1. Roles and subject matter
The customer is the controller and CasBizz Holding B.V. is the processor for personal data in screen content and related service data. This agreement forms part of the ScreenText agreement and applies for as long as we process that data on the customer’s behalf.
2. Processing and data subjects
Processing consists of temporarily receiving, storing in encrypted form and transmitting screen content, managing sessions and, only after explicit approval, providing temporary support access. The data may relate to employees, guests, customers or other people named in text submitted by the customer. The customer determines which categories of data it submits and avoids unnecessary special-category personal data.
3. Instructions and confidentiality
We process the data only on the customer’s documented instructions, except where required by law. People with access are bound by confidentiality obligations. If we believe an instruction infringes data protection law, we will inform the customer.
4. Security
Appropriate measures include end-to-end encryption using AES-256-GCM, TLS transport, role-based access, strong authentication, organisational separation, temporary and explicitly approved support access, audit logging and deletion of encrypted session content when a session ends.
5. Sub-processors
The customer gives general authorisation for sub-processors required for hosting, infrastructure, email and backups. We impose appropriate data protection obligations on them and remain responsible for their performance. We will notify the customer of a material new sub-processor so that it may object on reasonable grounds.
Mollie processes payment data for the contractual and billing relationship and is not a sub-processor of screen content for that processing.
6. Data breaches and assistance
We will notify the customer without undue delay of a confirmed security incident involving its personal data and provide available information needed for its notification obligations. Taking account of the nature of the processing, we will provide reasonable assistance with data subject requests, risk assessments and consultations with supervisory authorities.
7. Transfers, audits and information
Transfers outside the EEA take place only on a valid legal basis and with appropriate safeguards. We make information available that allows the customer to assess compliance with Article 28 GDPR. Any additional audit must be agreed in advance and must not unreasonably disrupt security or service delivery.
8. End of processing
Temporary screen content is deleted when a session is closed or expires. At the end of the main agreement, we will delete or return other personal data on request, except for data we are legally required to retain.
9. Contact
Questions about this Data Processing Agreement can be sent to info@casbizz.nl.