GDPR, article 28
Data processing annex
Monitoring a domain means reading reports that contain IP addresses. Running a phishing simulation means emailing the client's staff. Both are personal data processed on someone else's behalf, and these are the terms on which it happens.
Last updated
01
Roles of the parties
The client determines the purposes and means of the processing: it is the controller. Tom Gernez, trading as Ruvalin, acts on its behalf and on its instructions: he is the processor within the meaning of article 28 GDPR.
This annex forms an integral part of the services contract. It prevails over any conflicting provision of the terms of service
02
What is processed
- Purposes
- monitoring domain authentication, producing reports, running awareness campaigns
- Nature of the operations
- collection, consultation, analysis, aggregation, temporary storage, deletion
- Data subjects
- the client's staff and contractors receiving a simulation; individuals identifiable from the IP addresses appearing in reports
- Data processed
- business email addresses, sender IP addresses, header metadata, timestamps, campaign results
- Data excluded
- no content of the client's mail, no special category data within article 9, no access to mailboxes
- Duration
- the term of the engagement plus the agreed retention period, thirteen months by default for reports
03
Instructions
The processor processes the data only on documented instructions from the client, including as regards transfers outside the European Union. The signed contract and this annex constitute the initial instructions.
Where an instruction appears to him to infringe the GDPR or another data protection provision, the processor informs the client immediately and may suspend performance until written confirmation is given.
05
Security
Having regard to the state of the art and the nature of the data, the following measures are implemented (article 32 GDPR):
- encryption of all traffic in transit;
- two-factor authentication on every tool used;
- least privilege, and separation of data by client;
- minimisation: reports are worked with in aggregate form as soon as the analysis allows;
- logging of access to the data entrusted;
- automatic deletion of data once the agreed period expires.
06
Sub-processors
The client authorises the use of the following sub-processors, which offer sufficient guarantees and are bound by obligations equivalent to those in this annex:
- Vercel Inc.
- site hosting and cookieless audience measurement — United States
- Google Ireland Ltd.
- business email and receipt of DMARC reports; appointment scheduling, loaded only if you ask for it — Ireland, with transfers to the United States
- Notion Labs, Inc.
- prospect file and client relationship records — United States
- Allo
- business telephony and call history — European Union
Any addition or replacement is notified to the client thirty days in advance, during which it may object on legitimate data protection grounds. Failing a solution, it may terminate the service concerned without compensation.
07
Simulation campaigns: one particular rule
A phishing simulation produces, by its nature, the names of the people who clicked. Those individual results are not passed to the client: only aggregate statistics are, together with the collective lessons to draw from them.
This is not a preference, it is a condition of the engagement. The point of a campaign is vigilance, not finding someone to blame, and an exercise used to discipline an employee would be diverted from its stated purpose. The client further undertakes to inform its staff beforehand and to consult employee representative bodies where the law requires it.
08
Assistance to the client
- Data subject rights: the processor forwards any request received without delay and assists in answering it within the one-month period.
- Impact assessment: he provides the technical information needed should the client have to carry one out.
- Data breach: he notifies the client within forty-eight hours of becoming aware of the incident, with what is then known, and assists with notification to the CNIL and, where required, to the data subjects.
- Records: he maintains the record of categories of processing carried out on the client's behalf and makes it available.
09
What happens to the data at the end
At the end of the engagement, and at the client's written choice, the data is returned in a readable format and then deleted, or deleted outright. Deletion takes place within thirty days, including backup copies as their rotation cycle allows, and is confirmed in writing. Retention required by law is reserved.
10
Documentation and audit
The processor makes available to the client all information needed to demonstrate compliance with article 28, and allows for audits, including inspections, conducted by the client or an auditor it mandates, subject to reasonable notice, an annual frequency, and respect for the confidentiality of other clients.
11
Transfers outside the European Union
Any transfers to third countries rest on an adequacy decision, on the recipient's certification under the Data Privacy Framework, or on the European Commission's standard contractual clauses, supplemented by appropriate technical measures.
The processing Ruvalin carries out on its own account is set out in the privacy policy
12
Contact
Any question about this annex, including from the client's data protection officer: contact@ruvalin.com, or +33 6 44 64 17 13.