PART A — PERSONAL DATA PROCESSING POLICY FOR THE PRUSA CONNECT SERVICE
1. This Personal Data Processing Policy for the use of the Prusa Connect service (hereinafter the “Connect Data Processing Policy”) supplements the Prusa Privacy Policy (hereinafter the “General Privacy Policy”), available on the Operator’s website, in relation to the Connect Services. The General Privacy Policy remains unaffected by the Connect Data Processing Policy and applies to all processing of personal data within the offering of the PRUSA services; the Connect Data Processing Policy only regulates and supplements the specifics arising from the nature of the Connect Services.
2. Capitalised terms that are not defined in this Connect Data Processing Policy have the meaning set out in the Terms and Conditions for Prusa Link, Prusa Connect and Prusa Connect Farm (hereinafter the “Connect Terms”) or in the General Privacy Policy.
3. This Connect Data Processing Policy applies to all Users who activate, order or use the Connect Services, for the duration of their use. In the event of a conflict between the General Privacy Policy and this Connect Data Processing Policy, the Connect Data Processing Policy shall prevail in relation to the Connect Services.
4. The controller of personal data issuing this Connect Data Processing Policy is Prusa Research a.s., Id. No.: 06649114, with its registered office at Partyzánská 188/7a, Holešovice, 170 00 Prague 7, Czech Republic (hereinafter the “Operator”). Contact address for data protection matters: [email protected].
Prusa Connect and Prusa Connect Farm are cloud services (SaaS) within which personal data pass through the Operator’s servers. From a data protection perspective, what is decisive is not whether the basic Prusa Connect service or Prusa Connect Farm is used, but rather the nature of their use. If a natural person uses these services exclusively for personal or household activity, the exception for purely personal or household activity applies and the Operator, in relation to such person’s data, acts as an independent controller. If, on the other hand, the service is used within an Organisation (business, professional, educational, research, hobby or other than personal or household activity), it is necessary to distinguish two distinct roles in which the Operator acts in relation to personal data:
In relation to personal data for which the Operator itself determines the purposes and means of processing, it acts as an independent controller. This concerns, in particular:
This processing is governed by the General Privacy Policy and this Connect Data Processing Policy. The legal bases and retention periods are based on the General Privacy Policy.
In relation to personal data that the User enters into, uploads to, or processes through the service on behalf of the Organisation within an activity other than personal or household activity, and for which the Organisation determines the purposes and means, the Operator acts as a processor and the Organisation as a controller. This concerns, in particular:
For this processing, the Organisation is the controller, which determines the purposes and means and bears, towards the persons concerned, in particular the information obligation under Articles 13 and 14 of the GDPR. The relationship between the Organisation (controller) and the Operator (processor) is governed by a personal data processing agreement pursuant to Article 28 of the GDPR (hereinafter also the “DPA”) — see the annex to this Connect Data Processing Policy.
Important notice for the Organisation Representative: If you enter into the service personal data of third parties (in particular Team members as employees or collaborators, end customers from a marketplace or persons captured by a camera system), the Organisation on whose behalf you act is the controller in relation to such data. The Organisation is responsible for the lawful basis of the processing, for fulfilling the information obligation towards the persons concerned, and for compliance with data protection and labour law regulations. The Operator processes such data only in accordance with the Organisation’s instructions on the basis of the DPA (see the annex to this Connect Data Processing Policy).
The overview below summarises the main categories of personal data processed in connection with the service and the Operator’s role:
| Examples | Operator’s role | |
|---|---|---|
| Identification and accounting (account) | name, e-mail, PRUSA ACCOUNT ID, billing data, subscription | Controller |
| Operational and security | access logs, IP address, technical identifiers | Controller |
| Team member data | name, e-mail, role, permissions, activity and usage records within the Team | Processor* |
| Content and production data | print tasks, files, orders, material data (if they contain personal data) | Processor* |
| API / marketplace data | data of end customers in orders transmitted via the connector | Processor* |
| Camera streams and recordings | video streams from printers / workplace capturing persons | Processor* |
* Processor on behalf of the Organisation — the Organisation is the controller; the regime is governed by the DPA (see the annex to this Connect Data Processing Policy).
The following applies to processing for which the Operator is the controller:
| Legal basis (GDPR) | Retention period | |
|---|---|---|
| Provision and operation of the Connect Services | performance of a contract — Art. 6(1)(b) | for the duration of the use of the service and 5 years from the last login (see General Privacy Policy) |
| Security, prevention of misuse, stability of the service | legitimate interest — Art. 6(1)(f) | as a rule up to 12 months, unless a longer period is necessary |
| Invoicing and fulfilment of legal obligations | legal obligation — Art. 6(1)(c) | for the period laid down by law (tax/accounting regulations) |
| Development and improvement of the service | legitimate interest — Art. 6(1)(f); preferably aggregated/pseudonymised data | for the period necessary for the given purpose |
1. Prusa Connect Farm contains functions for the automatic distribution of print tasks, planning, analytics and performance evaluation of production resources. These functions serve exclusively for the coordination of printers and production resources and are of a supporting nature.
2. The Operator does not operate these functions for the purpose of automated individual decision-making or profiling of natural persons within the meaning of Article 22 of the GDPR. Any use of the outputs of these functions for the evaluation, monitoring or management of natural persons (in particular Team members) is exclusively at the decision and responsibility of the Organisation Representative; in such a case the Organisation is the controller and is responsible for compliance with the GDPR and employment regulations (see Article 5.5 of the Connect Terms).
1. For camera streams and recordings made available within the service, the Organisation is the controller. The Organisation is responsible in particular for the lawful basis for operating the camera system, for fulfilling the information obligation towards the persons concerned, and for setting the scope and retention period of the recordings.
2. For data transmitted via API integrations and marketplace connectors, the Operator provides only a technical interface and acts as a processor on behalf of the Organisation. The Operator does not verify the content or accuracy of such data and does not process it for its own purposes.
1. The range of recipients and categories of recipients, as well as the conditions for any transfer of personal data outside the European Economic Area, are governed by the General Privacy Policy. For processing where the Operator is a processor on behalf of the Organisation, the engagement of sub-processors and transfers outside the EEA are governed by the DPA – see the annex to this Connect Data Processing Policy.
2. For any transfer of personal data outside the EEA, the Operator shall ensure appropriate safeguards pursuant to Chapter V of the GDPR, in particular the standard contractual clauses adopted by the European Commission.
1. The rights of data subjects (access, rectification, erasure, restriction, portability, objection, withdrawal of consent, complaint to a supervisory authority) and the manner of their exercise are governed by the General Privacy Policy.
2. If the rights concern personal data for which the Operator is a processor on behalf of the Organisation (in particular Team member data), the Organisation, as controller, is competent to handle them. If such a person contacts the Operator, the Operator shall, without undue delay, refer them to the Organisation and provide the Organisation with cooperation under the DPA (see the annex to this Connect Data Processing Policy).
1. This Connect Data Processing Policy becomes effective on 01.10.2026. The Operator is entitled to update the Connect Data Processing Policy to a reasonable extent; it shall inform the User of material changes in a manner similar to Article 10.2 of the Connect Terms.
2. The current version of the Connect Data Processing Policy is always available on the Operator’s website together with the Connect Terms and the General Privacy Policy.
This Data Processing Agreement (the "DPA") forms an integral part of the Connect Data Processing Policy, of which it constitutes an annex, and supplements the Prusa Connect, Prusa Link and Prusa Connect Farm Terms and Conditions (the "Connect Terms"). It governs the processing of personal data by Prusa Research a.s., registered office at Partyzánská 188/7A, 170 00 Prague 7, Czech Republic (the "Processor"), on behalf of the Organisation (the "Controller") in connection with the use of the Prusa Connect Services (the "Services").
For the purposes of this DPA, "Organisation" and "Organisation Representative" have the meaning given to them in the Connect Terms. The Controller is the Organisation on whose behalf the Services are used for professional or otherwise non-personal/non-household purposes. This DPA is entered into on behalf of the Organisation by the Organisation Representative.
This DPA takes effect upon activation or ordering of the Services by the Organisation Representative on behalf of the Organisation. By activating, ordering or using the Services on behalf of the Organisation, the Organisation Representative accepts this DPA and confirms that they are authorised to represent the Organisation and to bind it to this DPA. If you are not so authorised, do not accept this DPA and do not provide personal data on behalf of the Organisation. Where a natural person uses the Services exclusively for personal or household purposes, no controller–processor relationship arises and this DPA does not apply.
The Parties enter into this DPA to ensure compliance with applicable EU Data Protection Laws, in particular the General Data Protection Regulation (GDPR), in the context of the Processor’s provision of the Services under the Connect Terms (the “Master Agreement”).
The terms listed in this DPA shall have the meanings assigned to them below.
“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
“EU Data Protection Laws” means the laws and regulations relating to the processing of personal data under applicable law that may apply to the Parties to this DPA, including but not limited to the GDPR and any national implementations of the GDPR.
“Processor” means Prusa Research a.s., with its registered office at Partyzánská 188/7A, 170 00 Prague 7, Czech Republic, as the operator of the PRUSA CONNECT Service. This term also has the meaning set forth in the EU Data Protection Laws.
“Controller” means the Organisation that determines the scope and purposes of the processing of personal data carried out by the Processor through the Services, and on whose behalf this DPA is entered into by the Organisation Representative. The Controller has the meaning of “controller” under the EU Data Protection Laws.
“Organisation” and “Organisation Representative” have the meaning given in the Connect Terms.
“Processing”, “Supervisory Authority” and “Personal Data Breach” each has the meaning set forth in the EU Data Protection Laws.
“Data Subject” has the meaning given in the EU Data Protection Laws and includes any corresponding terminology that refers to a natural person whose personal data is processed.
“Subprocessor” has the meaning set forth in the EU Data Protection Laws and designates a Subprocessor of the Processor authorised by the Controller as described below.
“Personal Data” means any personal data (as defined in the EU Data Protection Laws) that is provided and/or transferred to the Processor by or on behalf of the Controller pursuant to this DPA.
“Services” means the Prusa Connect and Prusa Connect Farm services, cloud remote printing solutions developed in-house and operated by the Processor. The Services form part of the Connect Services as defined in the Connect Terms.
“Standard Contractual Clauses“ means the standard contractual clauses for the transfer of personal data to third countries, as approved by the European Commission in Commission Implementing Decision (EU) 2021/914, or any set of clauses approved by the European Commission which amends or supersedes these.
“EU“ means the European Union.
“EEA“ means the European Economic Area.
2.1 In the course of providing the Services to the Controller pursuant to the Master Agreement, the Processor has access and need to process the Personal Data. Therefore, the Controller hereby commissions the Processor to process the Personal Data, as further specified herein, on behalf and in accordance with the instructions of the Controller as set forth herein.
2.2 Accordingly, the Processor shall, on behalf of the Controller, process the Personal Data.
2.3 For the avoidance of doubt the Parties agree that the Processor shall not be authorised to process the Personal Data for any other purposes than those specified in this DPA, and in particular for the Processor's own purposes.
3.1 The Processor shall process the Personal Data provided by the Controller solely in accordance with documented instructions and the provisions contained in this DPA and specific instructions that the Controller may issue at its discretion at any time. The Controller in particular may give instructions regarding type, extent and method of the data processing, within the limits of the technology used.
3.2 If the Processor is of the opinion that an instruction infringes the EU Data Protection Laws, it shall immediately notify the Controller.
4.1 The Processor shall only process the types of Personal Data relating to the categories of data subjects and for the specific purposes set out in Annex 1 hereto and shall not process, transfer, modify, amend or alter the Controller’s Personal Data or disclose or permit the disclosure of the Controller’s Personal Data to any third party other than in accordance with the Controller’s documented instructions, unless the processing is required by EU law or the law of an EU Member State to which the Processor is subject, in which case the Processor shall to the extent permitted by such law inform the Controller of that legal requirement before processing that Personal Data.
5.1 The DPA shall be effective from the Effective Date until the Services requiring processing of Personal Data on behalf of the Controller are terminated, in any event not later than until the termination of the Master Agreement, subject to points 5.2 and 5.3.
5.2 If the Processor commits a material breach of any provision of this DPA, the Controller may call in writing on the Processor to remedy the breach within a period specified by the Controller. If the breach is not remedied after the aforesaid notice period has expired, the Controller will be entitled, but not compelled, in addition to its rights in terms of this DPA and under applicable law, to terminate this DPA with immediate effect on further written notice to the Processor. A material breach of any provision of this DPA shall also be considered as a material breach of the Master Agreement.
5.3 The expiration or termination of this DPA shall not affect such provisions of this DPA which are expressly provided to operate after any such expiration or termination, or which of necessity must continue to have effect after such expiration or termination, notwithstanding that the relevant provisions themselves do not provide for this. Without derogating from or limiting the foregoing, this point 5.3 and sections 13., 15. and 16. shall continue in full force and effect after expiration or termination of this DPA.
6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, within the Processor’s area of responsibility the Processor shall structure their internal corporate organisation to ensure compliance with the specific requirements of the protection of the Personal Data. The Processor shall take at its own cost and expense the appropriate technical and organisational measures to adequately protect the Personal Data against misuse and loss in accordance with the requirements of applicable data protection regulations. In relation to the Personal Data measures hereunder shall include, but not be limited to:
6.1.1 the ability to ensure the ongoing security, confidentiality, integrity, availability and resilience of processing systems, networks and services;
6.1.2 the ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident;
6.1.3 a process for regularly monitoring, testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing;
6.1.4 the prevention of unauthorised persons’ gaining access to data processing systems (physical access control),
6.1.5 the prevention of data processing systems being used without authorisation (logical access control),
6.1.6 the Processor shall keep Personal Data logically separate from data processed on behalf of any third party,
6.1.7 applying encryption and pseudonymisation of the Personal Data, where appropriate;
6.1.8 ensuring that persons entitled to use a data processing system gain access only to such Personal Data as they are entitled to access in accordance with their legitimate access rights, and that, in the course of processing or use and after storage, Personal Data cannot be read, copied, modified or deleted without authorisation (data access control),
6.1.9 ensuring that the Personal Data cannot be read, copied, modified or deleted without authorisation during electronic transmission, transport or storage on storage media, and that the target entities for any transfer of the Personal Data by means of data transmission facilities can be established and verified (data transfer control),
6.1.10 ensuring the establishment of logging and an audit trail to document whether and by whom the Personal Data have been entered into, modified in, or removed from data processing systems (entry control),
6.1.11 maintaining an information security policy and security incident management and continuity plans, consisting of, among others, a clarification with regard to the analysis performed and the risk management of personal data, a description of various responsibilities and organisational rules, description of how security incidents are managed, the measure that were introduced to keep the security system up-to-date after installation;
6.1.12 organising information security by means of selection of an information security lead who has the necessary competences, is adequately trained, ensures that various responsibilities with regard to information security have been clearly, ensures that the responsibilities defined in the information policy are performed and who cannot discharge any function nor take up any responsibility that is incompatible with the information security governance role;
6.1.13 ensuring physical environment security, for instance by means of security and surveillance regarding building, premises and installations where carriers of personal data and computer systems processing the data are positioned, as well as prevention, detection and operating procedure in the case of fire, intrusion and water damage,
6.1.14 maintaining complete and up-to-date documentation proportionate to the risk profile of the processing operations, including, but not limited to, technical documentation of implemented security measures and other information necessary to demonstrate compliance with the requirements of this DPA,
6.1.15 ensuring that the Personal Data is processed solely in accordance with the relevant Controller’s instructions (control of instructions).
6.2 A measure as referred to in point 6.1 above shall be in particular, but shall not be limited to, the use of state-of-the-art encryption technology.
6.3 In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
6.4 The Processor shall assist the Controller in ensuring compliance with the obligations set forth in Articles 32 to 36 of the GDPR and maintain a record of processing activities under the Processor's responsibility, with relation to the Personal Data (in accordance and on terms as specified in Article 30 of the GDPR).
6.5 Without prejudice to point 10.1, the Processor shall, without undue delay, inform the Controller in case of a serious interruption of operations, suspicion of breaches of data protection, and any other irregularity in processing the Data.
6.6 The Processor shall, without undue delay, inform the Controller on controls/checks and other measures conducted by a data protection authority, unless the Processor is prohibited to do so under statutory law.
6.7 The Processor shall conduct regular control checks concerning its compliance with its obligations towards data protection and security hereunder.
7.1 The Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor who may have access to the Personal Data, ensuring in each case that access is strictly limited to those individuals who need to access the Personal Data, as strictly necessary for performance of that person’s duties, ensuring that all such individuals:
7.1.1 are informed of the confidential nature of the Personal Data and are aware of the Processor's obligations under this DPA in relation to the Personal Data;
7.1.2 have undertaken appropriate training in relation to information security and privacy, in particular the relevant EU Data Protection Laws;
7.1.3 are subject to confidentiality undertakings or professional or statutory obligations of confidentiality; and
7.1.4 are subject to user authentication and log-on processes when accessing the Personal Data.
7.2 The undertakings described above shall continue for a reasonable period after the termination of the relevant person’s access to the Personal Data.
8.1 For the purposes of providing the Services, the Controller hereby authorises the named Subprocessors and grants the Processor general written consent to engage new Subprocessors in connection with the provision of the Services, including for the processing and onward transfer of Personal Data on behalf of the Controller, subject to the following requirements:
8.1.1 the Processor shall maintain a current list of its Subprocessors used to process Personal Data under this DPA, which is available at https://www.prusa3d.com/p/prusa-connect/subprocessor/. This list may be reviewed periodically and updated from time to time by Processor in its sole discretion in accordance with this DPA;
8.1.2 before the Processor allows the Subprocessor(s) access to the Personal Data, the Processor shall make the necessary update on the relevant website of the Processor at least 10 days in advance. The Controller reserves the right to raise reasoned objections in writing within five (5) days of such delegation. Otherwise, the Controller shall be deemed to have consented to the processing of Personal Data by the relevant Subprocessor(s). If the Controller reasonably objects to the appointment of the Subprocessor(s), the parties shall discuss such objections in good faith with a view to reaching a resolution, provided that if this is not possible, the Controller reserves the right to suspend or terminate the Master Agreement.
8.2 With respect to each Subprocessor, the Processor shall:
8.2.1 provide the Controller, on request, with full details of the processing to be undertaken by each Subprocessor;
8.2.2 carry out adequate due diligence on each Subprocessor to ensure that it is capable of providing the level of protection for the Personal Data as is required by this DPA including, without limitation, sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of GDPR and this DPA;
8.2.3 include terms in the contract between the Processor and each Subprocessor which are the same as those set out in this DPA. Upon request, the Processor shall provide a copy of its agreements with Subprocessors to the Controller for its review;
8.2.4 insofar as that contract involves the transfer of the Personal Data outside of the EEA, incorporate the Standard Contractual Clauses or such other mechanism as directed by the Controller into the contract between the Processor and each Subprocessor to ensure the adequate protection of the transferred Personal Data; and
8.2.5 remain fully liable to the Controller for any failure by each Subprocessor to fulfil its obligations in relation to the processing of the Personal Data.
9.1 The Processor shall promptly notify the Controller if it receives a request from a data subject under any EU Data Protection Laws in respect of the Personal Data.
9.2 The Processor shall at its own cost and expense co-operate as requested by the Controller to enable the Controller to comply with any exercise of rights by a data subject under any EU Data Protection Laws in respect of the Personal Data and comply with any assessment, enquiry, notice or investigation under any EU Data Protection Laws in respect of the Personal Data or this DPA, which shall include:
9.2.1 the provision of all data requested by the Controller within any reasonable timescale specified by the Controller in each case but in any case not longer than three (3) days, including full details and copies of the complaint, communication or request and any the Personal Data it holds in relation to a data subject;
9.2.2 where applicable, providing such assistance as is reasonably requested by the Controller to enable the Controller to comply with the relevant request within the timescales prescribed by the relevant EU Data Protection Laws; and
9.2.3 implementing any additional technical and organisational measures as may be reasonably required by the Controller to allow the Controller to respond effectively to relevant complaints, communications or requests.
9.3 The Processor shall assist the Controller by appropriate technical and organisational measures with the fulfilment of the Controller’s obligation to respond to requests for exercising a data subject's rights as set out in Chapter III of the GDPR. In particular, the Processor undertakes that to take appropriate technical and organisational measures in order to be able to respond to data access requests, requests for data rectification and erasure, requests for restriction of processing as well as requests to exercise the right to data portability. The Processor shall satisfy such requests not later than within three (3) days as of the Controller’s request in this respect.
10.1 The Processor shall notify the Controller promptly, and in any case within forty eight (48) hours, upon becoming aware of or reasonably suspecting a Personal Data Breach providing the Controller with sufficient information which allows the Controller to meet any obligations to report a Personal Data Breach under the relevant EU Data Protection Laws. Such notification shall as a minimum:
10.1.1 describe the nature of the Personal Data Breach, the categories and numbers of data subjects concerned, and the categories and numbers of Personal Data records concerned, as well as information when the data breach occurred and when the Processor became aware thereof;
10.1.2 communicate the name and contact details of the Processor's data protection officer (if designated) or other relevant contact from whom more information may be obtained;
10.1.3 describe the likely consequences of the Personal Data Breach; and
10.1.4 describe the measures taken or proposed to be taken to address the Personal Data Breach.
Unless the Parties agree otherwise in writing, notification from the Processor to the Controller under this section 10. shall be made via the email address registered in connection with the execution of the Master Agreement.
If the Controller does not confirm receipt of the e-mail with notification within 1 hour as of sending the email and the Processor fails to contact the Controller using the phone at the number registered in connection with the execution of the Master Agreement, the Processor shall use its all efforts to immediately notify the Controller about the breach using other methods of communication.
10.2 The Processor shall co-operate at its own cost and expense with the Controller and take such reasonable steps as are directed by the Controller to assist in the investigation, mitigation and remediation of each Personal Data Breach.
10.3 In the event of a Personal Data Breach, the Processor shall not inform any third party without first obtaining the Controller’s prior written consent, unless notification is required by EU law or the law of an EU Member State to which the Processor is subject, in which case the Processor shall to the extent permitted by such law inform the Controller of that legal requirement, provide a copy of the proposed notification and consider any comments made by the Controller before notifying the Personal Data Breach.
11.1 The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments in relation to the processing of the Personal Data by the Processor, which are required under Article 35 GDPR and with any prior consultations to any supervisory authority of the Controller which are required under Article 36 GDPR.
12.1 The Processor shall promptly and in any event within 60 (sixty) calendar days of the earlier of: (i) cessation of processing of Personal Data by Processor; or (ii) termination of the DPA, at the choice of the Controller (such choice to be notified to the Processor in writing) either:
12.1.1 return a complete copy of all Personal Data to the Controller by secure file transfer in such format as notified by the Controller to the Processor and securely wipe all other copies of Personal Data Processed by Processor or any Authorised Subprocessor; or
12.1.2 securely wipe all copies of Personal Data Processed by Processor or any Authorised Subprocessor, and in each case provide written certification to the Controller that it has complied fully with this point 12.1.
12.2 Processor may retain Personal Data to the extent required by EU law or the law of an EU Member State and only to the extent and for such period as required by EU law or EU Member State law and always provided that Processor shall ensure the confidentiality of all such Personal Data and shall ensure that such Personal Data is only Processed as necessary for the purpose(s) specified in the EU law or EU Member State law requiring its storage and for no other purpose.
13.1 The Processor shall make available to the Controller on request information reasonable to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections by the Controller or another auditor mandated by the Controller of any premises where the processing of Personal Data takes place. The Processor shall permit the Controller or another auditor mandated by the Controller to inspect, audit and copy any relevant records, processes and systems in order that the Controller may satisfy itself that the provisions of this DPA are being complied with. The Processor shall provide full co-operation to the Controller in respect of any such audit and shall at the request of the Controller, provide the Controller with evidence of compliance with its obligations under this DPA. The Processor shall immediately inform the Controller if, in its opinion, an instruction pursuant to this section 13. (Audit Rights) infringes the GDPR or other EU Data Protection Laws.
14.1 The Processor shall process the Personal Data or permit any Subprocessor to process the Personal Data in a third (non-EEA) country on the basis of mechanisms permitted under the GDPR Chapter V.
15.1 The Processor shall indemnify and hold harmless the Controller against proven losses, fines and sanctions arising from a claim by a third party or Supervisory Authority that arises as a direct result of the Processor's breach of its obligations under this DPA, including administrative fines imposed upon the Controller pursuant to Article 83 of the GDPR and penalties imposed in accordance with Article 84 of the GDPR, to the extent that such losses, fines and sanctions arise from reasons attributable to the Processor or its Subprocessors. The Processor's obligation to indemnify under this paragraph shall be limited in accordance with the limitation of liability provisions of the Connect Terms; this limitation shall not apply in the case of damage caused intentionally or by gross negligence, nor to the extent that the limitation of liability is not permitted by mandatory provisions of applicable law.
16.1 Subject to section 10. and unless otherwise agreed by the Parties, the contact details related to the day-to-day communication regarding the matters related to the performance of this agreement shall be as follows:
For the Controller:
Email: address registered in connection with the execution of the Master Agreement;
number registered in connection with the execution of the Master Agreement.
For the Processor:
Email: [email protected]; Phone: +420 222 263 718.
17.1 Neither the rights nor the obligations of any Party may be assigned in whole or in part without the prior written consent of the other Party, provided, however, that this DPA may be transferred or assigned on the terms and conditions set out in the Master Agreement.
17.2 Each Party shall remain responsible for its compliance and the compliance of all its employees, agents and third parties with the obligations under this DPA. Each Party shall make or obtain and maintain so long as it is a party to this DPA all necessary licences or notifications which such Party is obliged to obtain and maintain pursuant to applicable EU Data Protection Laws.
17.3 In the event of any dispute arising between the Parties in connection with this DPA, the Parties shall negotiate in good faith to resolve their dispute. If the dispute cannot be resolved by good faith negotiations by the Parties, the dispute shall be finally settled by a public court as stipulated in the Master Agreement.
17.4 This DPA and any disputes relating to it are governed by and shall be construed in accordance with the laws of the Czech Republic, without regard to choice of governing law principles, and each Party submits itself to the exclusive jurisdiction of the courts of the Czech Republic.
17.5 Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
17.6 Any amendments to this DPA shall only be valid in a written form.
This Annex 1 includes certain details of the Processing of the Personal Data as required by Article 28(3) GDPR.
The subject matter and the duration of the processing of the Personal Data are set out in this DPA.
Personal Data is Processed for the purpose of providing the Services to the Controller under the Master Agreement, as these terms are defined in the DPA, in particular for the operation and provision of the cloud-based PRUSA CONNECT and PRUSA CONNECT FARM services developed and operated by the Processor.
The Processing is necessary to ensure the proper functioning of the Services, in particular for connecting and managing devices, authenticating users, managing organisations, teams, user roles and permissions, managing print files, orders and print jobs, planning and monitoring production, managing materials, monitoring device status, recording quality, maintenance and operational events, and ensuring the security, diagnostics and support of the Services, all in accordance with the Controller’s documented instructions and applicable European Union data protection laws.
Identification, contact, organisational and descriptive data registered or Processed through the PRUSA ACCOUNT, PRUSA CONNECT and PRUSA CONNECT FARM services, such as:
Technical and operational data necessary for the provision of the PRUSA CONNECT Service, such as:
The Services are not primarily intended for the Processing of special categories of Personal Data within the meaning of Article 9 GDPR or Personal Data relating to criminal convictions and offences within the meaning of Article 10 GDPR.
Controllers of the Services, the Controller’s employees, external contractors, suppliers, customers and prospective customers, contact persons of the Controller’s customers, suppliers and business partners, persons captured in visual records, and other natural persons whose Personal Data is submitted to the Services by the Controller.
The obligations and rights of the Controller are set out in this DPA.