Data Processing Information
1. Categories of data subject
The categories of data subject whose Personal Data may be processed comprise Users of the Platform, primarily employees, consultants, contractors and other staff associated with the Customer.
2. Types of Personal Data
The types of Personal Data to be processed include names, email addresses, and other Personal Data contained within Records processed through the Customer's connected Data Feeds and Actions.
3. Purposes of processing
The Personal Data may be processed for the following purposes: to execute the Customer's configured Processes and Actions, provision of SaaS services, customer support, system maintenance, communications, reporting, statistical analysis, and compliance with legal obligations.
4. Security measures for Personal Data
Security measures for Personal Data include encryption of Personal Data at rest and in transit, firewall protection, regular security audits, secure access controls, use of anonymisation where feasible, and ongoing staff training on data protection best practices.
5. Recipients and Sub-processors of Personal Data
Sub-processors of Personal Data include third-party cloud storage providers, accounting software, and other SaaS tool providers and providers of software development, support and maintenance services. We ensure that our sub-processors are GDPR compliant and have robust security measures.
Our sub-processors are the only recipients of Customer Personal Data except as required by law.
6. International Transfers
Any transfers of Personal Data outside of the EEA/UK are done with appropriate safeguards, ensuring the receiving country has an adequacy decision or through International Data Transfer Agreements (IDTAs) in a form approved by the ICO or other appropriate mechanisms to provide adequate safeguards for data subjects.
7. Retention
On termination of the Agreement between the Provider and Customer and any surviving provisions which require the continued processing of Personal Data, the Provider shall (unless required by Data Protection Laws) either:
(a) promptly destroy all copies of the Customer Personal Data in its possession; or
(b) at the Customer's written request received prior to termination of the Agreement return one complete copy of all Customer Personal Data in its possession to the Customer at the Customer's expense (calculated on the time spent by the Provider at its standard rates in securely locating, separating and transmitting such Customer Personal Data), and destroy all remaining copies in its possession,
provided, in either case, where prompt destruction is not practical, particularly but without limitation with regard to copies made for backup purposes and not for active use, the Personal Data concerned may be retained until the Provider's next deletion or destruction cycle for such data.
Note: this Schedule is subject to evaluation to reflect the evolving functionality of the Platform and changes in Data Protection Law and may accordingly be revised by the Provider from time to time.