1. Roles
This Data Processing Agreement forms part of the Terms of Service. Customer is the controller and [Legal Entity Name] is the processor in respect of personal data processed through the platform.
Each party will comply with the data protection law applicable to it. Customer warrants that it has a lawful basis for the processing it instructs, and that it has issued any notice that basis requires.
2. Subject matter and duration
Subject matter: provision of the AegisOne endpoint management platform.
Duration: the term of the Terms of Service, plus any agreed export window.
Nature and purpose: collection, storage, organisation, retrieval, use, transmission and deletion of endpoint and operator data for the purpose of endpoint monitoring, management, support, security and reporting.
Categories of data subject: Customer’s personnel and contractors who operate the platform, and the users of endpoints Customer enrols.
Categories of personal data: identity and contact data, account and authentication data, endpoint identifiers and telemetry attributable to a user, action and audit records, and any personal data Customer chooses to place in free-text fields such as tickets and documentation.
Customer must not place special category data in the platform unless the parties have agreed additional measures in writing.
3. Processor obligations
We will process personal data only on Customer’s documented instructions, of which the Terms of Service and use of the platform’s features are the primary instruction, unless required otherwise by law. Where law compels processing, we will inform Customer unless prohibited.
We will ensure that personnel authorised to process personal data are bound by confidentiality obligations.
We will not sell personal data, and will not use it for our own marketing or to train models offered to other customers.
4. Security measures
We will implement technical and organisational measures appropriate to the risk, including as at the date of this document:
- Encryption of data in transit using TLS.
- Role-based access control over operator functions and over the credential vault.
- Multi-factor authentication available for operator accounts, and login attempt tracking.
- Ticketed authorisation for remote sessions, with attribution to a named operator.
- Append-only audit logging of privileged actions.
- Rate limiting on authentication and API surfaces.
- Segregation of the demonstration environment from production customer environments.
Measures may change as the platform develops, provided the level of protection is not reduced. A current description is available on request.
5. Subprocessors
Customer gives general authorisation for us to engage subprocessors. A current list is available on request, and we will give at least [notice period] days’ notice before adding or replacing one.
Customer may object on reasonable data protection grounds within that notice period. If the objection cannot be resolved, Customer may terminate the affected service without penalty for the unused portion of a prepaid term.
We remain liable for the acts and omissions of our subprocessors as if they were our own.
6. International transfers
Where processing involves a transfer to a jurisdiction without an adequacy decision, the parties will rely on Standard Contractual Clauses, which are incorporated by reference and completed as set out in Annex [x], supported by a transfer risk assessment and any supplementary measures it identifies.
7. Assistance
Taking into account the nature of the processing, we will assist Customer with:
- Responding to data subject requests, including by providing export and deletion functionality within the platform. Where a request reaches us directly, we will refer it to Customer rather than answer it.
- Notification of personal data breaches. We will notify Customer without undue delay after becoming aware of a breach affecting Customer personal data, with the information available to us at the time, followed by updates as our investigation progresses.
- Data protection impact assessments and prior consultation with a supervisory authority, to the extent the information is within our control.
8. Audit
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by Customer or a mandated auditor, on reasonable notice, no more than once in any twelve-month period except following a breach, during business hours, and subject to confidentiality.
We hold no third-party audit report or certification at present. We will not represent otherwise, and Customer should factor that into its own assessment.
9. Deletion and return
On termination, Customer may export its data during the export window stated in the Terms of Service. After it closes, we will delete personal data within [deletion period] days, except where retention is required by law. Backup copies are deleted on the ordinary backup expiry cycle.