Pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR)
This Data Processing Agreement forms part of the contractual relationship between Chronos Web Tech Kft. ("Processor") and the customer using the Appointio service ("Controller"). The purpose is to establish the terms under which the Processor processes personal data on behalf of the Controller in connection with the Appointio online appointment scheduling platform.
Processing activities may include collection of appointment information, storage of customer records, synchronization with connected calendar services, processing of reminder notifications, invoicing-related processing, technical support, system maintenance, and secure backup creation. The Processor shall process personal data exclusively for the purpose of providing the Services.
Depending on the Controller's use, personal data may include names, email addresses, telephone numbers, appointment details, billing information, communication history, IP addresses, technical device information, and calendar event information where Google Calendar integration is enabled. Processing may relate to customers, prospective customers, employees, contractors, business partners, and other individuals whose personal data is entered into the Services by the Controller.
The Processor shall process personal data only on documented instructions from the Controller unless otherwise required by applicable law. Personnel authorized to process personal data are subject to confidentiality obligations, receive appropriate privacy and security training, and access personal data only where necessary. Confidentiality obligations survive termination of employment and termination of this Agreement.
The Processor implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risks associated with the processing. Measures may include encryption in transit using TLS, encrypted backups, secure authentication mechanisms, access control, least privilege principles, security monitoring, logging, regular software updates, vulnerability management, and malware protection.
The Controller grants general authorization for the Processor to engage subprocessors, provided that the Processor carefully selects subprocessors, equivalent data protection obligations are imposed by contract, and the Processor remains responsible for the performance of its subprocessors. An up-to-date list of subprocessors is maintained separately.
Where personal data is transferred outside the European Economic Area (EEA), the Processor shall ensure that appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms recognized under the GDPR.
The Processor shall provide reasonable assistance to enable the Controller to comply with obligations relating to data subject requests, security obligations, personal data breach notifications, data protection impact assessments (DPIAs), and prior consultation with supervisory authorities where required.
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller. The notification shall include, where available, the nature of the breach, categories of affected data, likely consequences, measures taken or proposed, and contact information for follow-up.
Upon termination of the Services, the Controller may request return of personal data in a structured, commonly used, and machine-readable format where technically feasible; or secure deletion of personal data, unless retention is required by law. Backups containing personal data shall be deleted in accordance with the Company's Data Retention & Deletion Policy.
Upon reasonable prior notice, the Controller may request information demonstrating the Processor's compliance with this Agreement. Where appropriate, the Processor may satisfy audit requests by providing security documentation, compliance reports, certifications (if any), audit summaries, or independent assessments. Physical on-site audits shall be subject to reasonable confidentiality, security, and operational requirements.
Each party shall remain responsible for its own compliance with applicable data protection legislation. This Agreement shall be governed by the laws applicable to the main service agreement unless otherwise agreed between the parties. In the event of any conflict between this Agreement and the main service agreement regarding personal data processing, this Agreement shall prevail to the extent of that conflict.