Applicable where Agnostec processes personal data on behalf of customers.
Roles
- Customer = Controller
- Agnostec = Processor
Processing Purpose
Agnostec shall process personal data solely to deliver contracted services.
Confidentiality
Agnostec will ensure personnel authorised to process personal data are bound by confidentiality obligations.
Security
Agnostec shall implement appropriate technical and organisational safeguards to protect personal data.
Third-Party Service Provider
Agnostec may engage approved third-party service provider where necessary to deliver services.
Data Subject Rights
Agnostec will assist customers in responding to data subject requests where appropriate.
Incident Notification
Agnostec will notify customers without undue delay upon becoming aware of a personal data breach affecting customer information.
Return and Deletion
Upon termination of services, customer data shall be returned or securely deleted, subject to legal and regulatory obligations.
Audit Rights
Customers may request reasonable evidence of security controls and compliance measures.