Legal
Effective Date: 29/03/2022
Version 2024.1
DATA PROCESSING AGREEMENT
Between
This Data Processing Agreement (“Agreement”) is entered into by and between THIRTY-ONE CIRCLES LTD incorporated and registered in England and Wales with company number 13999453 whose registered office is at The Gallery, 14 Upland Road, London, England, SE22 9EE (“Thirty-One Circles” or “Supplier” or the “Data Processor”) and the entity or person placing an Order for or accessing the Services (“Company” or the “Data Controller”)
(hereinafter collectively referred to as the “Parties”).
WHEREAS
Now therefore (and the preambles form an integral and substantial part of this Data Processing Agreement), the Parties agree to and stipulate the following:
1.1 The Parties expressly acknowledge and accept that, with reference to the processing of Personal Data, the Company performs the role of Data Controller. As such, it is solely responsible for the correctness and legitimacy of the Personal Data, for its use under the Agreement and the legitimacy of the methods with which such data was acquired.
1.2 The Company appoints the Supplier, pursuant to Article 28 of the UK GDPR, as Data Processor for the Personal Data processing connected to the provision of the Services.
The purpose of the Personal Data processing by the Supplier is the provision of the Services under the Agreement. The nature of the data processing, the type of Personal Data processed and the categories of Data Subjects are better described in Annex 1: Scope of the data processing.
3.1 The Personal Data shall be processed by the Data Processor in accordance with applicable rules on the processing of personal data, with this Data Processing Agreement, with any reasonable instructions received in writing by the Company, provided that these instructions are consistent with the terms of this Data Processing Agreement, and only and exclusively insofar as this is strictly necessary for the provision of the Services covered by the Agreement, expressly excluding any other and different use.
3.2 The only possible exception from the prohibition referred to in the preceding paragraph 3.1 is the existence of a legal obligation, or the reasoned request by an Administrative or judicial authority, including the Information Commissioner’s Office (“ICO”) or applicable Supervisory Authorities (hereinafter: “Authority”), in which case the Data Processor, within the limits permitted by law or by the Authority’s provisions, shall inform the Company of its need to process the Personal Data differently or outside the limits of the provisions set out in this Data Processing Agreement.
3.3 It is expressly understood that the Personal Data under the ownership of the Company:
3.4 The Data Processor undertakes to create, update and transmit to the Company, upon written request from the latter, the register of data processing activities carried out by the Data Processor on behalf of the Company, including all the information required by law.
4.1 The Data Processor shall adopt and maintain suitable technical and organisational measures to protect the security, confidentiality and integrity of the Personal Data, taking into account, inter alia, of the type of data processing, the purposes, the context and the specific circumstances in which the data processing takes place, as well as the applicable technology and implementation costs.
4.2 The Data Processor undertakes to adopt the necessary physical, organisational and logical measures referred to in Annex 2: Security measures. These measures may be changed only on condition that a security level which is at least equivalent to that existing at the time this Data Processing Agreement is signed, is maintained.
4.3 Any developments and/or changes of security measures, to be applied during the Agreement to address the changing needs of the Company and/or due to changes and updates to applicable legislation on the protection of personal data, including changes and updates needed for the purpose of adapting to the provisions of the UK GDPR, shall be adopted and implemented by the Supplier and/or its subcontractors, at the Company’s responsibility and expense and upon express request and indication by the latter, as well as on the basis of an impact assessment which shall be its responsibility to carry out as Data Controller, if necessary with the collaboration of the Supplier.
5.1 Without prejudice to the provisions of Section 11 below, the Data Processor guarantees that access to the Personal Data shall be limited to its own employees and collaborators, whose access to the Personal Data is necessary for the execution of the relevant Services and on condition that the individuals involved are appropriately instructed with regard to the processing of Personal Data and to the technical and organisational security measures required to protect the Personal Data.
5.2 The Data Processor shall also be required to attend to their training, monitor their actions and, on specific request, provide the Company with an updated list of said employees and collaborators.
The Data Processor undertakes to inform the Data Controller, without undue delay, of any suspected or actual security breach or data breach, which may involve the accidental or illicit destruction, loss, modification, unauthorised disclosure or access to Personal Data transmitted, stored or otherwise processed, as well as to provide all necessary support to the Data Controller concerning the fulfilment of its obligation to notify the aforementioned breaches to the Authority, pursuant to Article 33 of the UK GDPR or to communicate them to the data subjects, pursuant to Article 34 of the UK GDPR.
The Data Processor undertakes to provide the Data Controller with each and every element useful to the latter for the purpose of carrying out the impact assessment on data protection, where it is required to carry out such an assessment pursuant to Article 35 of the UK GDPR, as well as all necessary collaboration in carrying out any prior consultation with the ICO pursuant to Article 36 of the UK GDPR.
The Data Processor, at the Data Controller’s request, undertakes to assist the latter in the event of defence proceedings before the ICO or the Judicial Authority, including by allowing the prompt presentation of privacy forms and supporting documents which fall within the competence of the Data Processor.
9.1 To the extent permitted by law, the Data Processor shall inform the Company of any request received from a data subject to exercise his/her rights of access, modification, limitation of data processing, deletion, portability of data, opposition to the processing of data or the right not to be subject to decision-making processes based solely on automated processing, attaching a copy of the request to the communication.
9.2 In view of the nature of the data processing, the Data Processor shall assist the Company by way of appropriate technical and organisational measures, to the extent possible, in the fulfilment of the Company’s obligation to respond to requests from data subjects, in compliance with applicable standards.
9.3 It is expressly understood that the Data Processor shall not follow up on requests received pursuant to the preceding paragraph 9.1, without the prior written consent of the Company.
10.1 The Data Processor shall provide the Data Controller with all the information needed to demonstrate compliance with the obligations laid down in the applicable legislation and/or the Data Controller’s instructions referred to in this Data Processing Agreement; moreover, it shall allow the Data Controller to exercise the appropriate control and inspection powers, providing all reasonable collaboration in the audit activities carried out by the Data Controller or by another body appointed or authorised by it, which shall not be a competing company of the Data Processor, with the aim of verifying the fulfilment of the obligations and instructions referred to in this Data Processing Agreement. It is understood that any audit conducted pursuant to this paragraph 10.1 shall be carried out in such a way as not to interfere with the Data Processor’s normal course of business and by providing at least 20 working days prior notice.
10.2 The Data Processor undertakes to:
11.1 The Supplier may use additional Data Processors to process the Personal Data owned by the Company (hereinafter: “Sub-Data Processors”), only if the Company has given its prior written consent. It is hereby noted that the subcontracting of the service or part thereof is authorised in relation to the companies of the Data Processor’s Group.
11.2 The Data Processor undertakes to impose in writing to its Sub-Data Processors, by way of appropriate binding agreements, the same obligations regarding the protection of Personal Data with which the Data Processor is required to comply by virtue of this Data Processing Agreement, in particular with regard to security requirements.
11.3 The Data Processor expressly undertakes to inform the Company of any changes concerning the addition or replacement of the Sub-Data Processors; moreover, the Company shall have the right to oppose these changes, communicating its objection in writing within 15 (fifteen) calendar days from the Data Processor’s notification. The Data Processor shall not resort to the Sub-Data Processors to which the Company has objected. In the absence of any objections by the Company, the changes shall be deemed to have been accepted.
11.4 It is expressly understood that the Data Processor shall remain directly accountable to the Company with regard to the actions and omissions of its Sub-Data Processors.
The Data Processor shall be liable for all damages resulting from breaches of or non-compliance with the instructions referred to in this Data Processing Agreement, any subsequent ones transmitted in writing by the Company, as well as with the provisions of the UK GDPR specifically directed to the Data Processor, within the limits of 100% of the value of the Services Agreement. It is understood that under no circumstances shall the Data Processor, and more generally any company belonging to the Data Processor’s Group, as well as its agents, employees and/or authorised representatives, be liable to the Company for: (i) any indirect, incidental, special, punitive and/or consequential damage of any kind; (ii) any lost profits (whether direct or indirect); (iii) any loss of income (direct or indirect); or (iv) any damage to the latter’s reputation, in connection with or arising out of this Agreement.
Upon the expiry of the Agreement and/or termination of the Services or, in any case, in the event of termination, for any reason, of the effectiveness of this Data Processing Agreement, except where a legal obligation or national and/or Community regulation exists that foresees the retention of the Personal Data, the Data Processor shall interrupt all data processing operations relating to the Personal Data in question and provide, at the Data Controller’s discretion, for the immediate return of Personal Data to the same or for its full deletion, in both cases, providing a written statement that no copy thereof is held by the Data Processor. In the event of a written request by the Data Controller, the Data Processor shall specify the technical mechanisms and procedures used for the deletion/destruction of the data.
This Data Processing Agreement shall be effective from the date on which it is signed by the Parties and shall be valid until the termination of the Agreement for any reason and/or, in any case, of the Services, or until the premature termination for any reason by the Data Controller, it being understood that, even after termination of the Agreement or Services or revocation thereof, the Data Processor shall maintain the maximum confidentiality of the data and information relating to the Data Controller of which it has become aware while fulfilling its obligations.
The Data Processor shall appoint a Data Protection Officer, pursuant to Article 37 of the UK GDPR and undertakes to inform the Company of such appointment.
This Agreement shall be governed by the laws of England and Wales and shall be subject to the exclusive jurisdiction of the English courts.
ANNEX 1
SCOPE OF THE DATA PROCESSING
This Annex is an integral part of the Contract for the appointment of the Data Processor.
Data Processing Details
Processing of the Protected Data by the Supplier under this DPA shall be the subject matter, duration nature and purposes involve the type of Personal Data and categories of Data subjects as set out in Schedule 1
Subject matter of Processing
Processing the current Data Controller’s analytics data, CRM data and website users (and where applicable app users).
Including:
Nature and purpose of the Processing :
The Supplier will analyze the provided data to provide audience insights and audience segments for advertising targeting. During this process it will help manage compliance based on the data subject’s consent recorded.
Categories of Data Subjects
Customers user of Website and App
Sub-Processors
| Sub-Processor | Purpose | Types of Personal Data | Location |
| Amazon Web Services | Analysis to create audience segments and load these to the Customer’s Onwards Platforms | Online identifiers, Behavioral Data, Matching Data | UK (London) |
| Google Cloud Platform | Analysis to create audience segments and load these to the Customer’s Onwards Platforms | Online identifiers, Behavioral Data, Matching Data | UK (London) |
ANNEX 2
SECURITY MEASURES
Based on the activities supplied, as applicable to the purpose of the Agreement, the Data Processor and any authorised Sub-Data Processors, shall respect the following security measures.
[1] The need to know principle requires that data access rights are assigned consistently and not exceeding the specific corporate role; an individual must not view any data not deemed useful to the correct and efficient performance of their job.
[2] The least privilege principle requires that access privileges which do not exceed the specific company role are assigned (e.g. if for a given task specific data must only be consulted or viewed, no access rights should be granted to allow the modification of such data).
[3] The separation of duties (SOD) principle requires that the authorisation and the conduct of an action are not the responsibility of the same person.