Bu belge İngilizce ve İspanyolca olarak sunulmaktadır. İngilizce sürüm esas alınır.
This addendum forms part of the Terms of Service whenever Idovio Commerce processes personal data on behalf of a customer — typically the data of the buyers of the customer's shop that arrives through the accounts the customer connects. It sets out what Article 28 of the GDPR and of the UK GDPR require.
The customer is the controller of that personal data and Idovio Labs Ltd is the processor. Subject matter: providing Idovio Commerce. Duration: the term of the subscription and the retention period after it. Nature and purpose: reading, storing, displaying and updating order, customer-contact, delivery and support data so the customer can run its shop. Data subjects: the customer's buyers, contacts and staff. Categories of data: names, contact details, delivery addresses, order contents and messages; no special categories are intended.
Idovio Labs Ltd processes the data only on the customer's documented instructions — these terms and the customer's use and configuration of the service — unless the law requires otherwise, in which case it tells the customer first where the law allows. It tells the customer if it considers an instruction unlawful.
The people authorised to process the data are bound by confidentiality and access it only when needed to operate, secure or support the service.
Idovio Labs Ltd applies the technical and organisational measures described on the Security page and keeps them at least at that level.
The customer authorises the sub-processors listed on the Sub-processors page. Idovio Labs Ltd imposes on each the same data protection obligations as in this addendum and remains responsible for them. It announces a new sub-processor on that page and by e-mail to account owners at least 30 days before; a customer that objects on reasonable grounds may end the subscription before the change.
Idovio Labs Ltd helps the customer answer requests from data subjects, with the tools of the service and, where needed, on request. It passes to the customer any request it receives directly.
Idovio Labs Ltd tells the customer without undue delay after becoming aware of a breach of the customer's personal data, with what it knows about its nature, its likely consequences and the measures taken, and keeps the customer informed as more becomes known.
Idovio Labs Ltd gives the customer the information reasonably needed for data protection impact assessments and consultations with authorities that concern the service.
At the end of the service the customer can export its data during the retention period; after that, or earlier on request, Idovio Labs Ltd deletes the personal data, except what the law requires it to keep.
Idovio Labs Ltd makes available the information needed to show compliance with this addendum and answers reasonable written audit questions once a year, or after a breach.
Where personal data is transferred outside the United Kingdom or the European Economic Area to a country without an adequacy decision, the transfer is covered by the European Commission's standard contractual clauses and the UK addendum, which are incorporated into this addendum for that purpose.