Data processing agreement

The Article 28 terms on which TODO_LEGAL_ENTITY processes personal data on behalf of your organisation. Published so procurement can review it without asking.

Effective TODO_EFFECTIVE_DATE

Draft, not for publication. The legal entity, registered address, contact addresses and effective date are still placeholders in content/site.ts. This document also needs review by a solicitor before it goes live.

This agreement forms part of the terms of service. Where your organisation has signed a negotiated DPA with us, that one governs instead.

1. Roles

Your organisation is the controller. TODO_LEGAL_ENTITY is the processor, acting only on your documented instructions. Both parties will comply with applicable data protection law, including UK GDPR, the Data Protection Act 2018 and, where it applies, EU GDPR.

2. Scope of processing

Detail
Subject matterProvision of the CARDO risk analysis service
DurationThe term of the agreement, plus the deletion periods in clause 11
Nature and purposeHosting, storage, computation and display of risk data, and authentication of the users who access it
Categories of data subjectYour personnel and contractors who hold accounts, and any individual named in a risk record you upload
Types of personal dataName, work email address, organisational affiliation, role, IP address, activity and audit records, and whatever you choose to place in free text fields
Special category dataNone expected. The service is not designed for it and you should not upload it

3. Our instructions

We process personal data only on your documented instructions, which include the terms of service, this agreement, and your configuration of the service. We will tell you if we believe an instruction breaches data protection law. If the law requires us to process for another purpose, we will tell you first unless the law forbids it.

4. Confidentiality

Everyone we authorise to process your data is bound by a duty of confidence and is granted access only where they need it for their role.

5. Security measures

We implement appropriate technical and organisational measures under Article 32, including encryption in transit and at rest, role-based access control with per-organisation isolation enforced server-side, append-only audit logging, rate limiting, multi-factor authentication, and least-privilege administrative access. The current measures are described on the security overview.

6. Sub-processing

You give general authorisation for the sub-processors listed at sub-processors. We impose data protection obligations on each of them no less protective than these, and we remain liable to you for their performance. We give at least 30 days’ notice before adding or replacing one, and you may object on reasonable data protection grounds.

7. Assisting you

Taking account of the nature of the processing, we will help you respond to data subject requests, and assist with data protection impact assessments and prior consultations. Where a data subject contacts us directly about your data, we will refer them to you rather than answer on your behalf.

8. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event within 48 hours, with the information you need to meet your own 72-hour obligation to the ICO.

9. International transfers

Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with a transfer risk assessment. We will provide the detail you need for your own assessment on request.

10. Audit

We will make available the information needed to demonstrate compliance with this agreement, and allow an audit by you or an independent auditor you appoint, on reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, and subject to confidentiality.

11. Return and deletion

On termination you may export your data. At your choice we will return or delete it, and delete existing copies within 90 days, except where the law requires us to keep it. The retention exceptions are set out in the privacy policy.

To execute a signed copy, contact TODO_PRIVACY_EMAIL.