Scaling Innovation with AI: From Code to Systems – регистрирай се за събитието на Experian, за да разбереш как!

+
Вход

Въведи своя e-mail и парола за вход, ако вече имаш създаден профил в DEV.BG/Jobs

Забравена парола?
+
Създай своя профил в DEV.BG/Jobs

За да потвърдите, че не сте робот, моля отговорете на въпроса, като попълните празното поле:

100-6 =

+
Забравена парола

Въведи своя e-mail и ще ти изпратим твоята парола

This Data Processing Agreement (“DPA”) defines the roles and responsibilities of the parties with regard to the relevant processing of personal data and forms an integral part of all business terms agreed between the parties, including but not limited to DEV.BG’s General Terms and Conditions, advertising agreements, premium company profile agreements, job posting services agreements, as well as any additional terms (collectively the “Terms”).

In the event of any conflict or inconsistency between this DPA and the Terms, the provisions of this DPA shall prevail.

1. Definitions

For the purposes of this DPA, the terms set out below shall have the following meanings:

DEV.BG means “Dev Bulgaria” Ltd., a company registered in the Commercial Register of the Registry Agency under UIC 204566446, with its registered office and address at: 15 Samokov Str. Floor 11, apartment 58, Sofia 1113, Bulgaria, which may act as either an independent Controller or a Processor depending on the services provided under the Terms.
Client means the company party to the Terms, acting as a Controller of personal data and which may include, without limitation, an advertiser, employer, partner, or other entity under the Terms.
Adequacy Decision means a decision of the European Commission determining that a country outside the EU ensures an adequate level of protection for personal data in accordance with Data Protection Law.
Adequate Country means a country outside the EEA that the European Commission has determined provides a level of protection for personal data that is essentially equivalent to that guaranteed within the EU/EEA.
Appropriate Safeguards means the safeguards required under Data Protection Law for transfers of personal data to third countries, including reliance on Standard Contractual Clauses and, where applicable, conducting transfer risk or impact assessments in accordance with applicable guidance.
Controller means the entity which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor means the entity which processes personal data on behalf of the Controller.
Personal Data Complaint means any complaint or request relating to the obligations of either party under Data Protection Law applicable to this DPA, including any complaint by a Data Subject or any notice, investigation, or other action by a Supervisory Authority.
Data Protection Law means all applicable laws and regulations relating to the protection of personal data and privacy, including Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy Directive), the Bulgarian Personal Data Protection Act, and any applicable guidance or recommendations issued by competent supervisory authorities.
Data Subject Request means a request made by a Data Subject to exercise any of their rights under Data Protection Law in relation to their personal data.
EEA means the European Economic Area.
Standard Contractual Clauses (SCCs) means the standard contractual clauses adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021.
Personal Data means any information relating to an identified or identifiable natural person.
Shared Data means the term as defined in Section 4.
Processed Data means the term as defined in Section 5.
Supervisory Authority means an independent public authority established under Data Protection Law, including the Bulgarian Commission for Personal Data Protection.

Terms written in lowercase that are used but not defined in this DPA, such as “personal data”, “personal data breach”, “processing”, and “data subject”, shall have the meanings given to them in Data Protection Law.

2. Roles and Responsibilities

In the provision of services under the Terms and in the performance of its obligations thereunder, DEV.BG may act either as an independent Controller or as a Processor of personal data.

This DPA is structured as follows:

  • General Provisions – general data protection principles applicable irrespective of the roles of the parties 
  • Controller-to-Controller Terms – applicable where the Client and DEV.BG act as independent Controllers 

Controller-to-Processor Terms – applicable where the Client acts as Controller and DEV.BG acts as Processor

3. General Provisions

Purpose of Processing. The parties shall process Personal Data solely for the purposes of providing and/or receiving the services under the Terms, including for compliance with their applicable legal and regulatory obligations.

Personal Data shall be retained for no longer than is necessary to achieve these purposes, unless a longer retention period is required or permitted under applicable law.

Security of Processing. The parties shall process Personal Data in accordance with the principles of confidentiality and in compliance with Data Protection Law and the terms of this DPA.

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the parties shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

The parties shall maintain appropriate data protection and privacy, information security, and operational resilience policies, and shall ensure that their personnel comply with such policies. All personnel shall be subject to confidentiality obligations in relation to the processing of Personal Data.

International Data Transfers. The parties shall not transfer Personal Data to a country or territory that is not recognised as providing an adequate level of protection under Data Protection Law, unless Appropriate Safeguards have been implemented.

Each party warrants that any Personal Data disclosed or otherwise transferred by that party is accurate and that it has a valid and applicable legal basis for such disclosure or transfer.

Data Minimisation. The parties undertake not to disclose or share between themselves any excessive, irrelevant, or unnecessary Personal Data that is not required for the provision or receipt of the services under the Terms.

4. Controller-Controller Terms

Where the parties process Personal Data as independent Controllers under or in connection with the Terms, the provisions of this Section 4 shall apply to the processing of Shared Data, in addition to Section 3 (General Provisions).

Each party, in its capacity as an independent Controller, shall be responsible for complying with Data Protection Law in respect of the Personal Data it processes. Each party represents and warrants that it:

  • has a valid legal basis for the processing of Shared Data under applicable law; 
  • provides Data Subjects with all required notices and information regarding the processing of Personal Data in a transparent and lawful manner; 
  • implements appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing, loss, destruction, or damage; and 
  • complies with all its obligations relating to the exercise of Data Subject rights and notifications to Supervisory Authorities, where required. 

If the Client or DEV.BG becomes aware of any of the following circumstances, it shall notify the other party without undue delay and provide reasonable assistance in fulfilling any notification obligations under Data Protection Law:

  • any Personal Data Breach or unauthorised access to Personal Data; 
  • any complaint, enquiry, or request from a Data Subject or Supervisory Authority relating to Shared Data, unless such notification is prohibited by applicable law. 

Each party shall be responsible for responding to Data Subject Requests relating to its own processing of Shared Data.

5. Controller-Processor Terms

Where DEV.BG acts as a Processor in respect of the Processed Data in connection with the performance of the Terms, the provisions of this Section 5 shall apply in addition to Section 3 (General Provisions). In the event of any conflict between Section 5 and Section 3, the provisions of this Section 5 shall prevail.

Documented Instructions. Unless otherwise required by applicable law, DEV.BG shall process the Processed Data solely in accordance with the Terms and any other documented instructions of the Client.

Confidentiality and Security. DEV.BG shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Data Protection Law.

DEV.BG shall treat the Processed Data as confidential and shall ensure that its personnel and any Sub-processors are bound by equivalent confidentiality obligations.

Audits and Assistance. DEV.BG shall provide reasonable assistance to the Client in fulfilling its obligations under Data Protection Law, including by:

  • promptly forwarding any Data Subject Requests relating to the Processed Data; 
  • providing information reasonably necessary to conduct data protection impact assessments (DPIAs), audits, inspections, and to comply with obligations towards Supervisory Authorities. 

Upon written request and prior notice, DEV.BG shall assist the Client in conducting audits or inspections to the extent reasonably necessary to demonstrate compliance with its obligations as a Processor, provided that such audits or inspections are carried out no more than once in any twelve (12) month period, unless otherwise required by applicable law or by a binding order of a competent Supervisory Authority.

The Client shall ensure that any audit or inspection is conducted in a manner that does not cause undue disruption, damage, or interruption to DEV.BG’s equipment, personnel, systems, or operations, and shall comply with DEV.BG’s reasonable security and confidentiality requirements.

Personal Data Breach Notification. In the event of a Personal Data Breach affecting the Processed Data, DEV.BG shall notify the Client without undue delay after becoming aware of the breach.

Such notification shall include, at a minimum:

  • a description of the nature of the breach (including, where possible, the categories and approximate number of Data Subjects and records concerned); 
  • the likely consequences of the breach; 
  • the measures taken or proposed to address the breach, including mitigation measures where applicable; 
  • contact details for obtaining further information. 

Sub-processors. The Client hereby authorises the use of the Sub-processors listed in Annex 1. The Client also generally authorises the engagement of additional Sub-processors. DEV.BG shall notify the Client in advance of any intended changes concerning the addition or replacement of Sub-processors. The Client may object to such changes. If no response is received within seven (7) calendar days of notification, the change shall be deemed approved.

DEV.BG shall have the right to terminate the Terms with immediate effect if, in its reasonable opinion, the Client objects without justified grounds to the appointment of a Sub-processor, or if it becomes impossible for DEV.BG to provide the services without the rejected Sub-processor.

Where DEV.BG engages a Sub-processor, it shall impose on such Sub-processor the same data protection obligations as set out in this DPA.

International Data Transfers. DEV.BG may transfer Personal Data to third countries to the extent necessary for the provision of the services under the Terms.

Where processing involves transfers to Sub-processors or other business partners located outside the EEA, the parties agree that such transfers shall take place only where:

  • (i) the transfer is to a jurisdiction subject to an Adequacy Decision of the European Commission; or 
  • (ii) in the absence of such decision, Appropriate Safeguards are in place. 

Liability. Each party shall be liable for damages caused by processing only where it has failed to comply with its obligations under the GDPR or has acted outside or contrary to the lawful instructions of the other party, where applicable.

A party that has paid full compensation shall be entitled to recover from the other party the portion of the compensation corresponding to its responsibility.

Nothing in this DPA shall limit or exclude liability towards Data Subjects under the GDPR.

Return and Deletion of Data. Upon termination of the Terms and upon written request of the Client, DEV.BG shall, at the Client’s choice, either return all Processed Data to the Client or securely delete/destroy it, to the extent permitted under applicable law.

Where applicable law requires retention of part or all of the Processed Data for a specified period, DEV.BG shall be entitled to retain such data solely for the legally required period and in compliance with applicable data protection and security requirements, after which the data shall be permanently deleted or destroyed.

Notwithstanding the above, DEV.BG may delete Processed Data prior to termination of the Terms where required or necessary to comply with applicable law (for example, retention of candidate data in an employer profile for up to six (6) months), after which such data can be deleted or anonymised.

For the avoidance of doubt, DEV.BG shall provide technical means enabling the Client to delete Personal Data. The Client shall be responsible for and undertakes to delete candidate-related data after six (6) months from its initial storage. After the expiry of this period, DEV.BG shall have the right to delete such data in order to comply with applicable law.

Annex 1 – Details of Processing

Categories of Data Subjects

Data Subjects related to the Client (any identified or identifiable natural persons) whose Personal Data is processed by DEV.BG on behalf of the Client in connection with the services under the Terms, including, where applicable:

  • Job applicants 

Categories of Personal Data

  • Identification data 
  • Contact data 
  • Professional experience and education data (CVs, etc.) 
  • Other data as required for the services under the Terms

Special Categories of Data. DEV.BG does not process special categories of Personal Data.

Nature and Purpose of Processing. Processing of Personal Data on behalf of the Client for the purpose of providing the services under the Terms.

Frequency and Duration of Processing. Processing is carried out on a continuous basis for the duration of the Terms and/or for such specific period as required under applicable law.Sub-processing. Subject matter, nature, and duration of processing by Sub-processors:
Same as described above.

Technical MeasuresOrganisational Measures
– HTTPS (data encryption) 
– Password hashing and two-factor authentication (2FA) 
– Role-based access control 
– Protection against common attacks (SQL injection, XSS, CSRF) 
– Input validation 
– File upload restrictions and scanning 
– Backup procedures 
– Logging and monitoring 
– Data deletion mechanisms
– Data protection and information security policies 
– Restricted employee access 
– Staff training 
– Confidentiality and data protection measures 
– Incident response plan 
– Risk assessments and audits 
– Agreements with service providers 
– Data retention schedule

List of Sub-processors: 

Digital Ocean Web Hostinghosting services
SuperHosting.BGhosting services