Between
Weber IT-System,
Maribel Lopez Perez Ojeda 32,
weber-system.ch,
(hereinafter: “Processor”)
and
the Customer,
as specified during registration,
(hereinafter: “Controller”),
the following agreement is concluded:
§1 Subject of Processing
The Processor provides hosting and cloud services (Nextcloud). In doing so, the Processor processes personal data on behalf of the Controller.
§2 Duration
Processing is carried out for the duration of the contractual relationship regarding the booked product. After the contract ends, all data will be completely and irreversibly deleted.
§3 Nature and Purpose of Data Processing
Storage and management of personal files in Nextcloud
Access control and rights management
Backups according to product description
§4 Type of Data Processed
In particular, the following data may be processed:
Contact details of users
Content data (e.g., documents, photos)
Usage and metadata
§5 Categories of Data Subjects
Customers, clients, patients, or employees of the Controller
User accounts created by the Controller
§6 Obligations of the Processor
The Processor particularly undertakes:
to maintain confidentiality
to implement technical and organizational measures (TOMs)
to promptly notify the Controller of any data breaches
to support the Controller with data subject requests
to delete or return all data after contract termination
§7 Rights and Obligations of the Controller
The Controller remains the owner of the data at all times and is responsible for their lawful processing. The Controller must properly instruct the Processor and only transfer data in accordance with the GDPR.
§8 Subprocessors
The Processor may engage subprocessors (e.g., hosting providers, email providers). An up-to-date list will be provided upon request. The Controller will be informed of any changes.
§9 Technical and Organizational Measures
The Processor has implemented appropriate TOMs pursuant to Art. 32 GDPR, in particular:
Encrypted connections (HTTPS, SSL)
Password-protected access
Data backups
Firewalls and monitoring
§10 Final Provisions
This agreement enters into force upon the Controller’s electronic acceptance during the order process.
If incorrect or incomplete information is provided during registration, this agreement is invalid.
Swiss/EU law shall apply, depending on the location of the Processor.
Place of jurisdiction is Alicante, Spain.
Consent
By checking the box in the order form, the Controller confirms that they have read and accepted this agreement.