1. Scope & Roles
This Data Processing Agreement ("DPA") forms part of the Terms between the Company and the Customer. Where we process personal data on the Customer's behalf, the Customer is the controller and the Company is the processor under applicable data protection law.
2. Processing Instructions
We process personal data only on the Customer's documented instructions, including for transfers, unless required by law. We will inform the Customer if, in our opinion, an instruction infringes applicable data protection law.
3. Security Measures
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and regular review of our security practices.
4. Sub-processing
The Customer authorises our use of the sub-processors listed in our Sub-processors document. We remain responsible for their compliance and will give notice of intended changes, allowing the Customer to object on reasonable grounds.
5. Data Subject Requests & Breach Notification
We assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting breach-notification obligations. We notify the Customer without undue delay after becoming aware of a personal data breach.
6. Deletion & Audit
On termination we delete or return personal data at the Customer's choice, save where retention is required by law. We make available information necessary to demonstrate compliance and allow for audits on reasonable notice.