Ruvalin

GDPR, article 28

Data processing annex

Monitoring a domain means reading reports that contain IP addresses. Running a phishing simulation means emailing the client's staff. Both are personal data processed on someone else's behalf, and these are the terms on which it happens.

Last updated

01

Roles of the parties

The client determines the purposes and means of the processing: it is the controller. Tom Gernez, trading as Ruvalin, acts on its behalf and on its instructions: he is the processor within the meaning of article 28 GDPR.

This annex forms an integral part of the services contract. It prevails over any conflicting provision of the terms of service

02

What is processed

Purposes
monitoring domain authentication, producing reports, running awareness campaigns
Nature of the operations
collection, consultation, analysis, aggregation, temporary storage, deletion
Data subjects
the client's staff and contractors receiving a simulation; individuals identifiable from the IP addresses appearing in reports
Data processed
business email addresses, sender IP addresses, header metadata, timestamps, campaign results
Data excluded
no content of the client's mail, no special category data within article 9, no access to mailboxes
Duration
the term of the engagement plus the agreed retention period, thirteen months by default for reports

03

Instructions

The processor processes the data only on documented instructions from the client, including as regards transfers outside the European Union. The signed contract and this annex constitute the initial instructions.

Where an instruction appears to him to infringe the GDPR or another data protection provision, the processor informs the client immediately and may suspend performance until written confirmation is given.

04

Confidentiality and authorised persons

The data is accessible only to those whose involvement the engagement requires, bound by confidentiality and trained in the applicable rules. As the practice is run by one person, that access is in practice limited to the publisher and, for the engagements concerned alone, to expressly named partner engineers.

05

Security

Having regard to the state of the art and the nature of the data, the following measures are implemented (article 32 GDPR):

  • encryption of all traffic in transit;
  • two-factor authentication on every tool used;
  • least privilege, and separation of data by client;
  • minimisation: reports are worked with in aggregate form as soon as the analysis allows;
  • logging of access to the data entrusted;
  • automatic deletion of data once the agreed period expires.

06

Sub-processors

The client authorises the use of the following sub-processors, which offer sufficient guarantees and are bound by obligations equivalent to those in this annex:

Vercel Inc.
site hosting and cookieless audience measurement — United States
Google Ireland Ltd.
business email and receipt of DMARC reports; appointment scheduling, loaded only if you ask for it — Ireland, with transfers to the United States
Notion Labs, Inc.
prospect file and client relationship records — United States
Allo
business telephony and call history — European Union

Any addition or replacement is notified to the client thirty days in advance, during which it may object on legitimate data protection grounds. Failing a solution, it may terminate the service concerned without compensation.

07

Simulation campaigns: one particular rule

A phishing simulation produces, by its nature, the names of the people who clicked. Those individual results are not passed to the client: only aggregate statistics are, together with the collective lessons to draw from them.

This is not a preference, it is a condition of the engagement. The point of a campaign is vigilance, not finding someone to blame, and an exercise used to discipline an employee would be diverted from its stated purpose. The client further undertakes to inform its staff beforehand and to consult employee representative bodies where the law requires it.

08

Assistance to the client

  • Data subject rights: the processor forwards any request received without delay and assists in answering it within the one-month period.
  • Impact assessment: he provides the technical information needed should the client have to carry one out.
  • Data breach: he notifies the client within forty-eight hours of becoming aware of the incident, with what is then known, and assists with notification to the CNIL and, where required, to the data subjects.
  • Records: he maintains the record of categories of processing carried out on the client's behalf and makes it available.

09

What happens to the data at the end

At the end of the engagement, and at the client's written choice, the data is returned in a readable format and then deleted, or deleted outright. Deletion takes place within thirty days, including backup copies as their rotation cycle allows, and is confirmed in writing. Retention required by law is reserved.

10

Documentation and audit

The processor makes available to the client all information needed to demonstrate compliance with article 28, and allows for audits, including inspections, conducted by the client or an auditor it mandates, subject to reasonable notice, an annual frequency, and respect for the confidentiality of other clients.

11

Transfers outside the European Union

Any transfers to third countries rest on an adequacy decision, on the recipient's certification under the Data Privacy Framework, or on the European Commission's standard contractual clauses, supplemented by appropriate technical measures.

The processing Ruvalin carries out on its own account is set out in the privacy policy

12

Contact

Any question about this annex, including from the client's data protection officer: contact@ruvalin.com, or +33 6 44 64 17 13.

CallBook