Data Processing Agreement
The Eclipse Software Data Processing Agreement reflects the parties’ agreement with respect to the terms governing the Processing of Personal Data in association with services provided under the Eclipse Software Group Limited Standard Terms and Conditions, or any other applicable agreement governing the provision of Products or Services by ESG or the Relevant Group Company (the “Service Agreement”).
In this Data Processing Agreement, the Customer is defined as the Data Controller and ESG and/or the Relevant Group Company providing, administering, hosting, supporting or otherwise Processing Personal Data in connection with the Products or Services is defined as the Data Processor.
This Data Processing Agreement Includes:
• Article 28 Data Processing Terms
• Schedule 1, which includes details of the Services and Products provided by ESG or the Relevant Group Company where Personal Data is processed by the Data Processor on behalf of the Data Controller.
• Schedule 2, which includes details of the Personal Data processed by the Data Processor on behalf of the Data Controller.
• Schedule 3, which includes a description of the technical and organisational security measures implemented by the Data Processor.
• Schedule 4, which includes the list of Sub-Processors.
This Data Processing Agreement forms part of, and is incorporated into, the Service Agreement. The term of this Data Processing Agreement shall follow the term of the Service Agreement and shall continue for so long as the Data Processor Processes Personal Data on behalf of the Data Controller.
Terms not otherwise defined in this Data Processing Agreement shall have the meaning given to them in the Service Agreement.
ARTICLE 28 DATA PROCESSING TERMS
THIS AGREEMENT IS BETWEEN:
- The Customer receiving Products or Services under the Service Agreement (“Data Controller”); and
- Eclipse Software Group Limited, a company registered in England and Wales with company number 17326378, whose registered office is at 42-46 Station Road, Edgware, England, HA8 7AB, trading as Eclipse Software from Orega Piccadilly, 3 Piccadilly Place, Manchester, M1 3BN, and/or the Relevant Group Company providing, administering, hosting, supporting or otherwise Processing Personal Data in connection with the Products or Services (“Data Processor”).
WHEREAS:
- Under the Service Agreement, the Data Processor provides to the Data Controller the Services described in Schedule 1.
- The provision of the Services by the Data Processor involves the Processing of Personal Data described in Schedule 2 on behalf of the Data Controller.
- Under the UK General Data Protection Regulation and the Data Protection Act 2018, the Data Controller is required to put in place a written agreement with any organisation which processes Personal Data on its behalf governing the processing of that Personal Data.
- The parties have agreed to enter into this Data Processing Agreement to ensure compliance with those requirements in relation to the Processing of Personal Data by the Data Processor for the Data Controller.
- The terms of this Data Processing Agreement apply to all Processing of Personal Data carried out for the Data Controller by the Data Processor and to all Personal Data held by the Data Processor in relation to such Processing.
IT IS AGREED as follows:
1. DEFINITIONS AND INTERPRETATION
1.1 In this Data Processing Agreement, unless the context otherwise requires, the following expressions have the following meanings:
1.1.1 “Controller”, “Processor”, “Processing”, “Personal Data”, “Personal Data Breach”, “Data Subject”, “Special Category Data” and “Sub-Processor” shall have the meanings given to those terms in the Data Protection Legislation.
1.1.2 “Customer”, “Controller” or “Data Controller” means the customer receiving the Products or Services under the Service Agreement.
1.1.3 “Data Protection Legislation” means all applicable data protection and privacy legislation in force from time to time in the United Kingdom, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any legislation, regulations or guidance replacing, amending or supplementing them.
1.1.4 “ESG” means Eclipse Software Group Limited, a company registered in England and Wales with company number 17326378, whose registered office is at 42-46 Station Road, Edgware, England, HA8 7AB, trading as Eclipse Software from Orega Piccadilly, 3 Piccadilly Place, Manchester, M1 3BN.
1.1.5 “Group Company” means ESG, any holding company or subsidiary of ESG from time to time, and any subsidiary undertaking or associated company of ESG, including Eclipse Recruitment Software Ltd, a company registered in England and Wales with company number 17301040, Eclipse Recruitment Websites Ltd, a company registered in England and Wales with company number 07008719, and Eclipse Software Services Limited, a company registered in England and Wales with company number 17328346.
1.1.6 “Group Personnel” means the employees, workers, officers, contractors, consultants, subcontractors, agents and representatives of ESG, the Relevant Group Company or any Group Company, including personnel employed or engaged by Eclipse Software Services Limited.
1.1.7 “ICO” means the United Kingdom’s supervisory authority, the Information Commissioner’s Office.
1.1.8 “Processor”, “Data Processor”, “we”, “us” or “our” means ESG and/or the Relevant Group Company providing, administering, hosting, supporting or otherwise Processing Personal Data in connection with the Products or Services.
1.1.9 “Relevant Group Company” means the Group Company identified on the applicable Order Form, invoice, renewal notice, subscription confirmation, Direct Debit mandate, payment instruction or other written communication as being responsible for supplying, licensing, administering, invoicing, collecting payment for or providing the relevant Products or Services.
1.1.10 “Service Agreement” means the agreement between the Customer and ESG or the Relevant Group Company, including the applicable Terms and Conditions, Order Form, Subscription Contract, quotation, renewal notice, invoice, Data Processing Agreement, Acceptable Usage Policy and any other document expressly incorporated by reference.
1.1.11 “Services” means the Products and Services provided or made available to the Controller by ESG or the Relevant Group Company, including those described in Schedule 1.
1.1.12 “Sub-Processor” means any processor engaged by ESG or the Relevant Group Company to Process Personal Data on behalf of the Controller in connection with the Services.
1.2 Unless the context otherwise requires, each reference in this Data Processing Agreement to:
1.2.1 “writing” includes email and other electronic communications;
1.2.2 a statute or provision of a statute is a reference to that statute or provision as amended, replaced or re-enacted from time to time;
1.2.3 this Data Processing Agreement includes its Schedules;
1.2.4 a Schedule is a schedule to this Data Processing Agreement; and
1.2.5 a Clause or paragraph is a reference to a clause or paragraph of this Data Processing Agreement.
1.3 Headings are for convenience only and shall not affect interpretation.
1.4 Words in the singular include the plural and vice versa.
1.5 References to persons include individuals, companies, corporations, partnerships and other legal entities.
2. SCOPE AND APPLICATION OF THIS AGREEMENT
2.1 This Data Processing Agreement applies to the Processing of Personal Data described in Schedule 2, carried out for the Data Controller by the Data Processor, and to all Personal Data held by the Data Processor in relation to such Processing.
2.2 This Data Processing Agreement applies whether the Personal Data is held by the Data Processor at the date of this Data Processing Agreement or received afterwards.
2.3 This Data Processing Agreement forms part of the Service Agreement and shall apply to all Processing of Personal Data carried out in connection with the Services.
2.4 In the event of any conflict between this Data Processing Agreement and the Service Agreement in relation to the Processing of Personal Data on behalf of the Data Controller, this Data Processing Agreement shall prevail.
2.5 This Data Processing Agreement shall continue in full force and effect for so long as the Data Processor is Processing Personal Data on behalf of the Data Controller, and thereafter to the extent required by this Data Processing Agreement, the Service Agreement or applicable law.
3. GROUP COMPANIES AND GROUP PERSONNEL
3.1 The Data Controller acknowledges and agrees that ESG and the Relevant Group Company may use Group Companies, including Eclipse Software Services Limited, and Group Personnel to provide, support, administer, maintain, secure and operate the Services.
3.2 Group Companies and Group Personnel may Process Personal Data where reasonably necessary for the provision, administration, hosting, support, maintenance, security, operation, billing, account management or improvement of the Services.
3.3 ESG or the Relevant Group Company shall ensure that Group Personnel authorised to Process Personal Data are subject to appropriate confidentiality, security and data protection obligations.
3.4 Where a Group Company Processes Personal Data on behalf of the Data Controller as a Sub-Processor, ESG or the Relevant Group Company shall ensure that such Group Company is subject to written obligations no less protective than those set out in this Data Processing Agreement.
4. PROVISION OF THE SERVICES AND PROCESSING PERSONAL DATA
4.1 The Data Processor shall carry out the Services and Process Personal Data received from or on behalf of the Data Controller:
4.1.1 for the purposes of providing the Services;
4.1.2 to the extent and in such manner as is necessary for those purposes;
4.1.3 in accordance with the Service Agreement;
4.1.4 in accordance with this Data Processing Agreement; and
4.1.5 in accordance with the documented instructions of the Data Controller.
4.2 The Data Controller’s documented instructions include the Service Agreement, this Data Processing Agreement, the Data Controller’s use and configuration of the Services, and any written instructions provided by the Data Controller and accepted by ESG or the Relevant Group Company.
4.3 The Data Processor shall not Process Personal Data for any purpose other than the provision, administration, hosting, support, maintenance, security, operation, billing, account management, improvement or enforcement of the Services, except where required by law.
5. DATA PROTECTION COMPLIANCE
5.1 Each party shall comply with its obligations under Data Protection Legislation.
5.2 The Data Controller warrants, represents and undertakes that:
5.2.1 it has all necessary rights, permissions, notices, consents and lawful bases required to provide Personal Data to the Data Processor;
5.2.2 the Personal Data has been collected, used, disclosed and supplied to the Data Processor lawfully;
5.2.3 the Processing of Personal Data by the Data Processor in accordance with the Service Agreement and this Data Processing Agreement shall not cause the Data Processor to breach Data Protection Legislation;
5.2.4 all required privacy notices have been provided to Data Subjects;
5.2.5 the Personal Data is accurate, relevant and limited to what is necessary for the Data Controller’s use of the Services; and
5.2.6 the Data Controller shall not instruct the Data Processor to Process Personal Data in a way that would breach Data Protection Legislation.
5.3 The Data Processor shall Process Personal Data only on the documented instructions of the Data Controller, unless required by law to Process Personal Data otherwise.
5.4 The Data Processor shall promptly inform the Data Controller if, in the Data Processor’s reasonable opinion, an instruction from the Data Controller infringes Data Protection Legislation.
5.5 The Data Processor shall ensure that persons authorised to Process Personal Data are subject to appropriate confidentiality obligations.
5.6 The Data Processor shall implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration or disclosure, taking into account the nature of the Processing and the risks presented by the Processing. Such measures are described in Schedule 3.
5.7 The Data Processor shall provide reasonable assistance to the Data Controller, at the Data Controller’s cost, in complying with the Data Controller’s obligations under Data Protection Legislation in relation to:
5.8 The Data Processor shall make available to the Data Controller such information as is reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this Data Processing Agreement.
5.9 The Data Processor may use Sub-Processors in accordance with Clause 12.
5.10 The Data Processor shall not transfer Personal Data outside the United Kingdom unless such transfer is carried out in accordance with Clause 8.
6. DATA SUBJECT ACCESS, COMPLAINTS AND REQUESTS
6.1 The Data Processor shall, at the Data Controller’s cost, assist the Data Controller in complying with its obligations under Data Protection Legislation in relation to Data Subject requests, complaints and enquiries.
6.2 The Data Processor shall notify the Data Controller without undue delay if it receives:
6.2.1 a subject access request from a Data Subject; or
6.2.2 any other complaint, enquiry or request relating to the Processing of Personal Data.
6.3 The Data Processor shall not respond directly to a Data Subject request except:
6.3.1 on the documented instructions of the Data Controller;
6.3.2 where required by law; or
6.3.3 to confirm that the request should be directed to the Data Controller.
6.4 The Data Controller shall be responsible for responding to Data Subject requests, complaints and regulatory enquiries relating to Personal Data for which the Data Controller is responsible.
7. PERSONAL DATA BREACHES
7.1 The Data Processor shall notify the Data Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed by the Data Processor on behalf of the Data Controller.
7.2 The notification shall, to the extent reasonably available to the Data Processor, include:
7.2.1 a description of the nature of the Personal Data Breach;
7.2.2 the categories and approximate number of Data Subjects affected;
7.2.3 the categories and approximate number of Personal Data records affected;
7.2.4 the likely consequences of the Personal Data Breach;
7.2.5 measures taken or proposed to address the Personal Data Breach; and
7.2.6 details of any further information reasonably required by the Data Controller.
7.3 The Data Processor shall provide reasonable assistance to the Data Controller in investigating, mitigating and responding to any Personal Data Breach, subject to payment of the Data Processor’s reasonable costs where permitted by law.
8. INTERNATIONAL TRANSFERS
8.1 The Data Processor shall not transfer Personal Data outside the United Kingdom unless such transfer is carried out in accordance with Data Protection Legislation.
8.2 Where Personal Data is transferred outside the United Kingdom, the Data Processor shall ensure that an appropriate transfer mechanism is in place, such as:
8.2.1 an adequacy regulation;
8.2.2 the International Data Transfer Agreement;
8.2.3 the UK Addendum to the EU Standard Contractual Clauses;
8.2.4 any replacement or alternative mechanism permitted by Data Protection Legislation; or
8.2.5 another lawful basis for transfer under Data Protection Legislation.
9. AUDIT AND INFORMATION
9.1 The Data Processor shall make available to the Data Controller such information as is reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this Data Processing Agreement.
9.2 The Data Processor shall allow for and contribute to audits, including inspections, conducted by the Data Controller or an auditor mandated by the Data Controller, provided that:
9.2.1 the Data Controller gives at least 30 days’ written notice;
9.2.2 the audit is conducted during normal business hours;
9.2.3 the audit does not unreasonably disrupt the Data Processor’s business or service;
9.2.4 the audit is subject to appropriate confidentiality and security restrictions;
9.2.5 the audit does not require the Data Processor to disclose information relating to other customers, commercially sensitive information, security-sensitive information, trade secrets or legally privileged information; and
9.2.6 the Data Controller pays the Data Processor’s reasonable costs of assisting with the audit.
9.3 The requirement to give notice in Clause 9.2.1 shall not apply where the Data Controller reasonably believes that the Data Processor is in material breach of this Data Processing Agreement or Data Protection Legislation, but any audit shall still be subject to appropriate confidentiality, security and operational restrictions.
10. DATA PROTECTION CONTACTS
10.1 Each party shall appoint a Data Protection Officer or data protection contact where required by Data Protection Legislation.
10.2 The Data Processor’s data protection contact details are:
Eclipse Software Group Limited
Orega Piccadilly
3 Piccadilly Place
Manchester
M1 3BN
Email: dpo@eclipse-software.co.uk
10.3 The Data Controller shall provide details of its Data Protection Officer or data protection contact to the Data Processor on request.
11. LIABILITY AND INDEMNITY
11.1 The Data Controller shall be liable for, and shall indemnify and keep indemnified, the Data Processor, each Relevant Group Company, each Group Company and each Sub-Processor against all losses, liabilities, damages, fines, penalties, costs, claims and expenses arising out of or in connection with:
11.1.1 any breach by the Data Controller of this Data Processing Agreement;
11.1.2 any breach by the Data Controller of Data Protection Legislation;
11.1.3 any Processing carried out by the Data Processor or a Sub-Processor in accordance with the Data Controller’s instructions where such instructions infringe Data Protection Legislation;
11.1.4 the Data Controller’s failure to provide appropriate privacy notices or establish a lawful basis for Processing;
11.1.5 Personal Data supplied by or on behalf of the Data Controller being inaccurate, unlawful, excessive or unsuitable; or
11.1.6 any claim by a Data Subject, regulator or third party arising from the Data Controller’s acts or omissions.
11.2 The Data Processor shall be liable to the Data Controller only to the extent that loss or damage results directly from the Data Processor’s breach of this Data Processing Agreement or Data Protection Legislation and not to the extent that the loss or damage is caused or contributed to by the Data Controller.
11.3 Nothing in this Data Processing Agreement shall exclude or limit either party’s liability to Data Subjects or regulators where such liability cannot lawfully be excluded or limited.
11.4 Subject to Clause 11.3, the liability of ESG, the Relevant Group Company, Group Companies and Sub-Processors under or in connection with this Data Processing Agreement shall be subject to the limitations and exclusions of liability set out in the Service Agreement.
12. APPOINTMENT OF SUB-PROCESSORS
12.1 The Data Controller gives general written authorisation for ESG and the Relevant Group Company to appoint Group Companies and third-party Sub-Processors as reasonably required to provide, support, administer, secure, host, maintain, operate, bill, collect payment for or otherwise perform the Services.
12.2 The Data Processor shall maintain a list of Sub-Processors used in connection with the Services. The current list of Sub-Processors is set out in Schedule 4.
12.3 The Data Processor may update the list of Sub-Processors from time to time.
12.4 Where the Data Processor appoints a new Sub-Processor, the Data Processor shall provide notice by updating the published list of Sub-Processors or by such other reasonable method as the Data Processor may determine.
12.5 The Data Controller may object to the appointment of a new Sub-Processor on reasonable and legitimate data protection grounds by giving written notice within 14 days of being notified of the change.
12.6 If the Data Controller objects to a new Sub-Processor, the parties shall discuss the objection in good faith. If the Data Processor cannot reasonably accommodate the objection, the Data Controller may terminate the affected Services by giving written notice, provided that such termination shall not affect any accrued payment obligations or other rights of the Data Processor under the Service Agreement.
12.7 The Data Processor shall ensure that each Sub-Processor Processing Personal Data on behalf of the Data Controller is subject to a written contract imposing data protection obligations no less protective than those set out in this Data Processing Agreement.
12.8 The Data Processor shall remain responsible to the Data Controller for the performance of any Sub-Processor’s data processing obligations.
13. INTELLECTUAL PROPERTY RIGHTS IN PERSONAL DATA
13.1 All copyright, database rights and other intellectual property rights subsisting in Personal Data shall remain with the Data Controller, the relevant Data Subject or the relevant third-party owner.
13.2 The Data Processor is authorised to use such Personal Data only to the extent necessary to provide, administer, host, support, maintain, secure and operate the Services and to perform the Service Agreement.
14. CONFIDENTIALITY
14.1 The Data Processor shall keep Personal Data confidential and shall not disclose Personal Data except:
14.1.1 to Group Companies, Group Personnel and Sub-Processors where required for the provision of the Services;
14.1.2 to professional advisers, insurers, auditors or legal representatives where reasonably required;
14.1.3 where required by law, regulation, court order, regulator, law enforcement authority or other competent authority;
14.1.4 where required to enforce the Service Agreement or protect the rights of ESG, the Relevant Group Company, a Group Company or the Data Controller; or
14.1.5 as otherwise permitted by this Data Processing Agreement or the Service Agreement.
14.2 The Data Processor shall ensure that any person authorised to Process Personal Data is subject to confidentiality obligations.
14.3 The confidentiality obligations in this Clause 14 shall continue after termination or expiry of this Data Processing Agreement.
15. DELETION, RETURN AND RETENTION OF PERSONAL DATA
15.1 At the end of the provision of the Services, or when Processing is no longer required for the performance of the Service Agreement, the Data Processor shall, at the Data Controller’s written request, delete or return Personal Data Processed on behalf of the Data Controller within a reasonable period.
15.2 The Data Processor may charge the Data Controller for any data export, extraction, migration, transfer, deletion, technical assistance, administration or professional costs incurred in connection with the return or deletion of Personal Data.
15.3 The Data Processor shall not be required to return or delete Personal Data where retention is required or permitted by law, regulation, court order, accounting requirements, audit requirements, dispute resolution, debt recovery, compliance, security, backup, disaster recovery, insurance or legitimate business purposes.
15.4 Personal Data retained under Clause 15.3 shall remain subject to appropriate confidentiality and security obligations.
15.5 Where Personal Data is stored in backups or disaster recovery systems, the Data Processor may retain such Personal Data until it is overwritten or deleted in accordance with the Data Processor’s ordinary backup retention cycle, provided that such Personal Data is not restored to live systems except where required for legal, security, continuity or compliance purposes.
15.6 Personal Data shall be deleted, destroyed or put beyond use using appropriate technical and organisational methods.
16. LAW AND JURISDICTION
16.1 This Data Processing Agreement and any non-contractual obligations arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales.
16.2 The courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Data Processing Agreement, including any non-contractual dispute or claim.
SCHEDULE 1
SERVICES
The Services may include, without limitation:
1. recruitment software subscriptions, software licences, software hosting, software support, implementation, configuration, training, consultancy, data import, data migration and data cleansing services;
2. hosting of recruitment software, CRM systems, associated databases, documents, files and customer data;
3. website services, recruitment websites, website hosting, web subscriptions, APIs, integrations, web forms, candidate portals, client portals, job board integrations, domain-related services and associated services;
4. hosting of data in web integration products, API products, websync products, customer websites, portals and related online services;
5. technical support, helpdesk support, remote support, system monitoring, maintenance, updates, patches, upgrades and service administration;
6. billing, account administration, subscription management, Direct Debit administration, payment collection and customer account management;
7. security, backup, disaster recovery, audit logging, troubleshooting, diagnostics and service improvement activities; and
8. any other Products or Services supplied, licensed, hosted, supported, administered or made available to the Data Controller under the Service Agreement.
SCHEDULE 2
1. Categories of Data Subjects
Personal Data Processed under the Services may relate to:
1.1 candidates;
1.2 applicants;
1.3 workers;
1.4 contractors;
1.5 employees;
1.6 referees;
1.7 clients;
1.8 client contacts;
1.9 prospects;
1.10 suppliers;
1.11 website users;
1.12 job applicants;
1.13 end users of the Data Controller;
1.14 employees, workers, officers, contractors and authorised users of the Data Controller; and
1.15 individuals attempting to communicate with, apply to, register with or transfer Personal Data to the Data Controller or its users.
DETAILS OF PROCESSING OF PERSONAL DATA
2. Types of Personal Data
Personal Data Processed under the Services may include:
2.1 names;
2.2 addresses;
2.3 email addresses;
2.4 telephone numbers;
2.5 employment history;
2.6 education history;
2.7 CVs;
2.8 application records;
2.9 compliance records;
2.10 right-to-work documents;
2.11 identification documents;
2.12 DBS or criminal record information, where uploaded or Processed by the Data Controller;
2.13 bank details, where uploaded or Processed by the Data Controller;
2.14 payroll or payment-related information, where uploaded or Processed by the Data Controller;
2.15 ethnicity, sex, health, disability or other Special Category Data, where uploaded or Processed by the Data Controller;
2.16 referee details;
2.17 client and contact records;
2.18 notes, communications, emails, attachments, documents and uploaded files;
2.19 website enquiry data;
2.20 API data;
2.21 integration data;
2.22 system usage data;
2.23 log data;
2.24 IP addresses;
2.25 user account data;
2.26 technical metadata; and
2.27 any other Personal Data submitted, stored, sent, received, uploaded, imported, migrated, hosted or Processed by or on behalf of the Data Controller through the Services.
3. Subject Matter and Nature of Processing
3.1 The subject matter of the Processing is the provision, administration, hosting, support, maintenance, security and operation of the Products and Services.
3.2 Processing may include:
3.2.1 collection;
3.2.2 recording;
3.2.3 organisation;
3.2.4 structuring;
3.2.5 storage;
3.2.6 hosting;
3.2.7 retrieval;
3.2.8 consultation;
3.2.9 use;
3.2.10 transmission;
3.2.11 disclosure by transmission;
3.2.12 alignment;
3.2.13 combination;
3.2.14 restriction;
3.2.15 erasure;
3.2.16 destruction;
3.2.17 migration;
3.2.18 import;
3.2.19 export;
3.2.20 backup;
3.2.21 restoration;
3.2.22 troubleshooting;
3.2.23 support access;
3.2.24 technical administration; and
3.2.25 security monitoring.
4. Purpose of Processing
Personal Data is Processed for the purposes of:
4.1 providing the Services;
4.2 enabling the Data Controller and its authorised users to access and use the Services;
4.3 hosting and maintaining Personal Data;
4.4 providing support and troubleshooting;
4.5 performing implementation, migration, configuration and data conversion services;
4.6 operating websites, APIs, integrations and hosted services;
4.7 securing, monitoring, maintaining and improving the Services;
4.8 administering accounts, subscriptions, billing and payment collection; and
4.9 complying with legal, regulatory, security, audit, accounting and contractual obligations.
5. Duration of Processing
5.1 Personal Data shall be Processed for the duration of the Service Agreement and thereafter for such period as is reasonably required for termination, data export, deletion, backup, legal, regulatory, accounting, audit, dispute resolution, security, compliance, debt recovery or legitimate business purposes.
SCHEDULE 3
TECHNICAL AND ORGANISATIONAL MEASURES
1. The Data Processor shall maintain appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration or disclosure.
2. Such measures may include, as appropriate to the Services provided:
2.1 information security policies and procedures;
2.2 risk assessment and security governance;
2.3 access controls based on least privilege and role-based access;
2.4 user authentication controls;
2.5 password controls and secure credential management;
2.6 multi-factor authentication where appropriate;
2.7 encryption in transit where appropriate;
2.8 encryption at rest where appropriate;
2.9 physical security controls for premises and infrastructure;
2.10 network security controls including firewalls and segmentation where appropriate;
2.11 anti-malware and endpoint protection controls;
2.12 vulnerability management and patching;
2.13 logging, monitoring and audit trails;
2.14 backup and restoration procedures;
2.15 disaster recovery and business continuity arrangements;
2.16 secure data transfer methods;
2.17 secure deletion and disposal procedures;
2.18 incident detection, response and breach management procedures;
2.19 staff confidentiality obligations;
2.20 staff training and awareness;
2.21 supplier and Sub-Processor management;
2.22 segregation of customer environments or logical access controls where appropriate;
2.23 change control procedures;
2.24 periodic review of security measures; and
2.25 such additional organisational, operational and technological measures as are appropriate to the nature of the Services and the Personal Data Processed.
SCHEDULE 4
SUB-PROCESSORS
1. The following Sub-Processors may be used in connection with the Services.
2. Intra-group processors / service providers:
2.1 Eclipse Software Services Limited — group operational, technical, support, implementation, development, account administration and service delivery personnel.
3. Third-party Sub-Processors:
3.1 Microsoft Corporation / Microsoft Ireland Operations Ltd — cloud infrastructure, hosting and related Microsoft services.
3.2 ANS Group Limited — hosting, email, infrastructure or related managed services, where applicable.
4. The Data Processor may update this list from time to time in accordance with Clause 12.
Request a signed Data Processing Agreement by clicking here and complete the contact form (choose, a signed data processing agreement).