Data Processing Agreement
This Data Processing Agreement provides a general framework for NetaMate's processing of personal data on behalf of a customer.
This DPA applies when it is incorporated into a customer agreement, order form or statement of work, or when applicable data-protection law requires its terms to govern NetaMate's processing on the customer's behalf.
1. Parties and scope
This Data Processing Agreement, DPA, is between the customer identified in the applicable agreement, Customer, and NetaMate Solutions, NetaMate. It forms part of the agreement governing the relevant service.
This DPA applies to personal data that NetaMate processes on Customer's behalf in providing the service. Terms such as controller, processor, personal data, processing and data subject have the meanings given by applicable data-protection law.
2. Roles of the parties
Customer acts as controller, business or equivalent decision-maker for Customer Personal Data, and NetaMate acts as processor, service provider or equivalent recipient processing that data on Customer's behalf, except where law requires a different role for a particular activity.
Customer is responsible for ensuring that its instructions and use of the service comply with applicable law and that it has the necessary rights and notices for the personal data it provides.
3. Processing instructions
NetaMate will process Customer Personal Data only on documented instructions from Customer, including instructions contained in the agreement, service configuration and authorized support requests, unless applicable law requires other processing. If law requires processing outside Customer's instructions, NetaMate will inform Customer before processing unless the law prohibits that notice.
If NetaMate reasonably believes an instruction violates applicable data-protection law, NetaMate may suspend the affected processing and inform Customer so the parties can resolve the issue.
4. Confidentiality and authorized access
NetaMate will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access the data only as reasonably needed to provide, secure or support the service.
5. Security measures
NetaMate will maintain technical and organizational measures appropriate to the risk of the processing. Depending on the service, these may include encrypted transport, access controls, infrastructure hardening, network restrictions, operational monitoring, secrets management, backup and recovery procedures, controlled deployment processes and incident response.
Customer acknowledges that security measures may evolve as technology, threats and services change, provided that NetaMate does not materially reduce the overall level of protection for Customer Personal Data during an active service term without reasonable justification.
6. Subprocessors
Customer authorizes NetaMate to use subprocessors to provide the service. NetaMate remains responsible for requiring subprocessors that process Customer Personal Data to protect that data through appropriate contractual obligations.
NetaMate maintains a public Subprocessor List. When required by applicable law or the customer agreement, NetaMate will provide reasonable notice before adding a new subprocessor that will materially process Customer Personal Data. Customer may raise a reasonable data-protection objection, and the parties will work in good faith toward a practical resolution.
7. Data-subject requests
Taking into account the nature of the processing, NetaMate will provide reasonable assistance to Customer with requests by individuals to exercise applicable privacy rights where Customer cannot reasonably fulfill the request using the service itself.
If NetaMate receives a request relating to Customer Personal Data for which Customer is responsible, NetaMate may direct the requester to Customer unless law requires NetaMate to respond directly.
8. Personal-data breaches
NetaMate will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data where notification is required by applicable law. The notice will include information reasonably available to NetaMate that Customer needs to meet its own breach obligations.
NetaMate will take reasonable steps to contain and remediate the incident. Notification of an incident is not an admission of fault or liability.
9. Compliance assistance
Taking into account the nature of the processing and information available to NetaMate, NetaMate will provide reasonable assistance with data-protection impact assessments, regulator consultations and other processor obligations required by applicable law, where the assistance relates to the service and cannot reasonably be completed by Customer without NetaMate.
10. International transfers
NetaMate may process Customer Personal Data in countries where NetaMate or its subprocessors operate. Where applicable law requires a transfer mechanism, the parties will use an appropriate lawful mechanism, which may include applicable Standard Contractual Clauses, the UK International Data Transfer Addendum or another recognized safeguard.
11. Return and deletion
At the end of the relevant service, NetaMate will return or delete Customer Personal Data as provided by the service and applicable agreement, unless law requires continued retention. Backup copies may remain for a limited backup lifecycle and will remain protected by this DPA until deleted or overwritten in the ordinary course.
12. Information and audits
NetaMate will make available information reasonably necessary to demonstrate compliance with processor obligations applicable to the service. Where legally required and not reasonably satisfied by available documentation, Customer may request a reasonable audit subject to advance notice, confidentiality, security safeguards and measures designed to avoid unnecessary disruption or exposure of other customers' information.
13. Processing details
- Subject matter
- Provision, operation, support, security, backup and maintenance of the NetaMate services purchased by Customer.
- Duration
- For the service term and any limited retention or backup period permitted by the agreement or applicable law.
- Nature and purpose
- Hosting, storing, transmitting, organizing, retrieving, securing, troubleshooting, backing up and otherwise processing data as necessary to provide the service and follow Customer's documented instructions.
- Data subjects
- May include Customer personnel, users, customers, suppliers, contacts, support requesters, email correspondents, device users and other individuals whose data Customer chooses to process through the service.
- Data categories
- May include identifiers, contact information, account data, communications, support records, documents, attachments, technical logs, device or endpoint information and other content submitted by Customer.
- Sensitive data
- The service is not intended to require sensitive or special-category data unless the applicable service and written agreement expressly support it. Customer should avoid submitting such data unless necessary, lawful and appropriately protected.
14. Conflict and term
If this DPA conflicts with another part of the agreement on the processing of Customer Personal Data, this DPA controls for that issue unless the parties expressly agree otherwise in writing. This DPA remains in effect for as long as NetaMate processes Customer Personal Data on Customer's behalf.
15. Contact
Data-protection questions relating to this DPA can be sent to contact@netamate.com.