Legal
Data Processing Agreement
Client engagements where Thynkr acts as processor.
1. Scope
This Data Processing Agreement (“DPA”) forms part of the agreement between THYNKR SYSTEMS LTD, a company registered in England and Wales under company number 15306717 with its registered office at Office 2, 1st Floor, 73 Station Passage, London E18 1JL and contact email info@thynkrsystems.com (“Processor”, “THYNKR”) and the client (“Controller”, “Client”) under the Client Services Terms and any Statement of Work (“SOW”) where THYNKR processes Personal Data on the Client’s behalf.
This DPA applies to processing subject to the UK GDPR, the Data Protection Act 2018 and, where applicable, other data-protection legislation including the EU GDPR (“Data Protection Law”).
It does not apply to THYNKR’s products, which have their own data processing terms.
Capitalised terms not defined here have the meanings given in the Client Services Terms or applicable Data Protection Law.
2. Roles
The Client is the Controller of Client Personal Data where it determines the purposes and means of processing.
THYNKR is the Processor when it processes that data solely on the Client’s documented instructions to provide the Services.
THYNKR may separately act as Controller for limited processing undertaken for its own legitimate purposes, such as engagement administration, invoicing, security, legal compliance and establishment or defence of claims. Such controller processing is governed by THYNKR’s Privacy Policy.
3. Details of processing
Subject matter
Provision of software development, consultancy and technical stewardship services under a SOW, including building, testing, migrating, hosting, operating, maintaining and supporting systems that contain Client Personal Data.
Duration
For the duration of the applicable SOW and any lawful retention or transition period thereafter.
Nature and purpose
Access, collection, storage, organisation, retrieval, transmission, hosting, migration, testing, analysis, support, deletion and other processing necessary to perform the Services described in the SOW.
Categories of data subjects and types of Personal Data
As described in the SOW or its data-processing annex for each engagement. [TO CONFIRM: a standard annex template listing data subjects, data types and any special-category data per engagement].
Special-category data
THYNKR will process special-category data only where the SOW identifies it and the Controller has a lawful basis and appropriate safeguards.
4. Controller instructions
THYNKR will process Client Personal Data only:
- on documented instructions from the Client, including instructions embodied in the Client Services Terms and the SOW; or
- where processing is required by applicable law.
If law requires processing outside the Client’s instructions, THYNKR will inform the Client before processing unless the law prohibits that notice.
THYNKR will promptly inform the Client if, in THYNKR’s reasonable opinion, an instruction infringes Data Protection Law. THYNKR may suspend the affected processing until the parties resolve the issue.
5. Confidentiality
THYNKR will ensure that personnel authorised to process Client Personal Data are subject to an appropriate duty of confidentiality.
6. Security
Taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing, and the risk to individuals, THYNKR will maintain appropriate technical and organisational measures under Article 32 or equivalent applicable requirements. Measures may include, as appropriate:
- encryption in transit;
- encryption at rest where appropriate;
- access control and least privilege;
- authentication controls;
- separation of client environments and data;
- secure development practices;
- logging and monitoring;
- backup and restoration procedures;
- vulnerability and patch management;
- incident-response procedures;
- personnel confidentiality obligations; and
- periodic review of security effectiveness.
Where THYNKR works inside systems or environments controlled by the Client, the Client is responsible for the security controls of those systems.
Security measures may evolve as technology and threats change, provided THYNKR does not materially reduce the overall protection of Client Personal Data.
7. Subprocessors
The Client grants THYNKR general written authorisation to engage subprocessors necessary to provide the Services. THYNKR will:
- maintain information about material subprocessors [TO CONFIRM: the current subprocessor list for client engagements, or confirm it will be stated per SOW];
- impose written data-protection obligations providing a level of protection appropriate to the processing and consistent with applicable Article 28 requirements;
- remain responsible to the Client for performance of the subprocessor’s applicable data-protection obligations to the extent required by law; and
- give notice of a new material subprocessor by email or another reasonable mechanism.
The Client may object to a new subprocessor on reasonable data-protection grounds by notifying THYNKR within 14 days of receiving notice. The parties will work in good faith to address a valid objection. If no commercially reasonable solution is available, either party may terminate the materially affected Services without penalty for the unused prepaid period relating to those Services.
8. Data subject requests
Taking into account the nature of the processing, THYNKR will provide reasonable assistance to enable the Client to respond to requests from Data Subjects exercising rights under Data Protection Law.
If THYNKR receives a request relating to Client Personal Data, THYNKR may direct the Data Subject to the Client unless law requires THYNKR to respond directly. THYNKR will not independently fulfil a Controller’s Data Subject request except on documented instruction or where legally required.
9. Assistance with compliance
Taking into account the nature of processing and information available to THYNKR, THYNKR will provide reasonable assistance with:
- security obligations;
- Personal Data breach assessment and notification;
- data-protection impact assessments;
- prior consultation with regulators where required; and
- other obligations under Articles 32–36 or equivalent provisions.
Where assistance goes materially beyond the Services described in the SOW, THYNKR may charge reasonable professional-services fees where legally permitted and agreed in advance.
10. Personal Data breaches
THYNKR will notify the Client without undue delay after becoming aware of a confirmed Personal Data Breach affecting Client Personal Data. The notification will provide information reasonably available to THYNKR, which may include:
- the nature of the incident;
- affected data or individuals where known;
- likely consequences where known;
- measures taken or proposed; and
- a contact point for further information.
Information may be provided in phases as investigation continues. Notification of an incident is not an admission of fault or liability.
The Client remains responsible for determining whether it must notify a regulator or affected Data Subjects unless applicable law provides otherwise.
11. Deletion and return
On completion or termination of the affected Services, THYNKR will, at the Client’s choice, return or delete Client Personal Data within a reasonable period, unless:
- applicable law requires retention;
- the data is contained in secure backups that cannot reasonably be isolated immediately; or
- retention is required for establishment, exercise or defence of legal claims.
Data retained in backup systems will remain protected and will be deleted or overwritten according to ordinary secure backup-retention cycles.
12. Audits and information rights
THYNKR will make available information reasonably necessary to demonstrate compliance with applicable Article 28 obligations. Where appropriate, THYNKR may satisfy audit requests by providing security documentation, questionnaires or other evidence. If additional audit is reasonably required:
- the Client must provide at least 30 days’ written notice unless a regulator or confirmed material incident reasonably requires shorter notice;
- audits must occur during normal business hours and must not unreasonably disrupt operations;
- the auditor must be independent and bound by confidentiality;
- the audit must avoid access to other clients’ data or THYNKR trade secrets beyond what is reasonably required;
- no more than one Client-requested audit may take place in a twelve-month period unless required by law or following a material breach; and
- the Client bears its audit costs and THYNKR’s reasonable costs of supporting non-routine audits, except where the audit identifies a material breach by THYNKR.
Nothing in this clause limits a regulator’s lawful powers.
13. International transfers
THYNKR will not make a restricted transfer of Client Personal Data unless an applicable lawful transfer mechanism is in place. Where required, the parties will incorporate or execute an appropriate mechanism, which may include:
- the UK International Data Transfer Agreement;
- the UK Addendum to EU Standard Contractual Clauses;
- applicable Standard Contractual Clauses;
- adequacy arrangements; or
- another legally recognised safeguard.
The parties will cooperate with any required transfer-risk or supplementary-measures assessment. If a transfer mechanism is amended, replaced or invalidated, the parties will cooperate in good faith to implement a lawful replacement.
14. Government requests
Unless prohibited by law, THYNKR will seek to direct a governmental request for Client Personal Data to the Client where appropriate. Where THYNKR must respond directly, it will disclose only information legally required and may challenge an overbroad or unlawful demand where reasonable and lawful.
15. Controller obligations
The Client warrants that:
- it has a lawful basis for processing Client Personal Data;
- it provides required privacy information;
- it has obtained required consents where consent is relied upon;
- its instructions comply with Data Protection Law;
- it will tell THYNKR before providing special-category data or data not described in the SOW; and
- it will respond to Data Subject requests and regulator communications for which it is Controller.
16. Liability
Liability under this DPA is subject to the liability provisions of the Client Services Terms, except to the extent Data Protection Law prohibits contractual limitation. Nothing in this DPA relieves either party of direct statutory obligations imposed on it by Data Protection Law.
17. Priority
If this DPA conflicts with the Client Services Terms or a SOW concerning processing of Client Personal Data, this DPA takes priority for that subject matter. Where mandatory transfer clauses apply, those clauses take priority to the extent required by law.
18. Changes in Data Protection Law
The parties will cooperate in good faith to amend this DPA where reasonably necessary to comply with a material change in Data Protection Law or binding regulatory requirements.