1. Scope and roles
This addendum forms part of our Terms of Service and applies whenever we process personal data on your behalf while providing the services. You are the controller and we are your processor. Your Order Form records the systems, kinds of personal data and people involved.
2. Instructions
We process personal data only on your documented instructions: your Order Form, these terms, and the tasks you give us in writing, including tickets and messages. We tell you if we believe an instruction breaks data protection law.
3. Data minimisation
We develop and test with anonymised or dummy data by default. We access production data only when a task requires it and use only what that task needs. We never copy it to personal devices and never enter it into AI-assisted tools.
4. Confidentiality
Everyone who may access your personal data is bound by a written confidentiality agreement.
5. Security
- Multi-factor authentication and a password manager for every account.
- Encrypted, up-to-date work devices.
- Least-privilege access through accounts you control, removed when the engagement ends.
6. Specialists and other sub-processors
You give general written authorisation for us to involve vetted specialists and service providers as sub-processors. Each is bound by written terms that protect your data at least as well as this addendum, and we remain responsible for them. On request, we tell you who can access your personal data. We notify you before adding a sub-processor with such access, and you may object on reasonable grounds within 14 days of our notice. If we cannot resolve the objection, you may cancel the affected services.
7. Personal data breaches
We notify you without undue delay, and within 48 hours, after becoming aware of a breach affecting your personal data, with the information you need to meet your own obligations.
8. Assistance
We help you respond to people exercising their data protection rights, and with your security, breach notification and impact assessment obligations. Where this takes significant time, it is billed from your plan hours.
9. Deletion and return
When the services end, we return or delete your personal data, as you choose, and delete remaining copies unless the law requires us to keep them.
10. Audits
We make available the information needed to show we comply with this addendum, and allow reasonable audits with reasonable notice, at your cost.
11. International transfers
We are based in the Philippines. For personal data subject to the EU GDPR, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference: Module 2 between you and us, and Module 3 for onward transfers to our sub-processors. For Clause 9, option 2 (general written authorisation) applies, and we inform you of intended changes at least 14 days in advance. For Clauses 17 and 18, the law and courts are those of the EU Member State where you are established. Your Order Form and this addendum provide the information for the annexes.
For personal information covered by the Australian Privacy Act 1988, we handle it consistently with the Australian Privacy Principles, so that you can meet your obligations under APP 8.
Under Section 4 of the Philippine Data Privacy Act of 2012, personal information collected from residents of other countries under their own laws and processed in the Philippines remains governed by those laws. We nonetheless apply security measures that meet the Data Privacy Act of 2012 and the rules of the National Privacy Commission.
12. Precedence
For personal data, this addendum prevails over the Terms of Service. The Standard Contractual Clauses prevail over this addendum.
Contact
Data protection questions: [email protected].
