Discover more about Semieta - Watch Video
Enhancing Security with Smarter Visitor Management - Click Here
Enhancing Security with Smarter Contractor Management - Click Here
Enhancing Security with Smarter Access Management - Click Here
Discover more about Semieta - Watch Video
Enhancing Security with Smarter Visitor Management - Click Here
Enhancing Security with Smarter Contractor Management - Click Here
Enhancing Security with Smarter Access Management - Click Here

Data Processing Agreement

IT IS AGREED as follows: 

1. Definitions and Interpretation  

1.1 In this Agreement, unless the context otherwise requires, the following expressions have the following meanings:

2. Scope and Application of this Agreement 

2.1 The provisions of this Agreement shall apply to the processing of the Personal Data described in Schedule 2, carried  out for the Client by the Data Processor, and to all Personal Data held by the Data Processor in relation to all such  processing whether such Personal Data is held at the date of this Agreement or received afterwards. 

2.2 The provisions of this Agreement shall be deemed to be incorporated into the Service Agreement as if expressly  set out in it. Subject to sub-Clause 2.3, definitions and interpretations set out in the Service Agreement shall apply  to the interpretation of this Agreement. 

2.3 In the event of any conflict or ambiguity between any of the provisions of this Agreement and the Service  Agreement and/or any other agreement between the Parties, the provisions of this Agreement shall prevail. 

3. Provision of the Services and Processing Personal Data 

3.1 Schedule 2 describes the type(s) of Personal Data, the category or categories of Data Subject, the nature of the  processing to be carried out, the purpose(s) of the processing, and the duration of the processing. 

3.2 Subject to sub-Clause 4.1, the Data Processor is only to carry out the Services, and only to process the Personal  Data received from the Data Controller: 

       a) for the purposes of those Services and not for any other purpose; 

       b) to the extent and in such a manner as is necessary for those purposes; and 

       c) strictly in accordance with the express written authorisation and instructions of the Client (which may  be specific instructions or instructions of a general nature or as otherwise notified by the Client to the  Data Processor). 

3.3 The Client shall retain control of their own Personal Data at all times and shall remain responsible for its  compliance with the Data Protection Legislation including, but not limited to, its collection, holding, and  processing of the Personal Data, having in place all necessary and appropriate consents and notices to enable the  lawful transfer of the Personal Data to the Data Processor, and with respect to the written instructions given to  the Data Processor. 

4. The Data Processor’s Obligations 

4.1 As set out above in Clause 3, the Data Processor shall only process the Personal Data to the extent and in such a  manner as is necessary for the purposes of the Services and not for any other purpose. All instructions given by  the Client to the Data Processor shall be made in writing and shall at all times be in compliance with the Data  Protection Legislation. The Data Processor shall act only on such written instructions from the Client unless the  Data Processor is required by domestic law to do otherwise (as per Article 29 of the UK GDPR) (in which case, the  Data Processor shall inform the Client of the legal requirement in question before processing the Personal Data  for that purpose unless prohibited from doing so by law). 

4.2 The Data Processor shall not process the Personal Data in any manner which does not comply with the provisions  of this Agreement or with the Data Protection Legislation. The Data Processor must inform the Client promptly if,  in its opinion, any instructions given by the Client do not comply with the Data Protection Legislation.

 4.3 The Data Processor shall promptly comply with any written request from the Client requiring the Data Processor  to amend, transfer, delete (or otherwise dispose of), or to otherwise process the Personal Data. 

4.4 The Data Processor shall promptly comply with any written request from the Client requiring the Data Processor  to stop, mitigate, or remedy any unauthorised processing involving the Personal Data. 

4.5 The Data Processor shall provide all reasonable assistance (at its own cost) to the Client in complying with its  obligations under the Data Protection Legislation including, but not limited to, the protection of Data Subjects’  rights, the security of processing, the notification of Personal Data Breaches, the conduct of data protection  impact assessments, and in dealings with the Information Commissioner (including, but not limited to,  consultations with the Information Commissioner where a data protection impact assessment indicates that there  is a high risk which cannot be mitigated). 

4.6 For the purposes of sub-Clause 4.5, “all reasonable assistance” shall take account of the nature of the processing  carried out by the Data Processor and the information available to the Data Processor. 

4.7 In the event that the Data Processor becomes aware of any changes to the Data Protection Legislation that may,  in its reasonable interpretation, adversely impact its performance of the Services and the processing of the  Personal Data under this Agreement, the Data Processor shall inform the Client promptly. 

5. Confidentiality 

5.1 The Data Processor shall maintain the Personal Data in confidence, and in particular, unless the Client has given  written consent for the Data Processor to do so, the Data Processor shall not disclose the Personal Data to any  third party. The Data Processor shall not process or make any use of any Personal Data supplied to it by the Client  otherwise than as necessary and for the purposes of the provision of the Services to the Data Controller. 

5.2 Nothing in this Agreement shall prevent the Data Processor from complying with any requirement to disclose or  process Personal Data where such disclosure or processing is required by domestic law, court, or regulator  (including, but not limited to, the Information Commissioner). In such cases, the Data Processor shall notify the  Client of the disclosure or processing requirements prior to disclosure or processing (unless such notification is  prohibited by domestic law) in order that the Client may challenge the requirement if it wishes to do so. 

5.3 The Data Processor shall ensure that all employees who are to access and/or process any of the Personal Data are  informed of its confidential nature and are contractually obliged to keep the Personal Data confidential. 

6. Employees and Data Protection Officer 

6.1 The Client has appointed a data protection officer in accordance with Article 37 of the UK GDPR, whose details  are as follows: Ivor Saunders, Ivor.saunders@accessitdata.com. 

6.2 The Data Processor shall appoint a data protection officer in accordance with Article 37 of the UK GDPR and shall  supply the details of the data protection officer to the Client prior to the commencement of the processing of the  Personal Data. 

6.3 The Data Processor shall ensure that all employees who are to access and/or process any of the Personal Data are  given suitable training on the Data Protection Legislation, the Data Processor’s obligations under it, their  obligations under it, and its application to their work, with particular regard to the processing of the Personal  Data under this Agreement. 

7. Security of Processing 

7.1 The Data Processor shall implement appropriate technical and organisational measures as described in Schedule  3, and take all steps necessary to protect the Personal Data against unauthorised or unlawful processing or  accidental or unlawful loss, destruction, or damage. The Data Processor shall inform the Client in advance of any  changes to such measures. 

7.2 The measures implemented by the Data Processor shall be appropriate to the nature of the personal data, to the  harm that may result from such unauthorised or unlawful processing or accidental or unlawful loss, destruction,  or damage (in particular to the rights and freedoms of Data Subjects) and shall have regard for the state of  technological development and the costs of implementation. 

7.3 The measures implemented by the Data Processor may include, as appropriate, pseudonymisation and encryption  of the Personal Data; the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of  processing systems and services; the ability to restore the availability of and access to the Personal Data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing, and  evaluating the effectiveness of the technical and organisational measures. 

7.4 The Data Processor shall, if so requested by the Client (and within the timescales required by the Data Controller)  supply further details of the technical and organisational systems in place to safeguard the security of the Personal  Data held and to prevent unauthorised access. 

7.5 The Data Processor shall document all technical and organisational measures in writing and shall review them on  a quarterly basis to ensure that they remain suitable and up to date.

8. Data Subject Rights and Complaints 

8.1 The Data Processor shall take appropriate technical and organisational measures and provide all reasonable  assistance (at its own cost) to the Client in complying with its obligations under the Data Protection Legislation  with particular regard to the following: 

                 a) the rights of Data Subjects under the Data Protection Legislation including, but not limited to, the right  of access (data subject access requests), the right to rectification, the right to erasure, portability rights,  the right to object to processing, rights relating to automated processing, and rights to restrict  processing; and 

                 b) compliance with notices served on the Client by the Information Commissioner pursuant to the Data  Protection Legislation. 

8.2 In the event that the Data Processor receives any notice, complaint, or other communication relating to the  Personal Data processing or to either Party’s compliance with the Data Protection Legislation, it shall notify the  Client immediately in writing. 

8.3 In the event that the Data Processor receives any request from a Data Subject to exercise any of their rights under  the Data Protection Legislation including, but not limited to, a data subject access request, it shall notify the Client  without undue delay. 

8.4 The Data Processor shall cooperate fully (at its own cost) with the Client and provide all reasonable assistance in  responding to any complaint, notice, other communication, or Data Subject request, including by: 

                    a) providing the Client with full details of the complaint or request; 

                    b) providing the necessary information and assistance in order to comply with a subject access request; 

                    c) providing the Client with any Personal Data it holds in relation to a Data Subject (within the timescales  required by the Data Controller); and 

                    d) providing the Client with any other information requested by the Data Controller. 

8.5 The Data Processor shall act only on the Data Controller’s instructions and shall not disclose any Personal Data to  any Data Subject or to any other party except as instructed in writing by the Data Controller, or as required by  domestic law. 

9. Personal Data Breaches 

9.1 The Data Processor shall within 24 hours notify the Client in writing if it becomes aware of any form of Personal  Data Breach including, but not limited to the accidental or unlawful destruction, loss, alteration, unauthorised  disclosure of, or access to, the Personal Data. 

9.2 When the Data Processor becomes aware of a Personal Data Breach, it shall provide the following information to  the Client in writing without undue delay: 

                a) a description of the Personal Data Breach including the category or categories of Personal Data involved,  the number (approximate or exact, if known) of Personal Data records involved, and the number  (approximate or exact, if known) of Data Subjects involved; 

                b) the likely consequences of the Personal Data Breach; and 

                c) a description of the measures it has taken to address the Personal Data Breach, including, where  appropriate, measures to mitigate its possible adverse effects. 

9.3 In the event of a Personal Data Breach as described above, the Parties shall cooperate with one another to investigate it. The Data Processor shall provide all reasonable assistance to the Client including, but not limited  to: 

                  a) assisting the Client with its investigation of the Personal Data Breach; 

                  b) providing and facilitating the Client with access to any relevant facilities, operations, and personnel  (including, if applicable, former personnel involved in the Personal Data Breach); 

                  c) making available all records, logs, files, reports, and similar as reasonably required by the Client or as  otherwise required by the Data Protection Legislation; and 

                  d) promptly taking all reasonable steps to mitigate the effects of the Personal Data Breach and to minimise  any damage caused by it. 

9.4 The Data Processor shall use all reasonable endeavours to restore any Personal Data lost, destroyed, damaged,  corrupted, or otherwise rendered unusable in the Personal Data Breach as soon as possible after becoming aware  of the Personal Data Breach. 

9.5 The Data Processor shall not inform any third party of any Personal Data Breach as described above without the  express written consent of the Client unless it is required to do so by domestic law. 

9.6 The Client shall have the sole right to determine whether or not to notify affected Data Subjects, the Information  Commissioner, law enforcement agencies, or other applicable regulators of the Personal Data Breach as required  by law or other applicable regulations, or at the Data Controller’s discretion, including the form of such  notification. 

9.7 The Client shall have the sole right to determine whether or not to offer any remedy to Data Subjects affected by  the Personal Data Breach, including the form and amount of such remedy. 

9.8 Subject to the provisions of Clause 16, the Data Processor shall bear all reasonable costs and expenses incurred  by it and shall reimburse the Client for all reasonable costs and expenses incurred by the Client in responding to  the Personal Data Breach, including the exercise of any functions or carrying out of any obligations by the Client  under any provision of this Clause 9, unless the Personal Data Breach resulted from the Data Processor’s express  written instructions, negligence, breach of this Agreement, or other act or omission, in which case the Client shall  instead bear and shall reimburse the Data Processor with such costs and expenses incurred by it. 

10. Personal Data Transfers Outside of the UK or the EEA 

The Data Processor (and any subcontractor appointed by it) shall not process or transfer the Personal Data outside of the  UK or the EEA, unless express authorisation has been given by the Client, and subject to the provisions of an addenda to this  Agreement signed by both Parties. 

11. Appointment of Subcontractors 

11.1 The Data Processor shall not subcontract any of its obligations or rights under this Agreement without the prior  written consent of the Client (such consent not to be unreasonably withheld). 

11.2 In the event that the Data Processor appoints a subcontractor to process any of the Personal Data (with the  specific written consent of the Client on a per-subcontractor basis), the Data Processor shall: 

                  a) enter into a written agreement with each subcontractor, which shall impose upon the subcontractor the  same obligations, on substantially the same terms, as are imposed upon the Data Processor by this  Agreement, particularly with regard to technical and organisational security measures required to  comply with the Data Protection Legislation, which shall permit both the Data Processor and the Client  to enforce those obligations, and which shall terminate automatically on the termination of this  Agreement for any reason; 

                  b) at the written request of the Data Controller, provide copies of such agreements or, as applicable, the  relevant parts thereof; 

                  c) ensure that all subcontractors comply fully with their obligations under the abovementioned agreement  and under the Data Protection Legislation; and 

                  d) maintain control over all Personal Data transferred to subcontractors. 

11.3 In the event that a subcontractor fails to meet its data protection obligations, the Data Processor shall remain  fully liable to the Client for the subcontractor’s compliance with its data protection obligations.

11.4 The Data Processor shall be deemed to legally control any and all Personal Data that may be at any time controlled  practically by, or be in the possession of, any subcontractor appointed by it under this Clause 11. 

12. Return and/or Deletion or Disposal of Personal Data 

12.1 The Data Processor shall, at the written request of the Client (and at the Data Controller’s choice), securely delete  (or otherwise dispose of) the Personal Data or return it to the Client in the format(s) reasonably requested by the  Client within a reasonable time after the earlier of the following: 

                   a) the end of the provision of the Services; or 

                   b) the termination of the Service Agreement, for any reason; or 

                   c) the processing of that Personal Data by the Data Processor is no longer required for the performance of  the Data Processor’s obligations under this Agreement and the Service Agreement. 

12.2 Subject to sub-Clauses 12.3 and 12.4, the Data Processor shall not retain all or any part of the Personal Data after  deleting (or otherwise disposing of) or returning it under sub-Clause 12.1. 

12.3 If the Data Processor is required to retain copies of all or any part of the Personal Data by law, regulation,  government, or other regulatory body, it shall inform the Client of such requirement(s) in writing, including precise  details of the Personal Data that it is required to retain, the legal basis for the retention, details of the duration of  the retention, and when the retained Personal Data will be deleted (or otherwise disposed of) once it is no longer  required to retain it. 

12.4 The Data Processor may retain one copy of the Personal Data for up to 24 months for monitoring and Subject  Access Release purposes only. 

12.5 Upon the deletion (or disposal) of the Personal Data, the Data Processor shall certify the completion of the same  in writing to the Client within 21 days of the deletion (or disposal). 

12.6 All Personal Data to be deleted or disposed of under this Agreement shall be deleted or disposed of using the  following method(s): The Client has access to the deletion section of the program, and can delete all data or  specific data as required, up to and including todays date 

13. Information and Records 

13.1 The Data Processor shall make available to the Client any and all such information as is reasonably required and  necessary to demonstrate the Data Processor’s compliance with the Data Protection Legislation and this  Agreement. 

13.2 The Data Processor shall maintain complete, accurate, and up-to-date written Records of all processing activities  carried out by the Data Processor on behalf of the Client which shall include: 

                      a) the name and contact details of the Data Processor and the Client and, where applicable, each Party’s  representative and data protection officer; 

                       b) the categories of processing carried out by the Data Processor; and 

                       c) a general description of the technical and organisational security measures in place, as referred to in  Clause 7. 

                       d) Accessit Cloud Solutions are registered with the Information Commissioner’s Office, under registration  number 00016335087. 

14. Audits

14.1 The Data Processor shall, on at least reasonable prior notice, allow the Client or a third-party auditor appointed  by the Client to audit the Data Processor’s compliance with its obligations under this Agreement and with the  Data Protection Legislation. 

14.2 The Data Processor shall provide all necessary assistance (at its own cost) in the conduct of such audits including,  but not limited to: 

                     a) access (including physical and remote) to, and copies of, all Records and any other relevant information  kept by the Data Processor;

                     b) access to all of its employees who are to access and/or process any of the Personal Data including, where  reasonably necessary, arranging interviews between the Client and such employees; and 

                     c) access to and the inspection of all Records, infrastructure, equipment, software, and other systems used  to store and/or process the Personal Data. 

14.3 The requirement for the Client to give notice under sub-Clause 14.1 shall not apply if the Client has reason to  believe that the Data Processor is in breach of any of its obligations under this Agreement or under the Data  Protection Legislation, or if it has reason to believe that a Personal Data Breach has taken place or is taking place. 

14.4 The Data Processor must inform the Client promptly if, in its opinion, any instructions given by the Client or any  third-party auditor appointed by the Client do not comply with the Data Protection Legislation. 

15. Warranties 

15.1 The Client hereby warrants and represents that the Personal Data and its use with respect to the Services and the  Service Agreement and this Agreement shall comply with the Data Protection Legislation in all respects including,  but not limited to, its collection, holding, and processing. 

15.2 The Data Processor hereby warrants and represents that: 

                      a) the Personal Data shall be processed by the Data Processor (and by any subcontractors appointed under  Clause 11) in compliance with the Data Protection Legislation and any and all other relevant laws,  regulations, enactments, orders, standards, and other similar instruments; 

                      b) it has no reason to believe that the Data Protection Legislation in any way prevents it from complying  with its obligations pertaining to the provision of the Services under the Service Agreement; and 

                       c) it will implement appropriate technical and organisational measures to protect the Personal Data  against unauthorised or unlawful processing or accidental or unlawful loss, destruction, or damage, as  set out in Clause 7 and described in Schedule 3. 

16. Liability and Indemnity 

16.1 The Client shall be liable for, and shall indemnify (and keep indemnified) the Data Processor in respect of, any and  all actions, proceedings, liabilities, costs, claims, losses, expenses (including reasonable legal fees and payments  on a solicitor and client basis), or demands, suffered or incurred by, awarded against, or agreed to be paid by, the  Data Processor and any subcontractor appointed by the Data Processor under Clause 11 arising directly or in  connection with: 

                       a) any non-compliance by the Client with the Data Protection Legislation; 

                     b) any Personal Data processing carried out by the Data Processor or any subcontractor appointed by the  Data Processor under Clause 11 in accordance with instructions given by the Client to the extent that  the instructions infringe the Data Protection Legislation; or 

                   c) any breach by the Client of its obligations or warranties under this Agreement; 

but not to the extent that the same is or are contributed to by any non-compliance by the Data Processor or any  subcontractor appointed by the Data Processor under Clause 11 with the Data Protection Legislation or its breach  of this Agreement. 

16.2 The Data Processor shall be liable for, and shall indemnify (and keep indemnified) the Client in respect of, any and  all actions, proceedings, liabilities, costs, claims, losses, expenses (including reasonable legal fees and payments  on a solicitor and client basis), or demands, suffered or incurred by, awarded against, or agreed to be paid by, the  Client arising directly or in connection with: 

                    a) any non-compliance by the Data Processor or any subcontractor appointed by the Data Processor under  Clause 11 with the Data Protection Legislation; 

                    b) any Personal data processing carried out by the Data Processor or any subcontractor appointed by the  Data Processor under Clause 11 which is not in accordance with instructions given by the Client to the  extent that the instructions are in compliance with the Data Protection Legislation; or 

                    c) any breach by the Data Processor of its obligations or warranties under this Agreement; 

but not to the extent that the same is or are contributed to by any non-compliance by the Client with the Data  Protection Legislation or its breach of this Agreement.

16.3 The Client shall not be entitled to claim back from the Data Processor under sub-Clause 16.2 or on any other basis  any sums paid in compensation by the Client in respect of any damage to the extent that the Client is liable to  indemnify the Data Processor under sub-Clause 16.1. 

16.4 Nothing in this Agreement (and in particular, this Clause 16) shall relieve either Party of, or otherwise affect, the  liability of either Party to any Data Subject, or for any other breach of that Party’s direct obligations under the  Data Protection Legislation. Furthermore, the Data Processor hereby acknowledges that it shall remain subject to  the authority of the Information Commissioner and shall co-operate fully therewith, as required, and that failure  to comply with its obligations as a data processor under the Data Protection Legislation may render it subject to  the fines, penalties, and compensation requirements set out in the Data Protection Legislation. 

16.5 Nothing in this Clause 16 shall be deemed to be limited, excluded, or prejudiced by any other provision(s) of this  Agreement. 

16.6 Any limit of liability set out in the Service Agreement shall not apply to any indemnity or reimbursement provisions  set out in this Agreement. 

17. Term and Termination 

17.1 This Agreement shall come into force on the date shown at the beginning of this Agreement and shall continue in  force for the longer of: 

                  a) The duration of the Services, as set out in Schedule 1; or the period that the Service Agreement remains  in effect; or the period that the Data Processor has any of the Personal Data in its possession or control. 

17.2 Any provision of this Agreement which, expressly or by implication, is to come into force or remain in force on or  after its termination or expiry shall remain in full force and effect. In the event that changes to the Data Protection  Legislation necessitate the re-negotiation of any part this Agreement, either Party may require such re negotiation. 

18. Notices 

18.1 All notices under or in connection with this Agreement shall be in writing. Furthermore, all such notices given to  the Client under or in connection with this Agreement must be addressed to the nominated Data Protection officer. 

18.2 All notices given to the Data Processor under or in connection with this Agreement must be addressed to the  nominated Data Protection officer.. 

18.3 Notices shall be deemed to have been duly given: 

18.4.1 (a) when physically delivered, if delivered by courier or other messenger (including registered mail)  during normal business hours of the recipient; or (b) when sent, if transmitted by facsimile or e-mail and  a successful transmission report or return receipt is generated; or (c) on the fifth business day following  mailing, if mailed by national ordinary mail, postage prepaid. 

18.4.2 In each case notices shall be addressed as indicated above. Social media Platform or  other Instant Messaging methods shall be hereby expressly excluded as being sufficient  notice. 

19. Law and Jurisdiction 

19.1 This Agreement (including any non-contractual matters and obligations arising therefrom or associated  therewith) shall be governed by, and construed in accordance with, the Laws of England and Wales. 

19.2 Any dispute, controversy, proceedings or claim between the Parties relating to this Agreement (including any non contractual matters and obligations arising therefrom or associated therewith) shall fall within the exclusive  jurisdiction of the courts in England.