1. Definitions
Terms including Personal Data, Processing, Controller, Processor, Data Subject, Personal Data Breach, Supervisory Authority, and Special Categories of Personal Data shall have the meanings assigned under Regulation (EU) 2016/679 ("GDPR").
Services means the services provided pursuant to the Agreement.
2. Scope and Relationship of the Parties
2.1 The parties acknowledge that:
- •Customer acts as Controller (or a Processor acting on behalf of a Controller);
- •Processor acts as Processor.
2.2 Processor shall Process Personal Data solely:
- •to provide and support the Services;
- •on documented instructions from Customer;
- •as required by applicable law.
2.3 Customer is responsible for:
- •establishing a lawful basis for Processing;
- •compliance with applicable privacy laws;
- •providing required privacy notices;
- •obtaining any required consents.
2.4 Processor shall promptly inform Customer if it believes an instruction violates applicable data protection laws unless prohibited by law.
3. Details of Processing
Subject Matter
Provision of the Services under the Agreement.
Nature of Processing
The Processing may include:
- •Collection
- •Recording
- •Organization
- •Storage
- •Retrieval
- •Consultation
- •Transmission
- •Hosting
- •Analysis
- •Backup
- •Deletion
Purpose
Processing is carried out solely to:
- •provide the Services;
- •authenticate users;
- •store Customer Content;
- •deliver requested functionality;
- •maintain service security;
- •provide technical support;
- •perform backup and recovery operations;
- •comply with legal obligations.
Processor shall not use Customer Personal Data for its own advertising or marketing purposes.
Duration
For the duration of the Agreement and any applicable post-termination retention period permitted by law.
Categories of Data Subjects
May include:
- •Employees
- •Contractors
- •Authorized users
- •Customers
- •Clients
- •End users
- •Website visitors
- •Support contacts
Categories of Personal Data
May include:
- •Names
- •Email addresses
- •Account identifiers
- •Company information
- •Uploaded content
- •Support communications
- •IP addresses
- •Device information
- •Usage logs
- •Metadata
- •Customer-generated content
Customer shall not provide Special Categories of Personal Data unless expressly authorized by Processor in writing.
4. Processor Obligations
Processor shall:
- •Process Personal Data only on documented instructions from Customer;
- •ensure authorized personnel are bound by confidentiality obligations;
- •implement appropriate technical and organisational measures;
- •assist Customer in complying with GDPR obligations;
- •notify Customer of Personal Data Breaches without undue delay;
- •provide information reasonably necessary to demonstrate compliance;
- •comply with Article 28 GDPR and other applicable privacy laws.
5. Confidentiality
Processor shall ensure that all persons authorized to Process Personal Data:
- •are subject to written confidentiality obligations; or
- •are under an appropriate statutory duty of confidentiality.
Such obligations shall survive termination of employment or engagement.
6. Security Measures
Processor shall maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Measures may include:
- •encryption in transit;
- •encryption at rest where supported;
- •access controls;
- •role-based permissions;
- •secure authentication;
- •password hashing;
- •logging and monitoring;
- •vulnerability management procedures;
- •secure software development practices;
- •incident response processes;
- •backup and disaster recovery procedures.
Processor may update these measures from time to time provided the overall level of protection is not materially reduced.
7. Subprocessors
7.1 Customer authorizes Processor to engage subprocessors necessary to provide the Services.
7.2 Processor shall:
- •maintain an up-to-date subprocessor list;
- •impose data protection obligations substantially equivalent to those contained in this DPA;
- •remain responsible for subprocessor compliance where required by law.
7.3 Processor shall provide notice of material subprocessor changes through its website, customer portal, email, or similar mechanism.
8. International Data Transfers
Processor may transfer Personal Data outside the European Economic Area, United Kingdom, or Switzerland only where appropriate safeguards are implemented. Such safeguards may include:
- •adequacy decisions;
- •Standard Contractual Clauses (SCCs);
- •UK International Data Transfer Addendum;
- •other lawful transfer mechanisms.
Applicable SCCs shall be incorporated by reference where required by law.
9. Assistance to Customer
Taking into account the nature of Processing and available information, Processor shall provide reasonable assistance regarding:
- •Data Subject requests;
- •security obligations;
- •breach reporting obligations;
- •data protection impact assessments (DPIAs);
- •consultations with Supervisory Authorities.
Processor may charge reasonable fees for excessive, repetitive, or unusually burdensome requests.
10. Data Subject Requests
If Processor receives a request from a Data Subject relating to Personal Data processed on behalf of Customer, Processor shall:
- •promptly notify Customer;
- •not respond directly except as required by law or authorized by Customer.
Customer remains responsible for responding to such requests.
11. Personal Data Breaches
Processor shall maintain procedures to identify, investigate, mitigate, and remediate Personal Data Breaches. Upon becoming aware of a Personal Data Breach affecting Customer Personal Data, Processor shall notify Customer without undue delay and provide available information including:
- •nature of the breach;
- •affected categories of data;
- •likely consequences;
- •remedial actions taken or planned.
Such notification shall not constitute an admission of fault or liability.
12. Government and Law Enforcement Requests
If Processor receives a legally binding request from a governmental authority for Customer Personal Data, Processor shall:
- •notify Customer before disclosure where legally permitted;
- •limit disclosure to the extent legally required;
- •challenge overbroad requests where appropriate and legally permissible.
Where notification is prohibited by law, Processor shall comply with applicable legal requirements.
13. Audits and Compliance Information
Processor shall make available information reasonably necessary to demonstrate compliance with this DPA. Where required by law, Customer may conduct an audit or appoint an independent auditor subject to:
- •reasonable advance written notice;
- •confidentiality obligations;
- •no unreasonable disruption to Processor’s operations;
- •no more than one audit annually unless legally required.
Existing certifications, audit reports, penetration test summaries, or security assessments may satisfy audit requests where appropriate.
Each party shall bear its own audit expenses unless otherwise agreed.
14. Return and Deletion of Data
Upon termination of the Services and at Customer's request, Processor shall:
- •return Customer Personal Data;
- •provide a reasonable export mechanism where available; or
- •securely delete Customer Personal Data.
Processor may retain Personal Data only where:
- •legally required;
- •necessary to establish, exercise, or defend legal claims;
- •contained within routine backup systems pending scheduled deletion.
Any retained data shall remain protected under this DPA.
15. Liability
Liability arising under this DPA shall be governed by the liability provisions of the Terms of Service, except where such limitations are prohibited by applicable law.
Nothing in this DPA excludes liability that cannot lawfully be limited or excluded.
16. Governing Law
This DPA shall be governed by the governing law specified in the Agreement unless otherwise required by applicable data protection laws.
17. Order of Precedence
In the event of any conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA shall prevail with respect to such Processing.
Annex A · Subprocessors
Processor's current subprocessor list is available at: {{SubprocessorURL}}
Processor may update this list in accordance with Section 7.
Annex B · Technical and Organisational Measures (TOMs)
Processor maintains measures including:
Access Security
- •Role-based access controls
- •Least-privilege permissions
- •Administrative authentication controls
- •Employee onboarding and offboarding procedures
Data Security
- •HTTPS/TLS encryption
- •Encryption at rest where supported
- •Backup and recovery procedures
- •Secure data deletion procedures
Operational Security
- •Security logging and monitoring
- •Vulnerability management
- •Incident response procedures
- •Change management controls
Personnel Security
- •Confidentiality obligations
- •Security awareness training
- •Access reviews
Business Continuity
- •Backup systems
- •Disaster recovery processes
- •Availability and resilience procedures
