Algemene voorwaarden

[Data protection

Personal Data Exchange Agreement


This Personal Data Exchange Agreement forms an integral part of the service agreement between the Supplier and the Customer (the “Online Sales Agreement”). In order to facilitate the sale of products to end-consumers as provided in the Online Sales Agreement, the Parties will exchange certain personal data. The Parties’ obligations relating to processing of personal data and their respective responsibilities for compliance with the data protection law and regulations, including, without limitation General Data Protection Regulation (GDPR) and the Swiss Data Protection Act (DPA), (collectively the “Data Protection Regulations”) are set forth in this Personal Data Exchange Agreement. 


PURPOSE OF THIS AGREEMENT

  1. This Agreement sets out the framework for the sharing of personal data between the Parties. As the Parties jointly determine the purpose and means of processing personal data in the context of the Online Sales Agreement, the Parties agree that they are joint controllers as intended in Article 26 of the GDPR.

  2. Each Party shall be individually and separately responsible for complying with the obligations that apply to it as data controller under any applicable Data Protection Regulations in relation to the personal data processed under the Online Sales Agreement. 

ROLES AND RESPONSIBILITIES OF THE PARTIES

  1. The Customer, which is responsible for the content of the Online Store, will be responsible to provide all information to visitors of the Online Store and consumers who make purchases there (hereafter also “data subjects”) in accordance with any applicable legal requirements, including in particular Article 13 and 14 GDPR. 

  2. The Customer is designated as the contact point for data subjects about the processing of their personal data. Requests from data subjects about their rights will be handled in accordance with Section 8 below.

  3. The Customer is responsible for the processing of personal data within its own systems. The Supplier shall be responsible for its further processing of the personal data, after it has received (access to) it.  

SHARED PERSONAL DATA

  1. The following types of personal data will be shared between the Parties during the Term of the Agreement:

  • Identity Data includes [name, title, date of birth and gender].

  • Contact Data includes [billing address, delivery address, email address and phone numbers].

  • Financial Data includes [bank account and payment card details].

  • Transaction Data includes [details about payments to and from you and other details of products and services you have purchased / ordered from us].

  • Technical Data includes [internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this Website].

  • Profile Data includes [details of your username and password as a registered user of our Website; purchases or orders made by you in relation to any products or services; subscriptions by you to any newsletters or to any products or services we provide; details of any interests, preferences, survey responses, feedback or complaints which you have communicated to us; and details which you have provided in relation to taking part in any competition or promotion sponsored by us].

  • Usage Data includes [information about how you use our website, products and services].

  • Marketing and Communications Data includes [name, email address, your preferences in receiving marketing materials, promotions and/or newsletters from us and your communication preferences].

  1. Specific categories of personal data will not be shared between the Parties. 

  2. Customer guarantees that the personal data that the Supplier receives or has access to is accurate and complete.  

LEGAL BASIS OF PROCESSING

  1. Each Party shall ensure that it processed the shared personal data fairly and lawfully in accordance with Data Protection Regulations. 

  2. The Customer guarantees to have the right to provide the Supplier with (access to) the personal data, either based on the data subjects’ informed consent or the Parties’ legitimate interest to sell Products to consumers.  

  3. To the extent Customer has based the provision of (access to) the personal data to the Supplier on the data subjects’ informed consent, Customer will upon request of the Supplier provide the Supplier (access to) all the information regarding the consent of data subjects, such as, but not limited to, logs of their consent.    

PURPOSES OF PROCESSING

  1. The Supplier will process the personal data it obtains (access to) from Customer for the performance of the contract it is about to enter into or has entered into with Consumer, performance of the “Merchant of Record” services, and payment of relevant taxes. The Supplier may also analyse personal data in order to derive aggregated information which no longer relates to any specific identified or identifiable persons, such as data about sales numbers relating to (categories) of products, countries, demographics and similar metrics. 

  2. The Customer will process the personal data in the context of the performance of the Online Sales Agreements for the following purposes:

  • Where it is necessary for the purposes of its legitimate interests (or those of a third party) and the data subject’s interests and fundamental rights do not override those legitimate interests;

  • Where the Customer needs to comply with any legal obligation or regulatory requirement;

  • For marketing purpose. 

  1. In the event the Parties mutually agree in writing on any further purposes for processing personal data, and/or that any other party will receive personal data, the Parties will mutually ensure that data subjects are appropriately informed and obtain and retain their consent where required under applicable law.  

  2. The obligations arising from this Personal Data Exchange Agreement are also applicable to those who process personal data under the authority of the Parties. 

  3. Parties will process the personal data only for the agreed purposes described in Sections 5.1 and 5.2 and will only provide each other with the amount of personal data that is necessary to achieve fulfilment of the purposes described in Sections 5.1 and 5.2

SECURITY MEASURES 

  1. Parties are independently responsible for the protection of personal data, processed under their own responsibility. Each Party shall ensure that its staff members are appropriately trained to handle and process the personal data in accordance with the Data Protection Regulations. 

  2. Parties shall take appropriate technical and organisational measures against loss, destruction or any form of unlawful processing (such as unauthorised disclosure, deterioration, alteration or disclosure of personal data). The Parties shall keep such security measures under review and shall carry out such updates as they agree are appropriate throughout the term of this Agreement. 

PERSONAL DATA BREACHES 

  1. In the event either Party becomes aware of a personal data breach affecting the personal data processed under this Agreement, that Party shall notify the other Party without undue delay, where possible within 24 hours.  

  2. In case the personal data breach is discovered by Customer, Customer will notify the Supplier by e-mail via info@heytipple.com and by telephone. In case the security breach and/or data breach is discovered by the Supplier, the Supplier will notify Customer by e-mail via Jamie@heytipple.com and by telephone.  

  3. After notification of the personal data breach (as described in Sections 7.1 and 7.2), the Parties will mutually assess what the (potential) consequences of the breach are for both Parties, as well as the data subjects, and any actions the Parties should take to minimise the (potential) damage.  

  4. Parties are and remain individually responsible for reporting a data breach, occurred during the processing under their own responsibility, to the relevant supervisory authority(ies) and/or the affected data subjects. 

  5. Parties will provide each other with reasonable mutual assistance, i.e. by providing relevant information, in order to help the other Party report to the to the relevant supervisory authority(ies) and/or the affected data subjects, if necessary.  

DATA SUBJECTS’ RIGHTS 

  1. The Parties agree to provide such assistance as is reasonably required to enable the other Party to comply with data subject’s right request with the term and conditions imposed by the Data Protection Regulations. 

  2. In accordance with Article 26 of the GDPR, data subjects may exercise their rights under the GDPR in respect of each of the Parties. The Party that is designated as contact point for data subjects in accordance with Section 2.2 above will have the primary responsibility to respond to data subject requests.

  3. In case either Party receives a data subject request that (likely) has any impact on the other Party, or for which the assistance of the other Party is required, the receiving Party will promptly notify the other Party and seek its input and/or assistance as appropriate. The other Party will make all reasonable efforts to provide such input and/or assistance without delay, in order to enable the receiving Party to appropriately handle the data subject request.    

NON-DISCLOSURE AND CONFIDENTIALITY 

  1. All personal data provided back and forth within the framework of this Personal Data Exchange Agreement is subject to a duty of confidentiality vis-à-vis third parties. A Party shall not share nor disclose any such personal data with a third party unless the other Party has given its prior written consent. 

  2. Each Party shall ensure that all of its employees and any other parties engaged to perform obligation in connection with the Online Sales Agreement subject to Section above are subject to written contractual obligations concerning the personal data which are no less that those imposed by this Agreement. 

  3. This duty of confidentiality will not apply in the event that (i) the Parties have expressly authorised each other the furnishing of such information to third parties, (ii) where the furnishing of the information to third parties is reasonably necessary with a view on the nature of the instructions and the implementation of this Personal Data Exchange Agreement, or (iii) if there is a legal obligation to make the information available to a third party. 

  4. If one of the Parties is required, by a legal obligation or a judicial decision, to provide a third party with the personal data of data subjects, this Party shall forthwith inform the other Party about this, unless this is prohibited by law.  

TRANSFER

  1. For the purpose of this clause, transfer of personal data shall mean any sharing of personal data by a Party to a third party. 

  2. In addition to the prior written consent as set forth in Section 9.1 above, a Party willing to transfer personal data outside Switzerland and the EU, shall ensure that:

    1. The transfer is to a country approved under the applicable Data Protection Regulations as providing adequate protection;

    2. There are appropriate safeguards or binding corporate rules in place pursuant to Data Protection Regulations; or 

    3. One of the derogations for specific situations in the applicable Data Protection Regulations appliers to the transfer. 

DURATION AND TERMINATION 

  1. This Personal Data Exchange Agreement is entered for the duration of the Online Sales Agreement. 

  2. The Parties shall not retain or process the shared personal data for longer than is necessary to carry out the agreed purposes as described in Sections 5.1 and 5.2. Each Party is individually responsible for establishing, implementing and enforcing its own retention periods of the personal data processed under this Personal Data Exchange Agreement, in accordance with the Data Protection Regulations and any additional laws which may apply.

  3. At the written request of the Party having disclosed the personal data, the other Party shall delete or return the shared personal data and copies thereof to the disclosing Party on termination of the Agreement unless required by law to store the personal data.      


INDEMNITY


Parties indemnify each other for any claims and procedures of third parties, expressly understood including European and national supervisory authorities and the data subjects, based on or resulting from a breach of the Personal Data Regulations and/or the Personal Data Exchange Agreement to be attributed to their own individual processing. 


MISCELLANEOUS 

  1. This Personal Data Exchange Agreement may only be amended by the Parties by written agreement. 

  2. The Parties shall provide each other their full cooperation in amending this Personal Data Exchange Agreement in the event this becomes necessary as a result of any (new) applicable (privacy) laws and regulations.

  3. Nothing in this agreement is intended, or shall be deemed to, establish any partnership or joint venture between any pf the Parties, constitute any Party the agent of another Party, or authorise any Party to make or enter into any commitments for or on behalf of any Party.

JURISDICTION AND GOVERNING LAW

  1. This Agreement, and any dispute or claim (including non-contractual disputes or claims) arising out or in connection with it or its subject matter or formation shall be governed by, and construed in accordance with the laws of Ireland. 

  2. Each Party agrees that the courts of Dublin (Ireland) shall have exclusive jurisdiction to settler any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with the Agreement or its subject matter or formation.