Parties and Execution |
|
---|---|
'Customer' | 'Sphinx Technology Limited' |
Variables |
|
Parties' relationship | Controller to Processor |
Parties' roles |
Customer will act as the Controller (as defined in Section 1 of the Terms). Sphinx Technology Limited will act as the Processor (as defined in Section 1 of the Terms). |
Main Agreement | Sphinx Technology Services Agreement |
Term | This DPA will commence on the final date of signature by the Customer and will continue for the term of the Sphinx Technology Services Agreement. |
Breach Notification Period | Without Undue Delay after becoming aware of a personal data breach |
Sub-processor Notification Period | A reasonable timeframe before the new sub-processor is granted access to Personal Data. |
Governing Law and Jurisdiction | United Kingdom |
Data Protection Laws |
All laws, regulations and court orders which apply to the processing of Personal Data, including in the United Kingdom (UK). This includes:
|
Services related to processing | Controller instructs Processor to process certain Personal Data in order for Processor to carry out vetting checks. |
Duration of processing | For the term of the Main Agreement |
Nature and purpose of processing | Processor shall process the Personal Data (as set out below) for the purpose of contacting end data subjects whose background checks it is carrying out. |
Legal Basis for Processing | This is dependent on the data, as detailed in the Privacy Policy |
Personal Data | The types of personal data processed are listed in the Privacy Policy |
Data subjects |
The individuals whose Personal Data will be processed are:
OR
|
Annex 1 |
|
---|---|
Security measures. Technical and organisational measures to ensure the security of Personal Data | Processor shall use reasonable security measures appropriate to the type and sensitivity of Personal Data processed. |
Annex 2 |
|
Sub-processors. Current sub-processors | Please see "Disclosure to third party service providers" in the Processor Privacy Policy. |
1. What is this agreement about?
1.1 Purpose. The parties are entering into this Data Processing Agreement (DPA) for the purpose of processing Personal Data (as defined above).
1.2 Definitions. Under this DPA:
2. What are each party's obligations?
2.1 Controller obligations. Controller instructs Processor to process Personal Data in accordance with this DPA, and is responsible for providing all notices and obtaining all consents, licences and legal bases required to allow Processor to process Personal Data.
2.2 Processor obligations. Processor will:
2.3 Warranties. The parties warrant that they and any staff and/or subcontractors will comply with their respective obligations under Data Protection Laws for the Term.
3. Sub-processing
3.1 Use of sub-processors. Controller authorises Processor to engage other processors (referred to in this section as sub-processors) when processing Personal Data. Processor's existing sub-processors are listed in Annex 2.
3.2 Sub-processor requirements. Processor will:
3.3 Approvals. Processor may appoint new sub-processors provided that they notify Controller in writing in accordance with the Sub-processor Notification Period.
3.4 Objections. Controller may reasonably object in writing to any future sub-processor. If the parties cannot agree on a solution within a reasonable time, either party may terminate this DPA.
4. International personal data transfers
4.1 Instructions. Processor will transfer Personal Data outside the UK, the EEA or an adequate country only on documented instructions from Controller, unless otherwise required by law.
4.2 Transfer mechanism. Where a party is located outside the UK, the EEA or an adequate country and receives Personal Data:
4.3 Additional measures. If the Transfer Mechanism is insufficient to safeguard the transferred Personal Data, the data importer will promptly implement supplementary measures to ensure Personal Data is protected to the same standard as required under Data Protection Laws.
4.4 Disclosures. Subject to terms of the relevant Transfer Mechanism, if the data importer receives a request from a public authority to access Personal Data, it will (if legally allowed):
5. Other important information
5.1 Survival. Any provision of this DPA which is intended to survive the Term will remain in full force.
5.2 Order of precedence. In case of a conflict between this DPA and other relevant agreements, they will take priority in this order:
5.3 Notices. Formal notices under this DPA must be in writing and sent to the Contact on the DPA's front page as may be updated by a party to the other in writing.
5.4 Third parties. Except for affiliates, no one other than a party to this DPA has the right to enforce any of its terms.
5.5 Entire agreement. This DPA supersedes all prior discussions and agreements and constitutes the entire agreement between the parties with respect to its subject matter and neither party has relied on any statement or representation of any person in entering into this DPA.
5.6 Amendments. Any amendments to this DPA must be agreed in writing.
5.7 Assignment. Neither party can assign this DPA to anyone else without the other party's consent.
5.8 Waiver. If a party fails to enforce a right under this DPA, that is not a waiver of that right at any time.
5.9 Governing law and jurisdiction. The Governing Law applies to this DPA and all disputes will only be litigated in the courts of the Jurisdiction.