Privacy Policy for Havelock JSC.

Last updated on 28 October 2025

DATA PROCESSING PPOLICY of “Havelock” JSC

Whereas: Customer had accepted the General Terms and Conditions of Havelock JSC and/or Customer and Havelock JSC had executed a Master Service Agreement and therefore Customer and Havelock JSC had entered into contractual relation (hereinafter referred to as the Agreement);

Whereas: Havelock JSC, a company, established and existing under the laws of Republic of Bulgaria, having its company No: 205602831 at Bulgarian Trade Register, having its registered seat and address at 54 “Iskar” str., city of Sofia, Republic of Bulgaria, contact e-mail info@havelock.app (hereinafter referred to as “Havelock”) administrates and/or processes information relating to an identified or identifiable natural persons provided by or on behalf of Customer as part of the provision of the Havelock Product(s) (hereinafter referred to as Personal Data);

Whereas: both parties are intending to sets out their obligations with regards to the processing of the Personal Data, including such obligations as are required in order to comply with the  EU Regulation (EU) 2016/679 of 27 April 2016 as amended from time to time (General Data Protection Regulation, GDPR) on a mutually beneficial basis;

the following Data Processing Policy (DPP) shall apply:

1. Roles of parties

  1. The parties acknowledge and agree that: 
    1. Havelock shall process Personal Data in connection with the access of Customer’s employees – members of Customer’s staff, solely on behalf of Customer and in accordance with Customer’s instructions. 
    2. Accordingly,  in the circumstances as per a) hereinabove, Havelock acts as a Processor in respect of these data processing services (as such term is defined in the GDPR) and Customer acts as Controller to this personal data;

2. Subject-matter of the processing, nature and purpose of the processing, types of personal data and categories of data subjects

  1. Where Havelock acts as a Processor, the purpose of the processing of Personal Data (pursuant to Art. 28(3) GDPR) by Havelock is the provision of the Havelock Products pursuant to the Agreement. The types of Personal Data and categories of Data Subjects Processed by Havelock, when acting as a Processor, under this DPP are further specified in Annex 1 (Data Processing Details Annex) to this DPP.
  2. Customer shall be obliged to create technical and legal prerequisites, so that before commencing any interaction with Havelock Product (s), the individuals as per clause 1.1., letter “a” above provide their clear and unequivocal consent that their Personal Data is processed, as described in Annex 1 below by a third party – data processor, different from the Customer.  

3. Compliance with Data Protection Law

  • In respect of the Personal Data for which Customer and Havelock each act as Controllers, Customer and Havelock shall comply with their respective obligations under the GDPR and all other mandatory laws and regulations of the European Union (Data Protection Laws). The parties acknowledge that this DPP may allocate responsibility for compliance with a particular requirement under Data Protection Law to one party, but that such contractual allocation of responsibility shall not relieve either party from its obligations under Data Protection Law.
  • Whenever Havelock processes Personal Data as Processor, it shall comply with Data Protection Laws as they apply to Havelock as a Processor.

4. Processing of Personal Data and Customer’s instructions

  1. Havelock shall only process Personal Data that it processes as a Processor in accordance with Customer’s instructions (pursuant to Art. 28 clause (3)(a) GDPR) or as required by law. Customer instructs Havelock to process Personal Data to provide the Havelock Products (s) as described in the DPP and the Agreement. 
  2. Customer shall (a) ensure that any instructions it issues to Havelock pursuant to clause 4.1 shall comply with Data Protection Laws; (b) have sole responsibility for the accuracy, quality, and legality of Personal Data, and the means by which Customer acquired Personal Data; (c) notify Havelock upon becoming aware that Personal Data has become inaccurate or out of date; and (d) establish the legal basis for processing under Data Protection Laws, including by providing all notices and obtaining all consents as may be required under Data Protection Laws in order for Havelock to lawfully and fairly process Personal Data in order to provide the Havelock Products (s) and as otherwise contemplated by this DPP and the remainder of the Agreement.
  3. Customer warrants that (a) the disclosure of Personal Data to Havelock is limited to what is necessary in order for Havelock to perform the Services; and (b) such Personal Data is accurate and up to date at the time that it is provided to Havelock.
  4. Without prejudice to Customer’s obligations under clause 4.2., Havelock shall inform Customer if, in its reasonable opinion, an instruction issued by Customer infringes Data Protection Laws and shall, without liability, be entitled to stop processing Personal Data in accordance with such infringing instruction. The parties acknowledge and agree that a failure or delay by Havelock to identify that an instruction infringes Data Protection Laws shall not cause Havelock to be in breach of neither DPP nor Agreement. 
  5. Customer agrees that during and after the term of the Agreement Havelock may use any information it collects and uses in connection with the provision of the Service, together with information from its other services, for data analytics purposes, including to create insights, reports and other analytics to improve the quality of and market Havelock advice, products and services. 

5. Confidentiality and security of processing, Breach Management and Notification

  1. Havelock shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (pursuant to Art. 28(3)(b) GDPR). Havelock shall not disclose Personal Data to any third parties without Customer’s prior consent, except as required by law or permitted by the Agreement. 
  2. Havelock shall take the technical and organisational measures set out in Annex 2 (Security Measures) to protect the confidentiality, integrity, availability and resilience of Havelock systems which are involved in processing Personal Data. Customer has assessed the level of security appropriate to the processing in the context of its obligations under Data Protection Laws and agrees that the security measures set out in Addendum 2 are consistent with such assessment. 
  3. Customer shall take appropriate technical and organisational measures to protect the security of the Personal Data, including ensuring that Personal Data is securely transferred to Havelock. 
  4. Havelock shall promptly notify Customer upon becoming aware of the occurrence of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, transmitted, stored or otherwise processed (Personal Data Breach) and provide Customer with the following information as it becomes available:
    1. a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects concerned;
    2. the name and contact details of the Havelock contact from whom more information can be obtained; and
    3. a description of the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
  5. Customer shall promptly notify Havelock upon becoming aware of the occurrence of a Personal Data Breach.
  6. The parties agree to coordinate in good faith on developing the content of any related public statements and any required notices to the affected data subjects and/or the relevant supervisory authority with authority under Data Protection Laws over the processing of Personal Data (Data Protection Regulator) in connection with a Personal Data Breach.

6. Data Subject Rights; Other Complaints and Requests

  1. If Havelock receives a request from a data subject to access, correct, amend, transfer or delete that person’s Personal Data consistent with that person’s rights under Data Protection Laws (Data Subject Request), then to the extent permitted by law or unless otherwise agreed by the parties:
    1. Havelock shall promptly notify Customer upon receipt of the Data Subject Request. Following receipt of a Data Subject Request, Havelock may contact the relevant data subject to acknowledge receipt of the Data Subject Request and to notify the data subject that it has referred the Data Subject Request to Customer, but Havelock shall otherwise not respond to any Data Subject Request without Customer’s prior written instructions; 
    2. Customer shall handle the Data Subject request in accordance with Data Protection Law; and
    3. Havelock shall provide such commercially reasonable assistance as Customer may reasonably request to help Customer fulfil its obligations under Data Protection Laws to respond to Data Subject Requests. Customer shall be responsible for any reasonable costs arising from Havelock provision of such assistance.
  2. To the extent permitted by law, Havelock shall promptly notify Customer upon receipt of any complaint or request (other than Data Subject Requests or enquiries of Data Protection Regulators described in clause 7) relating to: (a) Customer’s obligations under data protection laws; or (b) Personal Data. 

Unless otherwise agreed between the parties, Customer shall handle the relevant complaint or request in accordance with Data Protection Law and Havelock shall provide such commercially reasonable assistance as Customer may reasonably request in relation to such complaint or request. Customer shall be responsible for any reasonable costs arising from Havelock provision of such assistance.

7. Cooperation with Data Protection Regulators and Conduct of Claims

  1. Havelock shall notify Customer of all enquiries from a Data Protection Regulator that Havelock receives which relate to the processing of Personal Data, unless prohibited from doing so at law or by the Data Protection Regulator. 
  2. In respect of Personal Data that Havelock processes in relation to Services that it provides as a Processor, unless a Data Protection Regulator requests in writing to engage directly with Havelock or the parties (acting reasonably and taking into account the subject matter of the request) agree that Havelock shall handle a Data Protection Regulator request itself, Customer shall: (a) be responsible for all communications or correspondence with the Data Protection Regulator in relation to the processing of Personal Data and the provision or receipt of the Services; and (b) keep Havelock informed of such communications or correspondence to the extent permitted by law.

8. Return and Deletion of Personal Data

  1. On termination of the Agreement for any reason, or upon written request from Customer at any time, Havelock shall cease processing any Personal Data, and (at Customer’s direction) return to Customer or delete (in accordance with Havelock document retention and deletion policies), any Personal Data in Havelock possession or control, except as required by law or as required in order to defend any actual or possible legal claims and except as retained pursuant to clause 4.5. 
  2. Customer acknowledges and agrees that Havelock shall have no liability for any losses incurred by Customer arising from or in connection with Havelock inability to perform the Services as a result of Havelock complying with a request to delete or return Personal Data made by Customer.

9. Conflict with the Agreement, term of this DPP and Miscellaneous

  1. In the event of a conflict between the terms of the Agreement and the terms of this DPP, the terms of this DPP shall prevail. 
  2. The binding effect of this DPP to the relations between Havelock and the Customer will be terminated when Havelock ceases to process Personal Data, unless otherwise agreed in writing between the parties.
  3. Unless expressly stated otherwise in this DPP, the parties agree that all liabilities between them under this DPP will be subject to the limitations and exclusions of liability and other terms of the Agreement.
  4. To the extent required by applicable Data Protection Laws, this DPP shall be governed by the laws  of the European Union. In all other cases, this DPP shall be governed by the laws of the jurisdiction specified in the Agreement.

ANNEX 1

Data Processing Details Annex

1. Controller

Customer and the Customer affiliates that process Personal Data for their own business purposes.

2. Processor

The processor is Havelock.

3. Data subjects

The Personal Data processed concern the following categories of data subjects:

  • employees of the Customer – members of Customer’s staff, like, but not limited to, individuals, directly involved in Customer’s operations and using Havelock Product (s) as End Users as defined in the Terms; 
  • individuals that interact with the Customer in relation with Customer’s  business operations as commercial counterparts, suppliers and other external service providers of the Customer, who’s Personal Data may, for any reason become subject to processing by Havelock in relation to Customer’s use of the Havelock Product (s). 

4. Categories of data

The Personal Data processed concern the following categories of data of the Data subjects: 

  • Identification data : name, e-mail adress, position in the company, phone number, nickname and avatar created within the Haveloc Product (s). 
  • Behavioral data regarding performance of employment duties.

Processing operations

The Personal Data processed will be subject to the following basic processing activities:

Havelock, acting as a Processor, will, depending on the scope of its engagement, process the Personal Data provided by the Customer, to comply with its statutory and regulatory obligations, to maintain accounts and records and to conduct analysis in order to improve its products and services. This will involve, among other things, the collection, storage, analysis (including – automated profyling) and disclosure of Personal Data that Havelock receives from the Controller within the course of provision of the Havelock Products (s).

Personal Data sjhall be stored, through the cloud service providers of Havelock only in  the territory of EU and will not, for whatever reason be exported to any Third Countries withat the explicit written approval of the Customer.

ANNEX 2

Security Measures

In satisfaction of its obligation under clause 5.2 of this DPP, Havelock shall implement the following: 

  1. Organizational management and dedicated staff responsible for the development, implementation and maintenance of Havelock information security program. 
  2. Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Havelock’s organization, monitoring and maintaining compliance with Havelock policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
  3. Data security controls which include at a minimum, but may not be limited to, logical segregation of data, restricted (e.g. role-based) access and monitoring, and utilization of commercially available and industry standard encryption technologies for Personal Data that is:
    1. transmitted over public networks (i.e. the Internet) or when transmitted wirelessly; or
    2. at rest or stored on portable or removable media (i.e. laptop computers, CD/DVD, USB drives, back-up tapes). 
  4. Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, (e.g. granting access on a need-to-know and least privilege basis, use of unique IDs and passwords for all users, periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).
  5. Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords and requiring that Havelock passwords that are assigned to its employees: (i) be at least eight (8) characters in length, (ii) not be stored in readable format on Havelock computer systems; (iii) must be changed every ninety (90) days; must have defined complexity; (v) must have a history threshold to prevent reuse of recent passwords; and (vi) newly issued passwords must be changed after first use.
  6. System audit or event logging and related monitoring procedures to proactively record user access and system activity for routine review. 
  7. Physical and environmental security of data center, server room facilities and other areas containing Personal Data designed to: (i) protect information assets from unauthorised physical access, (ii) manage, monitor and log movement of persons into and out of Havelock facilities, and (iii) guard against environmental hazards such as heat, fire and water damage.
  8. Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems according to prescribed internal and adopted industry standards, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Havelock possession.
  9. Change management procedures and tracking mechanisms designed to test, approve and monitor all changes to Havelock technology and information assets.
  10. Incident / problem management procedures designed to allow Havelock to investigate, respond to, mitigate and notify of events related to Havelock technology and information assets. 
  11. Network security controls that provide for the use of enterprise firewalls and intrusion detection systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack.
  12. Vulnerability assessment, patch management, and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
  13. Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergency situations or disasters. 

Havelock reserves the right to revise the security measures set out in this Annex 2 at any time, without notice, so long as any such revisions will not materially reduce or weaken the protection provided for Personal Data that Havelock processes in the course of providing the Service to the Customer.

 

Approved by the Executive Director of Havelock JSC Ltd. on September 25, 2019, amended by the Executive Director of Havelock JSC on September 9, 2024 and October 28th, 2025.