1. Parties and incorporation

This Data Processing Agreement (the “DPA”) forms part of the SoundEar Cloud Terms and applies where SoundEar A/S processes Customer Personal Data on behalf of a business customer in connection with SoundEar Cloud™.

The parties are:

  • Customer: the business customer purchasing, activating or using SoundEar Cloud™ access and acting as controller of Customer Personal Data.
  • Processor: SoundEar A/S, VAT DK21060380, Alfavej 4C, DK-3250 Gilleleje, Denmark, email: soundear@soundear.com.

By accepting the SoundEar Cloud Terms, the Customer also accepts this DPA. This DPA is binding for the duration of SoundEar Cloud access and for any period during which SoundEar processes Customer Personal Data on behalf of the Customer.

2. Definitions

Terms such as controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meaning given to them in applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 (GDPR), where applicable.

“Customer Personal Data” means any personal data processed by SoundEar on behalf of the Customer through SoundEar Cloud™. “Customer Data” means data submitted to, generated by or stored in SoundEar Cloud™ for the Customer, including measurement data and reports.

3. Roles of the parties

For Customer Personal Data processed in SoundEar Cloud™, the Customer is the controller and SoundEar is the processor. SoundEar may act as an independent controller for limited business administration purposes outside this DPA, including billing, accounting, legal compliance and general customer relationship management, as described in SoundEar’s Privacy Policy.

4. Subject matter and purpose of processing

SoundEar processes Customer Personal Data solely for the purpose of providing, securing, supporting and improving SoundEar Cloud™ in accordance with the SoundEar Cloud Terms, this DPA and the Customer’s documented instructions.

SoundEar Cloud™ is used for online access to sound-level/noise measurement data, device overview, reporting, documentation and online configuration for compatible SoundEar devices. No audio is recorded or stored in SoundEar Cloud™; only sound-level/noise measurement data and related technical and account data are processed.

5. Customer instructions

The Customer instructs SoundEar to process Customer Personal Data as necessary to provide SoundEar Cloud™ and related support, security, maintenance, reporting, data export and administration. The SoundEar Cloud Terms, this DPA, the Customer’s use of SoundEar Cloud™ and written instructions accepted by SoundEar constitute the Customer’s documented instructions.

6. Customer responsibilities

The Customer is responsible for ensuring that it has a lawful basis for processing Customer Personal Data in SoundEar Cloud™, that users are properly authorised, and that the Customer does not submit data that is unlawful, excessive or outside the intended use of SoundEar Cloud™. The Customer must not intentionally submit special categories of personal data, audio recordings, health records, personnel files or other sensitive personal data to SoundEar Cloud™ unless expressly agreed in writing with SoundEar.

7. SoundEar’s processor obligations

SoundEar shall process Customer Personal Data only on documented instructions from the Customer, unless required to do otherwise by applicable law. SoundEar shall ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations. SoundEar shall implement appropriate technical and organisational measures as described in Schedule 2.

8. Security measures

SoundEar shall maintain commercially reasonable technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include, as applicable, access control, encryption in transit, protected secrets management, monitoring/logging, backup routines, system updates and administrative access restrictions.

9. Hosting and data location

SoundEar Cloud™ is hosted on Microsoft Azure in the Western Europe / West Europe region within the EU/EEA. According to the technical information confirmed by SoundEar, database, file storage, backups, logs and telemetry are located in the same EU/EEA region. SoundEar Cloud™ email communications, including report emails with PDF attachments, are sent using Azure Email Services. Customer Personal Data, logs, telemetry and support data are not sent outside the EU/EEA under the current architecture.

10. Sub-processors

SoundEar may use sub-processors to provide SoundEar Cloud™. The current sub-processors are listed in Schedule 3. SoundEar remains responsible to the Customer for the performance of its sub-processors’ data protection obligations. SoundEar may appoint or replace sub-processors where this is reasonably necessary for the operation, security or improvement of SoundEar Cloud™, provided that the Customer is informed through the DPA, the Privacy Policy, the SoundEar website or another reasonable channel.

11. Data subject requests

SoundEar shall provide reasonable assistance to the Customer, taking into account the nature of the processing, to enable the Customer to respond to data subject requests under applicable data protection law. The Customer remains responsible for responding to data subjects unless SoundEar is legally required to respond directly.

12. Personal data breach

SoundEar shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Such notice shall include available information reasonably required by the Customer to assess the breach and fulfil any notification obligations, to the extent such information is available to SoundEar.

13. Assistance and compliance

Taking into account the nature of processing and the information available to SoundEar, SoundEar shall provide reasonable assistance to the Customer in relation to security, breach notification, data protection impact assessments and prior consultation with supervisory authorities, where required by applicable data protection law. SoundEar may charge the Customer for assistance that is not included in ordinary SoundEar Cloud™ support or is caused by the Customer’s special requirements, unless prohibited by law.

14. Data export, expiry and deletion

During active access, the Customer can export available measurement data from SoundEar Cloud™ in CSV format. Reports may be downloaded where reporting functionality is available and may be sent to Customers by email as PDF attachments using Azure Email Services. After expiry of access, measuring points without active access may no longer deliver fresh data to SoundEar Cloud™, while user access may remain available for read-only/export purposes for 30 days. After the 30-day export period, historical Customer Data may be deleted or anonymised. Backups are retained on a rolling 14-day basis, after which deleted data is removed through normal backup rotation.

15. Return or deletion at end of processing

Upon expiry or termination of SoundEar Cloud™ access and after any applicable export/read-only period, SoundEar shall delete or anonymise Customer Data in accordance with the retention process described above, unless continued retention is required by law or necessary for legitimate security, compliance, accounting or dispute-resolution purposes.

16. International transfers

SoundEar’s current architecture is intended to process Customer Personal Data within the EU/EEA. If SoundEar later needs to transfer Customer Personal Data outside the EU/EEA, SoundEar shall ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, Standard Contractual Clauses or another valid legal mechanism under applicable data protection law.

17. Audits and information

SoundEar shall make available information reasonably necessary to demonstrate compliance with this DPA. Audits shall be conducted in a manner that protects SoundEar’s systems, security, confidentiality and other customers’ data. On-site audits or penetration testing of SoundEar systems require SoundEar’s prior written approval and may be subject to reasonable limitations, confidentiality obligations, security requirements and cost reimbursement.

18. Aggregated and anonymised data

Data that has been irreversibly anonymised so that neither the Customer, individual users nor data subjects can reasonably be identified is not Customer Personal Data. SoundEar may use aggregated and anonymised data for statistics, benchmarking, product improvement, development, algorithms, models, insights and features, in accordance with the SoundEar Cloud Terms.

19. Order of precedence

In the event of conflict between this DPA and the SoundEar Cloud Terms, this DPA shall prevail only with respect to the processing of Customer Personal Data. The SoundEar Cloud Terms continue to govern commercial matters including payment, access, liability, governing law and disputes.

20. Contact

Questions regarding this DPA or SoundEar’s processing of personal data may be sent to soundear@soundear.com.

 

Schedule 1 – Details of processing

Item Description
Subject matter Provision of SoundEar Cloud™ access for compatible SoundEar devices, including online access to logged sound-level/noise measurement data, device overview, reporting, documentation, data export and online configuration.
Duration For the duration of the Customer’s active SoundEar Cloud™ access and any applicable read-only/export period. Backup retention follows a rolling 14-day cycle. After expiry and any applicable export period, Customer Data may be deleted or anonymised unless retention is legally required.
Purpose To provide, secure, support, maintain and improve SoundEar Cloud™ and to enable the Customer to manage noise measurement data and reporting.
Categories of data subjects Customer administrators, Cloud users, business contacts, support contacts and persons whose device or network usage may be reflected in logs. Fixed-location sound-level/noise measurement data may relate to a workplace or environment but is not intended to identify individuals.
Categories of personal data Name, business email, company details, user/account information, device ID, measuring point information, logged sound-level/noise measurement data, reports, report PDF attachments, login/access logs, IP addresses, technical logs and telemetry. No audio is recorded or stored.
Special categories of personal data None intended. The Customer must not intentionally submit special categories of personal data or other sensitive personal data to SoundEar Cloud™ unless expressly agreed in writing.
Processing operations Collection, receipt, storage, hosting, structuring, access, retrieval, display, reporting, PDF report generation, email transmission of reports, export, transmission, security monitoring, logging, backup, deletion and anonymisation.
Export format CSV export for available measurement data. Reports may be downloaded where reporting functionality is available and may be sent by email as PDF attachments.

 

Schedule 2 – Technical and organisational measures

SoundEar applies technical and organisational measures appropriate to the nature of SoundEar Cloud™ and the risk associated with the processing. Measures may include the following, as applicable:

Measure Description
Hosting and environment Hosting on Microsoft Azure in the Western Europe / West Europe region within the EU/EEA. Database, file storage, backups, logs and telemetry are kept in the same EU/EEA region according to the current architecture. Cloud email communications, including report emails with PDF attachments, are sent using Azure Email Services.
Access control Administrative access is restricted to authorised personnel and is granted on a need-to-know basis. User access is account-based.
Secrets and configuration Protected management of credentials and secrets, including use of secure secrets management where applicable.
Encryption and transmission Use of encrypted communication channels where applicable for data transmission between devices, users and SoundEar Cloud™.
Logging and monitoring Operational logs and telemetry are used for security, troubleshooting, performance and availability monitoring. Customer Personal Data, logs, telemetry and support data are not sent outside the EU/EEA under the current architecture.
Backups Rolling backup retention of 14 days. Deleted data is removed from backups through normal rotation.
Separation and minimisation Processing is limited to data necessary to provide, secure and support SoundEar Cloud™. No audio is recorded or stored.
Confidentiality Personnel authorised to process Customer Personal Data are subject to confidentiality obligations.
Incident response Procedures for investigating, mitigating and notifying relevant Customers of personal data breaches affecting Customer Personal Data.
Security information Detailed internal service architecture and security configuration are not publicly disclosed where disclosure could increase security risk.

 

Schedule 3 – Current sub-processors

The following sub-processors are used in connection with SoundEar Cloud™ or related Cloud operation. One.com is not listed as a SoundEar Cloud sub-processor because, according to the current technical information confirmed by SoundEar, it is used only for domain configuration and does not process SoundEar Cloud Customer Data.

Sub-processor Purpose Location / region
Microsoft Azure / Microsoft Cloud hosting, infrastructure, storage, database, logs, telemetry, backup and email communications/report delivery, including PDF attachments sent through Azure Email Services Western Europe / West Europe, EU/EEA
Datalix.eu Hosting of MQTT server and processing of associated production device/data traffic for SoundEar Cloud™ EU/EEA

 

Schedule 4 – Publication links to insert

Document URL
SoundEar Cloud Terms https://soundear.com/soundear-cloud-terms/
SoundEar Cloud Data Processing Agreement https://soundear.com/soundear-cloud-data-processing-agreement/
Privacy Policy https://soundear.com/privacy-policy/
Cookie Policy https://soundear.com/cookie-policy/