Master Data Processing Agreement
Contract Details
SUPPLIER (Processor)
Company name and number: SETYL LTD (company number: 12677958). Address: St James House, St James Road, London, KT6 4QH, UK. Email: hello@setyl.com
CUSTOMER (Controller)
The Customer’s company name, address and email are as stated in the Order Form under the Principal Agreement.
Each a “Party” and together the “Parties”.
This Master Data Processing Agreement (“Agreement”) forms part of, and is subject to, the Master Software License Agreement between the Parties (the “Principal Agreement”). The processing details are set out in Annex 1.
Background
A. The Supplier provides services to the Customer under the Principal Agreement, in the course of which the Supplier processes Customer Personal Data on the Customer’s behalf to fulfil the Purpose.
B. This Agreement sets out the terms on which the Supplier will process Customer Personal Data, in accordance with the Data Protection Laws.
Agreed terms
1. Definitions and interpretation
1.1.
In this Agreement, unless the context otherwise requires, the following expressions have the following meanings:
Agreement means this Master Data Processing Agreement, including the Contract Details and the Annexes.
Customer Personal Data means the Personal Data processed by the Supplier on behalf of the Customer under this Agreement, as described in Annex 1.
Data Protection Laws means all applicable data protection and privacy legislation in force in the United Kingdom, including but not limited to: (a) the UK GDPR as defined in section 3(10) of the Data Protection Act 2018, as supplemented by section 205(4) (“UK GDPR”); (b) the Data Protection Act 2018; and (c) the Privacy and Electronic Communications Regulations 2003 (SI 2003 No. 2426), in each case as amended, updated or replaced from time to time, together with any guidance or codes of practice issued by the DP Regulator from time to time.
Data controller, data processor, personal data, processing and appropriate technical and organisational measures each have the meanings given in the UK GDPR.
DP Regulator means a supervisory authority as defined in the UK GDPR, which in the UK is the Information Commissioner’s Office.
Duration of Processing means the length of time the Supplier will process Customer Personal Data, as described in Annex 1.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, Customer Personal Data.
Purpose means the purpose for processing Customer Personal Data, as described in Annex 1.
Standard Contractual Clauses means the standard data protection clauses adopted by the UK Information Commissioner, including the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
Sub-Processor means any processor (including any agent, sub-contractor or other third party) engaged by the Supplier (or by any other Sub-Processor) to carry out processing of Customer Personal Data.
1.2.
A reference to a “person” means an individual, firm, company, unincorporated body or government entity, and any of its successors or permitted assignees.
1.3.
Clause, schedule and paragraph headings do not affect interpretation.
1.4.
References to legislation are to that legislation as amended, supplemented, re-enacted or replaced from time to time.
1.5.
The words “include”, “including” and similar expressions do not limit the words that precede them.
1.6.
A reference to “writing” or “written” includes email.
1.7.
If there is any conflict between this Agreement and the Principal Agreement in relation to the processing of Personal Data, this Agreement prevails.
1.8.
Capitalised terms used but not defined in this Agreement (including “Business Day” and “Business Hours”) have the meanings given to them in the Principal Agreement.
1.9.
Where the Supplier processes Customer Personal Data that is subject to the EU GDPR or Swiss data protection law, the EU Data Processing Addendum (available at setyl.com/legal) supplements this Agreement and applies to that processing.
2. Data protection roles and relationship
2.1.
The Parties acknowledge that, for the purposes of the Data Protection Laws, the Customer is the controller and the Supplier is the processor of the Customer Personal Data uploaded, stored or transmitted via the Software by the Customer’s personnel.
2.2.
Each Party will comply with its obligations under the Data Protection Laws in relation to Personal Data shared or processed under this Agreement. This Agreement does not relieve either Party of its own obligations under the Data Protection Laws.
3. Data processing obligations
3.1.
Each Party will maintain records of its processing of Personal Data as required by the Data Protection Laws, and will make those records available to a DP Regulator on request.
3.2.
To the extent the Supplier processes Customer Personal Data on behalf of the Customer, the Supplier will:
3.2.1.
process the Customer Personal Data only on the documented instructions of the Customer (including as set out in Annex 1), unless required to do otherwise by applicable law, in which case the Supplier will (where lawful) notify the Customer before processing. The Supplier will notify the Customer if, in its opinion, an instruction infringes the Data Protection Laws;
3.2.2.
implement appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, as described in Annex 3 and including, as appropriate: (a) the pseudonymisation and encryption of Personal Data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore availability of and access to Personal Data in a timely manner after an incident; and (d) a process for regularly testing and evaluating the effectiveness of those measures;
3.2.3.
ensure that any personnel authorised to process Customer Personal Data are bound by obligations of confidentiality, and not disclose Customer Personal Data to any third party except as permitted by this Agreement or required by law;
3.2.4.
taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures (insofar as possible) in responding to requests from data subjects exercising their rights under the Data Protection Laws. The Supplier will promptly (and within 5 Business Days) notify the Customer of any such request it receives relating to Customer Personal Data, and will not respond to it except on the Customer’s documented instructions or as required by law;
3.2.5.
taking into account the nature of the processing and the information available to the Supplier, assist the Customer in ensuring compliance with its obligations relating to the security of processing, personal data breach notification, data protection impact assessments and prior consultation with the DP Regulator;
3.2.6.
notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of any Personal Data Breach affecting Customer Personal Data, and provide the Customer with sufficient information to allow it to meet any obligation to report the breach to a DP Regulator or notify affected data subjects.
3.3.
The Supplier will provide the assistance described in clauses 3.2.4 and 3.2.5 at no additional cost, save that the Customer will reimburse the Supplier’s reasonable costs where the assistance requested is unreasonable in scope or frequency, or requires material engineering effort beyond the standard functionality of the Software.
4. Sub-processors
4.1.
The Customer provides general written authorisation for the Supplier to appoint Sub-Processors to process Customer Personal Data. The Supplier’s current Sub-Processors are listed on the Supplier’s sub-processor page at setyl.com/legal (the “Sub-processor Page”), which is referenced in Annex 2 and is the authoritative list of Sub-Processors for the purposes of this Agreement.
4.2.
Where the Supplier appoints a Sub-Processor, it will:
4.2.1.
impose on the Sub-Processor, by written contract, data protection obligations that are materially similar to, and no less protective than, those in this clause 4;
4.2.2.
remain fully liable to the Customer for the acts and omissions of the Sub-Processor as if they were the Supplier’s own; and
4.2.3.
give the Customer at least 30 days’ prior written notice (which may be given by email or by updating the Sub-processor Page and notifying subscribed Customers) of any intended addition or replacement of a Sub-Processor, so as to give the Customer the opportunity to object.
4.3.
If the Customer reasonably objects to a new Sub-Processor on legitimate data protection grounds within the notice period, the Parties will work together in good faith to find a mutually acceptable resolution. If no resolution is reached, the Customer may, as its sole remedy, terminate the affected part of the Services and receive a refund of any pre-paid Fees for the terminated period.
5. International transfers
5.1.
The Supplier will not transfer Customer Personal Data outside the United Kingdom unless it has taken the measures necessary to ensure the transfer complies with the Data Protection Laws. Such measures may include transferring to a country subject to UK adequacy regulations, or entering into the Standard Contractual Clauses.
5.2.
The Customer authorises the Supplier to enter into the Standard Contractual Clauses (as the Customer’s agent where required) with any Sub-Processor located outside the United Kingdom, on the Customer’s behalf. Where the Customer’s own signature is required, the Customer will promptly comply with any reasonable request of the Supplier to enter into such clauses.
6. Audit
6.1.
The Supplier will maintain complete, accurate and up-to-date records of all categories of processing carried out on behalf of the Customer, including the information required by Articles 30(1) and 30(2) of the UK GDPR.
6.2.
The Supplier will make available to the Customer such information as is reasonably necessary to demonstrate compliance with this Agreement and the Data Protection Laws, and will allow for and contribute to audits (including inspections) conducted by the Customer or an auditor mandated by the Customer.
6.3.
The Customer may exercise its audit right no more than once in any 12-month period (except following a Personal Data Breach or where required by a DP Regulator), on at least 30 days’ prior written notice, during Business Hours, and in a manner that causes minimal disruption to the Supplier’s business. The Supplier may satisfy an audit request by providing its most recent third-party certifications or audit reports (such as ISO 27001), where these reasonably address the Customer’s request.
6.4.
Each Party bears its own costs of an audit, save that the Customer will reimburse the Supplier’s reasonable costs of supporting an audit that goes beyond the provision of existing certifications and records.
7. Termination and effect of termination
7.1.
This Agreement remains in effect for the Duration of Processing, after which it automatically terminates. It also terminates automatically on termination or expiry of the Principal Agreement.
7.2.
On termination, and at the Customer’s written direction, the Supplier will delete (so far as technically possible) or return the Customer Personal Data and any copies within 30 days, unless required by applicable law to retain it, in which case the Supplier will keep it confidential and process it only as required by that law.
7.3.
For the purposes of this clause 7, Customer Personal Data is considered deleted where it can no longer be accessed or used by the Supplier in the ordinary course, including where it is retained only in routine backups that are overwritten in the ordinary backup cycle.
8. General
8.1.
Costs. Except as otherwise stated in this Agreement, each Party is responsible for its own legal and other costs in relation to this Agreement.
8.2.
Survival. Clauses 1, 6, 7 and 8, and all clauses required for their interpretation, survive termination.
8.3.
Relationship of the Parties. The Parties are independent businesses and not partners, principal and agent, or employer and employee.
8.4.
Third party rights. For the purposes of the Contracts (Rights of Third Parties) Act 1999, this Agreement does not give any non-party any right to enforce its provisions, without affecting any right or remedy that exists apart from that Act.
8.5.
Assignment. Neither Party may assign, subcontract or encumber any right or obligation under this Agreement without the other Party’s prior written consent, except as expressly permitted in this Agreement or the Principal Agreement.
8.6.
Entire agreement. This Agreement and the Principal Agreement contain the whole agreement between the Parties relating to their subject matter and supersede any prior agreements, representations or understandings. Nothing in this clause limits liability for fraud or fraudulent misrepresentation.
8.7.
Variation. No variation of this Agreement is valid unless agreed in writing and signed by an authorised signatory of each Party.
8.8.
Severability. If any provision (or part of a provision) is found to be illegal, invalid or unenforceable, it will be modified to the minimum extent necessary to make it valid, and the remainder will continue in force.
8.9.
Waiver. No delay, act or omission by either Party in exercising any right or remedy is a waiver of that or any other right or remedy.
8.10.
Notices. Notices under this Agreement must be in writing and sent to the other Party’s address or email as set out in the Contract Details. Letters sent within the United Kingdom are deemed delivered 3 Business Days after posting. Emails are deemed delivered the same day, or the next Business Day if sent after 5pm or on a non-Business Day at the recipient’s location.
8.11.
Execution. This Agreement forms part of the Principal Agreement and does not require separate signature. It takes effect when the Parties sign the Order Form that incorporates the Principal Agreement.
8.12.
Liability. Each Party’s liability arising out of or in connection with this Agreement (whether in contract, tort (including negligence), breach of statutory duty or otherwise) is subject to, and counts towards, the exclusions and limitations of liability set out in the Principal Agreement, except to the extent that such exclusion or limitation is not permitted by the Data Protection Laws.
8.13.
Governing law and jurisdiction. This Agreement is governed by the laws of England and Wales. The Parties submit to the exclusive jurisdiction of the courts of England and Wales.
This Master Data Processing Agreement forms part of the Principal Agreement. By signing the Order Form that incorporates the Principal Agreement, the Parties agree to the terms of this Agreement, which takes effect on the date of that signature. Separate signature of this Agreement is not required.
Annex 1 — Processing details
Purpose. The Supplier’s provision of Setyl’s IT asset management platform, and related products and services, to the Customer.
Subject matter and nature of the processing. Collection, storage, hosting, organisation, retrieval, use, transmission and deletion of Customer Personal Data, in digital format, as necessary to provide the IT asset management platform and related services.
Categories of data subject. The Customer’s employees, workers, contractors and other personnel whose profiles are held in the platform, and the Customer’s authorised users of the platform.
Categories of personal data. Name; photo/avatar; job title; email; status; department; location; legal entity; join date; leave date; contract type; detection sources; employee ID; phone number; address; username; manager; personal email; notes; location type; role; assigned app licences; managed apps; assigned assets; platform activity; password (if set); authentication data; survey responses; documents; support tickets; marketing preferences; and communications with Setyl.
Special category data. None is required for the Services. The Customer must not upload special category data except where strictly necessary, and remains responsible for its lawful basis for doing so.
Duration of processing. For the duration that the Supplier provides the platform to the Customer under the Principal Agreement, plus any period during which the Supplier is required by law to retain the data.
Supplier’s Data Protection contact. Christopher Batts (hello@setyl.com).
Annex 2 — Approved Sub-Processors
The Supplier’s approved Sub-Processors are set out on the Supplier’s sub-processor page at setyl.com/legal (the Sub-processor Page). The Sub-processor Page is the authoritative and up-to-date list of Sub-Processors for the purposes of this Agreement and is incorporated into this Agreement by reference.
The Supplier maintains the Sub-processor Page, and notifies additions and replacements of Sub-Processors in accordance with clause 4.2.3. Customers may subscribe to change notifications using the mechanism described on the Sub-processor Page, or by contacting hello@setyl.com. A copy of the Sub-processor Page as at the date of this Agreement is available from the Supplier on request.
Annex 3 — Technical and organisational measures
The Supplier maintains an information security programme aligned with ISO/IEC 27001, including at least the following measures.
Access control. Role-based access control; least-privilege access; unique named accounts; multi-factor authentication for administrative and remote access; prompt revocation of access on personnel changes.
Encryption. Encryption of Customer Personal Data in transit (TLS) and at rest.
Network and application security. Firewalls and network segmentation; secure software development practices; regular vulnerability scanning and periodic penetration testing; timely patching.
Confidentiality, integrity, availability and resilience. Redundancy and high-availability architecture; monitoring and logging; documented change management.
Backup and recovery. Regular encrypted backups; documented business continuity and disaster recovery processes; periodic restoration testing.
Incident management. A documented incident and breach response process, including breach notification in accordance with clause 3.2.6.
Personnel. Confidentiality obligations for all personnel; background checks where lawful; regular security and data protection training.
Sub-processor management. Due diligence and written data protection terms with all Sub-Processors.
Physical security. Reliance on the physical security controls of the Supplier’s certified hosting providers.