Neotouch Data Processing Addendum (Article 28 of the GDPR)
SECTION I
Clause 1 - Purpose and scope
a) The purpose of these standard contractual clauses (hereinafter the ‘Clauses’) is to ensure compliance with Article 28, paragraphs 3 and 4, of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
b) The controllers and processors listed in Annex I have accepted these clauses in order to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 and/or the provisions of Article 29(3) and (4) of Regulation (EU) 2018/1725.
c) These clauses apply to the processing of personal data as described in Annex II.
d) Annexes I to IV form an integral part of these clauses.
e) These clauses are without prejudice to the obligations to which the controller is subject under Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.
f) These clauses alone are not sufficient to ensure compliance with the obligations relating to international transfers in accordance with Chapter V of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.
Clause 2 - Invariability of the Clauses
a) The Parties undertake not to amend the clauses, except in respect of the addition of information to the annexes or the updating of the information contained therein.
b) The Parties are not, however, prevented from including the standard contractual clauses set out in these clauses in a broader contract, nor from adding other clauses or additional safeguards, provided that these do not directly or indirectly contradict the clauses or infringe upon the fundamental rights and freedoms of the data subjects.
Clause 3 - Interpretation
a) Where terms defined in Regulation (EU) 2016/679 or in Regulation (EU) 2018/1725 appear in the clauses, they shall have the same meaning as in the relevant Regulation.
b) These clauses must be read and interpreted in the light of the provisions of Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 respectively.
c) These clauses must not be interpreted in a manner contrary to the rights and obligations set out in Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or in a manner that infringes upon the fundamental rights or freedoms of data subjects.
Clause 4 - Hierarchy
In the event of any conflict between these Clauses and the provisions of any related agreements existing between the parties at the time these clauses are agreed or which are concluded subsequently, these clauses shall prevail.
Clause 5 - Annex
a) Any entity that is not a party to these clauses may, with the agreement of all Parties, accede to them at any time, either as a data controller or as a data processor, by completing the annexes and signing Annex I.
b) Once the annexes referred to in point (a) have been completed and signed, the acceding entity shall be deemed a party to these clauses and shall enjoy the rights and be subject to the obligations of a data controller or a data processor, in accordance with its designation in Annex I.
c) These clauses do not create any rights or obligations for the adhering party for the duration of the adherence period.
SECTION II - OBLIGATIONS OF THE PARTIES
Clause 6 - Description of the processing operation(s)
Details of the processing operations, including the categories of personal data and the purposes of the processing for which personal data are processed on behalf of the data controller, are set out in Annex II.
Clause 7 - Obligations of the parties
7.1 Instructions
a) The processor shall process personal data only on documented instructions from the controller, unless required to do so by Union law or the law of the Member State to which the processor is subject. In such a case, the processor shall inform the controller of that legal obligation prior to processing, unless prohibited from doing so by law on important grounds of public interest. Further instructions may also be given by the controller at any time during the processing of personal data. Such instructions must always be documented.
b) The processor shall immediately inform the controller if, in its opinion, an instruction given by the controller constitutes a breach of Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or other provisions of Union law or the law of the Member States relating to data protection.
7.2 Purpose limitation
The processor shall process personal data only for the specific purpose(s) of the processing, as set out in Annex II, unless further instructions are given by the controller.
7.3 Duration of the processing of personal data
Processing by the processor shall take place only for the duration specified in Annex II.
7.4 Security of processing
a) The processor shall implement at least the technical and organisational measures specified in Annex III to ensure the security of personal data. These measures include the protection of data against any security breach leading, accidentally or unlawfully, to the destruction, loss, alteration, unauthorised disclosure of personal data or unauthorised access to such data (personal data breach). When assessing the appropriate level of security, the parties shall take due account of the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to data subjects.
b) The processor shall grant its staff access to the personal data being processed only to the extent strictly necessary for the performance, management and monitoring of the contract. The processor shall ensure that persons authorised to process personal data undertake to respect confidentiality or are subject to an appropriate legal obligation of confidentiality.
7.5 Sensitive data
The processing does not involve sensitive data within the meaning of the GDPR. As such, such data may not be subcontracted for the purposes agreed under the main contract initially concluded between the parties.
7.6 Documentation and compliance
a) The parties must be able to demonstrate compliance with these clauses.
b) The processor shall deal promptly and appropriately with requests from the controller regarding the processing of data in accordance with these clauses.
c) The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations set out in these clauses and arising directly from Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. At the request of the controller, the processor shall also allow and assist in audits of the processing activities covered by these clauses, at reasonable intervals or where there are indications of non-compliance. When deciding on an inspection or audit, the controller may take into account any relevant certifications held by the processor.
d) The data controller may decide to carry out the audit itself or to appoint an independent auditor. Audits may also include inspections at the data processor’s premises or physical facilities and shall, where appropriate, be carried out subject to reasonable notice. Audits may be carried out subject to a minimum notice period of 15 days. In the event of a conflict of interest with the third-party auditor, the processor may refuse the audit, provided that the refusal is justified in writing to the data controller. In such a case, the data controller may propose another third-party auditor or carry out the audit itself.
e) The parties shall make the information set out in this clause, including the results of any audit, available to the competent supervisory authority/authorities upon request.
7.7 Use of subprocessors
a) GENERAL WRITTEN AUTHORISATION: the processor has the data controller’s general authorisation to engage subprocessors from an agreed list. The processor shall specifically inform the controller in writing of any proposed changes to this list by adding or replacing subprocessors at least twenty-five (25) days in advance, thereby giving the controller sufficient time to object to such changes before the relevant subprocessor(s) are engaged. The processor shall provide the controller with the information necessary to enable the controller to exercise its right to object.
b) Where the processor engages a subprocessor to carry out specific processing activities (on behalf of the controller), it shall do so by means of a contract which imposes on the subprocessor, in substance, the same data protection obligations as those imposed on the processor under these clauses. The processor shall ensure that the subprocessor complies with the obligations to which the processor itself is subject under these clauses and Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.
c) At the request of the controller, the processor shall provide the controller with a copy of this contract concluded with the subprocessor and of any subsequent amendments thereto. To the extent necessary to protect trade secrets or other confidential information, including data processing (Article 28 of the GDPR) personal data, the processor may redact the text of the contract before distributing a copy.
d) The processor remains fully liable to the controller for the performance of the subprocessor’s obligations in accordance with the contract concluded with the subprocessor. The processor shall inform the controller of any breach by the subprocessor of its contractual obligations.
7.8 International transfers
a) Any transfer of data to a third country or an international organisation by the processor shall be carried out only on the basis of documented instructions from the controller or in order to comply with a specific requirement of Union law or the law of the Member State to which the processor is subject, and shall be carried out in accordance with Chapter V of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725.
b) The controller agrees that where the processor engages a subprocessor in accordance with clause 7.7 to carry out specific processing activities (on behalf of the controller) and those processing activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the processor and the subprocessor may ensure compliance with Chapter V of Regulation (EU) 2016/679 by using the standard contractual clauses adopted by the Commission on the basis of Article 46(2) of Regulation (EU) 2016/679, provided that the conditions for the use of those standard contractual clauses are met.
Clause 8 - Assistance to the controller
a) The processor shall inform the controller without delay of any request it has received from the data subject. It shall not act on that request itself, unless authorised to do so by the controller.
b) The processor shall assist the controller in fulfilling its obligation to respond to requests from data subjects to exercise their rights, taking into account the nature of the processing. In carrying out its obligations under points (a) and (b), the processor shall comply with the controller’s instructions.
c) In addition to the processor’s obligation to assist the controller under Clause 8(b), the processor shall also assist the controller in ensuring compliance with the following obligations, taking into account the nature of the processing and the information available to the processor:
1. the obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (‘data protection impact assessment’) where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons;
2. the obligation to consult the competent supervisory authority/authorities prior to processing where a data protection impact assessment indicates that the processing would result in a high risk unless the controller takes measures to mitigate the risk;
3. the obligation to ensure that personal data is accurate and up to date, by informing the controller without delay if the processor becomes aware that the personal data it processes is inaccurate or has become out of date;
d) the obligations set out in Article 32 of Regulation (EU) 2016/679. The parties shall set out in Annex III the appropriate technical and organisational measures by which the processor is required to assist the controller in the application of this clause, as well as the scope and extent of the assistance required.
Clause 9 - Notification of personal data breaches
In the event of a personal data breach, the processor shall cooperate with the controller and assist the controller in complying with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679 or Articles 34 and 35 of Regulation (EU) 2018/1725, whichever is applicable, taking into account the nature of the processing and the information available to the processor.
9.1 Data breach relating to data processed by the controller
In the event of a personal data breach relating to data processed by the controller, the processor shall assist the controller:
a) for the purposes of notifying the personal data breach to the competent supervisory authority/competent supervisory authorities as soon as possible after the controller becomes aware of it, where applicable (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);
b) for the purpose of obtaining the following information which, in accordance with Article 33(3) of Regulation (EU) 2016/679, must be included in the data controller’s notification, and shall include, at a minimum:
1. the nature of the personal data, including, where possible, the categories and approximate number of data subjects affected by the breach and the categories and approximate number of personal data records concerned;
2. the likely consequences of the personal data breach;
3. the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate any adverse consequences.
Where, and to the extent that, it is not possible to provide all the information at the same time, the initial notification shall contain the information available at that time and, as further information becomes available, it shall be provided as soon as possible;
c) for the purposes of complying, in accordance with Article 34 of Regulation (EU) 2016/679, with the obligation to communicate the personal data breach to the data subject as soon as possible, where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.
9.2 Data breaches relating to data processed by the processor
In the event of a personal data breach relating to data processed by the processor, the processor shall notify the controller without undue delay after becoming aware of it. This notification shall contain at least:
a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects affected by the breach and the personal data records concerned);
b) the contact details of a point of contact from whom further information may be obtained regarding the personal data breach;
c) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate any adverse consequences.
Where, and to the extent that, it is not possible to provide all the information at the same time, the initial notification shall contain the information available at that time and, as further information becomes available, it shall be provided as soon as possible.
The parties shall set out in Annex III all other information that the processor must provide when assisting the controller in fulfilling the latter’s obligations under Articles 33 and 34 of Regulation (EU) 2016/679.
SECTION III. FINAL PROVISIONS
Clause 10 - Breach of clauses and termination
a) Without prejudice to the provisions of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725, in the event of a breach by the processor of its obligations under these clauses, the controller may instruct the processor to suspend the processing of personal data until the processor has complied with these clauses or until the contract is terminated. The processor shall promptly inform the controller if it is unable to comply with these clauses, for whatever reason.
b) The controller shall be entitled to terminate the contract insofar as it relates to the processing of personal data in accordance with these clauses if:
1. the processing of personal data by the processor has been suspended by the controller in accordance with point (a) and compliance with these clauses is not restored within a reasonable period and, in any event, within one month of the suspension;
2. the processor is in serious or persistent breach of these clauses or of its obligations under Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725;
3. The processor fails to comply with a binding decision of a competent court or the competent supervisory authority/competent supervisory authorities concerning its obligations under these clauses or Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.
c) The processor shall be entitled to terminate the contract insofar as it relates to the processing of personal data under these clauses where, after informing the controller that its instructions breach the applicable legal requirements in accordance with clause 7.1(b), the controller insists that its instructions be followed.
d) Following termination of the contract, the processor shall, at the controller’s discretion, all personal data processed on behalf of the controller and certify to the controller that it has done so, or return all personal data to the controller and destroy existing copies, unless Union or national law requires them to be retained for a longer period. The processor shall continue to ensure compliance with these clauses until the data has been deleted or returned.
ANNEX I - List of parties
Data controller(s):
Name: Customer, as specified in the contract.
Name, role and contact details of the contact person for data protection matters: as specified in the contract.
Data processor:
Name: QUADIENT France
Represented by Stéphanie AUCHABIE, with full authority for the purposes hereof
Address: 7 Rue Henri Becquerel 92500 RUEIL-MALMAISON
Position and contact details of the contact person for data protection matters: Data Protection Officer (France), privacyteam@quadient.com.
ANNEX II - Description of the processing
Categories of data subjects whose personal data are processed:
The Client’s employees who use the solution
Recipients of mailings
The Client’s customers
Categories of personal data processed:
Personal data relating to the Client: surname, first name, postal address, telephone/fax number, email address, job title where applicable, and any personal data contained in the documents processed;
Data relating to the Client’s authorised NEOTOUCH Users and Administrators: email address, work telephone number, surname, first name, profession, contact details and username of persons authorised to interact with the solution. This refers to the information transmitted by the platform when the Client creates user accounts;
Login details of the Client’s authorised NEOTOUCH Users and Administrators: username, IP address, date and time.
Nature of the processing: From the Neotouch platform, collection, organisation, archiving, consultation and distribution of the Client’s outsourced correspondence.
Purposes for which personal data is processed on behalf of the Data Controller:
Forwarding of documents to recipients
Archiving of documents for future reference
Creation and management of user accounts
Providing assistance to authorised users where necessary (support)
Forwarding documents from the platform to the relevant parties
Compliance with contractual obligations
Post-event invoicing of Clients
Maintenance / Patches
Duration of processing: duration of the contract.
ANNEX III - Technical and organisational measures, including those designed to ensure data security
Notwithstanding any additional measures agreed in the main contract, Quadient has implemented and will maintain the following security measures for the company’s and the client’s data (the “data”), which, together with the security commitments in this Data Processing Agreement (“DPA”) (including the provisions of the GDPR), constitute Quadient’s sole liability with regard to the security of such data.
Scope | Practices |
Organisation of information security | Ownership of security. Quadient has appointed one or more security officers responsible for coordinating and monitoring security policies and procedures. Security roles and responsibilities. Quadient staff with access to data are subject to confidentiality obligations. Risk management programme. Quadient has carried out a risk assessment prior to processing the data or launching the relevant service. Quadient retains its security documents in accordance with its retention requirements after they have ceased to be in force. |
Physical and Environmental Security | Physical access to premises. Quadient restricts access to facilities housing information systems that process data to identified authorised personnel. |
Asset management | Asset Inventory. Quadient maintains an inventory of all assets on which data is stored. Access to these asset inventories is restricted to Quadient staff authorised in writing to access them. Handling of assets. - Quadient classifies data in order to identify it and restrict access to it appropriately. - Quadient imposes restrictions on the printing of data and has procedures in place for the disposal of printed documents containing data. - Quadient staff must obtain Quadient’s authorisation before storing data on portable devices, accessing data remotely or processing data outside Quadient’s premises. |
Human Resources Security | Security training. Quadient informs its staff of the relevant security procedures and their respective roles. Quadient also informs its staff of the possible consequences of breaching security rules and procedures. Quadient uses only anonymised data for training purposes. Protection against disruptions. Quadient uses a variety of industry-standard systems to protect against data loss due to power failure or line interference. Data deletion. Quadient uses industry-standard processes to delete data when it is no longer required. |
Communications and Operations Management | Operational policy. Quadient maintains security documentation describing its security measures and the relevant procedures and responsibilities of its staff with access to data. Data Recovery Procedures. - On an ongoing basis, but in any event no less frequently than once a week (unless no updates have taken place during that period), Quadient maintains multiple backups of the data from which such data can be recovered. - Quadient stores the Data backups and data recovery procedures in a location separate from that of the main IT equipment processing the Data. - Quadient has implemented specific procedures governing access to Data backups. - Quadient records data restoration efforts, including the person responsible, a description of the restored Data and, where applicable, the person responsible and the Data (if any) that had to be entered manually during the data restoration process. Malware. Quadient has anti-malware controls in place to prevent malware from gaining unauthorised access to data, including malware originating from public networks Data across borders. - Quadient encrypts data transmitted over public networks. - Quadient restricts access to data on media leaving its premises. Event logging. Quadient logs access to and use of information systems containing data, recording the access ID, time, authorisation granted or denied, and the relevant activity. |
Access Control | Access policy. Quadient maintains a register of the security privileges of individuals with access to data. Access authorisation. - Quadient maintains and updates a register of staff authorised to access Quadient systems containing data. - Quadient deactivates authentication credentials that have not been used for a period not exceeding six months. - Quadient identifies the staff who can grant, modify or revoke authorised access to data and resources. - Quadient ensures that these individuals have separate usernames/logins. Need-to-know. - Technical support staff are only authorised to access data on a need-to-know basis. - Quadient restricts access to data to only those individuals who require such access to perform their duties. Integrity and confidentiality. - Quadient requires its staff to log out of administrative sessions when leaving Quadientcontrolled premises or when computers are left unattended. - Quadient stores passwords in a way that renders them unreadable whilst they are in use. Authentication. - Quadient uses industry-standard practices to identify and authenticate users attempting to access information systems. - Where authentication mechanisms are password-based, Quadient requires that password management be configured so that the password is changed immediately if there is a risk that it has been compromised. - Where authentication mechanisms are password-based, Quadient requires that the password be at least thirteen characters long. - Quadient ensures that deactivated or expired credentials are not reissued to other individuals. - Quadient monitors repeated attempts to access the information system using an invalid password. - Quadient maintains industry-standard procedures for deactivating passwords that have been compromised or inadvertently disclosed. - Quadient uses password protection practices that comply with industry standards, including practices designed to maintain the confidentiality and integrity of passwords when they are assigned and distributed, and whilst they are in storage. Network design. Quadient has controls in place to prevent individuals from assuming access rights that have not been assigned to them to access data to which they are not authorised to have access. |
Information Security Incident Management | Incident response process. - Quadient maintains a record of security breaches, including a description of the breach, the timeframe, the consequences of the breach, the source of the report, and the key mitigation and recovery measures. - For each breach constituting a security incident, Quadient will provide notification without undue delay. Service Monitoring. - Quadient’s operations staff check logs on a regular basis to propose corrective measures where necessary. |
Business Continuity Management | - Quadient maintains emergency and contingency plans for the facilities housing Quadient’s information systems that process data. Quadient’s redundant storage and data recovery procedures are designed to attempt to restore the Data to its original state or to the last state reproduced prior to the time it was lost or destroyed. |
ANNEX IV - List of Quadient France’s subprocessors
NATURE OF OPERATIONS | NATURE OF THE SUBCONTRACTOR SUBPROCESSOR OF QUADIENT FRANCE | ADDRESS | CERTIFICATIONS | PERSONAL DATA (PD) PROCESSED |
Collect, process, use, archive, organise, transfer. Electronic signature of the invoice and validation of the electronic signature. Archiving. Electronic Mail dispatch. System monitoring without data replication by US teams to ensure 24/7 platform availability. Digitisation of SEPA direct debits and online payment processing. Sending and receiving faxes. Third-party provider of electronic registered mail in accordance with the 2011 decree. Sending SMS messages. | Esker S.A. | 113 Boulevard de la Bataille de Stalingrad, 69100, Villeurbanne, France. | ISO 27001. | User’s first and last name, work email address, job title and telephone number. Esker shares PDFs of documents, including invoices, so any personal data contained within the document (either as metadata or within the PDF). Contact details of email recipients. Surname, first name, title, email address and telephone number of the end customer’s contact. Recipient’s fax number and personal data contained in the file sent in TIF format + name, address, home telephone number and fax number during portability operations. Information used to identify the recipient of an LRE: surname, first name, email address, SMS number, language and Personal Data contained in the documents sent. Personal data contained in a message and telephone number. |
In the interests of transparency regarding information and communications, below is a list of Esker S.A.’s potential subsequent processors (Esker S.A. itself being a subsequent processor of QUADIENT France)
NAME OF THE SUBPROCESSOR | ADDRESS | NATURE OF THE | PERSONAL DATA PROCESSED |
Esker S.A. | 113 Boulevard de la Bataille de Stalingrad, 69100, Villeurbanne. | Collect, process, use, archive, organise, transfer. | User’s first and last name, work email address, job title and telephone number. |
Trustweaver | 195 Boulevard Saint-Germain, 75007, Paris. | Electronic archiving. | All DCPs contained in the document (either as metadata or within the PDF). |
Ricoh BE | Medialaan 28A, 1800, Vilvoorde, Belgium. | Esker sends the PDFs along with any DCP contained within the document (either as metadata or within the PDF. | |
Esker, Inc. Esker Inc. is a wholly-owned subsidiary of Esker and has has obtained Data Privacy Framework certification | 1212 Deming Way, Suite 350, Madison, Wisconsin, 53717. | Replication of the platform’s user database and sending of emails. | User contact details (surname, first name, email address and work telephone number) / contact details of email recipients. |
Slimpay | 12, rue Godot de Mauroy, 75009 Paris. | Digitisation of SEPA direct debits and processing of online payments. | Surname, first name, title, email address and telephone number of the end customer’s contact. |
Colt | Sending and receiving faxes. | Recipient’s fax number and DCP contained in the file sent in TIF format + Surname, address, home telephone number and fax number during portability operations. | |
Equisign | 76 Rue de la Demi Lune, 92057 Paris La Défense. | Third-party provider of registered electronic mail within the meaning of the 2011 decree. | Information used to identify the recipient of an LRE: surname, first name, email address, mobile number, language and DCP contained in the documents sent. |
SMSBOX | SMS transmission. | DCPs contained in a message and telephone number. |











