This Data Processing Agreement ("DPA") forms part of the Terms of Service between Brrr Company ("Brrr", "Processor", "we"), a company registered in England and Wales, and the customer accepting them ("Controller", "you"). It applies whenever we process personal data on your behalf in running the service, and it is the agreement required by Article 28 of the UK GDPR and the EU GDPR.
1. When this applies
This DPA covers personal data you or your agent put into your company about other people, such as clients, contacts, candidates and staff, which we process on your instructions.
It does not cover personal data for which we are the controller, meaning your account, your use of the service and your billing. The Privacy Policy governs that, and this DPA gives you no rights over it.
Where you have more than one company, this DPA applies to each of them, and section 9's liability position is the total across all of them, not one per company.
Terms used here and not defined have the meaning given in the UK GDPR.
2. Your instructions
2.1 We process the personal data only to provide the service and on your documented instructions, which are these Terms, this DPA and your use of the service's features. Your instructions may not require processing the service does not offer.
2.2 You confirm you have a lawful basis for the data, that you have given whatever notices and obtained whatever consents the law requires, and that your instructions do not put us in breach of data protection law. If we think an instruction does, we may decline it and tell you why.
2.3 Where the law obliges us to process for another reason, we may, subject to the notice Article 28(3)(a) requires.
3. What we do on our side
3.1 People we authorise to process the data are bound by confidentiality.
3.2 We keep technical and organisational measures as Article 32 requires; Annex B describes them. We may change them as the service changes, provided we do not materially reduce the protection they give.
3.3 Assistance with your own obligations under Articles 32 to 36 is given as Article 28(3)(f) requires, taking account of the nature of the processing and what we know, at your reasonable cost.
4. Sub-processors
4.1 You give us general authorisation to engage sub-processors, on the conditions Article 28 puts on it.
4.2 If you object in writing to a sub-processor, you may stop using the affected part of the service; that is the remedy, and fees already paid are not refunded.
4.3 We impose data protection obligations on each sub-processor no less protective than these, and we remain responsible to you for its performance, subject to section 9.
5. Sending data abroad
Where personal data moves out of the United Kingdom or the European Economic Area to a country without an adequacy decision, the parties incorporate by reference the European Commission's Standard Contractual Clauses, module two for controller to processor and module three for onward transfers, and for United Kingdom transfers the UK International Data Transfer Addendum. Where those clauses conflict with this DPA, they win.
6. Requests from the people the data is about
6.1 We will not answer a data subject's request directly, beyond telling them to contact you; it is passed to you as the assistance Article 28(3)(e) requires.
6.2 Any further assistance in answering it is given so far as the service lets us and at your reasonable cost.
7. If there is a breach
7.1 A personal data breach affecting the personal data we process for you is notified to you as Article 33(2) requires.
7.2 A notice says what we know at the time. It is not an admission of fault or of a breach of this DPA.
7.3 Notifying supervisory authorities and data subjects is yours to do. Assistance with it is given at your reasonable cost.
8. Checking up on us
8.1 On reasonable written request, and not more than once in twelve months, we will make available the information necessary to demonstrate compliance with this DPA. What that information is, and the form it takes, are ours to choose.
8.2 Where the law requires more and that documentation is not enough, you may audit us once in twelve months, on 30 days' written notice, in business hours, under confidentiality, at your cost, and without access to other customers' data, our staff's personal data or anything that would put our security at risk. We may charge for the time supporting it.
9. Liability
Liability under this DPA is subject to the exclusions and the cap in section 9 of the Terms, which apply to all claims under the Terms and this DPA taken together.
10. Deletion and return
10.1 When your company closes, or on your written request, the personal data we process for you is deleted or returned as Article 28(3)(g) requires, except where the law requires us to keep it.
10.2 Copies held in our replication and backups are removed on their ordinary cycle rather than individually.
10.3 Where you ask for return rather than deletion, it is given in the formats the service exports, at your reasonable cost.
11. General
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. Where it conflicts with the Terms on the processing of personal data, this DPA prevails. We may update this DPA where the law or the service changes; the version on this page applies.
Annex A — What is processed
- Subject matter. Personal data put into your company, by you or by your agent, in the course of the service.
- Duration. While your company is open, plus what section 10 and the law allow.
- Nature and purpose. Storing, transmitting to the sub-processors under section 4, displaying to you, backing up and logging, so that the agent can do the work you asked for.
- Categories of data subject. The people you seat in your company; and the people your agent deals with for you, such as clients, customers, candidates, suppliers and contacts.
- Categories of personal data. Names, email addresses, phone numbers, postal and company details, the content of messages and documents to and from those people, and whatever else you or your agent records about them.
- Special category data. Not asked for and not expected. If you put it in, that is your instruction and your lawful basis.
Annex B — Security measures
We keep technical and organisational measures appropriate to the risk, as Article 32 requires. They cover:
- Tenancy: each company's agent works on a machine of its own.
- Encryption: saved credentials at rest, and traffic in transit.
- Access: the production system is reachable by authorised people only.
- Segregation: a company's data is reachable only through that company.
- Traceability: changes to the records the service versions are logged.
- Continuity: the database is replicated to off-site storage.
What sits under each heading is ours to set and to change as section 3.2 allows.
Annex C — Sub-processors
We use sub-processors to run the models behind the agent, the machine it works on, our payments, our backups and file storage, our hosting, the addresses its browser goes out through, and the media it generates.