The terms on which we process personal data that our customers put into the service. Required by Article 28 of the GDPR, and part of the agreement between us from the moment an account is opened.
For the packaging data a customer puts into the service, the customer is the controller and the operator named above is the processor. For account data and the visitor data on the public pages, the operator is the controller — see the privacy notice.
This agreement takes effect when an account is opened and lasts as long as we process data for the customer.
| Subject matter | Providing the packaging-compliance service the customer has subscribed to. |
|---|---|
| Duration | The term of the subscription, plus the deletion period in section 9. |
| Nature and purpose | Storing, organising, calculating on and displaying the data the customer enters, and generating documents from it. |
| Types of personal data | Business contact details that appear in the customer's own records: the name, role and signature block of the person who signs a declaration, supplier contacts, and the identity of the user who made a change. |
| Categories of data subject | The customer's employees and its suppliers' employees. |
| Special categories | None. The service is not designed for special-category data and it should not be entered. |
We process the data only on the customer's documented instructions, which are these terms and the customer's use of the service. If we are required by EU or Member State law to process it otherwise, we will tell the customer first unless that law forbids it.
If an instruction appears to us to breach data protection law, we will say so.
Everyone we allow to process the data is bound by a duty of confidentiality, and is given access only to what their work requires.
We take the measures set out in section 9 of the privacy notice, and keep them appropriate to the risk as the service changes. Those measures are part of this agreement.
The customer gives general authorisation for the sub-processors listed below. Each is bound by written terms no less protective than these, and we remain responsible for their performance.
We will give notice before adding or replacing a sub-processor, in time for the customer to object. If a reasoned objection cannot be resolved, the customer may terminate the affected part of the service without penalty.
The service lets a customer find, correct, export and delete records itself, which is normally the fastest route. Where it is not enough, we will help — taking account of the nature of the processing and the information available to us — and will pass on any request that reaches us instead of answering it ourselves.
We will notify the customer without undue delay after becoming aware of a breach affecting their data, with what we know at the time and updates as we learn more, so they can meet their own 72-hour obligation.
On termination the customer can export everything from the service. We delete the data within 90 days, including from backups on their normal rotation, unless EU or Member State law requires us to keep it — in which case we keep only that, and only for as long as required.
We will make available the information needed to show compliance with Article 28, and allow an audit by the customer or an auditor it mandates, on reasonable notice, no more than once a year unless a supervisory authority or a breach makes more necessary, and on terms that protect other customers' confidentiality.
Any transfer outside the EEA relies on an adequacy decision or on standard contractual clauses, as set out in section 5 of the privacy notice.
Where this agreement conflicts with the terms of service, this agreement prevails for anything concerning the processing of personal data.