Data retention policy
All instructions given by the Data Controller to the Data Processor shall be made in writing and shall at all times be in compliance with applicable laws. The Data Processor shall act only on such written instructions from the Data Controller unless the Data Processor is required by law to do otherwise.
The Data Processor shall promptly comply with any request from the Data Controller requiring theData Processor to amend, transfer, delete, or otherwise dispose of the Personal Data, or to cease, mitigate, or remedy any authorized processing.
The Data Processor shall transfer all Personal Data to the Data Controller on the Data Controller’s request in the formats, at the times, and in compliance with the Data Controller’s written instructions.
Both Parties shall comply at all times with Applicable Legislation and shall not perform their obligations under this Agreement or any other agreement or arrangement between themselves in such a way as to cause either Party to breach any of its applicable obligations under Applicable Legislation.
The Data Controller hereby warrants, represents, and undertakes that the Personal Data and its use with respect to the Service Agreement and this Agreement shall comply with applicable Data Protection Legislation in all respects including, but not limited to, its collection, holding, and processing.
Data archiving and removal policy
The Data Processor shall, at the written request of the Data Controller, delete (or otherwise dispose of) the Personal Data or return it to the Data Controller in the format(s) reasonably requested by the Data Controller within a reasonable time after the earlier of the following:
the end of the provision of the Services under the Service Agreement;
the termination of the Service Agreement; or
If the Data Processor is required by law, government, or other regulatory body to retain any documents or materials that the Data Processor would otherwise be required to return, delete, or otherwise dispose of under this Agreement, the Data Processor shall notify the Data Controller in writing of the requirement. Such notice shall give details of all documents or materials that the Data Processor is required to retain, the legal basis for that retention, and the timeline for deletion and/or disposal at the end of the retention period.
Data storage policy
The Data Processor shall implement suitable technical and organizational security measures in order to protect the Personal Data against unauthorized or unlawful access, processing, disclosure, copying, alteration, storage, reproduction, display, or distribution; and against loss, destruction, or damage, whether accidental or otherwise. Such measures shall include, but not be limited to, those set out in Schedule 2.
App/service has sub-processors
no
App/service uses large language models (LLM)
no