1.01As integral parts of this agreement, CORETECH and the CLIENT agree on the following factual premises:
- (a) as indicated in the service contract, CORETECH provides IT services as described therein (IaaS, SaaS, related maintenance services) which involve the need to potentially access CLIENT data, as a technical prerequisite for providing the services or provide related assistance;
- (b) this therefore means that CORETECH carries out processing of the personal data managed by the CLIENT through the services provided, performing such processing exclusively on behalf of the latter;
- (c) the personal data managed by the CLIENT through the Services in question can be of any type, common, particular, or even related to criminal convictions or crimes, being only the CLIENT to decide how to use the Services and which personal data to enter and which processing, CORETECH limiting itself to providing only IT Services;
- (d) the CLIENT can also carry out the processing of personal data by deciding the purposes and means of processing or he can in turn process the data on behalf of another subject, from which he receives instructions on the processing of such personal data;
- (e) the CLIENT can therefore be either directly a data controller (or co-owner) or a data processor or sub-manager depending on the type of service that the CLIENT provides to third parties;
- (f) given these premises, it is necessary to regulate how CORETECH manages the processing of personal data on behalf of the CLIENT, in order to ensure that the processing respects the privacy regulations and guarantees the protection of the rights and freedoms of the data subjects;
- (g) this agreement is intended to govern the obligations and rights of the parties, CORETECH and the CLIENT, concerning compliance with the requirements of privacy legislation, in particular Regulation (EU) 2016/679 (hereinafter GDPR) and the privacy code referred to in Legislative Decree 30.06.2003 no. 196, as amended by Legislative Decree 10.08.2018 no. 101 and any subsequent amendments or additions as well as the related regulatory framework deriving from it;
- (h) CORETECH has adopted technical and organizational measures to ensure that the services offered to its customers have adequate protection, according to market technical standards, in order to ensure effective protection of the rights and freedoms of data subjects in relation to their personal data.
1.02 This agreement shall be understood as an integral part of the CORETECH service supply contract, governing the resulting obligations under art. 28 GDPR, allocating them between CORETECH and the CLIENT according to the principle of shared responsibility as specified below.