Forms part of the Terms of Service between Global Agentic Holdings Limited ("Processor") and the Customer ("Controller") where we process personal data on Customer's behalf.
Customer is controller (or processor for its own principals) of personal data it submits. globalEPR™ is processor (or sub-processor) and processes such data solely to provide the Service per documented instructions (these Terms, in-product configuration, support tickets).
Customer authorises the sub-processors in Privacy Policy §5. 30 days' notice of additions; objection on reasonable data-protection grounds within the window; if unresolved, Customer may terminate the affected part of the Service.
We will: (a) process only on documented instructions, including for international transfers, unless law requires otherwise (informing Customer unless prohibited); (b) bind personnel to confidentiality; (c) implement the measures in Privacy Policy §11; (d) assist with data-subject requests, DPIAs and authority consultations, at Customer's reasonable cost for material effort; (e) notify Customer without undue delay of a personal data breach affecting Customer Data; (f) on termination, delete or return Customer Data per ToS §9, except legally required retention; (g) make available compliance information and allow audits (reasonable notice, confidentiality, max once per 12 months absent breach or regulatory need); (h) maintain a Record of Processing Activities (Art. 30 GDPR) covering processing performed for Customer, and make the relevant extract available on request as part of (g).
Transfers outside the EEA/UK rely on the mechanisms in Privacy Policy §6. EU Standard Contractual Clauses (Module 2, and Module 3 where Customer is itself a processor) are incorporated by reference and available for countersignature on request; in case of conflict, the SCCs prevail over this DPA.
Subject to the limitation of liability in ToS §11.
Same as the ToS (§20.1), without prejudice to Customer's mandatory local law.