TASKING Data Processing Addendum

Ver­sion 1.0 Feb­ru­ary 2025 

1. DEFINITIONS 

“Applic­a­ble Data Pro­tec­tion Law” shall mean any and all applic­a­ble manda­to­ry data pro­tec­tion and pri­va­cy laws.  

Data Con­troller”“Data Proces­sor”“Data Sub­ject”, “Person­al Data” shall have the mean­ings giv­en in Applic­a­ble Data Pro­tec­tion Laws. 

“EU Data Pro­tec­tion Law” the EU-Gen­er­al Data Pro­tec­tion Reg­u­la­tion (“GDPR”, Reg­u­la­tion 2016/679) as  amend­ed  or super­seded from time to time. 

“Swiss  Data  Pro­tec­tion  Law”  the  Swiss  Fed­er­al  Act  on  Data  Pro­tec­tion  (Revised  FADP) as  amend­ed  or super­seded from time to time. 

“UK  Data  Pro­tec­tion  Law”  the  data  pri­va­cy  leg­is­la­tion  adopt­ed  by  the  Data  Pro­tec­tion,  Pri­va­cy  and  Elec­tron­ic Com­mu­ni­ca­tions  (Amend­ments  etc.)  (EU  Exit)  Reg­u­la­tions  2019/419  as  sup­ple­ment­ed  by  the  terms  of  the  Data Pro­tec­tion Act 2018 (UK DPA) and the UK GDPR (Retained Regulation(EU) 2016/679 (UK GDPR) pur­suant to sec­tion 3 of the Euro­pean Union (With­draw­al) Act 2018), as amend­ed or super­seded from time to time. 

“Ade­quate   Coun­try” a   coun­try   that   the Euro­pean Com­mis­sion, the Unit­ed Kingdom’s (“UK”) Infor­ma­tion Commissioner’s Office or the Swiss Fed­er­al Data Pro­tec­tion and Infor­ma­tion Com­mis­sion­er (as applic­a­ble based on respec­tive area of com­pe­tence) has deter­mined as ensur­ing an ade­quate lev­el of data pro­tec­tion. 

“Third Coun­try” a coun­try out­side of the EU, EEA, the UK or Switzer­land (as applic­a­ble) which is not an Ade­quate Coun­try.  

“Sub­proces­sor”, means “TASKING Group enti­ty” (a com­pa­ny con­trol­ling, con­trolled by or under com­mon con­trol with TASKING that may assist in the per­for­mance of the Ser­vices) or a “Third Par­ty Sub­proces­sor” (a third-par­ty sub­con­trac­tor, oth­er than a TASKING Group enti­ty, engaged by TASKING which, as part of the subcontractor’s role of deliv­er­ing the Ser­vices or parts of the Ser­vices, will process Per­son­al Data of the Cus­tomer). 

“Stan­dard Con­trac­tu­al Claus­es” means Stan­dard Con­trac­tu­al Claus­es for the trans­fer of Per­son­al Data to third coun­tries pur­suant to Reg­u­la­tion (EU) 2016/679 of the Euro­pean Par­lia­ment and the Coun­cil approved by Euro­pean Com­mis­sion Imple­ment­ing Deci­sion (EU) 2021/914 of 4 June 2021, as cur­rent­ly set out at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj as may be amend­ed, super­seded or replaced 

2. PROCESSING OF PERSONAL DATA  

In order to exe­cute the Agree­ment, and in par­tic­u­lar to per­form the Ser­vices, Cus­tomer appoints TASKING as a Data Proces­sor to process the Per­son­al Data spec­i­fied and for the pur­pos­es described in the Terms and Con­di­tions and Annex I. TASKING shall not retain, use or dis­close data for any oth­er pur­pose, includ­ing retain­ing, using or dis­clos­ing the Data for a com­mer­cial pur­pose oth­er than the Per­mit­ted Pur­pose. TASKING shall not buy or sell the Data. TASKING will com­ply with all manda­to­ry Applic­a­ble Data Pro­tec­tions Law to the extent that such pro­vi­sions by their terms impose oblig­a­tions direct­ly upon TASKING as a Data Proces­sor in con­nec­tion with the ser­vices spec­i­fied in the Agree­ment or Terms and Con­di­tions. 

If TASKING process­es Per­son­al Data for Ser­vice avail­abil­i­ty and secu­ri­ty pur­pos­es, TASKING is the Data Con­troller.  

Cus­tomer will at all times remain the Data Con­troller for the pur­pos­es of the Ser­vices, the Agree­ment, and this Data Pro­cess­ing Agree­ment. Cus­tomer is respon­si­ble for com­pli­ance with its oblig­a­tions as a Data Con­troller under Applic­a­ble Data Pro­tec­tion Law, in par­tic­u­lar for jus­ti­fi­ca­tion of any trans­mis­sion of Per­son­al Data to TASKING (includ­ing pro­vid­ing any required notices and obtain­ing any required con­sents and autho­riza­tions), and for its deci­sions and actions con­cern­ing the pro­cess­ing and use of the Per­son­al Data. 

3. COOPERATION AND RIGHTS OF DATA SUBJECTS 

Tak­ing into account the nature of the pro­cess­ing, TASKING will fol­low Customer’s detailed writ­ten instruc­tions to access, delete, release, cor­rect or block Per­son­al Data held in Ser­vices envi­ron­ment if this can­not be done with the Cus­tomer him­self. 

Inso­far this is pos­si­ble, TASKING shall pro­vide rea­son­able and time­ly assis­tance to Cus­tomer to enable Cus­tomer to respond to a) any request from a data sub­ject to exer­cise any of its rights under Applic­a­ble Data Pro­tec­tion Law and b) any oth­er cor­re­spon­dence, enquiry or com­plaint received from a data sub­ject, reg­u­la­tor or any oth­er third par­ty in con­nec­tion with the pro­cess­ing of data.  

In the event that any such request, cor­re­spon­dence or com­plaint is direct­ly made to TASKING, TASKING will prompt­ly inform Cus­tomer pro­vid­ing full details of the same. TASKING will not be respon­si­ble for respond­ing direct­ly to the request, unless oth­er­wise required by law. 

4. DATA PROTECTION IMPACT ASSESSMENT 

TASKING shall pro­vide Cus­tomer with rea­son­able coop­er­a­tion (pro­vide the infor­ma­tion nec­es­sary) to enable Cus­tomer to con­duct any manda­to­ry data pro­tec­tion impact assess­ment that is required to under­take under Applic­a­ble Data Pro­tec­tion Law. 

5. DATA INCIDENT OR DATA BREACH 

If TASKING becomes aware of a data inci­dent or data breach, TASKING shall inform Cus­tomer with­out undue delay and shall pro­vide rea­son­able infor­ma­tion and coop­er­a­tion to Cus­tomer so that Cus­tomer can ful­fil any data breach report­ing oblig­a­tions it may have under Applic­a­ble Data Pro­tec­tion Law. TASKING shall fur­ther take such rea­son­able nec­es­sary mea­sures and actions to mit­i­gate the effects of the data inci­dent or data breach and shall keep Cus­tomer informed of all mate­r­i­al devel­op­ments in con­nec­tion with the data inci­dent or data breach. 

6. INTERNATIONAL TRANSFERS & DATA LOCALIZATION LAWS 

6.1 If any Data is pro­tect­ed under EU Data Pro­tec­tion Law, TASKING shall not trans­fer the Data to a Third Coun­try with­out Ade­qua­cy Deci­sion unless it has tak­en such mea­sures as are manda­to­ry and nec­es­sary to ensure the trans­fer is in com­pli­ance with EU  Data Pro­tec­tion Law. Such mea­sure may include (with­out lim­i­ta­tion) trans­fer­ring the Data to a recip­i­ent a) that has achieved bind­ing cor­po­rate rules autho­ri­sa­tion in accor­dance with Applic­a­ble Data Pro­tec­tion Law, b) that has exe­cut­ed Stan­dard Con­trac­tu­al Claus­es adopt­ed or approved by Euro­pean Com­mis­sion or sim­i­lar.  

6.2. If Per­son­al Data pro­tect­ed under “EU Data Pro­tec­tion Law” is trans­ferred to a TASKING enti­ty in a Third Coun­try, the Stan­dard Con­trac­tu­al Claus­es, UK adden­dum and Swiss adden­dum will be incor­po­rat­ed by ref­er­ence and form part of the Data Pro­cess­ing Agree­ment as fol­lows:   

(A) The Mod­ule Three  (Proces­sor to Proces­sor) terms apply to the extent TASKING is a Proces­sor of Cus­tomer Per­son­al Data and trans­fers the Per­son­al Data to anoth­er TASKING enti­ty in a Third Coun­try; in Clause 7, the option­al dock­ing clause applies; in Clause 9, Option 2 applies and changes to Sub-Proces­sors will be noti­fied in accor­dance with the ‘Sub­pro­cess­ing’ sec­tion of this Data Pro­cess­ing Agree­ment; in Clause 11, the option­al lan­guage is delet­ed;  in Claus­es 17 and 18, the par­ties agree that the gov­ern­ing law and forum for dis­putes for the Stan­dard Con­trac­tu­al Claus­es will be deter­mined in accor­dance with the Agree­ment or Terms and Con­di­tions; if not spec­i­fied this will be the law of Ger­many; the Annex­es of the Stan­dard Con­trac­tu­al Claus­es will be deemed com­plet­ed with the infor­ma­tion set out in the Annex­es of this DPA; and the super­vi­so­ry author­i­ty that will act as com­pe­tent super­vi­so­ry author­i­ty will be deter­mined in accor­dance with GDPR. 

6.3 For Data orig­i­nat­ing from the Unit­ed King­dom (“UK”) or Switzer­land ref­er­ences in this Sec­tion 8 to: (a) “EU Data Pro­tec­tion Law” shall be replaced with “UK Data Pro­tec­tion Law” or “Swiss Data Pro­tec­tion Law”, as applic­a­ble; and  (b) the “Euro­pean Com­mis­sion” shall be replaced with the “Infor­ma­tion Commissioner’s Office” or the “Fed­er­al Data Pro­tec­tion and Infor­ma­tion Com­mis­sion­er”, as applic­a­ble. 

6.4 If Cus­tomer is placed in a third-coun­try the Mod­ule Three  (Proces­sor to Con­troller) terms apply to the extent TASKING is a Proces­sor of Cus­tomer Per­son­al Data and trans­fers the Per­son­al Data to Cus­tomer in a third-coun­try; in Claus­es 17 and 18, the par­ties agree that the gov­ern­ing law and forum for dis­putes for the Stan­dard Con­trac­tu­al Claus­es will be deter­mined in accor­dance with the Agree­ment or Terms and Con­di­tions; if not spec­i­fied this will be the law of Ger­many; (vi) the Annex­es of the Stan­dard Con­trac­tu­al Claus­es will be deemed com­plet­ed with the infor­ma­tion set out in the Annex­es of this DPA. 

7. SUBPROCESSING 

Cus­tomer con­sents to TASKING engag­ing any TASKING affil­i­ate if rel­e­vant for the pur­pos­es of this Agree­ment with­out spe­cif­ic con­sent and with­out pri­or noti­fi­ca­tion. TASKING may use exist­ing TASKING Intra­group trans­fer mech­a­nisms for pro­cess­ing activ­i­ties. Upon request, the cus­tomer receives an overview of the affil­i­ates who have received Per­son­al Data. TASKING remains liable for any breach of the Agree­ment that is caused by an act, error or omis­sion of its affil­i­ate.  

Cus­tomer con­sents to TASKING engag­ing third-par­ty sub­proces­sors as pro­vid­ed in Annex III to process Per­son­al Data for the pur­pos­es as defined in Annex I. TASKING shall a) impose data pro­tec­tion terms on any third-par­ty sub­proces­sor it appoints that require it to pro­tect the Per­son­al Data to the stan­dard required by Applic­a­ble Data Pro­tec­tion Law, b) remain liable for any breach of the Agree­ment that is caused by an act, error or omis­sion of its third-par­ty sub­proces­sor and c) update the sub­proces­sor List with details of any change in third-par­ty sub­proces­sors with appro­pri­ate advance notice to the Cus­tomer. Cus­tomer may object to TASKING’s appoint­ment or replace­ment of a third-par­ty sub­proces­sor pri­or to its appoint­ment or replace­ment, pro­vid­ed such objec­tion is based on rea­son­able ground relat­ing to data pro­tec­tion. 

8. SECURITY AND CONFIDENTIALITY 

TASKING has imple­ment­ed and will main­tain appro­pri­ate tech­ni­cal and orga­ni­za­tion­al  mea­sures to ensure a lev­el of secu­ri­ty appro­pri­ate to the risk, as spec­i­fied in Arti­cle 32 of the GDPR for the pro­cess­ing of Per­son­al Data as set out in Annex II. These mea­sures are intend­ed to pro­tect Per­son­al Data against acci­den­tal or unau­tho­rized loss, destruc­tion, alter­ation, unau­tho­rized dis­clo­sure of or access to the Per­son­al Data, and against all oth­er unlaw­ful forms of Pro­cess­ing. TASKING’s Infor­ma­tion Secu­ri­ty Man­age­ment Sys­tem (ISMS) is cer­ti­fied. 

The tech­ni­cal and organ­i­sa­tion­al mea­sures are sub­ject to tech­ni­cal progress and fur­ther develop­ment. In this respect, it is per­mis­si­ble for TASKING to imple­ment alter­na­tive ade­quate mea­sures. In so doing, the secu­ri­ty lev­el of the defined mea­sures must not be reduced. Sub­stan­tial changes must be doc­u­ment­ed. 

TASKING shall process Per­son­al Data as con­fi­den­tial infor­ma­tion and shall only share it with autho­rized indi­vid­u­als who need access to the Per­son­al Data for the pur­pos­es and are sub­ject  to a statu­to­ry or con­trac­tu­al duty of con­fi­den­tial­i­ty or as explic­it­ly per­mit­ted under the Agree­ment. 

TASKING has cer­ti­fi­ca­tions (e.g. infor­ma­tion secu­ri­ty cer­tifi­cates) in place. If evi­dence for the cer­ti­fi­ca­tions is nec­es­sary, this can be shared on request. 

9. RETURN AND DELETION OF PERSONAL DATA UPON END OF SERVICES 

Fol­low­ing ter­mi­na­tion of the Ser­vices, TASKING will return or delete the Customer’s Per­son­al Data as spec­i­fied in the Agree­ment or Terms and Con­di­tions. Cus­tomer has the pos­si­bil­i­ty to delete data itself as described in Annex I.  

Exclud­ed from this is data TASKING has to keep because of legal oblig­a­tions. In this case this data will be blocked so that pro­cess­ing is restrict­ed.  

ANNEX I   

LIST OF PARTIES  

Data exporter:  

Name: The Cus­tomer, as defined in the Agreement/Service plat­form.  

Address: The Cus­tomer’s address, as set out in the Agreement/Service plat­form.  

Con­tact person’s name, posi­tion, and con­tact details, includ­ing email: The Customer’s con­tact details, as set out in the Agreement/Service plat­form.  

Activ­i­ties rel­e­vant to the data trans­ferred under these Claus­es: As set out in the Agree­ment or Terms and Con­di­tions and Annex I. 

Role (controller/processor): Data Con­troller  

Data Importer:  

Name: TASKING Ger­many GmbH and fur­ther TASKING affil­i­ates (if rel­e­vant for the activ­i­ties) 

Address: Stre­it­feld­strasse 19, 81673 Munich, Ger­many 

Con­tact person’s name, posi­tion, and con­tact details: Pri­va­cy con­tact as men­tioned in the web­site pri­va­cy pol­i­cy https://www.tasking.com/privacy-policy; tech­ni­cal sup­port via the tick­et­ing sys­tem. 

Activ­i­ties rel­e­vant to the data trans­ferred under these Claus­es: As set out in the Agree­ment or Terms and Con­di­tions and Annex I. 

Role (controller/processor): Data Proces­sor 

DESCRIPTION OF TRANSFER  

Cat­e­gories of data sub­jects whose Per­son­al Data is trans­ferred:  

  • Cus­tomer employ­ees or third-par­ty employ­ees work­ing for the cus­tomer 

Cat­e­gories of Per­son­al Data trans­ferred:  

  • Title 
  • Full name 
  • Cor­po­rate e‑mail address 
  • Cor­po­rate phone num­ber 
  • Com­pa­ny name 
  • Depart­ment 
  • Com­pa­ny address (street, city, ZIP, coun­try) 
  • Time­zone 
  • Pass­word (masked) 
  • No sen­si­tive Per­son­al Data is trans­ferred. 

The fre­quen­cy of the trans­fer:  

  • Con­tin­u­ous data trans­fer dur­ing the con­trac­tu­al relationship/during the use of the ser­vices. 

Nature of the pro­cess­ing:  

  • Data Col­lec­tion 
  • Data Stor­age 

Purpose(s) of the data trans­fer and fur­ther pro­cess­ing:  

  • Pro­vi­sion of the TASKING Sup­port tick­et­ing sys­tem for sup­port requests and for file exchange. 
  • Set up the autho­riza­tions in the plat­form on behalf of the Cus­tomer. 

The peri­od for which the Per­son­al Data will be retained, or, if that is not pos­si­ble, the cri­te­ria used to deter­mine that peri­od: 

  • The Cus­tomer can anonymize Per­son­al Data with­in tick­ets him­self.  
  • If the con­trac­tu­al rela­tion­ship ends/the ser­vices are not used any­more the Per­son­al Data will be anonymized/deleted. 

For trans­fers to (sub-) proces­sors, also spec­i­fy sub­ject mat­ter, nature and dura­tion of the pro­cess­ing:  

  • As defined in Annex III. 

COMPETENT SUPERVISORY AUTHORITY 

The com­pe­tent Super­vi­so­ry Author­i­ty is the author­i­ty with­in the Mem­ber State of the Data Exporter. If the Data Exporter is not locat­ed with­in the EU, the Super­vi­so­ry Author­i­ty of Bavaria (Ger­many) is defined as the com­pe­tent Super­vi­so­ry Author­i­ty. 

 ANNEX II  

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA  

The TASKING TOMs in accor­dance with Art. 32 GDPR can be sent to the cus­tomer on request. Please con­tact TASKING as stat­ed in the web­site pri­va­cy pol­i­cy https://www.tasking.com/privacy-policy or by con­tact­ing dataprotection@tasking.com

ANNEX III  

LIST OF SUB-PROCESSORS 

Name: Google Cloud EMEA Lim­it­ed  

Address: Velas­co Clan­william Place Dublin 2 Ire­land 

Descrip­tion of pro­cess­ing (includ­ing a clear delim­i­ta­tion of respon­si­bil­i­ties in case sev­er­al sub-proces­sors are autho­rized): Google Cloud Plat­form (data host­ing, Europe West data cen­ters) 

Scroll to Top