Data Processing Agreement

1. Introduction

This Data Processing Agreement ("DPA") forms part of our Terms of Service and reflects the parties' agreement with respect to the processing of personal data in accordance with the requirements of Data Protection Laws and Regulations.

2. Definitions

"Controller" means the entity which determines the purposes and means of the Processing of Personal Data.

"Processor" means the entity which Processes Personal Data on behalf of the Controller.

"Personal Data" means any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data.

3. Processing of Personal Data

3.1 Processor's Obligations

  • Process Personal Data only on documented instructions from the Controller
  • Ensure persons authorized to process Personal Data are under confidentiality obligations
  • Implement appropriate technical and organizational measures
  • Assist the Controller in responding to requests from data subjects
  • Assist the Controller in ensuring compliance with security obligations

4. Security Measures

The Processor shall implement appropriate technical and organizational measures including:

  • Encryption of personal data
  • Ability to ensure ongoing confidentiality, integrity, and availability
  • Regular testing and evaluation of security measures
  • Access controls and authentication
  • Backup and disaster recovery procedures

5. Sub-processing

The Processor shall not engage another processor without prior specific or general written authorization of the Controller.

Where the Processor engages another processor, the same data protection obligations shall apply.

6. Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach and shall assist the Controller in addressing the breach.

7. Data Protection Impact Assessment

The Processor shall provide assistance to the Controller with any data protection impact assessments and prior consultations with supervisory authorities.

8. Return or Deletion of Data

At the choice of the Controller, the Processor shall delete or return all Personal Data after the end of the provision of services, unless storage is required by law.

9. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance and allow for audits, including inspections.

10. International Transfers

Any transfer of Personal Data to a third country shall be done in compliance with applicable Data Protection Laws and Regulations.

11. Contact Information

For any questions about this DPA, please contact:

  • Data Protection Officer: [email protected]
  • Phone: +44 7494 488 176
  • Address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

Last Updated: March 19, 2024