Data Processor Terms
The terms referenced in the Agreement that govern Our processing of Your personal data
These Data Processor Terms are the terms referred to in the definition of “Data Processor Terms” in the Core Terms. They govern how We process Your personal data when We provide You with Access Products and Services, and they form part of the Agreement between Us.
The Data Processor Terms are made up of two layers: this page, which sets out the terms that apply across every Data Processing Addendum, and the Data Processing Addendum that applies to Your Agreement, which deals with the position under the specific data protection law that governs Your personal data. It’s important you read them together.
1. How these terms fit together
- 1.1 The Data Processor Terms are made up of (a) this page, and (b) the Data Processing Addendum that applies to Your Agreement, identified using the table at clause 2 below.
- 1.2 A capitalised term used but not defined in the Data Processor Terms takes the meaning given to it in the Core Terms.
- 1.3 If anything on this page conflicts with the applicable Data Processing Addendum on an issue the Addendum specifically deals with, the Addendum takes priority on that issue. This page governs everything else.
2. Which Data Processing Addendum applies
- 2.1 The Data Processing Addendum that applies to Your Agreement depends on the governing law of the Access entity You are contracting with, as set out at the Governing Law page referenced in the Core Terms. Use the table below to identify it, unless clause 2.2 or 2.3 says otherwise.
|
Governing law |
Data Processing Addendum |
|
England and Wales (excluding AMS) |
UK GDPR Data Processing Addendum — www.theaccessgroup.com/en-gb/legal-hub/uk-gdpr-data-processing-addendum |
|
England and Wales (AMS only) |
UK GDPR AMS Data Processing Addendum — www.theaccessgroup.com/en-gb/legal-hub/uk-gdpr-ams-data-processing-addendum |
|
Republic of Ireland; Norway; Spain |
EU GDPR Data Processing Addendum — www.theaccessgroup.com/en-gb/legal-hub/eu-gdpr-data-processing-addendum |
|
Australia; Singapore |
APAC Data Processing Addendum — www.theaccessgroup.com/en-gb/legal-hub/apac-data-processing-addendum |
|
New York |
US Data Processing Addendum — www.theaccessgroup.com/en-gb/legal-hub/us-data-processing-addendum |
- 2.2 If the governing law is Australia, Singapore or New York, and You are incorporated or otherwise based in the EEA, the EU Standard Contractual Clauses is the Data Processing Addendum.
- 2.3 If the governing law is Australia, Singapore or New York, and You are incorporated or otherwise based in the United Kingdom, the UK International Data Transfer Agreement is the Data Processing Addendum.
- 2.4 Where Your Order covers Access Products or Services that are subject to more than one Data Processing Addendum, We will confirm this with You in the Order.
3. Terms that apply to every Data Processing Addendum
The provisions in this clause 3 apply to Our processing of Your personal data under every Data Processing Addendum, in addition to the specific terms of the Addendum that applies to You. We have collected them here so they only need to be agreed once, rather than repeated with minor variations across each Addendum.
3.1 How We notify each other
- 3.1.1 Any notification requirements set out in the Core Terms do not apply to notices given under the Data Processor Terms. Instead, an email to the primary contact each party has on file for the other is sufficient.
3.2 Confidentiality of the people who process Your data
- 3.2.1 We ensure that anyone We authorise to process Your personal data is subject to a written duty of confidentiality.
3.3 Security standards
- 3.3.1 We have implemented, and We will maintain technical and organisational measures designed in accordance with industry standard practices to protect the security, confidentiality, and integrity of Your Customer Data, as set out in this section 3.
- 3.3.2 We implement appropriate technical and organisational measures to keep Your personal data secure, proportionate to the risk of processing it, and We will help You meet Your own security obligations by appropriate technical and organisational means.
- 3.3.3 We maintain organisational management and dedicated staff responsible for the development, implementation, and maintenance of Our information security program and Our privacy information program.
- 3.3.4 Our operational procedures and controls define physical, technical, and administrative safeguards that provide for the configuration, monitoring and maintenance of technology and information systems that process Customer Data according to prescribed internal and adopted industry standards.
- 3.3.5 We maintain a robust suite of internal security and privacy policies that are communicated and distributed to all personnel, including (but not limited to) policies covering information security, privacy, physical security, supplier relationships, asset management, risk, access control, secure development, business continuity, and incident response.
- 3.3.6 Access Product specific security is described in the Product Fact Sheets.
- 3.3.7 We may review and update these measures from time to time, provided that any such update will not materially diminish the overall security of the Customer Data during the term of the Agreement.
3.4 Sub-processing
- 3.4.1 We may engage other processors (“Sub-Processors”) to help process Your personal data — for example, in connection with onboarding, support, development, professional services and or offboarding. Any entity within The Access Group may act as a Sub-Processor.
- 3.4.2 Sub-Processors in place as of the Effective Date are listed in the Product Fact Sheet and are accepted by You, unless Your Order says otherwise.
- 3.4.3 By entering into the Agreement, You give Us general written authorisation to add, replace or remove a Sub-Processor where We consider it necessary. We will tell You when We appoint a new Sub-Processor (for example, by email, through Our customer success portals, or within the relevant Access Product), and You may object on reasonable grounds within 14 days of that notice (or any longer period We specify), giving Your reasons. We will work with You to try to resolve the objection, and We will not share Your personal data with a Sub-Processor You have validly objected to.
- 3.4.4 We put appropriate data processing terms in place with each Sub-Processor and remain liable for a Sub-Processor’s acts and omissions as if they were Our own.
3.5 Data breaches
- 3.5.1 If We become aware of a Data Breach affecting Your personal data, We will notify You without undue delay and give You reasonable assistance to mitigate its impact, including with any notification You need to make to a supervisory authority or affected individuals, taking into account the nature of the processing and the information available to Us.
- 3.5.2 We will use reasonable efforts to identify the cause of a Data Breach, take the steps We consider necessary and reasonable to remediate it, and keep You informed as the position develops.
- 3.6.2 We reserve the right to withhold or stop providing assistance, and/or charge a reasonable fee to You, where We decide, acting reasonably, that the root cause of the Data Breach is due to an act or failure to act by You or Your Permitted Users.
3.6 Helping You respond to individual rights requests
- 3.6.1 We will promptly tell You if We receive a request, complaint or other communication directly from an individual or a third party that relates to Your personal data.
- 3.6.2 If an individual exercises a data protection right against You that relates to Your personal data, We will use reasonable commercial efforts to help You respond and aim to provide a suitable response within 5 business days of Your written request. We may extend that period where reasonably necessary, and We may charge You on a time-and-materials basis where We reasonably consider the assistance onerous, complex, frequent or time-consuming. We are under no obligation to assist You with a data protection right request where a self-serve feature exists within the Access Product that allows You to fulfil the data protection right without assistance from Us.
3.7 Impact assessments
- 3.7.1 We give You reasonable assistance and information to help You carry out a data protection or privacy impact assessment by making available to You information about Our data protection, privacy and security posture.
- 3.7.2 Where You require our support with a consultation with a supervisory authority, we will give You reasonable assistance upon your written request. Our support will relate only to Our processing of Your personal data and to the extent the information is available to Us. We may charge You for this assistance on a time-and-materials basis.
3.8 Audits
- 3.8.1 On Your written request, We will make available the information reasonably necessary to demonstrate Our compliance with clauses 3.2 to 3.7 above, and We will allow for, and contribute to, audits (including inspections) in accordance with Our Audit Conditions.
3.9 Returning or deleting Your personal data
- 3.9.1 Following the earlier of termination or expiry of the Agreement (the “End Date”), Your instruction is for Us to delete the personal data We hold on Your behalf. Before doing so, We will send You a request confirming whether that instruction still stands (a “Revised Instruction”). You have 30 days from the date We send the Revised Instruction to respond (the “Timeframe”).
- 3.9.2 Within the Timeframe, and at no additional cost, You may instead ask Us to return Your personal data in the format set out in the Product Fact Sheet, in any applicable exit policy, or as We otherwise agree. If You later ask Us to restore data We have deleted or returned on Your instruction, We may charge additional fees for the restoration work, where restoration is possible.
- 3.9.3 Where applicable law requires Us to keep all or part of Your personal data beyond the Timeframe, We will tell You about that requirement.
3.10 Where We process personal data as an independent controller
- 3.10.1 Nothing in the Data Processor Terms governs Our processing of personal data where We act as an independent controller. Our independent controller activities are described in our privacy notices.
3.11 Third-party integrations and APIs
- 3.11.1 Some Access Products have an application programming interface (“API”) that lets data (which may include personal data) pass to and from the Access Product and a third-party product (“Third-Party API”), or a separate Access Product You are licensed to use.
- 3.11.2 Whether a Third-Party API is switched on is Your choice. Switching it on authorises Us to share the relevant data through it and, where relevant, to receive data back through it for input into the Access Product. We are not liable for the quality, accuracy, or onward handling of any data transferred outbound through a Third-Party API (“Transferred API Data”) — that is governed by the contract between You and the relevant third party.
- 3.11.3 If You choose to connect a third-party product that requires access to, or a transfer of, Your data outside of an API described above, that access or transfer is between You and the relevant third-party provider.
- 3.11.4 In the context of this section 3, the third-party product providers are third parties You have a direct relationship with and are not third parties engaged by Us. Where any API exists, We use reasonable commercial efforts to document its existence (for example, in the Product Fact Sheets).
3.12 Anonymised data
- 3.12.1 Where the Agreement permits Our use of anonymised data derived from Your personal data, You authorise Us, to the extent the authorisation is required, to take the steps necessary to anonymise the data.
3.13 Finding the detail of how We process Your personal data
- 3.13.1 The Product Fact Sheet for Your Access Product sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the types of personal data, the categories of data subjects, and the Sub-Processors engaged as at the Effective Date. We may update the Product Fact Sheet from time to time, including to reflect a change permitted under clause 3.4.
- 3.13.2 You can find Product Fact Sheets and further detail on subjects including data protection, privacy and security at Our Data Processing Portal. We may amend the Product Fact Sheet from time to time.
3.14 Keeping these terms current
- 3.14.1 If a change in the law relating to the protection or processing of personal data means either of Us reasonably considers that the Data Processor Terms need to be updated, that party will tell the other, and both parties will act reasonably and in good faith to agree the necessary amendment.
- 3.14.2 You can find archived versions of these Data Processor Terms at the archive link referenced in the Core Terms.
3.15 Liability for Your instructions
- 3.15.1 We are not liable for a claim brought against You to the extent it arises directly from Your instructions to Us, or from Your failure to comply with the Data Processor Terms.
4. Definitions used across the Data Processor Terms
Where a defined term is used in a Data Processing Addendum and a definition is not given there, it has the meaning below. If it is not defined here either, it takes the meaning given in the Core Terms.
Data Breach — means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data processed by Us or a Sub-Processor.
Data Processing Addendum — means each addendum listed in the table at clause 2.1, as applicable to Your Agreement.
Data Processing Portal — is found at https://access-support.force.com/Support/s/gdpr-hub. We may change the location of the Data Processing Portal or the Product Fact Sheets from time to time; where We do, We will notify You.
End Date — as defined at clause 3.9.1.
EU Standard Contractual Clauses — found here at pages.theaccessgroup.com/EU-SCC-Ts-Cs.html.
Product Fact Sheet — means the content described as a ‘product fact sheet’, made available by Us and relevant to the Access Product You have procured.
Revised Instruction — as defined at clause 3.9.1.
Sub-Processor — as described at clause 3.4.1.
Third-Party API, API Data, and Transferred API Data — each have the meanings given at clause 3.11.
Timeframe — as defined at clause 3.9.1.
UK International Data Processing Agreement — found here at www.theaccessgroup.com/en-gb/legal-hub/documents/uk-idta-ts-cs
AU & NZ
SG
MY
US
IE