This Data Processing Addendum (“DPA”) applies where iSolicitude LTD, trading as “iSolicitude”, processes personal data on a client’s behalf — for example, personal data contained in project files, client-supplied databases or support content. It forms part of the agreement between the client and iSolicitude and, to the extent of any conflict on the subject of data processing, takes precedence over our general Terms & Conditions.
1. Roles and scope
The client is the controller and iSolicitude is the processor. The subject-matter, duration, nature and purposes of the processing, and the categories of personal data and of data subjects, are described in the applicable proposal or statement of work.
2. Processor obligations
- Process personal data only on the client’s documented instructions, including as to international transfers, unless required to do otherwise by law (in which case we inform the client where legally permitted).
- Ensure that personnel authorised to process the personal data are bound by confidentiality.
- Apply the technical and organisational measures described in our Security Overview.
- Notify the client without undue delay after becoming aware of a personal-data breach affecting the client’s data.
- Assist the client, at reasonable cost, with data-subject requests and with data-protection impact assessments and prior consultations.
- At the client’s choice, delete or return the client’s personal data at the end of the engagement, subject to any legal retention obligation.
- Make available to the client the information reasonably necessary to demonstrate compliance with this DPA and allow for audits on reasonable notice.
3. Subprocessors
The client provides a general authorisation for iSolicitude to engage the subprocessors listed at /legal/subprocessors. We impose data-protection obligations on our subprocessors that are substantially equivalent to those in this DPA, give the client advance notice of any intended change, and allow the client to object on reasonable data-protection grounds.
4. International transfers
Where personal data is transferred to a country outside the client’s jurisdiction, we rely on the data-transfer terms offered by our subprocessors and apply appropriate safeguards consistent with applicable data-protection law.
5. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement between the parties.