Whereas: Customer had accepted the General Terms and Conditions of Havelock JSC and/or Customer and Havelock JSC had executed a Master Service Agreement and therefore Customer and Havelock JSC had entered into contractual relation (hereinafter referred to as the Agreement);
Whereas: Havelock JSC, a company, established and existing under the laws of Republic of Bulgaria, having its company No: 205602831 at Bulgarian Trade Register, having its registered seat and address at 54 “Iskar” str., city of Sofia, Republic of Bulgaria, contact e-mail info@havelock.app (hereinafter referred to as “Havelock”) administrates and/or processes information relating to an identified or identifiable natural persons provided by or on behalf of Customer as part of the provision of the Havelock Product(s) (hereinafter referred to as Personal Data);
Whereas: both parties are intending to sets out their obligations with regards to the processing of the Personal Data, including such obligations as are required in order to comply with the EU Regulation (EU) 2016/679 of 27 April 2016 as amended from time to time (General Data Protection Regulation, GDPR) on a mutually beneficial basis;
the following Data Processing Policy (DPP) shall apply:
- If Havelock receives a request from a data subject to access, correct, amend, transfer or delete that person’s Personal Data consistent with that person’s rights under Data Protection Laws (Data Subject Request), then to the extent permitted by law or unless otherwise agreed by the parties:
- Havelock shall promptly notify Customer upon receipt of the Data Subject Request. Following receipt of a Data Subject Request, Havelock may contact the relevant data subject to acknowledge receipt of the Data Subject Request and to notify the data subject that it has referred the Data Subject Request to Customer, but Havelock shall otherwise not respond to any Data Subject Request without Customer’s prior written instructions;
- Customer shall handle the Data Subject request in accordance with Data Protection Law; and
- Havelock shall provide such commercially reasonable assistance as Customer may reasonably request to help Customer fulfil its obligations under Data Protection Laws to respond to Data Subject Requests. Customer shall be responsible for any reasonable costs arising from Havelock provision of such assistance.
- To the extent permitted by law, Havelock shall promptly notify Customer upon receipt of any complaint or request (other than Data Subject Requests or enquiries of Data Protection Regulators described in clause 7) relating to: (a) Customer’s obligations under data protection laws; or (b) Personal Data.
Unless otherwise agreed between the parties, Customer shall handle the relevant complaint or request in accordance with Data Protection Law and Havelock shall provide such commercially reasonable assistance as Customer may reasonably request in relation to such complaint or request. Customer shall be responsible for any reasonable costs arising from Havelock provision of such assistance.
Customer and the Customer affiliates that process Personal Data for their own business purposes.
The processor is Havelock.
The Personal Data processed concern the following categories of data subjects:
- employees of the Customer – members of Customer’s staff, like, but not limited to, individuals, directly involved in Customer’s operations and using Havelock Product (s) as End Users as defined in the Terms;
- individuals that interact with the Customer in relation with Customer’s business operations as commercial counterparts, suppliers and other external service providers of the Customer, who’s Personal Data may, for any reason become subject to processing by Havelock in relation to Customer’s use of the Havelock Product (s).
The Personal Data processed concern the following categories of data of the Data subjects:
- Identification data : name, e-mail adress, position in the company, phone number, nickname and avatar created within the Haveloc Product (s).
- Behavioral data regarding performance of employment duties.
The Personal Data processed will be subject to the following basic processing activities:
Havelock, acting as a Processor, will, depending on the scope of its engagement, process the Personal Data provided by the Customer, to comply with its statutory and regulatory obligations, to maintain accounts and records and to conduct analysis in order to improve its products and services. This will involve, among other things, the collection, storage, analysis (including – automated profyling) and disclosure of Personal Data that Havelock receives from the Controller within the course of provision of the Havelock Products (s).
Personal Data sjhall be stored, through the cloud service providers of Havelock only in the territory of EU and will not, for whatever reason be exported to any Third Countries withat the explicit written approval of the Customer.
In satisfaction of its obligation under clause 5.2 of this DPP, Havelock shall implement the following:
- Organizational management and dedicated staff responsible for the development, implementation and maintenance of Havelock information security program.
- Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Havelock’s organization, monitoring and maintaining compliance with Havelock policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
- Data security controls which include at a minimum, but may not be limited to, logical segregation of data, restricted (e.g. role-based) access and monitoring, and utilization of commercially available and industry standard encryption technologies for Personal Data that is:
- transmitted over public networks (i.e. the Internet) or when transmitted wirelessly; or
- at rest or stored on portable or removable media (i.e. laptop computers, CD/DVD, USB drives, back-up tapes).
- Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, (e.g. granting access on a need-to-know and least privilege basis, use of unique IDs and passwords for all users, periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).
- Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords and requiring that Havelock passwords that are assigned to its employees: (i) be at least eight (8) characters in length, (ii) not be stored in readable format on Havelock computer systems; (iii) must be changed every ninety (90) days; must have defined complexity; (v) must have a history threshold to prevent reuse of recent passwords; and (vi) newly issued passwords must be changed after first use.
- System audit or event logging and related monitoring procedures to proactively record user access and system activity for routine review.
- Physical and environmental security of data center, server room facilities and other areas containing Personal Data designed to: (i) protect information assets from unauthorised physical access, (ii) manage, monitor and log movement of persons into and out of Havelock facilities, and (iii) guard against environmental hazards such as heat, fire and water damage.
- Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems according to prescribed internal and adopted industry standards, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Havelock possession.
- Change management procedures and tracking mechanisms designed to test, approve and monitor all changes to Havelock technology and information assets.
- Incident / problem management procedures designed to allow Havelock to investigate, respond to, mitigate and notify of events related to Havelock technology and information assets.
- Network security controls that provide for the use of enterprise firewalls and intrusion detection systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack.
- Vulnerability assessment, patch management, and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
- Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergency situations or disasters.
Havelock reserves the right to revise the security measures set out in this Annex 2 at any time, without notice, so long as any such revisions will not materially reduce or weaken the protection provided for Personal Data that Havelock processes in the course of providing the Service to the Customer.
Approved by the Executive Director of Havelock JSC Ltd. on September 25, 2019, amended by the Executive Director of Havelock JSC on September 9, 2024 and October 28th, 2025.