CZĘŚĆ A — POLITYKA PRZETWARZANIA DANYCH OSOBOWYCH DLA USŁUGI PRUSA CONNECT
1. Niniejsza Polityka przetwarzania danych osobowych dla korzystania z usługi Prusa Connect (zwana dalej „Polityką przetwarzania danych Connect”) uzupełnia Politykę prywatności Prusa (zwaną dalej „Ogólną Polityką prywatności”), dostępną na stronie internetowej Operatora, w odniesieniu do Usług Connect. Ogólna Polityka prywatności pozostaje nienaruszona przez Politykę przetwarzania danych Connect i ma zastosowanie do wszystkich operacji przetwarzania danych osobowych w ramach oferty usług PRUSA; Polityka przetwarzania danych Connect reguluje i uzupełnia jedynie specyfikę wynikającą z charakteru Usług Connect.
2. Terminy pisane wielką literą, które nie są zdefiniowane w niniejszej Polityce przetwarzania danych Connect, mają znaczenie określone w Warunkach korzystania z Prusa Link, Prusa Connect i Prusa Connect Farm (zwanych dalej „Warunkami Connect”) lub w Ogólnej Polityce prywatności.
3. Niniejsza Polityka przetwarzania danych Connect ma zastosowanie do wszystkich Użytkowników, którzy aktywują, zamawiają lub korzystają z Usług Connect, przez cały okres ich użytkowania. W przypadku konfliktu między Ogólną Polityką prywatności a niniejszą Polityką przetwarzania danych Connect, Polityka przetwarzania danych Connect ma pierwszeństwo w odniesieniu do Usług Connect.
4. Administratorem danych osobowych wydającym niniejszą Politykę przetwarzania danych Connect jest Prusa Research a.s., nr identyfikacyjny: 06649114, z siedzibą pod adresem Partyzánská 188/7a, Holešovice, 170 00 Praga 7, Republika Czeska (zwany dalej „Operatorem”). Adres kontaktowy w sprawach ochrony danych: [email protected].
Prusa Connect i Prusa Connect Farm to usługi chmurowe (SaaS), w ramach których dane osobowe przechodzą przez serwery Operatora. Z perspektywy ochrony danych decydujące jest nie to, czy używana jest podstawowa usługa Prusa Connect czy Prusa Connect Farm, ale raczej charakter ich użycia. Jeśli osoba fizyczna korzysta z tych usług wyłącznie do celów osobistych lub domowych, zastosowanie ma wyjątek dotyczący wyłącznie działalności osobistej lub domowej, a Operator, w odniesieniu do danych takiej osoby, działa jako niezależny administrator. Jeśli natomiast usługa jest używana w ramach Organizacji (działalność gospodarcza, zawodowa, edukacyjna, badawcza, hobbystyczna lub inna niż osobista lub domowa), należy rozróżnić dwie odrębne role, w których Operator działa w odniesieniu do danych osobowych:
W odniesieniu do danych osobowych, dla których Operator sam określa cele i sposoby przetwarzania, działa jako niezależny administrator. Dotyczy to w szczególności:
Przetwarzanie to podlega Ogólnej Polityce prywatności i niniejszej Polityce przetwarzania danych Connect. Podstawy prawne i okresy przechowywania opierają się na Ogólnej Polityce prywatności.
W odniesieniu do danych osobowych, które Użytkownik wprowadza, przesyła lub przetwarza za pośrednictwem usługi w imieniu Organizacji w ramach działalności innej niż osobista lub domowa, i dla których Organizacja określa cele i sposoby, Operator działa jako podmiot przetwarzający, a Organizacja jako administrator. Dotyczy to w szczególności:
W przypadku tego przetwarzania Organizacja jest administratorem, który określa cele i środki oraz ponosi, wobec osób, których dane dotyczą, w szczególności obowiązek informacyjny zgodnie z art. 13 i 14 RODO. Relacja między Organizacją (administratorem) a Operatorem (podmiotem przetwarzającym) jest regulowana umową o przetwarzaniu danych osobowych zgodnie z art. 28 RODO (zwaną dalej również „DPA”) — patrz załącznik do niniejszej Polityki przetwarzania danych Connect.
Ważna informacja dla przedstawiciela organizacji: Jeśli wprowadzasz do usługi dane osobowe osób trzecich (w szczególności członków zespołu jako pracowników lub współpracowników, klientów końcowych z rynku lub osób uchwyconych przez system kamer), Organizacja, w imieniu której działasz, jest administratorem w odniesieniu do takich danych. Organizacja jest odpowiedzialna za podstawę prawną przetwarzania, za wypełnienie obowiązku informacyjnego wobec osób, których dane dotyczą, oraz za zgodność z przepisami o ochronie danych i prawa pracy. Operator przetwarza takie dane wyłącznie zgodnie z instrukcjami Organizacji na podstawie DPA (patrz załącznik do niniejszej Polityki przetwarzania danych Connect).
The overview below summarises the main categories of personal data processed in connection with the service and the Operator’s role:
| Examples | Operator’s role | |
|---|---|---|
| Identification and accounting (account) | name, e-mail, PRUSA ACCOUNT ID, billing data, subscription | Controller |
| Operational and security | access logs, IP address, technical identifiers | Controller |
| Team member data | name, e-mail, role, permissions, activity and usage records within the Team | Processor* |
| Content and production data | print tasks, files, orders, material data (if they contain personal data) | Processor* |
| API / marketplace data | data of end customers in orders transmitted via the connector | Processor* |
| Camera streams and recordings | video streams from printers / workplace capturing persons | Processor* |
* Podmiot przetwarzający w imieniu Organizacji — Organizacja jest administratorem; reżim jest regulowany przez DPA (patrz załącznik do niniejszej Polityki przetwarzania danych Connect).
The following applies to processing for which the Operator is the controller:
| Legal basis (GDPR) | Retention period | |
|---|---|---|
| Provision and operation of the Connect Services | performance of a contract — Art. 6(1)(b) | for the duration of the use of the service and 5 years from the last login (see General Privacy Policy) |
| Security, prevention of misuse, stability of the service | legitimate interest — Art. 6(1)(f) | as a rule up to 12 months, unless a longer period is necessary |
| Invoicing and fulfilment of legal obligations | legal obligation — Art. 6(1)(c) | for the period laid down by law (tax/accounting regulations) |
| Development and improvement of the service | legitimate interest — Art. 6(1)(f); preferably aggregated/pseudonymised data | for the period necessary for the given purpose |
1. Prusa Connect Farm contains functions for the automatic distribution of print tasks, planning, analytics and performance evaluation of production resources. These functions serve exclusively for the coordination of printers and production resources and are of a supporting nature.
2. Operator nie obsługuje tych funkcji w celu zautomatyzowanego indywidualnego podejmowania decyzji lub profilowania osób fizycznych w rozumieniu art. 22 RODO. Wszelkie wykorzystanie wyników tych funkcji do oceny, monitorowania lub zarządzania osobami fizycznymi (w szczególności członkami zespołu) leży wyłącznie w gestii i odpowiedzialności Przedstawiciela Organizacji; w takim przypadku Organizacja jest administratorem i odpowiada za zgodność z RODO i przepisami prawa pracy (zob. art. 5.5 Warunków Connect).
1. For camera streams and recordings made available within the service, the Organisation is the controller. The Organisation is responsible in particular for the lawful basis for operating the camera system, for fulfilling the information obligation towards the persons concerned, and for setting the scope and retention period of the recordings.
2. For data transmitted via API integrations and marketplace connectors, the Operator provides only a technical interface and acts as a processor on behalf of the Organisation. The Operator does not verify the content or accuracy of such data and does not process it for its own purposes.
1. The range of recipients and categories of recipients, as well as the conditions for any transfer of personal data outside the European Economic Area, are governed by the General Privacy Policy. For processing where the Operator is a processor on behalf of the Organisation, the engagement of sub-processors and transfers outside the EEA are governed by the DPA – see the annex to this Connect Data Processing Policy.
2. For any transfer of personal data outside the EEA, the Operator shall ensure appropriate safeguards pursuant to Chapter V of the GDPR, in particular the standard contractual clauses adopted by the European Commission.
1. The rights of data subjects (access, rectification, erasure, restriction, portability, objection, withdrawal of consent, complaint to a supervisory authority) and the manner of their exercise are governed by the General Privacy Policy.
2. If the rights concern personal data for which the Operator is a processor on behalf of the Organisation (in particular Team member data), the Organisation, as controller, is competent to handle them. If such a person contacts the Operator, the Operator shall, without undue delay, refer them to the Organisation and provide the Organisation with cooperation under the DPA (see the annex to this Connect Data Processing Policy).
1. This Connect Data Processing Policy becomes effective on 01.10.2026. The Operator is entitled to update the Connect Data Processing Policy to a reasonable extent; it shall inform the User of material changes in a manner similar to Article 10.2 of the Connect Terms.
2. The current version of the Connect Data Processing Policy is always available on the Operator’s website together with the Connect Terms and the General Privacy Policy.
Niniejsza Umowa o przetwarzaniu danych („UoPD”) stanowi integralną część Polityki przetwarzania danych Connect, której jest załącznikiem, i uzupełnia Warunki Prusa Connect, Prusa Link i Prusa Connect Farm („Warunki Connect”). Reguluje ona przetwarzanie danych osobowych przez Prusa Research a.s. z siedzibą pod adresem Partyzánská 188/7A, 170 00 Praga 7, Republika Czeska („Procesor”), w imieniu Organizacji („Administrator”) w związku z korzystaniem z Usług Prusa Connect („Usługi”).
For the purposes of this DPA, "Organisation" and "Organisation Representative" have the meaning given to them in the Connect Terms. The Controller is the Organisation on whose behalf the Services are used for professional or otherwise non-personal/non-household purposes. This DPA is entered into on behalf of the Organisation by the Organisation Representative.
This DPA takes effect upon activation or ordering of the Services by the Organisation Representative on behalf of the Organisation. By activating, ordering or using the Services on behalf of the Organisation, the Organisation Representative accepts this DPA and confirms that they are authorised to represent the Organisation and to bind it to this DPA. If you are not so authorised, do not accept this DPA and do not provide personal data on behalf of the Organisation. Where a natural person uses the Services exclusively for personal or household purposes, no controller–processor relationship arises and this DPA does not apply.
The Parties enter into this DPA to ensure compliance with applicable EU Data Protection Laws, in particular the General Data Protection Regulation (GDPR), in the context of the Processor’s provision of the Services under the Connect Terms (the “Master Agreement”).
The terms listed in this DPA shall have the meanings assigned to them below.
„RODO” oznacza Rozporządzenie Parlamentu Europejskiego i Rady (UE) 2016/679 z dnia 27 kwietnia 2016 r. w sprawie ochrony osób fizycznych w związku z przetwarzaniem danych osobowych i w sprawie swobodnego przepływu takich danych oraz uchylenia dyrektywy 95/46/WE (ogólne rozporządzenie o ochronie danych).
„Unijne Przepisy o Ochronie Danych” oznaczają ustawy i rozporządzenia dotyczące przetwarzania danych osobowych zgodnie z obowiązującym prawem, które mogą mieć zastosowanie do Stron niniejszej DPA, w tym między innymi RODO i wszelkie krajowe implementacje RODO.
„Procesor” oznacza Prusa Research a.s. z siedzibą Partyzánská 188/7A, 170 00 Praga 7, Republika Czeska, jako operator usługi PRUSA CONNECT. Termin ten ma również znaczenie określone w Unijnych Przepisach o Ochronie Danych.
„Administrator” oznacza Organizację, która określa zakres i cele przetwarzania danych osobowych realizowanego przez Procesora za pośrednictwem Usług, i w imieniu której niniejsza DPA jest zawierana przez Przedstawiciela Organizacji. Administrator ma znaczenie „administratora” zgodnie z Unijnymi Przepisami o Ochronie Danych.
„Organizacja” i „Przedstawiciel Organizacji” mają znaczenie nadane w Warunkach Connect.
„Przetwarzanie”, „Organ nadzorczy” i „Naruszenie ochrony danych osobowych” mają znaczenie określone w przepisach UE o ochronie danych.
„Osoba, której dane dotyczą” ma znaczenie nadane w Unijnych Przepisach o Ochronie Danych i obejmuje wszelką odpowiadającą terminologię odnoszącą się do osoby fizycznej, której dane osobowe są przetwarzane.
„Podprocesor” ma znaczenie określone w Unijnych Przepisach o Ochronie Danych i oznacza Podprocesora Procesora upoważnionego przez Administratora, jak opisano poniżej.
„Dane Osobowe” oznaczają wszelkie dane osobowe (zgodnie z definicją w Unijnych Przepisach o Ochronie Danych), które są dostarczane i/lub przekazywane Procesorowi przez Administratora lub w jego imieniu zgodnie z niniejszą DPA.
„Usługi” oznaczają usługi Prusa Connect i Prusa Connect Farm, rozwiązania do zdalnego drukowania w chmurze opracowane wewnętrznie i obsługiwane przez Procesora. Usługi stanowią część Usług Connect, zgodnie z definicją w Warunkach Connect.
„Standardowe Klauzule Umowne” oznaczają standardowe klauzule umowne dotyczące przekazywania danych osobowych do państw trzecich, zatwierdzone przez Komisję Europejską w Decyzji Wykonawczej Komisji (UE) 2021/914, lub wszelkie klauzule zatwierdzone przez Komisję Europejską, które zmieniają lub zastępują te klauzule.
„UE” oznacza Unię Europejską.
„EOG” oznacza Europejski Obszar Gospodarczy.
2.1 In the course of providing the Services to the Controller pursuant to the Master Agreement, the Processor has access and need to process the Personal Data. Therefore, the Controller hereby commissions the Processor to process the Personal Data, as further specified herein, on behalf and in accordance with the instructions of the Controller as set forth herein.
2.2 Accordingly, the Processor shall, on behalf of the Controller, process the Personal Data.
2.3 For the avoidance of doubt the Parties agree that the Processor shall not be authorised to process the Personal Data for any other purposes than those specified in this DPA, and in particular for the Processor's own purposes.
3.1 The Processor shall process the Personal Data provided by the Controller solely in accordance with documented instructions and the provisions contained in this DPA and specific instructions that the Controller may issue at its discretion at any time. The Controller in particular may give instructions regarding type, extent and method of the data processing, within the limits of the technology used.
3.2 If the Processor is of the opinion that an instruction infringes the EU Data Protection Laws, it shall immediately notify the Controller.
4.1 The Processor shall only process the types of Personal Data relating to the categories of data subjects and for the specific purposes set out in Annex 1 hereto and shall not process, transfer, modify, amend or alter the Controller’s Personal Data or disclose or permit the disclosure of the Controller’s Personal Data to any third party other than in accordance with the Controller’s documented instructions, unless the processing is required by EU law or the law of an EU Member State to which the Processor is subject, in which case the Processor shall to the extent permitted by such law inform the Controller of that legal requirement before processing that Personal Data.
5.1 The DPA shall be effective from the Effective Date until the Services requiring processing of Personal Data on behalf of the Controller are terminated, in any event not later than until the termination of the Master Agreement, subject to points 5.2 and 5.3.
5.2 If the Processor commits a material breach of any provision of this DPA, the Controller may call in writing on the Processor to remedy the breach within a period specified by the Controller. If the breach is not remedied after the aforesaid notice period has expired, the Controller will be entitled, but not compelled, in addition to its rights in terms of this DPA and under applicable law, to terminate this DPA with immediate effect on further written notice to the Processor. A material breach of any provision of this DPA shall also be considered as a material breach of the Master Agreement.
5.3 The expiration or termination of this DPA shall not affect such provisions of this DPA which are expressly provided to operate after any such expiration or termination, or which of necessity must continue to have effect after such expiration or termination, notwithstanding that the relevant provisions themselves do not provide for this. Without derogating from or limiting the foregoing, this point 5.3 and sections 13., 15. and 16. shall continue in full force and effect after expiration or termination of this DPA.
6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, within the Processor’s area of responsibility the Processor shall structure their internal corporate organisation to ensure compliance with the specific requirements of the protection of the Personal Data. The Processor shall take at its own cost and expense the appropriate technical and organisational measures to adequately protect the Personal Data against misuse and loss in accordance with the requirements of applicable data protection regulations. In relation to the Personal Data measures hereunder shall include, but not be limited to:
6.1.1 the ability to ensure the ongoing security, confidentiality, integrity, availability and resilience of processing systems, networks and services;
6.1.2 the ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident;
6.1.3 a process for regularly monitoring, testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing;
6.1.4 the prevention of unauthorised persons’ gaining access to data processing systems (physical access control),
6.1.5 the prevention of data processing systems being used without authorisation (logical access control),
6.1.6 the Processor shall keep Personal Data logically separate from data processed on behalf of any third party,
6.1.7 applying encryption and pseudonymisation of the Personal Data, where appropriate;
6.1.8 ensuring that persons entitled to use a data processing system gain access only to such Personal Data as they are entitled to access in accordance with their legitimate access rights, and that, in the course of processing or use and after storage, Personal Data cannot be read, copied, modified or deleted without authorisation (data access control),
6.1.9 ensuring that the Personal Data cannot be read, copied, modified or deleted without authorisation during electronic transmission, transport or storage on storage media, and that the target entities for any transfer of the Personal Data by means of data transmission facilities can be established and verified (data transfer control),
6.1.10 ensuring the establishment of logging and an audit trail to document whether and by whom the Personal Data have been entered into, modified in, or removed from data processing systems (entry control),
6.1.11 maintaining an information security policy and security incident management and continuity plans, consisting of, among others, a clarification with regard to the analysis performed and the risk management of personal data, a description of various responsibilities and organisational rules, description of how security incidents are managed, the measure that were introduced to keep the security system up-to-date after installation;
6.1.12 organising information security by means of selection of an information security lead who has the necessary competences, is adequately trained, ensures that various responsibilities with regard to information security have been clearly, ensures that the responsibilities defined in the information policy are performed and who cannot discharge any function nor take up any responsibility that is incompatible with the information security governance role;
6.1.13 ensuring physical environment security, for instance by means of security and surveillance regarding building, premises and installations where carriers of personal data and computer systems processing the data are positioned, as well as prevention, detection and operating procedure in the case of fire, intrusion and water damage,
6.1.14 maintaining complete and up-to-date documentation proportionate to the risk profile of the processing operations, including, but not limited to, technical documentation of implemented security measures and other information necessary to demonstrate compliance with the requirements of this DPA,
6.1.15 ensuring that the Personal Data is processed solely in accordance with the relevant Controller’s instructions (control of instructions).
6.2 A measure as referred to in point 6.1 above shall be in particular, but shall not be limited to, the use of state-of-the-art encryption technology.
6.3 In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
6.4 The Processor shall assist the Controller in ensuring compliance with the obligations set forth in Articles 32 to 36 of the GDPR and maintain a record of processing activities under the Processor's responsibility, with relation to the Personal Data (in accordance and on terms as specified in Article 30 of the GDPR).
6.5 Without prejudice to point 10.1, the Processor shall, without undue delay, inform the Controller in case of a serious interruption of operations, suspicion of breaches of data protection, and any other irregularity in processing the Data.
6.6 The Processor shall, without undue delay, inform the Controller on controls/checks and other measures conducted by a data protection authority, unless the Processor is prohibited to do so under statutory law.
6.7 The Processor shall conduct regular control checks concerning its compliance with its obligations towards data protection and security hereunder.
7.1 The Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor who may have access to the Personal Data, ensuring in each case that access is strictly limited to those individuals who need to access the Personal Data, as strictly necessary for performance of that person’s duties, ensuring that all such individuals:
7.1.1 are informed of the confidential nature of the Personal Data and are aware of the Processor's obligations under this DPA in relation to the Personal Data;
7.1.2 have undertaken appropriate training in relation to information security and privacy, in particular the relevant EU Data Protection Laws;
7.1.3 are subject to confidentiality undertakings or professional or statutory obligations of confidentiality; and
7.1.4 are subject to user authentication and log-on processes when accessing the Personal Data.
7.2 The undertakings described above shall continue for a reasonable period after the termination of the relevant person’s access to the Personal Data.
8.1 For the purposes of providing the Services, the Controller hereby authorises the named Subprocessors and grants the Processor general written consent to engage new Subprocessors in connection with the provision of the Services, including for the processing and onward transfer of Personal Data on behalf of the Controller, subject to the following requirements:
8.1.1 Procesor będzie prowadził aktualną listę swoich Podprocesorów wykorzystywanych do przetwarzania Danych Osobowych na mocy niniejszej UoPD, która jest dostępna pod adresem https://www.prusa3d.com/p/prusa-connect/subprocessor/. Lista ta może być okresowo przeglądana i aktualizowana przez Procesora według jego wyłącznego uznania, zgodnie z niniejszą UoPD;
8.1.2 before the Processor allows the Subprocessor(s) access to the Personal Data, the Processor shall make the necessary update on the relevant website of the Processor at least 10 days in advance. The Controller reserves the right to raise reasoned objections in writing within five (5) days of such delegation. Otherwise, the Controller shall be deemed to have consented to the processing of Personal Data by the relevant Subprocessor(s). If the Controller reasonably objects to the appointment of the Subprocessor(s), the parties shall discuss such objections in good faith with a view to reaching a resolution, provided that if this is not possible, the Controller reserves the right to suspend or terminate the Master Agreement.
8.2 With respect to each Subprocessor, the Processor shall:
8.2.1 provide the Controller, on request, with full details of the processing to be undertaken by each Subprocessor;
8.2.2 carry out adequate due diligence on each Subprocessor to ensure that it is capable of providing the level of protection for the Personal Data as is required by this DPA including, without limitation, sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of GDPR and this DPA;
8.2.3 include terms in the contract between the Processor and each Subprocessor which are the same as those set out in this DPA. Upon request, the Processor shall provide a copy of its agreements with Subprocessors to the Controller for its review;
8.2.4 insofar as that contract involves the transfer of the Personal Data outside of the EEA, incorporate the Standard Contractual Clauses or such other mechanism as directed by the Controller into the contract between the Processor and each Subprocessor to ensure the adequate protection of the transferred Personal Data; and
8.2.5 remain fully liable to the Controller for any failure by each Subprocessor to fulfil its obligations in relation to the processing of the Personal Data.
9.1 The Processor shall promptly notify the Controller if it receives a request from a data subject under any EU Data Protection Laws in respect of the Personal Data.
9.2 Procesor będzie na własny koszt i ryzyko współpracował na żądanie Administratora, aby umożliwić Administratorowi przestrzeganie wszelkich praw podmiotu danych wynikających z przepisów UE o ochronie danych w odniesieniu do Danych Osobowych oraz przestrzeganie wszelkich ocen, zapytań, powiadomień lub dochodzeń wynikających z przepisów UE o ochronie danych w odniesieniu do Danych Osobowych lub niniejszej UoPD, co obejmuje:
9.2.1 the provision of all data requested by the Controller within any reasonable timescale specified by the Controller in each case but in any case not longer than three (3) days, including full details and copies of the complaint, communication or request and any the Personal Data it holds in relation to a data subject;
9.2.2 where applicable, providing such assistance as is reasonably requested by the Controller to enable the Controller to comply with the relevant request within the timescales prescribed by the relevant EU Data Protection Laws; and
9.2.3 implementing any additional technical and organisational measures as may be reasonably required by the Controller to allow the Controller to respond effectively to relevant complaints, communications or requests.
9.3 The Processor shall assist the Controller by appropriate technical and organisational measures with the fulfilment of the Controller’s obligation to respond to requests for exercising a data subject's rights as set out in Chapter III of the GDPR. In particular, the Processor undertakes that to take appropriate technical and organisational measures in order to be able to respond to data access requests, requests for data rectification and erasure, requests for restriction of processing as well as requests to exercise the right to data portability. The Processor shall satisfy such requests not later than within three (3) days as of the Controller’s request in this respect.
10.1 The Processor shall notify the Controller promptly, and in any case within forty eight (48) hours, upon becoming aware of or reasonably suspecting a Personal Data Breach providing the Controller with sufficient information which allows the Controller to meet any obligations to report a Personal Data Breach under the relevant EU Data Protection Laws. Such notification shall as a minimum:
10.1.1 describe the nature of the Personal Data Breach, the categories and numbers of data subjects concerned, and the categories and numbers of Personal Data records concerned, as well as information when the data breach occurred and when the Processor became aware thereof;
10.1.2 communicate the name and contact details of the Processor's data protection officer (if designated) or other relevant contact from whom more information may be obtained;
10.1.3 describe the likely consequences of the Personal Data Breach; and
10.1.4 describe the measures taken or proposed to be taken to address the Personal Data Breach.
Unless the Parties agree otherwise in writing, notification from the Processor to the Controller under this section 10. shall be made via the email address registered in connection with the execution of the Master Agreement.
If the Controller does not confirm receipt of the e-mail with notification within 1 hour as of sending the email and the Processor fails to contact the Controller using the phone at the number registered in connection with the execution of the Master Agreement, the Processor shall use its all efforts to immediately notify the Controller about the breach using other methods of communication.
10.2 The Processor shall co-operate at its own cost and expense with the Controller and take such reasonable steps as are directed by the Controller to assist in the investigation, mitigation and remediation of each Personal Data Breach.
10.3 In the event of a Personal Data Breach, the Processor shall not inform any third party without first obtaining the Controller’s prior written consent, unless notification is required by EU law or the law of an EU Member State to which the Processor is subject, in which case the Processor shall to the extent permitted by such law inform the Controller of that legal requirement, provide a copy of the proposed notification and consider any comments made by the Controller before notifying the Personal Data Breach.
11.1 The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments in relation to the processing of the Personal Data by the Processor, which are required under Article 35 GDPR and with any prior consultations to any supervisory authority of the Controller which are required under Article 36 GDPR.
12.1 The Processor shall promptly and in any event within 60 (sixty) calendar days of the earlier of: (i) cessation of processing of Personal Data by Processor; or (ii) termination of the DPA, at the choice of the Controller (such choice to be notified to the Processor in writing) either:
12.1.1 return a complete copy of all Personal Data to the Controller by secure file transfer in such format as notified by the Controller to the Processor and securely wipe all other copies of Personal Data Processed by Processor or any Authorised Subprocessor; or
12.1.2 securely wipe all copies of Personal Data Processed by Processor or any Authorised Subprocessor, and in each case provide written certification to the Controller that it has complied fully with this point 12.1.
12.2 Processor may retain Personal Data to the extent required by EU law or the law of an EU Member State and only to the extent and for such period as required by EU law or EU Member State law and always provided that Processor shall ensure the confidentiality of all such Personal Data and shall ensure that such Personal Data is only Processed as necessary for the purpose(s) specified in the EU law or EU Member State law requiring its storage and for no other purpose.
13.1 The Processor shall make available to the Controller on request information reasonable to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections by the Controller or another auditor mandated by the Controller of any premises where the processing of Personal Data takes place. The Processor shall permit the Controller or another auditor mandated by the Controller to inspect, audit and copy any relevant records, processes and systems in order that the Controller may satisfy itself that the provisions of this DPA are being complied with. The Processor shall provide full co-operation to the Controller in respect of any such audit and shall at the request of the Controller, provide the Controller with evidence of compliance with its obligations under this DPA. The Processor shall immediately inform the Controller if, in its opinion, an instruction pursuant to this section 13. (Audit Rights) infringes the GDPR or other EU Data Protection Laws.
14.1 The Processor shall process the Personal Data or permit any Subprocessor to process the Personal Data in a third (non-EEA) country on the basis of mechanisms permitted under the GDPR Chapter V.
15.1 The Processor shall indemnify and hold harmless the Controller against proven losses, fines and sanctions arising from a claim by a third party or Supervisory Authority that arises as a direct result of the Processor's breach of its obligations under this DPA, including administrative fines imposed upon the Controller pursuant to Article 83 of the GDPR and penalties imposed in accordance with Article 84 of the GDPR, to the extent that such losses, fines and sanctions arise from reasons attributable to the Processor or its Subprocessors. The Processor's obligation to indemnify under this paragraph shall be limited in accordance with the limitation of liability provisions of the Connect Terms; this limitation shall not apply in the case of damage caused intentionally or by gross negligence, nor to the extent that the limitation of liability is not permitted by mandatory provisions of applicable law.
16.1 Subject to section 10. and unless otherwise agreed by the Parties, the contact details related to the day-to-day communication regarding the matters related to the performance of this agreement shall be as follows:
Dla Administratora:
E-mail: adres zarejestrowany w związku z wykonaniem Umowy ramowej;
numer zarejestrowany w związku z wykonaniem Umowy Głównej.
Dla Procesora:
E-mail: [email protected]; Telefon: +420 222 263 718.
17.1 Neither the rights nor the obligations of any Party may be assigned in whole or in part without the prior written consent of the other Party, provided, however, that this DPA may be transferred or assigned on the terms and conditions set out in the Master Agreement.
17.2 Each Party shall remain responsible for its compliance and the compliance of all its employees, agents and third parties with the obligations under this DPA. Each Party shall make or obtain and maintain so long as it is a party to this DPA all necessary licences or notifications which such Party is obliged to obtain and maintain pursuant to applicable EU Data Protection Laws.
17.3 In the event of any dispute arising between the Parties in connection with this DPA, the Parties shall negotiate in good faith to resolve their dispute. If the dispute cannot be resolved by good faith negotiations by the Parties, the dispute shall be finally settled by a public court as stipulated in the Master Agreement.
17.4 This DPA and any disputes relating to it are governed by and shall be construed in accordance with the laws of the Czech Republic, without regard to choice of governing law principles, and each Party submits itself to the exclusive jurisdiction of the courts of the Czech Republic.
17.5 Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
17.6 Any amendments to this DPA shall only be valid in a written form.
This Annex 1 includes certain details of the Processing of the Personal Data as required by Article 28(3) GDPR.
Przedmiot i czas trwania przetwarzania Danych Osobowych są określone w niniejszej DPA.
Dane Osobowe są przetwarzane w celu świadczenia Usług Administratorowi na podstawie Umowy Głównej, zgodnie z definicjami tych terminów w DPA, w szczególności w celu obsługi i świadczenia usług PRUSA CONNECT i PRUSA CONNECT FARM opartych na chmurze, opracowanych i obsługiwanych przez Procesora.
Przetwarzanie jest niezbędne do zapewnienia prawidłowego funkcjonowania Usług, w szczególności do łączenia i zarządzania urządzeniami, uwierzytelniania użytkowników, zarządzania organizacjami, zespołami, rolami i uprawnieniami użytkowników, zarządzania plikami do druku, zamówieniami i zadaniami drukowania, planowania i monitorowania produkcji, zarządzania materiałami, monitorowania stanu urządzeń, rejestrowania jakości, konserwacji i zdarzeń operacyjnych, a także zapewnienia bezpieczeństwa, diagnostyki i wsparcia Usług, wszystko zgodnie z udokumentowanymi instrukcjami Administratora i obowiązującymi przepisami Unii Europejskiej o ochronie danych.
Dane identyfikacyjne, kontaktowe, organizacyjne i opisowe zarejestrowane lub przetwarzane za pośrednictwem usług PRUSA ACCOUNT, PRUSA CONNECT i PRUSA CONNECT FARM, takie jak:
Dane techniczne i operacyjne niezbędne do świadczenia usługi PRUSA CONNECT, takie jak:
Usługi nie są przeznaczone przede wszystkim do Przetwarzania szczególnych kategorii Danych Osobowych w rozumieniu art. 9 RODO ani Danych Osobowych dotyczących wyroków skazujących i naruszeń prawa w rozumieniu art. 10 RODO.
Administratorzy Usług, pracownicy Administratora, zewnętrzni wykonawcy, dostawcy, klienci i potencjalni klienci, osoby kontaktowe klientów, dostawców i partnerów biznesowych Administratora, osoby ujęte w zapisach wizualnych oraz inne osoby fizyczne, których Dane Osobowe są przekazywane do Usług przez Administratora.
Obowiązki i prawa Administratora są określone w niniejszej Umowie o Przetwarzaniu Danych.