on the services, data related to the emails exchanged between the data subjects, data related to meeting reminder e-mail and data related to the networks.
● Object of the processing: the performance by RINGO of the Service, and their use by the Client, in accordance with the Order Form(s) and the attached T&Cs concluded between RINGO and the Client.
● Nature of the processing : the collection and analysis of data including Personal Data on behalf of the Client.
● Purposes of the processing : the performance by RINGO, on behalf of the Client, of the Service , mainly the collection, the recording and the analysis of phone call, video conference recordings and mails, and the filling of the customer relationship management software as well as the assistance, back-up, security and maintenance services attached to the Service.
● Duration of the processing : Personal Data is processed by RINGO for the duration of the contractual relationship of the Client, logs are kept for a period of one (1) year. When the AI Assistant feature is activated by the Client, data is retained by Open AI for a maximum of 30 days for the purpose of content moderation and abuse prevention.
2- Instructions
RINGO shall process personal data only on documented instructions from the Client and in accordance with the above provisions, , unless required to do so by Union or Member State law to which RINGO is subject. In this case, RINGO shall inform the Client of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Subsequent instructions may also be given by the Client throughout the duration of the processing of personal data. These instructions shall always be documented.
Wenn RINGO der Ansicht ist, dass eine der Anweisungen des Kunden eine Verletzung der anwendbaren Vorschriften über den Schutz personenbezogener Daten darstellt, wird RINGO den Kunden unverzüglich informieren. RINGO wird in keiner Weise für die Anweisungen und Entscheidungen des Kunden und deren mögliche Folgen haftbar gemacht werden.
Die Bestimmungen dieses Vertrags sowie die Aktivierung der Übersetzungs- und KI-Assistentenfunktionen durch den Kunden, seine Administratoren oder Benutzer stellen dokumentierte Anweisungen vom Kunden an RINGO dar.
3 - Purpose limitation
RINGO wird die persönlichen Daten nur für die Zwecke der Verarbeitung, wie in Artikel 1 beschrieben, verarbeiten, es sei denn, sie erhält weitere Anweisungen vom Kunden.
4 - Duration of the processing of personal data
RINGO verarbeitet die persönlichen Daten nur für die Dauer der Verarbeitung, wie in Artikel 1 beschrieben, es sei denn, sie erhält weitere Anweisungen vom Kunden.
5 - Security of processing
RINGO undertakes to put in place appropriate technical and organisational security measures to ensure the security of the Personal Data it processes against any destruction, loss, alteration, unauthorised disclosure of, or access to, or any other form of unauthorised processing. In assessing the appropriate level of security, RINGO takes due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for the data subjects.
Eine Beschreibung dieser Maßnahmen wurde von RINGO in Übereinstimmung mit Artikel 32 der GDPR erstellt und ist auf schriftliche Anfrage erhältlich.
Wenn die Funktion AI Assistant vom Client aktiviert wird, stimmt der Client zu, dass die implementierten Sicherheitsmaßnahmen denen der OpenAI-Sicherheitsrichtlinie entsprechen.
RINGO grants access to the personal data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring the Service. RINGO ensures that persons authorised to process the personal data received are under an appropriate contractual obligation of confidentiality.
6 - Documentation and compliance
RINGO wird dem Kunden alle Informationen zur Verfügung stellen, die notwendig sind, um die Einhaltung der Verpflichtungen, die in diesem Vertrag festgelegt sind und direkt aus der GDPR hervorgehen, zu demonstrieren.
At the request of the Client, RINGO shall also permit and contribute to audits of the processing activities covered by this Contract, at reasonable intervals or if there are indications of non-compliance.
The reasonable intervals mean that an audit may be carried out at the rate of one (1) time per calendar year, and with sixty (60) days' written notice to RINGO.
Diese Prüfung muss in einer Weise durchgeführt werden, die die Sicherheit und Vertraulichkeit von RINGOs Dokumentation und Verfahren respektiert. It will last no more than one (1) day and will be held during normal business hours at RINGO's location.
The Controller may decide to carry out the audit itself or to appoint an independent auditor, chosen by mutual agreement between the parties and subject to an obligation of confidentiality.
Ungeachtet jeglicher gegenteiliger Bestimmungen ist der Kunde für alle Kosten und/oder Ausgaben verantwortlich, die als Ergebnis dieses Besuchs entstehen.
The parties shall make the information set out in this clause, including the results of any audit, available to the competent supervisory authority(ies) on request.
7 - Use of sub-processors
RINGO has the Client’s general authorisation for the engagement of sub-processors enumerated in the agreed list (Annex 1).
RINGO verpflichtet sich, auf Anfrage des Kunden eine aktuelle Liste seiner Sub-Prozessoren und deren Verarbeitungstätigkeiten bereitzustellen.
RINGO shall inform the Client of any intended changes of that list through the addition or replacement of sub-processors at least eight (8) days prior to the addition or the replacement date of the concerned sub-processor.
The Client may object to RINGO use of a new sub-processor by notifying RINGO promptly in writing (e.g., via email) and before the addition or the replacement date of the concerned sub-processor. In the event the Client objects, RINGO will use reasonable efforts to make available to the Client a change in the Service or recommend a commercially reasonable change to Client’s configuration or use of the Service to avoid process of Personal Data by the objected-to new sub-processor If RINGO is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, the Client may terminate the applicable Order Form with respect only to those services which cannot be provided by RINGO without the use of the objected-to new sub-processor by providing written notice to RINGO, with return receipt requested.
Das Fehlen von Einwänden des Kunden wird als Zustimmung des Kunden zu den Änderungen, die sich auf die Liste der Unterprozessoren auswirken, angesehen.
Where RINGO engages a sub-processor for carrying out specific processing activities on behalf of the Client, the sub-processor of RINGO is obliged to fulfil, in substance, the same data protection obligations as the ones imposed on RINGO in accordance with this Contract It is the responsibility of RINGO to ensure that the sub-processor presents sufficient guarantees as to the implementation of appropriate technical and organisational measures so that the processing meets the requirements of GDPR.
RINGO bleibt dem Kunden gegenüber voll verantwortlich für die Erfüllung seiner Verpflichtungen durch seine Sub-Prozessoren.
Einige Subprozessoren verarbeiten Client-Daten nur dann, wenn die Funktion, für die sie wirken, vom Administrator oder dem Benutzer des Clients aktiviert wird.
Thus, the sub-processor OpenAI processes Client data only when the Administrator has activated the AI Assistant . When this feature is enabled, OpenAI will process Client data for the provision of intelligent summaries, chapters and scoring.
Similarly, the sub-processor Deepl only processes Customer data when the User activates the translation feature for a specific record. When this feature is activated, Deepl will process the Client's data related to this record in order to provide a translation.
8- Assistance to the Client
The Client shall inform Data Subjects of the processing of their data and of their rights under the “Loi Informatique et Libertés” and GDPR (rights of access, information, opposition, etc.). In particular, the Client must inform its own employees and their correspondents of the recording of their telephone and video conversation and of the fact that they can at any time object to such recording. RINGO may not be held responsible for this obligation under any circumstances.
RINGO shall promptly notify the Client of any request it has received from the data subject. The Client undertakes to respond to requests from Data Subjects within one (1) month.
As a Processor, RINGO shall assist the Client in fulfilling its obligations to respond to data subjects’ requests to exercise their rights, taking into account the nature of the processing and the Client’s instructions.
RINGO shall also assist the Client in ensuring its compliance with its following obligations, taking into account the nature of the data processing and the information available to RINGO :
● the obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (a ‘data protection impact assessment’) where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons and, where applicable, the obligation to consult the competent supervisory authority prior to the processing
● the obligations set out in article 32 of GDPR.
9 - Inspections, control or audits by public authorities
In the event of an inspection, control or audit carried out by a public authority, including a Supervisory Authority, each Party undertakes to provide all necessary assistance to the other.
If the public authority considers that the processing carried out violates the applicable regulations on the protection of personal data, the parties undertake to communicate and immediately take the necessary measures to remedy the breach.
10 - Notification of personal data breach
In the event of a personal data breach, RINGO shall cooperate with and assist the Client for the Client to comply with its obligations under Articles 33 and 34 of GDPR, where applicable, taking into account the nature of processing and the information available to RINGO.
In the event of a data security breach not caused by the Client, RINGO undertakes to take immediate corrective measures to remedy the situation.
RINGO shall notify the Client of any breach without undue delay after becoming aware of such breach, by an email sent to the Client.
This notification shall contain all relevant information about the breach, in order to enable the Client, if necessary, to notify the Supervisory Authority concerned and/or the Data Subjects concerned by the breach, in accordance with its obligations as Controller.
The parties undertake to cooperate fully in order to put an end to the breach as soon as possible.
11 - Storage of Data inside the European Union and international transfers
Personal data processed by RINGO on behalf of the Client and RINGO’s websites and databases are hosted by Amazon Web Services on servers located in the European Economic Area (“EEA”).
Any transfer of data to a third country or an international organisation by RINGO shall be done only on the basis of this Contract or in order to fulfil a specific requirement under Union or Member State law to which the processor is subject and shall take place in compliance with Chapter V of GDPR.
Prior to a transfer authorised by the Client, RINGO undertakes to put in place the necessary measures to ensure that the recipient located in the country outside the European Economic Area presents an adequate level of protection.
When the Client has activated the AI Assistant feature, the Client agrees to the processing of its data by OpenAI in accordance with its processing terms and to the transfer of its data to the United States in accordance with the standard contractual clauses adopted by the European Commission.
RINGO might transfer personal data to the permitted sub-processors identified in Annex 1 “List of Permitted sub-processor”. Such sub-processors might be located outside the European Union. In such a case, RINGO makes sure the sub-processor can ensure compliance with Chapter V of GDPR by presenting an adequate level of protection, such as using standard contractual clauses adopted by the Commissions or approved BCR.
The exhaustive list and information about our sub-processors is provided in Annex 1.
12 - Changes and updates
RINGO reserves the right to change this DPA at any time. The Client is informed of these changes by email (sent to the email address of the Modjo Administrator) or on the website www.modjo.ai or on Modjo commercial conversational analysis platform, as decided by RINGO on its sole discretion.
Except for the use of sub-processors, as stated in Article 7 of this DPA, changes to this DPA will apply to the Client, even if it has registered before the change, eight (8) days after the information has been given to them. In the event the updated DPA would be of material detriment to the Client and the change is not required by applicable laws, regulations, directive, guidance or decision of an european data protection authority or a court order, the Client informs RINGO of the Client’s objection and its reason within eight (8) days of the information. If the Parties cannot reach an agreement within thirty (30) days following the receipt of the Client’s objection, the Client may terminate the Service affected by the change without penalty by written notice to RINGO. Any use of the Service after the information of the Client will be deemed as the Client’s acceptance of the updated DPA.
13 - Fate of data after the termination of the contract
Following termination of the Contract, the Client will have a period of one (1) month to request in writing the return, in a raw file format and under its own responsibility, of its recordings; failing such a request within this period, RINGO may proceed with the definitive destruction of all data, including logs and back-ups.
14 - Data Protection Officer
RINGO has a Data Protection Officer who might be contacted by email at dpo@modjo.ai.
15 - Record of processing activities
RINGO undertakes to keep an up-to-date Record of processing activities carried out in its capacity as Processor, including the following information:
● the name and contact details of the Controller, any sub-processors and the Data Protection Referent;
● the categories of processing carried out on behalf of the Controller;
● any transfers of Personal Data to countries outside the European Union and evidence of the existence of appropriate safeguards;
● a general description of the technical and organisational security measures put in place.
16 - RINGO responsibilities
For the duration of the Contract concluded between RINGO and the Client:
● RINGO guarantees the confidentiality of the Personal Data processed in its capacity as a Processor and ensures that the members of its staff who are authorised to process the Personal Data respect this principle of confidentiality and have received the necessary training in this regard
● RINGO undertakes to take into account the principle of protection of Personal Data by design and by default, with regard to the tools, products, applications or services that it uses
●
17 - Client’s responsibilities
The Client undertakes to collect and process Personal Data in compliance with applicable data protection and labour regulations, in particular regarding the methods, basis and purposes of the processing, the duration of retention of Personal Data,the rights of the Data Subjects and the information given to them.
In particular, the Client undertakes to comply with all regulations and obligations applicable to the Processing of employees’ data and to the processing of special categories of Personal Data (such as health data, religious beliefs, sexual orientation, etc.) and to carry out, prior to their Processing, the necessary verifications, studies and impact analyses, to inform Data Subjects according to articles 12, 13 and 14 of GDPR and to obtain, where applicable, the consent of the Data Subjects with regard to the collection and processing of their personal data and, in particular, the recording of their voice.
The Client undertakes to provide RINGO with all the information required to carry out the intended Processing activities in compliance with all applicable regulations and to document any instructions concerning the Processing.
The Client undertakes to provide to RINGO the Personal Data identified in Article 1 of this Contract and to guarantee the lawfulness and the accuracy of the data. The Client also undertakes to ensure the effectiveness of the rights of the Data Subjects.
The Client indemnifies RINGO against any claim or action in this respect.
The Client undertakes to supervise the Processing, including carrying out at its own expense the necessary audits and inspections of RINGO or to ensure at its own expense the conduct or defense of the interests of the parties in the context of any action, procedure or control.
Annex 1 : List of Permitted Sub-processors