1. Purpose
Those conditions governing the processing of personal data shall govern the relationship between the user and the provider regarding the personal data entered by the user on the platform HVAC.TOP..
HVAC.TOP
Installer operations
Legal
DPA regulates the relationship between user and provider regarding personal data entered by the user on the platform.
Date of entry into force: 17 June 2026
Those conditions governing the processing of personal data shall govern the relationship between the user and the provider regarding the personal data entered by the user on the platform HVAC.TOP..
For data entered by the user about his customers, employees, installers, contact persons, projects, services and orders, the user is normally the controller of personal data and the provider is the contractual processor.
In the case of data processed by the provider for its own business, accounting, accounting, support, security, prevention of abuse and management of user accounts, the provider is an independent personal data controller.
The provider processes the personal data of the user only in accordance with the conditions, subscription relationship, documented user instructions and applicable legislation.
If the provider considers that a specific user instruction is in breach of the law, it may refuse to implement such instruction or request further clarification.
In particular, the platform may process names and surnames, business names, addresses, telephone numbers, e-mail addresses, order details, services and projects, technical job descriptions, pictures, documents and attachments, data on employees or subcontractors, user and system logs.
The user may not enter specific types of personal data, health data, criminal convictions, identity documents or other sensitive data into the platform unless strictly necessary, legally and specifically agreed.
The provider shall process personal data during an active subscription and after termination of the period necessary for the export, security, proof, fulfilment of legal obligations or protection of legal interests.
Upon expiry of the retention period, the provider may delete or anonymous the data.
The provider shall implement reasonable technical and organisational measures such as access control, user authentication, limitation of access requirements, backups, technical maintenance, protection of server infrastructure, recording of relevant system events and measures to prevent unauthorised access.
The user shall grant the provider a general authorisation to use the sub-processors required to provide a platform such as roaming providers, e-mail services, payment services, analysts, security services and technical support.
Where personal data are transferred outside the EU/EEA, the provider shall provide an appropriate legal basis such as standard contractual clauses, adequacy decision or other legal mechanism.
The provider will, to a reasonable extent, assist the user in complying with the requirements of individuals, security incidents, deletion, rectification, access or restriction of processing, where the request relates to data processed in the platform.
If the provider detects a security incident concerning the personal data of the user, it will inform the user without undue delay when it has sufficient information available for reasonable notification.