Agency Data Processing Addendum

This Data Processing Addendum (Addendum) forms part of the Terms of Service, or other written agreement entered into between OIIKII Limited (OIIKII, we or us) and you (a User who is an Agency as defined in our Terms of Service) that incorporates this DPA by reference (Our Terms of Service, Cookies Policy, Privacy Policy and this Data Processing Agreement are collectively referred to as “the “Agreement”), and governs the Processing of Personal Information by you in providing or receiving services from the Service Provider (the “Service”) pursuant to the Agreement. This DPA is effective upon its incorporation into the Agreement. Upon its incorporation into the Agreement, the DPA will form a part of the Agreement. By using our services, you hereby agree to the provision of this Addendum, at signup, you would have agreed to the terms of this Addendum. If you need a copy of this Addendum signed, please sign the below Addendum and kindly send a signature request to info@oiikii.com .
Part A
Operative provisions
1. Definitions

1.1. In this Addendum:

Applicable lawmeans applicable law of the United Kingdom (or of a part of the United Kingdom);
Controllerhas the meaning given in applicable Data Protection Laws from time to time;
Data Protection Laws

means, as binding on either party or the Services:(a) the GDPR;

 

(b) the Data Protection Act 2018;

 

(c) any laws which implement or supplement any such laws; and

 

(d) any laws that replace, extend, re-enact, consolidate or amend any of the foregoing;

Data Subjecthas the meaning given in applicable Data Protection Laws from time to time;
GDPRmeans the General Data Protection Regulation, Regulation (EU) 2016/679, as it forms part of domestic law in the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018 (including as further amended or modified by the laws of the United Kingdom or of a part of the United Kingdom from time to time);
International Organisationhas the meaning given in applicable Data Protection Laws from time to time;
Personal Datahas the meaning given in applicable Data Protection Laws from time to time;
Personal Data Breachhas the meaning given in applicable Data Protection Laws from time to time;
Processinghas the meaning given in applicable Data Protection Laws from time to time (and related expressions, including process, processed and processes shall be construed accordingly);
Processorhas the meaning given in applicable Data Protection Laws from time to time;
Protected Datameans Personal Data received from or on behalf of the Agency in connection with the performance of OIIKII’s obligations under this Agreement; and
Sub-Processormeans any Processor engaged by OIIKII (or by any other Sub-Processor) for carrying out any processing activities in respect of the Protected Data on behalf of the Agency.
2. Agency’s compliance with Data Protection Laws

The parties agree that the Agency is a Controller and that OIIKII is a Processor for the purposes of processing Protected Data pursuant to this Agreement. The Agency shall, at all times, comply with all Data Protection Laws in connection with the processing of Protected Data. The Agency shall ensure all instructions given by it to OIIKII in respect of Protected Data (including the terms of this Agreement) shall at all times be in accordance with all Data Protection Laws. Nothing in this Agreement relieves the Agency of any responsibilities or liabilities under any Data Protection Laws.

3. OIIKII’s compliance with Data Protection Laws

OIIKII shall process Protected Data in compliance with the obligations placed on it under Data Protection Laws and the terms of this Agreement.

4. Indemnity

The Agency shall indemnify and keep indemnified OIIKII against all losses, claims, damages, liabilities, fines, sanctions, interest, penalties, costs, charges, expenses, compensation paid to Data Subjects, demands and legal and other professional costs (calculated on a full indemnity basis and in each case whether or not arising from any investigation by, or imposed by, a supervisory authority) arising out of or in connection with any breach by the Agency of its obligations under this Addendum.

5. Instructions

5.1. OIIKII shall only process (and shall ensure OIIKII Personnel only process) the Protected Data in accordance with Part B of this Addendum and this Agreement (including with regard to any transfer to which clause 11 of this Part A relates), except to the extent:

  5.1.1. that alternative processing instructions are agreed between the parties in writing; or

 5.1.2. otherwise required by applicable law (and shall inform the Agency of that legal requirement before processing, unless applicable law prevents it doing so on important grounds of public interest).

5.2. If OIIKII believes that any instruction received by it from the Agency is likely to infringe the Data Protection Laws it shall promptly inform the Agency and be entitled to cease to provide the relevant Services until the parties have agreed appropriate amended instructions which are not infringing. The Fees payable to OIIKII shall not be discounted or set-off as a result of any delay or non-performance of any obligation in accordance with this clause 5.2.

6. Security

6.1. OIIKII shall implement and maintain the technical and organisational measures set out in Part B of this Addendum to protect the Protected Data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access.

6.2. During the period in which OIIKII processes any Protected Data, the Agency shall undertake a documented assessment at least every 12 months of whether the security measures implemented in accordance with clause 6.1 of this Part A are sufficient (taking into account the state of technical development and the nature of processing) to protect the Protected Data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access. The Agency shall notify OIIKII within 10 days of full details of the assessment and its outcome and of any additional measures the Agency believes are required as a result of the assessment. OIIKII shall not be obliged to implement any further or alternative security measures except as agreed as a binding variation of this Agreement.

7. Sub-processing and personnel

7.1. OIIKII shall:

  7.1.1. not permit any processing of Protected Data by any Sub-Processor without the prior specific written authorisation of the Agency;

  7.1.2. prior to any Sub-Processor carrying out any processing activities in respect of the Protected Data, ensure such Sub-Processor is appointed under a binding written contract containing materially the same obligations as under this Addendum (including those relating to sufficient guarantees to implement appropriate technical and organisational measures) and ensure such Sub-Processor complies with all such obligations;

  7.1.3. remain fully liable to the Agency under this Agreement for all the acts and omissions of each Sub-Processor as if they were its own; and

  7.1.4. ensure that all natural persons authorised by OIIKII or any Sub-Processor to process Protected Data are subject to a binding written contractual obligation to keep the Protected Data confidential.

8. List of authorised Sub-Processors

The Agency hereby grants general authority to authorise OIIKII to engage its Affiliates and any third-parties approved by OIIKII to act as Sub-Processors to OIIKII under this Agreement (the “Sub-Processors”), including as to new or replacement Sub-Processors. Notwithstanding this general authorisation, OIIKII will notify Client of any intended changes to its Sub-Processors and give the Agency a reasonable opportunity, which shall not exceed ten (10) days, to object on commercially reasonable grounds to any such changes. OIIKII agrees that it will enter into a written contract with each such Sub-Processor that includes terms equivalent to those set out in this Agreement, and remains fully liable to the Agency for the performance of each such Sub-Processor’s obligations thereunder.

9. Assistance

9.1. OIIKII shall (at the Agency’s cost and expense) assist the Agency in ensuring compliance with the Agency’s obligations pursuant to Articles 32 to 36 of the GDPR taking into account the nature of the processing and the information available to OIIKII.

9.2. OIIKII shall (at the Agency’s cost and expense) and taking into account the nature of the processing, assist the Agency (by appropriate technical and organisational measures), insofar as this is possible, for the fulfilment of the Agency’s obligations to respond to requests for exercising the Data Subjects’ rights under Chapter III of the GDPR in respect of any Protected Data.

9.3. OIIKII shall promptly refer to the Agency all requests it receives for exercising any Data Subjects’ rights under Chapter III of the GDPR which relate to any Protected Data. It shall be the Agency’s responsibility to reply to all such requests as required by applicable law.

10. International transfers

To the extent that Applicable Data Protection Law applies to the processing of User Personal Data, OIIKII agrees that it will not transfer Protected Data out of the EEA, or the United Kingdom, to a country that has not been identified by the ICO, European Commission or a Supervisory Authority under Data Protection Law as a country that provides an adequate level of data protection except where OIIKII has ensured appropriate safeguards are in place, such as the Standard Contractual Clauses or International Data Transfer Agreement approved by the European Commission unless otherwise required by applicable law.

11. Audits and processing

OIIKII shall, in accordance with Data Protection Laws, make available to the Agency on request such information that is in its possession or control as is necessary to demonstrate OIIKII’s compliance with the obligations placed on it under this Addendum and to demonstrate compliance with the obligations on each party imposed by Article 28 of the GDPR, and allow for and contribute to audits, including inspections, by the Agency (or another auditor mandated by the Agency) for this purpose (subject to a maximum of one audit request in any 12 month period under this clause 12).

12. Breach

OIIKII shall notify the Agency without undue delay and in writing on becoming aware of any Personal Data Breach in respect of any Protected Data.

13. Deletion/return

13.1. On the end of the provision of the Services relating to the processing of Protected Data (the Processing End Date), at the Agency’s cost and expense and the Agency’s option, OIIKII shall either return all of the Protected Data to the Agency or securely dispose of the Protected Data (and thereafter promptly delete all existing copies of it) except to the extent that any applicable law requires OIIKII to store such Protected Data. To the extent the Agency has not notified OIIKII within 14 of the Processing End Date that it requires the return of any Protected Data OIIKII is irrevocably authorised to securely dispose of the Protected Data at the Agency’s cost and expense.

14. Survival

14.1. This Addendum shall survive termination or expiry of this Agreement:

14.1.1. indefinitely in the case of clauses 4 and 14 of this Part A; and

14.1.2. in the case of all other clauses and provisions of this Addendum, until the later of:

    1. the termination or expiry of this Agreement; or
    2. return or secure deletion or disposal of the last of the Protected Data in OIIKII’s (or any of its Sub-Processor’s) possession or control in accordance with this Agreement.
Part B
Data processing and security details
Section 1—Data processing details
Processing of the Protected Data by OIIKII under this Agreement shall be for the subject-matter, duration, nature and purposes and involve the types of Personal Data and categories of Data Subjects set out in this Part B.
  1. Subject-matter of processing:
  2. The subject matter of the processing is the Protected Data provided to OIIKI by Agencies in respect of the Services under the Agreement.
  3. Duration of the processing:
  4. The duration of the processing is the duration of the provision of the Services under the Agreement until disposal of the Protected Data in accordance with this Addendum.
  5. Nature and purpose of the processing:
  6. Our processing of Protected Data mainly pertains to the provision of our introductory Services to your Agency Workers. We shall only process Protected Data to the extent needed to manage the operations of your Agency Workers on our Platform.
  7. Type of Personal Data:
  8. Full Name Email Address Phone Number
  9. Categories of Data Subjects:
  10. Agency Workers.
  11. Specific processing instructions:
  12. Our processing of personal data on your behalf may commence when the Services commence. You hereby instruct us to process the Personal Data to perform our Services to you.  
Section 2—Minimum technical and organisational security measures
  1. OIIKII shall implement and maintain the following technical and organisational security measures to protect the Protected Data:
    1. Use secure databases for storage.
    2. Prevent Processing systems from being used without authorization by requiring strong passwords, two-steps login, change management, and access logging.
    3. Limit access rights and privileges to only persons entitled to access the Processing system and gain access to the Personal Information as they are entitled and ensure Personal Information cannot be read, copied, modified, or deleted without authorization.
    4. Allow only integrations into Processing systems through secure web services and from data sources controlled by the Controller
    5. Ensuring that Personal Information is Processed solely in accordance with the instructions of the Controller.
    6. Perform Back-ups on a regular basis to ensure that Personal Information is protected against accidental destruction or loss.
    7. We shall hereafter be entitled and under obligation to make decisions about the technical and organisational security measures that are to be applied to create the necessary (and agreed) level of data security.