Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the Terms of Service and governs the processing of personal data by Steema Software SL on behalf of customers using the Visamic platform.
Last updated: July 2025
Definitions
For the purposes of this DPA, the following terms have the meanings set forth below:
- Personal Data: Any information relating to an identified or identifiable natural person that is provided by Customer to Steema in connection with the Services.
- Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- Data Subject: The individual to whom Personal Data relates.
- GDPR: General Data Protection Regulation (EU) 2016/679.
Scope and Roles
Data Controller
The Customer acts as the Data Controller, determining the purposes and means of processing Personal Data.
Data Processor
Steema Software SL acts as the Data Processor, processing Personal Data on behalf of and according to the instructions of the Customer.
Data Processing Principles
Steema commits to processing Personal Data in accordance with the following principles:
- Process data lawfully, fairly, and transparently
- Collect data for specified, explicit, and legitimate purposes
- Ensure data is adequate, relevant, and limited to what is necessary
- Maintain accurate and up-to-date data
- Retain data only as long as necessary
- Process data securely with appropriate technical and organizational measures
Customer Instructions
Steema will process Personal Data only in accordance with Customer's documented instructions, unless required to do so by applicable law. The initial instruction is to provide the Services as described in the Terms of Service. Additional instructions must be provided in writing.
Security Measures
Steema implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Technical Measures
- Encryption of data at rest and in transit
- Access controls and authentication
- Regular security updates and patches
- Intrusion detection systems
Organizational Measures
- Staff training and awareness programs
- Confidentiality commitments
- Incident response procedures
- Regular security audits
Sub-Processors
Authorization
Customer provides general authorization for Steema to engage sub-processors to assist in providing the Services. Steema will maintain a list of current sub-processors on our website.
Requirements
Any sub-processor will be required to provide the same level of data protection as set forth in this DPA, and Steema will remain liable for the sub-processor's compliance.
Data Subject Rights
Steema will assist Customer in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under applicable data protection laws, including:
- Right of access to personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
Data Breach Notification
Steema will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data. The notification will include available information about the nature of the breach, affected data, likely consequences, and measures taken or proposed to address the breach.
Data Retention and Deletion
Return or Deletion
Upon termination of the Services, Steema will, at Customer's choice, return or delete all Personal Data, unless required by law to retain certain data.
Retention Period
A 30-day retention period is provided after termination to allow data recovery. After this period, all data will be securely deleted unless otherwise agreed or required by law.
Audits and Compliance
Steema will make available to Customer information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice and confidentiality obligations.
International Data Transfers
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA). Such transfers will be protected by appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission. For more information, contact privacy@steema.com.