011. Scope and Roles
Where a client engagement requires us to process personal data belonging to the client's own customers, employees, or users, we act as a data processor and the client acts as the data controller, consistent with the roles defined under GDPR Article 28 and equivalent provisions in other applicable frameworks.
022. Processing Instructions
We process personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country, unless required to do otherwise by applicable law.
033. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations, whether contractual or statutory.
044. Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption in transit, access controls, and regular review of security practices.
055. Sub-processors
We maintain a list of approved sub-processors (such as cloud hosting and infrastructure providers) and will notify clients of any intended changes, giving them the opportunity to object on reasonable grounds.
066. Data Subject Rights
We assist the controller, insofar as reasonably possible, in fulfilling its obligations to respond to requests from data subjects exercising their rights under applicable data protection law.
077. Data Deletion
At the end of the provision of services, we delete or return all personal data to the controller, and delete existing copies, unless retention is required by law.
