1. Parties, scope and instructions
This DPA forms part of the customer’s ERP agreement for personal data processed on the customer’s instructions. The customer acts as controller, or as an authorised processor appointing the operator as subprocessor; the operator acts as processor for the covered customer records. Process only on documented instructions, including transfers, unless Union or Member State law requires otherwise; inform the customer of that requirement beforehand unless prohibited. Immediately inform the customer if an instruction appears to infringe data-protection law and suspend the affected instruction while it is resolved. Own-controller activities disclosed in the Privacy Notice are outside this DPA.
2. Processing schedule
Subject: delivery and support of selected ERP modules. Duration: the service term plus agreed retrieval and deletion periods, subject to lawful retention. Operations: collection, storage, organisation, access, calculation, transmission, export and deletion as instructed. Data subjects: customer users, employees, contractors, business contacts, clients and suppliers. Categories: identifiers and work contacts, roles, activity records, project and transaction records, salary and payment information and instructed attachments. The signed order must narrow these categories to the modules actually used and expressly identify any permitted special-category data. Financing-partner assessment is not automatically included in this processor schedule.
3. Confidentiality and security
Authorised personnel must be bound by confidentiality. The processor must implement appropriate Article 32 measures proportionate to risk, including access management, tenant isolation, protection of data in transit and at rest where appropriate, resilience, recovery and regular evaluation. Any agreed security annex identifies the measures applicable to your service. This DPA does not claim an independent certification or a specific recovery time. Security changes must not materially reduce the agreed protection.
4. Subprocessors and transfers
The customer must receive the completed subprocessor register before authorisation. Under the general-authorisation mechanism, give at least 30 days’ advance notice of additions or replacements and allow reasoned data-protection objections. Resolve an objection through reasonable alternatives or permit termination of the affected service before the provider begins processing. Each subprocessor must accept materially equivalent data-protection duties; the operator remains responsible for its performance. No international transfer may occur without applicable Chapter V safeguards and documented instructions. The provider register identifies approved hosting; additional providers require disclosure and authorisation under this clause.
5. Rights, incidents and regulatory assistance
Taking account of the nature of processing, assist the customer with data-subject requests, security duties, breach assessment, DPIAs and prior consultation. Forward requests without answering for the customer unless authorised or legally required. Notify the customer without undue delay after becoming aware of a personal-data breach, with available facts about its nature, affected categories and approximate numbers, contact, likely consequences and mitigation; supplement information as it becomes available. The controller determines its own notification duties, including the GDPR 72-hour authority deadline where applicable. Assistance arrangements must not prevent statutory compliance.
6. Demonstrating compliance
Make available the information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the customer or its mandated auditor. Reasonable confidentiality, scheduling and security arrangements may protect other customers and systems but must not defeat Article 28 audit rights or regulatory access. Maintain the required processing records and evidence of instructions, provider approvals, incidents and deletion. The customer remains responsible for its lawful purposes, notices, minimisation and employee-monitoring assessment.
7. Return, deletion and further use
At the customer’s choice, return or delete covered personal data after the service ends and delete remaining copies unless applicable law requires storage. Agree export and retrieval periods before closure. Legally retained copies must be isolated and used only for that obligation. The final annex must define backup expiry and restoration controls so deleted records are not returned to active use. Processing to create anonymous datasets requires documented customer instructions and the customer’s lawful authority; this DPA does not permit independent reuse of personal data for advertising or general AI training. Genuine anonymous outputs may be used only within the Terms’ confidentiality and re-identification safeguards.