Data Processing Agreement

Security · Subprocessors · Business Terms · Data Processing Agreement · User Terms · Privacy Policy · Legal Notice

Download this DPA (plain text)

1. Scope and roles

This DPA applies to business use of Naayya under the Business Terms, including when you create a business account or sign an order form, with Naayya SARL as the Processor. The business is the Controller for customer data Naayya processes on its documented instructions. The Controller determines the lawful purposes and legal bases. Processing by Naayya as a separate controller, such as its own billing and account administration, is described in the Privacy Policy. Applicable data-protection law includes the GDPR and the Swiss Federal Act on Data Protection where applicable.

2. Processing details

Subject matter: provision of the subscribed business-management platform. Duration: the agreement and the return/deletion period below. Nature and purpose: hosting, organising, retrieving, communicating and exporting records for bookings, attendance, memberships, packages, credits, payment administration, customer communications and support, to the extent enabled by the Controller. Data subjects include customers, prospects, authorised staff and other individuals whose data the Controller lawfully supplies. Data may include identity and contact details, booking and attendance history, memberships, packages, credits, expiry dates, payment references and records, communications and account information. Optional health or safety disclosures may be processed only on lawful documented instructions with a valid additional legal condition where required. The Controller must limit sensitive data to what is necessary.

3. Instructions and confidentiality

Naayya processes personal data only on documented instructions, including for transfers, unless applicable law requires otherwise; we inform the Controller of such a requirement before processing unless prohibited by law. We inform the Controller if an instruction appears to infringe applicable data-protection law. Persons authorised to process the data must be bound by confidentiality duties. We do not use Controller data for unrelated purposes merely because we provide the platform.

4. Security measures

Taking account of the state of the art, implementation costs and the nature, scope, context, purposes and risks of processing, Naayya maintains appropriate technical and organisational measures. These include access restrictions based on role and need, authentication controls, protection of data in transmission, secure handling of credentials, incident-response procedures, and measures supporting availability and restoration. Our public Security page (Security & Data Protection) describes the hosting, backup/restoration and security arrangements. Naayya also makes additional relevant details available to the Controller on request. Specific schedules supplied with an order form form part of this DPA.

5. Subprocessors

The Controller grants general written authorisation for subprocessors identified in the provider register (Provider register) supplied or made available when this DPA is accepted. Naayya shall provide their identity, purpose and relevant processing-location information. Naayya shall notify the Controller at least thirty days before adding or replacing a subprocessor, allowing a reasoned data-protection objection during that period. The parties will seek a reasonable alternative; if none is available, the Controller may terminate the affected service before the change takes effect, with a refund of unused prepaid subscription fees for that service. Naayya imposes materially equivalent data-protection obligations on subprocessors and remains responsible for their performance as required by law.

6. Assistance and individual rights

Taking account of the nature of processing and information available, Naayya assists the Controller with data-subject requests, security obligations, breach notifications, impact assessments and prior consultations. Requests received directly are referred to the Controller where appropriate; Naayya does not independently decide the Controller’s response unless legally required. Assistance does not transfer the Controller’s responsibility for its own lawful processing.

7. Personal-data breaches

Naayya notifies the Controller without undue delay after becoming aware of a personal-data breach affecting data processed under this DPA. Available information will describe the nature of the breach, affected data and individuals where known, likely consequences, measures taken or proposed and a contact for follow-up. Information may be provided in phases as it becomes available. General support response windows do not delay this notification.

8. International transfers

Naayya uses a lawful transfer mechanism whenever applicable law requires one: an applicable adequacy decision, or the safeguards set out in the Transfers Annex, which forms part of this DPA. The applicable subprocessor information identifies relevant locations. EU primary hosting does not mean that every provider operation or support access takes place exclusively in the EU. For Swiss-regulated transfers, references and safeguards are adapted as required by Swiss law.

9. Information and audits

Naayya makes available information necessary to demonstrate compliance with this DPA and allows and contributes to audits, including inspections, by the Controller or its mandated auditor. The parties first use reasonably sufficient documentation where appropriate. Routine inspections require reasonable notice, confidentiality and coordination to minimise disruption and protect other customers. Such arrangements must not prevent an audit reasonably required following a breach, suspected non-compliance or a regulator’s request. Each party bears its own routine costs unless otherwise agreed or required by law.

10. Return and deletion

The Controller may request a standard exit export during the agreement or within sixty days after termination. The export scope is described in the Business Terms; delivery is within thirty days of request through a secure method. If a timely request remains outstanding at the end of the sixty-day period, the requested data is retained until delivery and for at least fourteen days for retrieval. At the Controller’s choice, Naayya returns or deletes personal data after the end of the service and deletes remaining copies unless applicable law requires retention. Backup copies remain protected, are not used for active processing and are removed under the applicable backup-retention schedule made available to the Controller. Legally retained data is restricted to the required purpose.

11. Relationship to the agreement

The agreement’s liability provisions apply between the parties to the extent lawful. This DPA does not restrict the rights of data subjects, supervisory authorities or liabilities that cannot be limited. It prevails over inconsistent commercial terms concerning personal-data processing. Luxembourg law and the agreed courts apply subject to mandatory law. Contact support@naayya.com for data-protection matters or to request the applicable security and subprocessor schedules.

Transfers Annex

This Annex applies to a transfer of personal data processed under this DPA that requires a transfer mechanism under applicable data-protection law (a restricted transfer).

A. EU Standard Contractual Clauses. For restricted transfers subject to the GDPR, the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (the SCCs) are incorporated into this DPA by reference, as follows.

Module Two (controller to processor) applies to a restricted transfer from the Controller, as data exporter, to Naayya, as data importer.

Module Three (processor to processor) applies to a restricted transfer from Naayya, as data exporter, to a subprocessor outside the EEA, as data importer. Naayya puts Module Three in place with that subprocessor, or relies on part C where it applies.

Clause 7 (docking clause) applies. Under Clause 9, option 2 (general written authorisation) applies, with the notice period in section 5. The optional wording in Clause 11 does not apply. Under Clause 17, option 1 applies and the SCCs are governed by Luxembourg law. Under Clause 18, the courts of Luxembourg have jurisdiction.

Annex I.A (list of parties): for Module Two, the Controller, as identified in its account or order form, is the data exporter, and Naayya (Naayya SARL, 13 rue Dideschpont, L-3622 Kayl, Luxembourg, support@naayya.com) is the data importer. For Module Three, Naayya is the data exporter and the subprocessor is the data importer. Acceptance of this DPA by the Controller and Naayya counts as their signature of Annex I.A for Module Two.

Annex I.B (description of transfer): as described in section 2, including the data subjects, the categories of personal data, any sensitive data and the nature and purpose of processing. Transfers are continuous for the duration of the agreement, and retention follows section 10. For Module Three, the purpose and location of each subprocessor’s processing are listed in the provider register (Provider register).

Annex I.C (competent supervisory authority): the authority determined under Clause 13. Where Naayya is the data exporter, this is the Commission nationale pour la protection des données (CNPD), Luxembourg.

Annex II (technical and organisational measures): the measures described in section 4, on the Security page (Security & Data Protection) and in any security schedule supplied with an order form.

Annex III (list of subprocessors): the provider register (Provider register), as updated under section 5.

B. UK International Data Transfer Addendum. For restricted transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022) (the UK Addendum) is incorporated into this DPA by reference and amends the SCCs in part A for those transfers. Tables 1 to 3 of the UK Addendum are completed with the information in part A. For Table 4, neither party may end the UK Addendum under its Section 19. The Mandatory Clauses of the UK Addendum apply, as revised by the Information Commissioner under their Section 18.

C. EU–US Data Privacy Framework. For a transfer to a subprocessor in the United States that is certified under the EU–US Data Privacy Framework, Naayya may rely on the European Commission’s adequacy decision for that Framework (Commission Implementing Decision (EU) 2023/1795) and, for transfers subject to the UK GDPR, on the UK Extension to it, within the scope of the certification. If the certification lapses or the Framework stops being a valid transfer mechanism, Naayya relies on the SCCs under part A, and the UK Addendum under part B, instead.

If the SCCs or the UK Addendum conflict with the rest of this DPA, the SCCs or the UK Addendum prevail.