This Data Processing Addendum (“DPA”) forms part of the SaaS Terms between TechComply (“Processor”) and the client that has accepted the Terms (“Controller”).
This DPA applies where Processor processes Personal Data on behalf of Controller in providing the Services.
Processor will process Personal Data only:
Processor will notify Controller if it believes an instruction violates applicable data-protection law, unless prohibited by law.
Subject matter: Provision of an IT-risk assessment and remediation-management SaaS platform.
Nature of processing: Collection, storage, organization, retrieval, analysis, display, transmission, sharing, reporting, deletion.
Purpose: Account administration, questionnaire processing, dashboard generation, report creation, client support, security, service maintenance, and related business operations.
Types of Personal Data: Names, business contact details, job titles, account credentials, user activity, technical identifiers, and information included by client in free-text fields or documents.
Categories of data subjects: client personnel, contractors, suppliers, clients, users, and other individuals whose information the client submits.
Client must not submit special category Personal Data (e.g. health, religion,sexual orientation data etc.), as those types of data are not needed for the provision of the Services. Should the Client provide any such data in the open text fields, they are solely liable for its sharing and processing,
Processor will ensure that persons authorized to process Personal Data are subject to confidentiality obligations.
Processor will maintain reasonable safeguards, including where appropriate:
Further measures may be described in the Security Annex.
Controller authorizes Processor to use the subprocessors listed below:
Processor will:
If the parties cannot resolve a valid objection, Controller may terminate the affected Services on written notice.
Taking into account the nature of processing, Processor will reasonably assist Controller with:
Processor may charge reasonable costs for unusual or excessive assistance.
Processor will notify Controller without undue delay after becoming aware of a Personal Data breach affecting Controller Data.
The notification will include, where available:
Processor will not notify affected individuals or regulators unless required by law or instructed by Controller.
Processor may transfer Personal Data internationally using a lawful transfer mechanism, including an adequacy decision, standard contractual clauses, UK transfer arrangements, or another legally recognized safeguard.
Processor will make available information reasonably necessary to demonstrate compliance.
At the end of the Services, Processor will delete or return Controller Data at Controller’s choice, unless applicable law requires retention. Data stored in routine backups may be deleted according to Processor’s normal backup lifecycle.
Controller is responsible for:
If this DPA conflicts with the Terms & Conditions, this DPA controls regarding Personal Data processing supersede the Terms & Conditions. If the standard contractual clauses or another mandatory transfer mechanism applies, it takes precedence over the rest of the data protection agreements to the extent of a conflict.