Legal

Data Processing Agreement

Effective Date: January 1, 2025 · Last Updated: January 1, 2025

This Data Processing Agreement ("DPA") forms part of the agreement between Artevotrade LLC ("Processor") and the client entity ("Controller") and governs the processing of personal data by Artevotrade LLC on behalf of the Controller in connection with the services provided.

1. Definitions

For the purposes of this DPA, the following definitions apply:

  • "Controller" means the client entity that determines the purposes and means of processing personal data.
  • "Processor" means Artevotrade LLC, which processes personal data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person as defined under applicable data protection law, including but not limited to the GDPR, CCPA, LGPD, POPIA, and PIPEDA.
  • "Processing" means any operation or set of operations performed on personal data, including collection, storage, use, disclosure, and deletion.
  • "Data Subject" means the natural person to whom the personal data relates.
  • "Applicable Data Protection Law" means all laws and regulations applicable to the processing of personal data under this DPA, including without limitation the EU General Data Protection Regulation (GDPR 2016/679), the California Consumer Privacy Act (CCPA), Brazil's Lei Geral de Proteção de Dados (LGPD), South Africa's Protection of Personal Information Act (POPIA), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

2. Subject Matter and Duration

This DPA applies to the processing of personal data by Artevotrade LLC as Processor in connection with the professional training, consulting, and technology transfer services ("Services") provided to the Controller pursuant to the applicable service agreement.

The duration of processing shall correspond to the term of the service agreement between the parties, unless otherwise specified or required by applicable law. Upon termination of the service agreement, Artevotrade LLC shall cease processing and, at the Controller's election, return or securely delete all personal data unless retention is required by law.

3. Nature and Purpose of Processing

Artevotrade LLC processes personal data solely as necessary to deliver the contracted Services, which may include:

  • Administration and scheduling of training programs and workshops
  • Delivery of e-learning, blended learning, and in-person training
  • Assessment and evaluation of learner performance
  • Communication with participants and organizational stakeholders
  • Generation of training completion reports and impact assessments
  • Technology transfer project coordination and documentation

Processing is carried out strictly on the documented instructions of the Controller, unless otherwise required by applicable law.

4. Categories of Personal Data and Data Subjects

4.1 Categories of Personal Data

Depending on the nature of the Services, Artevotrade LLC may process the following categories of personal data:

  • Identification data: name, job title, employee ID
  • Contact data: professional email address, telephone number
  • Training data: attendance records, assessment results, certifications of completion
  • Professional data: department, role, organization, seniority level
  • Technical data: login credentials for learning platforms, IP addresses, device identifiers

4.2 Categories of Data Subjects

  • Employees, staff, and contractors of the Controller organization
  • Trainees and program participants
  • Project stakeholders and designated contacts

5. Obligations of the Processor

Artevotrade LLC, as Processor, undertakes the following obligations:

  • Instruction compliance: Process personal data only on documented instructions from the Controller, unless required to do so by applicable law.
  • Confidentiality: Ensure that all personnel authorized to process personal data are bound by appropriate confidentiality obligations.
  • Security: Implement and maintain appropriate technical and organizational security measures in accordance with Section 7 of this DPA.
  • Sub-processors: Engage sub-processors only with prior written authorization (specific or general) from the Controller, and only under a written agreement imposing equivalent data protection obligations.
  • Data subject rights: Assist the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under applicable data protection law.
  • Data breach notification: Notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of any personal data breach, providing all information necessary for the Controller to fulfill its own notification obligations.
  • Data protection impact assessments: Provide reasonable assistance to the Controller in conducting data protection impact assessments and prior consultations with supervisory authorities where required.
  • Deletion or return: Upon termination of the Services, delete or return all personal data to the Controller as directed, and delete existing copies unless applicable law requires retention.
  • Audit cooperation: Make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by the Controller or its appointed auditor, with reasonable prior notice.

6. Obligations of the Controller

The Controller undertakes to:

  • Ensure that personal data is collected and transferred to Artevotrade LLC in compliance with applicable data protection law.
  • Provide clear and documented processing instructions to Artevotrade LLC.
  • Ensure that data subjects have been provided with appropriate privacy notices concerning the processing activities described herein.
  • Obtain all necessary consents or establish all necessary legal bases for the processing of personal data by Artevotrade LLC.
  • Promptly notify Artevotrade LLC of any changes in processing instructions.

7. Security Measures

Artevotrade LLC implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, including:

Technical Measures

  • • Encryption of personal data in transit (TLS 1.2+) and at rest
  • • Access controls and role-based permissions
  • • Multi-factor authentication for systems handling personal data
  • • Regular security assessments and vulnerability testing
  • • Data minimization and pseudonymization where feasible

Organizational Measures

  • • Data protection training for all personnel
  • • Internal data protection policies and procedures
  • • Need-to-know access restrictions
  • • Incident response and breach notification procedures
  • • Vendor due diligence for sub-processors

8. Sub-processors

Artevotrade LLC may engage sub-processors to assist in the delivery of Services. Where such sub-processors process personal data, Artevotrade LLC ensures that:

  • Sub-processors are bound by written data processing agreements imposing obligations equivalent to those in this DPA.
  • Sub-processors are selected on the basis of their ability to provide sufficient guarantees regarding technical and organizational security measures.
  • The Controller is informed of any intended changes to sub-processors, allowing the Controller a reasonable opportunity to object prior to such engagement.

A current list of sub-processors may be requested by contacting Artevotrade LLC at the contact details provided in Section 11.

9. International Data Transfers

Given the international nature of Artevotrade LLC's operations, personal data may be transferred to and processed in countries outside the jurisdiction of the Controller. Where such transfers occur, Artevotrade LLC ensures that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs): Transfers from the European Economic Area (EEA) to third countries are governed by the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable).
  • Adequacy decisions: Transfers to countries recognized by the European Commission as providing an adequate level of data protection.
  • Binding Corporate Rules or other equivalent mechanisms as may be applicable under the relevant data protection framework.

A copy of the applicable transfer mechanism may be requested by contacting Artevotrade LLC.

10. Data Subject Rights

Artevotrade LLC assists the Controller in fulfilling its obligations to respond to requests from data subjects. Data subjects may be entitled, under applicable law, to exercise the following rights:

Right of Access

Obtain confirmation and copies of personal data processed

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of personal data under certain conditions

Right to Restriction

Limit the processing of personal data in specific circumstances

Right to Portability

Receive personal data in a structured, machine-readable format

Right to Object

Object to processing based on legitimate interests or direct marketing

Data subjects wishing to exercise these rights should contact the Controller directly. Artevotrade LLC will cooperate with the Controller in addressing such requests within the timeframes required by applicable law.

11. Contact and Governing Law

For questions, concerns, or requests relating to this DPA or the processing of personal data, please contact:

Artevotrade LLC

Data Protection Contact

1209 Mountain Road PL NE, #10014

Albuquerque, NM 87110, USA

This DPA is governed by the laws of the State of New Mexico, USA, except where overriding mandatory provisions of applicable data protection law (such as the GDPR) apply. In the event of any conflict between this DPA and applicable data protection law, the provisions of applicable data protection law shall prevail.

12. Amendments

Artevotrade LLC reserves the right to amend this DPA to reflect changes in applicable data protection law, operational practices, or regulatory guidance. Material changes will be communicated to Controllers with reasonable advance notice. Continued use of the Services following such notice constitutes acceptance of the revised DPA.