Data Processing
Data Processing Agreement
The additional terms on which TDS Ultra processes personal data on behalf of the Customer, containing the mandatory clauses required by Article 28(3) of the UK GDPR.
Agreed terms
This Data Processing Agreement is made between:
Parties
(1) TDS ULTRA LIMITED, incorporated and registered in England and Wales with company number 10219630, whose registered office is at Europa House, Southwick Square, Southwick, Brighton, West Sussex, England, BN42 4FJ (“TDS Ultra”); and
(2) The Customer as defined in the TDS Ultra Proposal (“the Customer”).
Background
Agreed terms
1. Definitions and interpretation
Authorised Persons: the persons or categories of persons, including sub-contractors, that the Customer authorises to give TDS Ultra Personnel data processing instructions.
Business Purposes: the services described in this Data Processing Agreement or relevant Main Agreement or any other purpose specifically agreed in writing between the parties.
Commissioner: the UK Information Commissioner.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing: have the meanings given to them in the Data Protection Legislation.
Data Protection Legislation: the law of the United Kingdom or of a part of the United Kingdom which relates to the protection of Personal Data, including the DPA 2018 (and UK GDPR) as amended from time to time.
Data Subject: the identified or identifiable living individual to whom the Personal Data relates.
DPA 2018: Data Protection Act 2018.
Main Agreement: a commercial agreement entered into by the parties to which this Data Processing Agreement attaches.
Personal Data: means any information relating to an identified or identifiable living individual that is processed by TDS Ultra on behalf of the Customer as a result of, or in connection with, the provision of the services under the Master Agreement; an identifiable living individual is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the individual.
Personal Data Breach: a breach of security leading to the accidental, unauthorised or unlawful destruction, loss, alteration, disclosure of, or access to, the Personal Data.
Processing, processes, processed, process: any activity that involves the use of the Personal Data. It includes, but is not limited to, any operation or set of operations which is performed on the Personal Data or on sets of the Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Processing also includes transferring the Personal Data to third-parties.
Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.
Records: has the meaning given to it in Clause 12.
Term: this Agreement’s term as defined in Clause 10.
2. Personal data types and processing purposes
3. Provider’s obligations
4. Provider’s employees
5. Security
6. Personal data breach
7. Cross-border transfers of personal data
8. Subcontractors
9. Complaints, data subject requests and third-party rights
10. Term and termination
11. Data return and destruction
12. Records
13. Audit
14. Warranties
15. Liability
This Data Processing Agreement is agreed and entered into by TDS Ultra and the Customer on the date of the Main Agreement.