“Applicable Laws” shall mean all acts, laws, regulations, including but not limited to Data Protection Laws, applicable to each Party.
“Data Protection Laws” shall mean the applicable national laws concerning data protection including, if applicable, the national laws implementing Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of Personal Data and on the free movement of such data and Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of Personal Data and the protection of privacy in the
electronic communications sector (ePrivacy Directive) and the subsequent directives and regulations such as the General Data Protection Regulation (Regulation no. 2016/679, the GDPR) and the national implementations thereof and related national legislation.
“EEA” shall mean the European Economic Area.
“Personal Data” shall mean all information that is directly or indirectly referable to a natural living person such as name, email address, IP-address, location data etc.
“Personal Data Breach” shall mean a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
“Service Processing” shall mean the processing of Personal Data carried out by Confetti on behalf of the Customer, as specified in SCHEDULE 1.
The following types of Personal Data are processed by Confetti on behalf of the Customer in the Service Processing under the Agreement:
The processed Personal Data concerns the following categories of data subjects:
The following Service Processing operations shall be carried out for the below specified purposes by Confetti under this Agreement:
Service Processing operation Collecting information from Data Subject in registration forms.
Purpose To enable a record of attendees to an event and their respective payments as necessary to fulfil Confetti’s obligations to the Customer under the Customer Agreement, which includes processing of the data after the event to enable Customer to communicate with the attendees.
Confetti shall comply with the instructions set forth below with respect to the processing of the Personal Data under this Agreement.
The premises used by Confetti shall be protected with adequate physical security measures.
Confetti shall implement a security policy which states for example the manner in which the Personal Data shall be processed, to whom Confetti’s personnel shall turn in the event of a
burglary or other incident, which personnel are authorized as regards which type of information, back-up procedures, contingency plans, etc.
Confetti should create a safe IT-environment.
Confetti shall make it possible to log and trace processing of the Personal Data, including the disclosure and transfer of the Personal Data.
The Customer authorizes Confetti to, subject to the provisions of this Agreement, directly fulfil the requests of data subjects received by Confetti. Confetti undertakes to inform the Customer of any rectification, erasure, or restriction of processing of Personal Data performed by a direct request of a data subject, unless this proves impossible or involves disproportionate effort.
Confetti shall have routines to provide Personal Data concerning a data subject in at the Customer’s request.
Subject to the provisions of this Agreement, Confetti shall not maintain the processed Personal Data for longer than is necessary taking into consideration the purpose of the processing.