Annex 1: Subject Matter and Details of Data Processing
This is a part of our Data Processing Agreement (DPA).
A. LIST OF PARTIES
Data Exporter
The data exporter is the Customer, a non-Holistics entity, as defined in the Holistics Terms of Service (Terms) at https://www.holistics.io/terms/.
Company Name : ___________________________________
Company Address : _______________________________________________________
_______________________________________________________
Contact Person Name : ___________________________________
Contact Person Position : ___________________________________
Contact Position Email : ___________________________________
Customer Role (Check where it applies):
- EU Controller - EU SCC Module 2 Applies (Controller to Processor) - Annex 4A
- EU Controller - EU SCC Module 2 Applies (Processor to Processor) - Annex 4B
- UK Controller - UK SCC Applies (Processor to Processor) - Annex 5
Activities relevant to the data transferred under these Clauses: Processing of Personal Data in connection with Customer's use of the Holistics Subscription Services under the Holistics Terms of Service ("Terms")
Data importer
Name : Holistics Software Pte Ltd Address : 14 Robinson Road, Far East Finance Building, #08-01A, Singapore 048545 Role : Processor
Contact person's name, position and contact details :
Thanh Dinh Khac, Chief Engineer, Holistics Software Pte Ltd Email: [redactted]
Activities relevant to the data transferred under these Clauses : Processing of Personal Data in connection with Customer's use of the Holistics Subscription Services under the Holistics Terms of Service ("Terms")
B. DESCRIPTION OF TRANSFER
Data subjects
The personal data transferred concern the following categories of data subjects in two main categories
Customer End Users of the Holistics Subscription Service , mainly the employees of the Data Exporter, and other individuals who have been invited to access the Holistics Subscription Service in their customer account. This also includes users who have submitted their contact details through the Holistics website.
Data subjects whose data is stored in the Exporter's database connected to the Holistics application servers that may contain Personal Data.
Categories of data
Holistics Metadata and Usage Data (From Customer End Users)
The personal data transferred concern personal data, software license checks, audit trails, website usage information (URLs accessed, time of access, browser type), email data, metadata on reports and dashboards, data source schemas and other electronic data submitted, stored, sent, or received by users of the Subscription Service
Temporary Cached Query Results from the Customer (Exporter)'s database
Once the Customer's database is connected to the Holistics server, the Holistics cache temporarily retains data from the database that is fetched in response to a users' report queries. The Exporter can reduce the amount of time that query results are held in cache (minimum of 10 minutes), or to turn off the cache completely.
When a dashboard widget is exported into Excel/CSV file, the file will also be temporarily stored in Holistics' file storage system
Sensitive Data Transferred and Applied Restrictions or Safeguards
The parties do not anticipate the transfer of sensitive data. In the event sensitive data is stored in Customer's Database, Customer has flexibility to restrict or isolate sensitive data from the database user credential account that is used to connect to Holistics Software.
Frequency of the transfer
Adhoc. when a dashboard loads either from user access or from a scheduled job configured by the customer.
Purpose of the transfer and further processing
Holistics will process data for the purposes of providing the Subscription Services to Customer in accordance with the Holistics Terms of Service ("Terms").
Period for which Data will be retained
Temporary Cached Query Results will be stored for a minimum of 10 minutes (or higher) from the time the dashboard is first accessed.
Exported files (Excel/CSV downloads) are stored for up to 24 hours before they expire automatically.
Holistics Metadata and Usage Data (From Customer End Users) will be removed after 180 days after the Term expires, or earlier upon request by Customer..
Competent Supervisory Authority
For the purposes of the Standard Contractual Clauses, the supervisory authority that shall act as competent supervisory authority is either
- Where Customer is established in an EU Member State , the supervisory authority responsible for ensuring Customer's compliance with the GDPR;
- Where Customer is not established in an EU Member State but falls within the extra-territorial scope of the GDPR and has appointed a representative, the supervisory authority of the EU Member State in which Customer's representative is established ; or
- Where Customer is not established in an EU Member State but falls within the extra-territorial scope of the GDPR without having to appoint a representative, the supervisory authority of the EU Member State in which the Data Subjects are predominantly located in relation to Data Processed that is subject to the UK GDPR or Swiss DPA, the competent supervisory authority is the UK Information Commissioner or the Swiss Federal Data Protection and Information Commissioner (as applicable).
Signature: | Signature: |
---|---|
Name: [redacted] | Customer Name: |
Designation: [redacted] | Designation: |
Holistics Software Pte Ltd | Company: |
Date: | Date: |