Data Processing Agreement

This Schedule sets out the terms on which the Supplier processes personal data on behalf of the Customer and forms part of the agreement. It is intended to satisfy the requirements of Article 28 of the UK GDPR.

1Definitions

In this Schedule, the terms controller, processor, data subject, personal data, personal data breach, processing and appropriate technical and organisational measures have the meanings given to them in the Data Protection Laws.

Processing Instructions: the documented instructions of the Customer set out in this Schedule and as otherwise notified by the Customer to the Supplier in writing from time to time; and Sub-processor: any third party engaged by the Supplier to process personal data in connection with the Services.

2Status of the parties

The Parties acknowledge that, for the purposes of the Data Protection Laws, the Customer is the controller and the Supplier is the processor in respect of the personal data processed under this agreement. The nature and details of the processing are set out in Annex 1 (Details of Processing).

Each Party shall comply with its respective obligations under the Data Protection Laws. Nothing in this Schedule relieves either Party of its own direct responsibilities and liabilities under the Data Protection Laws.

3Processing on instructions

The Supplier shall process the personal data only on and in accordance with the Customer's documented Processing Instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by applicable law; in which case, the Supplier shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

The Supplier shall immediately inform the Customer if, in its opinion, a Processing Instruction infringes the Data Protection Laws.

4Confidentiality of processing

The Supplier shall ensure that any person authorised to process the personal data (including its staff and Sub-processors) is subject to a binding duty of confidentiality in respect of that personal data and processes it only on the Customer's instructions.

5Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, the Supplier shall implement and maintain the appropriate technical and organisational measures set out in Annex 2 (Technical and Organisational Measures) to ensure a level of security appropriate to the risk, including as appropriate the measures referred to in Article 32 of the UK GDPR.

6Sub-processing

The Supplier shall not engage any Sub-processor without the prior specific or general written authorisation of the Customer. The Customer provides its general authorisation to the engagement of the Sub-processors listed in Annex 1. Where the Supplier intends to appoint a new Sub-processor or replace an existing one, it shall give the Customer prior written notice and a reasonable opportunity to object, and shall not appoint that Sub-processor if the Customer reasonably objects.

The Supplier shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those set out in this Schedule, and shall remain fully liable to the Customer for the performance of each Sub-processor's obligations.

7International transfers

The Supplier shall not transfer any personal data to a country outside the United Kingdom, or to an international organisation, without the Customer's prior written consent, and shall in any event ensure that any such transfer is effected by a transfer mechanism that complies with the Data Protection Laws (including the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any transfer risk assessment and supplementary measures required).

8Assistance to the Customer

Taking into account the nature of the processing, the Supplier shall assist the Customer by appropriate technical and organisational measures, insofar as is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising the data subject's rights under the Data Protection Laws.

The Supplier shall assist the Customer in ensuring compliance with its obligations relating to security of processing, notification of personal data breaches, data protection impact assessments and prior consultation with the Information Commissioner, taking into account the nature of the processing and the information available to the Supplier.

9Personal data breach

The Supplier shall notify the Customer without undue delay, and in any event within [●] hours, after becoming aware of a personal data breach affecting the personal data, and shall provide the Customer with sufficient information to allow the Customer to meet its obligations to report or inform data subjects and the Information Commissioner. The Supplier shall co-operate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation and remediation of the breach.

10Return and deletion

On termination or expiry of the agreement, and at the choice of the Customer, the Supplier shall return to the Customer or securely delete all the personal data and delete existing copies, save to the extent that applicable law requires the Supplier to retain that personal data. This paragraph operates in addition to, and is consistent with, clause 7.7 (Data on exit).

11Audit and records

The Supplier shall make available to the Customer all information necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and this Schedule, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. This paragraph operates in addition to the audit and information rights set out in clause 7.

Annex 1 — Details of Processing

Subject matter of the processing
The provision of the Services (anti-money laundering, know-your-customer, onboarding and related compliance services) by the Supplier to the Customer under the agreement.
Duration of the processing
The Subscription Term, together with any period thereafter during which the Supplier retains personal data in accordance with clause 7.7 and paragraph 11 of this Schedule.
Nature and purpose of the processing
Collection, recording, organisation, structuring, storage, retrieval, use, disclosure by transmission, and erasure of personal data for the purpose of providing the Services and enabling the Customer to meet its regulatory obligations.
Types of personal data
Identity data (name, date of birth, nationality), contact data, identification document data, verification and screening results, and such other personal data as the Customer inputs to, or generates through, the Services.
Categories of data subjects
The Customer's clients and prospective clients, their beneficial owners, directors, officers and authorised representatives, and the Customer's Authorised Users.
Sub-processors
As set out in the List of Sub-processors below.

List of Sub-processors

The Customer provides its general authorisation to the engagement of the Sub-processors set out in the table below, in accordance with paragraph 6 (Sub-processing).

Draft for review: the Location and Data processed values below are drafted from Saafehouse's known infrastructure and standard vendor documentation. Please verify each entry before publishing.
Sub-processorLocationData processed
London, United Kingdom (eu-west-2) — UK/EEA data residencyPrimary cloud hosting infrastructure: storage, compute, databases and encrypted backups for all Client Data.
European Union (EU1 region — Frankfurt, Germany)Application performance monitoring, logging and infrastructure telemetry (may include technical and usage data and limited personal data contained in logs).
London / European Union (europe-west2)Supplementary cloud infrastructure and managed data processing services.
European Union / United KingdomBusiness email, document storage and collaboration (may contain personal data within correspondence and files).
Global edge network (UK/EU points of presence)Content delivery, DNS, DDoS mitigation and web application firewall; processes network traffic metadata and IP addresses in transit.
Book a Demo

Take Control of Your Asset & Cash Management

*Mandatory fields

Request sent

We will respond to you very soon.

Oops! Something went wrong while submitting the form.