This Data Processing Agreement (Agreement) governs the processing of personal data carried out by Waivern Limited (the Processor) on behalf of its customer (the Controller) in connection with the Controller’s use of Waivern Limited’s products and services. It is incorporated into the parties’ Main Agreement and requires no separate signature.
In this Agreement, the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given to them in the Main Agreement.
2.1 This Agreement is incorporated into and forms part of the Main Agreement between the Controller and the Processor governing the Controller’s use of the Services.
2.2 By entering into, signing, or otherwise accepting the Main Agreement, the Controller and the Processor agree to be bound by this Agreement. A separate signature to this Agreement is not required: execution or acceptance of the Main Agreement constitutes execution of this Agreement by the same parties, with effect from the effective date of the Main Agreement.
2.3 The parties to this Agreement are the parties identified in the Main Agreement. Where the Main Agreement is accepted by signature, order form, click-through or other online acceptance, that same acceptance binds the accepting parties to this Agreement to the same extent and by the same means.
3.1 The Processor shall Process Personal Data solely for the purpose of providing the Services to the Controller under the Main Agreement, and shall not Process Personal Data for any other purpose except as required by law.
3.2 As between the parties, the Controller is the controller and the Processor is the processor in respect of the Processing described in this Agreement and in Annex 1.
3.3 This Agreement shall take effect on the effective date of the Main Agreement and shall continue for the duration of the Processing carried out by the Processor in connection with the Services, unless terminated earlier in accordance with this Agreement or the Main Agreement.
The subject matter, duration, nature, purpose, categories of Personal Data and categories of Data Subjects in respect of the Processing carried out under this Agreement are set out in Annex 1. Where Annex 1 references the Record of Processing Activity (GDPR Article 30), that document forms the authoritative basis for the processing particulars and is incorporated by reference.
The Processing carried out under this Agreement arises from the Controller’s use of the Services, which comprise compliance readiness tooling combining automated evidence gathering from codebases, cloud infrastructure and policy documents with expert review and guidance. In providing the Services, the Processor may Process Personal Data included in materials submitted by the Controller or its authorised users.
The Processor SHALL comply with the following obligations in respect of all Personal Data Processed under this Agreement:
(a) Instructions. The Processor SHALL Process Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless Processing is required by applicable law to which the Processor is subject. Where the Processor is required by law to Process Personal Data otherwise than in accordance with the Controller’s instructions, the Processor SHALL inform the Controller of that legal requirement before Processing, unless the law prohibits such disclosure on important grounds of public interest.
(b) Confidentiality. The Processor SHALL ensure that persons authorised to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(c) Security. The Processor SHALL implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the UK GDPR. The Processor’s technical and organisational measures are described in Annex 2, which references the Processor’s Information Security Policy and the ISO27001 ISMS Statement of Applicability rather than reproducing those measures in full. The Processor SHALL not materially reduce the overall level of security maintained during the term of the Main Agreement.
(d) Sub-Processors. The Processor SHALL respect the conditions for engaging Sub-Processors set out in clause 6 of this Agreement.
(e) Data Subject rights. Taking into account the nature of the Processing, the Processor SHALL assist the Controller, by appropriate technical and organisational measures insofar as this is possible, to fulfil the Controller’s obligation to respond to requests for exercising Data Subjects’ rights under Chapter III of the UK GDPR (including rights of access, rectification, erasure, restriction, portability and objection).
(f) Controller’s compliance obligations. The Processor SHALL assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of the Processing and the information available to the Processor. This includes assisting with:
(g) Breach notification. The Processor SHALL notify the Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Personal Data Processed under this Agreement. Such notification SHALL include, to the extent then known:
Where it is not possible to provide all of the above information at the time of initial notification, the information may be provided in phases without undue further delay.
(h) Return or deletion. At the choice of the Controller, the Processor SHALL, following termination or expiry of the Main Agreement, delete or return to the Controller all Personal Data Processed under this Agreement, and shall delete existing copies of that Personal Data, unless storage of the Personal Data is required by applicable law. The Controller SHALL notify the Processor of its election to require return or deletion. The Processor SHALL confirm in writing when deletion has been completed.
(i) Audit and information. The Processor SHALL make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR, and SHALL allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Processor SHALL inform the Controller immediately if, in its opinion, an instruction infringes the Data Protection Laws. Audits shall be conducted with reasonable prior written notice, no more than once per calendar year except where there are reasonable grounds to suspect non-compliance, at the Controller’s cost, and subject to appropriate confidentiality obligations.
6.1 General authorisation. The Controller grants the Processor general written authorisation to engage Sub-Processors to Process Personal Data in connection with the Services. The Sub-Processors currently engaged by the Processor are set out in the Sub-Processor List, a separate document which is incorporated into and referenced by this Agreement and which the Processor updates from time to time in accordance with this clause 6.
6.2 Flow-down. The Processor SHALL impose on each Sub-Processor, by written contract, data protection obligations equivalent to those set out in this Agreement, and SHALL remain fully liable to the Controller for the performance of each Sub-Processor’s obligations under that contract.
6.3 Prior notice of changes. The Processor SHALL inform the Controller in advance, and in any event before the change takes effect, of any intended addition or replacement of a Sub-Processor, so as to give the Controller the opportunity to object to the change. Such notice may be given by updating the Sub-Processor List and notifying the Controller, or by such other written means as the parties agree.
6.4 Right to object and terminate. If the Controller objects to an intended addition or replacement of a Sub-Processor, the Controller MAY terminate this Agreement and the Main Agreement, without penalty for the act of termination, by giving written notice within thirty (30) days of the Processor’s communication of the change. If the Controller does not exercise this right within that thirty (30) day period, the change is deemed accepted and the new or replacement Sub-Processor may be engaged.
7.1 The Processor SHALL not transfer Personal Data outside the United Kingdom unless such transfer is made in compliance with an appropriate safeguard or transfer mechanism under the UK GDPR, including:
7.2 The Processor SHALL carry out international transfers of Personal Data only in accordance with the Controller’s instructions. The transfer mechanisms relied upon in respect of each Sub-Processor are set out in the Sub-Processor List. Transfer particulars are further documented in the Record of Processing Activity (GDPR Article 30) and the Transfer Risk Assessment. This Agreement does not restate those particulars.
7.3 Where a transfer mechanism relied upon by the Processor or a Sub-Processor ceases to be valid or is otherwise unavailable, the Processor SHALL notify the Controller without undue delay and take all reasonable steps to ensure that an alternative appropriate safeguard is put in place before any further transfer is made.
8.1 The Controller warrants and represents that:
8.2 The Controller is responsible for the accuracy, quality and legality of any Personal Data it provides to the Processor, and for the means by which it acquired that Personal Data.
9.1 Liability. The liability of each party under or in connection with this Agreement is governed by the provisions of the Main Agreement. Nothing in this Agreement shall be read as creating any liability cap or exclusion that does not exist under the Main Agreement. Where the Main Agreement does not address a particular head of liability arising under this Agreement, the parties’ liability shall be determined in accordance with the applicable law.
9.2 Term. This Agreement takes effect on the effective date of the Main Agreement and continues for the duration of the Processing carried out by the Processor in connection with the Services. Obligations that by their nature survive termination (including obligations regarding the return or deletion of Personal Data and the maintenance of confidentiality) shall continue to apply after termination or expiry of the Main Agreement.
9.3 Order of precedence. In the event of any conflict or inconsistency between this Agreement and the Main Agreement on matters concerning the protection, Processing or security of Personal Data, this Agreement shall prevail. For all other matters, the Main Agreement shall prevail.
9.4 Governing law and jurisdiction. The governing law and jurisdiction applicable to this Agreement are those specified in the Main Agreement.
9.5 Entire agreement. This Agreement, together with the Main Agreement and the documents referenced herein, constitutes the entire agreement between the parties in respect of the Processing of Personal Data carried out by the Processor on behalf of the Controller, and supersedes all prior agreements, representations and understandings on that subject matter.
9.6 Severability. If any provision of this Agreement is held to be invalid, unlawful or unenforceable, the remaining provisions shall continue in full force and effect.
9.7 Amendments. Any amendment to this Agreement must be agreed in writing by both parties, save that the Processor may update the Sub-Processor List in accordance with clause 6 without further formality.
The following table sets out the processing particulars for the purposes of Article 28(3) of the UK GDPR. Where a particular is not established in the available evidence, a placeholder is provided for the parties to complete.
| Field | Detail |
|---|---|
| Subject matter | The Processing of Personal Data by the Processor in the course of providing its compliance readiness tooling and associated services (the Services) to the Controller under the Main Agreement. |
| Duration | For the duration of the Main Agreement and any post-termination period during which the Processor retains Personal Data pending return or deletion in accordance with clause 5(h). |
| Nature and purpose of Processing | Automated and manual analysis of materials submitted by the Controller (including policy documents, codebase artefacts and cloud infrastructure evidence) for the purpose of generating compliance assessments, recommendations and audit-ready documentation. The Processor processes Personal Data only to the extent that it is included in materials submitted by the Controller or its authorised users. |
| Categories of Personal Data | The categories of Personal Data Processed are determined by the Controller and may include: names and contact details of the Controller’s staff and authorised users; personal data included in policy documents, risk registers or other compliance materials submitted by the Controller; personal data of the Controller’s own data subjects to the extent included in submitted materials. The Controller is responsible for ensuring that only Personal Data necessary for the Services is submitted. Full processing particulars are maintained in the Record of Processing Activity (GDPR Article 30). |
| Categories of Data Subjects | The Controller’s staff and authorised users; data subjects whose Personal Data is included in materials submitted by the Controller to the Services. |
The authoritative and current processing particulars are maintained in the Record of Processing Activity (GDPR Article 30). In the event of any inconsistency between this Annex and that document, the Record of Processing Activity (GDPR Article 30) shall prevail.
The Processor’s technical and organisational measures implemented pursuant to Article 32 of the UK GDPR are not reproduced in full in this Agreement. They are documented in the following reference documents, which are incorporated by reference:
The measures documented in those reference documents include, without limitation, controls addressing: encryption of Personal Data in transit; access controls and authentication; personnel confidentiality obligations; change management and secure development practices; incident response and breach notification procedures; and sub-processor security obligations.
The Processor shall not materially reduce the level of security documented in the above reference documents during the term of the Main Agreement without prior written notice to the Controller.
The current list of Sub-Processors authorised by the Controller under clause 6.1 of this Agreement is maintained in the Processor’s separate Sub-Processor List document. That document is incorporated into and referenced by this Agreement. The Sub-Processor List is not reproduced here; the Controller may obtain the current version at any time by requesting it from the Processor.
The Processor shall update the Sub-Processor List and notify the Controller of any intended addition or replacement of a Sub-Processor in accordance with clause 6.3 of this Agreement.