Data Processing Agreement
The terms governing how Waris International Consulting Ltd processes Customer Personal Data on behalf of CompCheck.IO customers.
This Data Processing Agreement forms part of the CompCheck.IO Terms of Service and applies where Waris International Consulting Ltd processes Personal Data on behalf of a Customer as Processor or, where applicable, as Sub-processor.
1. Purpose and Status of this DPA
1.1 This Data Processing Agreement ("DPA") governs the processing of Personal Data by WICL on behalf of the Customer in connection with the Customer's use of CompCheck.IO.
1.2 It applies where the Customer acts as a Controller of Personal Data and WICL processes that Personal Data as a Processor on behalf of the Customer.
1.3 This DPA is incorporated into and forms part of the CompCheck.IO Terms of Service and SaaS Agreement.
1.4 By entering into the Terms, creating or maintaining a CompCheck.IO Account or using Services involving the processing of Customer Personal Data, the Customer instructs WICL to process Personal Data in accordance with this DPA and the Terms.
1.5 Where the Customer acts as a Processor on behalf of another Controller, including where a consultant or Super Admin processes Personal Data on behalf of one of its clients, references in this DPA to the Customer as Controller shall, where appropriate, include the Customer acting as Processor and WICL acting as its Sub-processor.
1.6 Nothing in this DPA changes the parties' respective roles under applicable Data Protection Law. Those roles shall be determined by the factual circumstances of the relevant processing.
2. Definitions
"Applicable Data Protection Law" means applicable laws relating to privacy and the processing of Personal Data, including the UK GDPR, the Data Protection Act 2018 and other applicable UK data-protection legislation as amended from time to time.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Category Personal Data" and "Supervisory Authority" have the meanings given to them under Applicable Data Protection Law.
"Customer Personal Data" means Personal Data processed by WICL on behalf of the Customer through the Services.
"Services" means the applicable CompCheck.IO services described in the Terms, including Compliance, Academy, HR and associated functionality.
"Sub-processor" means another Processor engaged by WICL to process Customer Personal Data on behalf of the Customer.
"UK GDPR" means the United Kingdom General Data Protection Regulation as it forms part of UK law, as amended from time to time.
Terms defined in the Terms have the same meanings when used in this DPA unless otherwise stated.
3. Scope of Processing
3.1 The subject matter, nature, purpose and duration of the Processing, categories of Data Subjects and types of Personal Data are described in Schedule 1.
3.2 The Customer appoints WICL to process Customer Personal Data solely to the extent necessary to:
- provide the Services;
- host and maintain Customer Personal Data;
- provide functionality selected or configured by the Customer;
- provide technical support;
- maintain the security and integrity of the Services;
- perform backups, recovery and business-continuity functions;
- facilitate authorised integrations;
- perform the Customer's documented instructions; and
- comply with Applicable Data Protection Law.
3.3 The Customer's configuration and use of the Services, together with the Terms, this DPA and any additional written instructions accepted by WICL, constitute the Customer's documented instructions.
4. Customer Responsibilities
4.1 The Customer determines the purposes for which Customer Personal Data is processed through the Services, except where the Customer itself acts as Processor for another Controller.
4.2 The Customer is responsible for ensuring that:
- its Processing complies with Applicable Data Protection Law;
- it has an appropriate lawful basis for the Processing;
- where required, it satisfies additional conditions applicable to Special Category Personal Data;
- appropriate privacy information has been provided to Data Subjects;
- Customer Personal Data supplied to WICL has been collected lawfully;
- instructions given to WICL comply with Applicable Data Protection Law;
- the Customer does not instruct WICL to process Personal Data unlawfully;
- only Personal Data reasonably necessary for the Customer's purposes is entered into the Services;
- access permissions are appropriately configured; and
- Authorised Users are permitted to access the Personal Data made available to them.
4.3 The Customer remains responsible for determining appropriate retention periods for Customer Personal Data, except where retention is required independently by law.
4.4 Where the Customer is itself acting as a Processor, it warrants that the relevant Controller has authorised the Customer to appoint WICL as a Sub-processor, its instructions are consistent with the Controller's instructions and it is entitled to provide the relevant Personal Data to WICL.
5. WICL's Processing Obligations
5.1 WICL shall:
- process Customer Personal Data only on documented instructions from the Customer;
- process Customer Personal Data only for purposes necessary to provide the Services and comply with those instructions;
- comply with its applicable obligations as Processor under Applicable Data Protection Law; and
- promptly inform the Customer if, in WICL's reasonable opinion, an instruction infringes Applicable Data Protection Law.
5.2 If WICL is required by UK law to process Customer Personal Data otherwise than on the Customer's instructions, WICL shall inform the Customer of that legal requirement before processing unless applicable law prohibits such notification on important grounds of public interest.
5.3 WICL may make reasonable operational and technical decisions concerning how the Services are provided provided those decisions do not cause WICL to determine the Customer's purposes for processing Customer Personal Data.
5.4 If WICL determines the purposes and means of particular Processing independently of the Customer, WICL shall be a Controller in respect of that Processing to the extent required by Applicable Data Protection Law.
6. Confidentiality
6.1 WICL shall ensure that persons authorised by WICL to process Customer Personal Data:
- are subject to appropriate contractual or statutory obligations of confidentiality;
- process Customer Personal Data only where necessary for their authorised functions; and
- receive appropriate information, instruction or training regarding their data-protection responsibilities.
6.2 WICL shall restrict access to Customer Personal Data to persons who reasonably require access for provision, maintenance, security or support of the Services.
7. Security of Processing
7.1 Taking into account the state of the art, costs of implementation, nature, scope, context and purposes of Processing and the risk to the rights and freedoms of individuals, WICL shall implement appropriate technical and organisational measures designed to provide a level of security appropriate to the risk.
7.2 Such measures shall, where appropriate to the Services and risks involved, address:
- confidentiality of Personal Data;
- integrity of Personal Data;
- availability and resilience of processing systems;
- restoration of availability following an incident;
- access control;
- authentication;
- secure communications;
- system monitoring;
- vulnerability and patch management;
- backups and recovery;
- incident management;
- personnel confidentiality and access;
- data segregation where appropriate; and
- periodic review of relevant security measures.
7.3 A summary of WICL's applicable technical and organisational measures is contained in Schedule 2 and may be supplemented by other security documentation made available by WICL.
7.4 The Customer acknowledges that appropriate security is a shared responsibility and shall implement reasonable measures within its own control, including secure passwords, appropriate access permissions, secure devices, promptly disabling former users, protecting authentication credentials and appropriately managing exported data.
8. Special Category Personal Data
8.1 Depending upon the Customer's use of CompCheck.IO, Customer Personal Data may include Special Category Personal Data.
8.2 This may arise particularly in connection with sickness and absence records, occupational health information, disability or workplace-adjustment information, accident or incident records, health and safety records, employee records, equality or diversity information and other information entered by the Customer.
8.3 The Customer is responsible for determining whether such Processing is lawful and for establishing the applicable lawful basis and additional condition where required.
8.4 WICL does not require the Customer to upload Special Category Personal Data unless it is necessary for functionality selected and used by the Customer.
8.5 Customers should avoid entering unnecessary Special Category Personal Data into free-text fields, notes, documents or other areas of the Services.
9. Criminal Offence Data
9.1 The Customer may only process criminal offence data through the Services where it is lawful and appropriate to do so.
9.2 The Customer is responsible for establishing any legal authority, condition, policy document or other requirement applicable to such Processing.
9.3 WICL does not independently require criminal offence data to be entered into the Services unless expressly stated for a particular Service.
10. Data Subject Rights
10.1 Taking into account the nature of the Processing, WICL shall assist the Customer, through appropriate technical and organisational measures insofar as reasonably possible, to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Law.
10.2 This may include requests relating to access, rectification, erasure, restriction, data portability, objection and relevant rights concerning automated decision-making.
10.3 Where WICL receives a request directly from a Data Subject concerning Customer Personal Data, WICL shall, unless legally prohibited, direct the Data Subject to the relevant Customer or notify the Customer and shall not independently respond substantively except on the Customer's instructions or where required by law.
10.4 The Customer remains responsible for determining whether and how a Data Subject request should be fulfilled.
11. Personal Data Breaches
11.1 WICL shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
11.2 To the extent reasonably available, WICL's notification shall include information concerning the nature of the breach, affected categories of Data Subjects and Personal Data, approximate numbers of affected records or Data Subjects where known, likely consequences, measures taken or proposed and relevant contact information.
11.3 Where all information is not available at the same time, WICL may provide information in phases without undue further delay.
11.4 WICL shall take reasonable steps to contain the breach, mitigate its effects, investigate its cause and reduce the risk of recurrence where those matters fall within WICL's control.
11.5 Notification by WICL under this clause does not constitute an admission of fault or liability.
11.6 The Customer remains responsible, as Controller, for determining whether notification must be made to the ICO, another Supervisory Authority or affected Data Subjects.
12. Assistance with Compliance
12.1 Taking into account the nature of Processing and information available to WICL, WICL shall provide reasonable assistance to the Customer with obligations relating to security of Processing, Personal Data Breach assessment and notification, notification to affected Data Subjects, data protection impact assessments and prior consultation with the ICO or another competent Supervisory Authority where required.
12.2 WICL may provide relevant information regarding the Services, security measures and Processing to assist the Customer with a DPIA.
12.3 Unless required because of WICL's breach of this DPA, WICL may charge reasonable fees for substantial assistance materially exceeding ordinary support included within the Customer's Subscription, provided such charges are agreed or notified in advance where practicable.
13. Sub-processors
13.1 The Customer gives WICL general written authorisation to engage Sub-processors to process Customer Personal Data for the purpose of providing the Services.
13.2 WICL shall maintain a list of material Sub-processors used in connection with Customer Personal Data.
13.3 WICL shall ensure that each Sub-processor is subject to written contractual obligations providing an equivalent level of protection for Customer Personal Data as required by Article 28 of the UK GDPR.
13.4 WICL remains responsible to the Customer for the performance of a Sub-processor's applicable data-protection obligations to the extent required by Applicable Data Protection Law.
13.5 Where WICL intends to add or replace a material Sub-processor, WICL shall provide reasonable notice to affected Customers by email, through the Platform, through a published Sub-processor list or update mechanism, or another reasonable electronic method.
13.6 The Customer may raise a reasonable written objection to a new Sub-processor on genuine data-protection grounds within 14 days of receiving notice.
13.7 The parties shall seek in good faith to resolve a valid objection.
13.8 Where no commercially reasonable alternative is available, WICL may permit the Customer to terminate the materially affected Service without penalty, subject to payment of fees accrued before termination.
14. International Transfers
14.1 WICL shall not transfer Customer Personal Data to a country or recipient in circumstances prohibited by Applicable Data Protection Law.
14.2 Where Customer Personal Data is transferred outside the United Kingdom and an appropriate safeguard is required, WICL shall ensure that a lawful transfer mechanism is used.
14.3 Such mechanisms may include, where applicable, UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, another lawful transfer mechanism recognised under UK law or an applicable statutory exemption where legally appropriate.
14.4 WICL shall implement supplementary measures where required by Applicable Data Protection Law having regard to the relevant transfer risk.
14.5 Details of material international Processing locations may be identified in applicable Sub-processor information.
15. Records and Demonstration of Compliance
15.1 WICL shall maintain records relating to Processing activities where required by Applicable Data Protection Law.
15.2 WICL shall make available to the Customer information reasonably necessary to demonstrate compliance with WICL's obligations under Article 28 and this DPA.
15.3 WICL may satisfy reasonable information requests by providing appropriate documentation, questionnaires, policies, certifications, audit reports or other evidence where available.
16. Audits and Inspections
16.1 WICL shall allow for and contribute to audits and inspections by the Customer or an auditor mandated by the Customer to the extent required by Applicable Data Protection Law.
16.2 Except following a Personal Data Breach materially affecting Customer Personal Data or where a Supervisory Authority requires otherwise:
- the Customer shall provide reasonable advance written notice;
- audits shall normally occur no more than once in any 12-month period;
- audits shall take place during normal business hours;
- audits shall not unreasonably interfere with WICL's operations;
- auditors must be subject to appropriate confidentiality obligations;
- audits must not compromise security, confidentiality or Personal Data of other customers; and
- the Customer shall bear its own audit costs.
16.3 WICL may charge reasonable costs associated with an audit where the Customer requires substantial personnel or resources beyond WICL's ordinary compliance obligations, unless the audit identifies a material breach of this DPA by WICL.
16.4 Nothing in this clause limits any audit or inspection right which cannot lawfully be restricted.
17. Return and Deletion of Personal Data
17.1 Upon termination or expiry of the relevant Services, and subject to functionality made available by WICL, the Customer should export Customer Personal Data it wishes to retain.
17.2 At the Customer's choice, WICL shall delete or return Customer Personal Data following termination of relevant Processing, unless applicable UK law requires continued storage.
17.3 WICL may operate a reasonable post-termination period during which Customer Personal Data remains recoverable before permanent deletion.
17.4 Customer Personal Data contained in backups or disaster-recovery systems may remain until the applicable backup is overwritten or deleted in accordance with WICL's normal retention cycle, provided that the data is put beyond ordinary operational use, remains protected under this DPA and is subsequently deleted in accordance with the applicable cycle.
17.5 WICL may retain Personal Data where required by law, provided it is retained only for the applicable legal purpose and remains appropriately protected.
18. Customer Data Exports
18.1 Where the Services provide export functionality, the Customer is responsible for making appropriate exports before termination.
18.2 Once Customer Personal Data has been exported from CompCheck.IO, the Customer is responsible for the security and subsequent Processing of that exported data.
18.3 WICL is not responsible for Personal Data once it has been downloaded or exported to systems outside WICL's or its Sub-processors' control, except where WICL remains legally responsible for the relevant Processing.
19. Consultant and Super Admin Arrangements
19.1 CompCheck.IO may permit consultants, professional advisers or other service providers to establish and administer client Accounts.
19.2 The parties acknowledge that data-protection roles in such arrangements may vary according to the circumstances.
19.3 For example:
may constitute:
Controller → Processor → Sub-processor
where the consultant processes Personal Data solely on its client's instructions.
19.4 Alternatively, a consultant may act as an independent Controller for certain Personal Data where it determines its own purposes and means of Processing.
19.5 The consultant is responsible for determining and documenting its own role in relation to each client.
19.6 Where WICL acts as Sub-processor, the consultant warrants that the Controller has authorised WICL's appointment, its instructions are consistent with the Controller's instructions and it remains responsible for its own obligations to the Controller.
20. HR and Workforce Data
20.1 Depending on the Customer's use of the HR Platform, WICL may process Personal Data concerning employees, workers, contractors, job applicants, former employees or workers, managers, directors and other personnel.
20.2 The Customer remains responsible for determining what HR information is collected, why it is processed, how long it is retained, who may access it, whether decisions are made using it and the lawful basis and other conditions applicable to the Processing.
20.3 The fact that CompCheck.IO provides functionality capable of storing or analysing particular information does not itself constitute an instruction or recommendation by WICL that the Customer should collect that information.
21. Recruitment Data
21.1 Recruitment functionality may process information concerning applicants and candidates, including application information, CVs, interview records, correspondence, assessment information and onboarding information.
21.2 The Customer is responsible for its recruitment privacy information, lawful basis, retention arrangements and recruitment decisions.
21.3 WICL shall not determine whether an applicant should be recruited merely by providing the software through which recruitment information is processed.
22. Attendance and Workforce Scheduling
22.1 Where Customers use clock-in/out, time and attendance or workforce-scheduling functionality, WICL processes relevant information on the Customer's instructions.
22.2 The Customer determines which individuals are required to use the functionality, purposes for which attendance information is used, applicable retention periods and employment or management decisions made using that information.
22.3 If location-based attendance functionality is introduced or enabled, additional Processing associated with such functionality shall be governed by Applicable Data Protection Law and relevant product information.
23. Payroll-Related Information
23.1 The Services may process information used by the Customer for payroll or remuneration administration.
23.2 The Customer remains responsible for payroll instructions, accuracy of source information, statutory deductions, tax treatment, pension arrangements, payment decisions and compliance with applicable employment, tax and payroll obligations.
23.3 WICL's processing of payroll-related Personal Data does not make WICL the employer or Controller of the Customer's workforce data merely by reason of providing the Services.
24. Academy and Training Data
24.1 Academy may process Personal Data relating to learners, employees, trainers, instructors, course creators, administrators and purchasers or recipients of training.
24.2 Such Processing may include course enrolment, assigned training, progress, completion, assessment results, certificates, training history and learning records.
24.3 The Customer determines the purposes for which employee or learner training information is processed where WICL acts as Processor.
25. Compliance, Incident and Risk Data
25.1 Customer Personal Data processed through Compliance functionality may include information contained within risk assessments, audits, checklists, inspections, incident or accident records, forms, policies and procedures, tickets, tasks and corrective actions, uploaded documents, photographs, comments and communications, electronic acknowledgements and signatures.
25.2 Customers should recognise that free-text compliance records can contain sensitive Personal Data and should ensure that only information reasonably necessary for the relevant purpose is recorded.
26. Electronic Signatures
26.1 Where CompCheck.IO processes electronic signatures or acknowledgement records on behalf of the Customer, WICL shall process those records in accordance with the Customer's instructions and this DPA.
26.2 The Customer determines who is requested to sign or acknowledge a document, why the signature is collected, the document concerned and the applicable retention period.
27. Communications
27.1 Where the Customer uses CompCheck.IO to send emails, messages, notifications or broadcasts to employees, clients, learners or other recipients, WICL processes relevant contact and communication data on the Customer's instructions where acting as Processor.
27.2 The Customer is responsible for ensuring communications it initiates comply with applicable privacy, electronic communications, marketing and other laws.
28. Relationship with WICL's Controller Processing
28.1 This DPA applies only where WICL processes Personal Data on behalf of the Customer.
28.2 WICL may separately process certain Personal Data as an independent Controller for its own legitimate purposes, including as appropriate:
- Account administration;
- contractual records;
- billing;
- payment administration;
- security and fraud prevention;
- service communications;
- legal compliance;
- establishment, exercise or defence of legal claims;
- business administration; and
- other purposes described in the CompCheck.IO Privacy Policy.
28.3 Such Controller Processing is governed by WICL's Privacy Policy and Applicable Data Protection Law rather than this DPA.
29. Liability
29.1 The liability provisions and limitations contained in the Terms apply to this DPA to the maximum extent permitted by law.
29.2 Nothing in this DPA excludes or limits liability to the extent such liability cannot lawfully be excluded or limited.
29.3 Nothing in this clause affects the rights, responsibilities or liabilities of either party under Applicable Data Protection Law.
30. Priority
30.1 If there is a conflict between this DPA and the Terms concerning the Processing of Customer Personal Data, this DPA shall prevail to the extent of the conflict.
30.2 If the parties enter into an applicable international data-transfer mechanism and that mechanism conflicts with this DPA, the mandatory provisions of the transfer mechanism shall prevail in relation to the relevant transfer.
31. Changes to this DPA
31.1 WICL may update this DPA where reasonably necessary to comply with changes in Applicable Data Protection Law, reflect regulatory guidance, reflect changes to the Services, update Sub-processor arrangements, improve data-protection safeguards or correct errors or ambiguities.
31.2 WICL shall provide reasonable notice of material changes where required or appropriate.
31.3 No amendment shall materially reduce the protection afforded to Customer Personal Data during an existing paid Subscription Period unless required by law or agreed with the Customer.
32. Governing Law
32.1 This DPA is governed by the law governing the Terms.
32.2 Unless mandatory law requires otherwise, the courts specified in the Terms shall have jurisdiction.
Schedule 1 — Details of Processing
1. Subject Matter
Provision of the CompCheck.IO software-as-a-service platform and associated functionality selected by the Customer, potentially including:
- Compliance management;
- HR and workforce management;
- Academy and learning management;
- recruitment and onboarding;
- time and attendance;
- workforce scheduling;
- payroll-related administration;
- employee records;
- absence management;
- appraisals and performance records;
- workforce analytics;
- risk assessments;
- checklists;
- audits;
- forms;
- policies and procedures;
- records;
- document management;
- management systems;
- electronic signatures and acknowledgements;
- sites and locations;
- tasks, tickets and corrective actions;
- communications;
- consultant CRM;
- consultant/client administration;
- proposals;
- invoicing;
- subscription administration; and
- associated platform functionality.
2. Duration
Processing shall continue for the duration of the Customer's use of the relevant Services, together with any reasonable post-termination retention, backup, deletion or legal-retention period described in this DPA, the Terms or applicable retention documentation.
3. Nature of Processing
Processing may include collection, recording, organisation, structuring, storage, hosting, retrieval, consultation, display, transmission, assignment, updating, alteration, calculation, analysis, document generation, document population, communication, sharing at the Customer's direction, backup, recovery, export, restriction, archiving and deletion.
4. Purpose of Processing
To enable WICL to provide functionality selected and used by the Customer through CompCheck.IO and to perform associated hosting, maintenance, security, support, backup and technical operations.
5. Categories of Data Subjects
- employees;
- prospective employees;
- job applicants;
- former employees;
- workers;
- agency workers;
- contractors;
- volunteers;
- directors;
- officers;
- managers;
- shareholders where recorded by the Customer;
- learners;
- trainees;
- course creators;
- trainers and instructors;
- Customer users;
- client personnel;
- supplier personnel;
- consultants;
- consultant clients;
- client contacts;
- customers;
- prospective customers;
- visitors;
- witnesses;
- persons involved in incidents or accidents;
- complainants;
- persons named in compliance records; and
- other individuals whose Personal Data the Customer lawfully processes using the Services.
6. Types of Personal Data
Depending upon Customer configuration and use, Personal Data may include:
- identity and contact information;
- employee/personnel numbers;
- usernames and account identifiers;
- photographs and signatures;
- job titles and department information;
- employment status and dates;
- working patterns, attendance, hours and shifts;
- absence and leave;
- appraisals and performance records;
- disciplinary or grievance information where uploaded;
- qualifications, competency and training records;
- CVs and recruitment information;
- payroll/remuneration-related information;
- training enrolment, progress, completion and certificates;
- risk assessments and audit records;
- checklist and inspection responses;
- incident and accident information;
- corrective actions and tickets;
- forms, comments and photographs;
- client and CRM information;
- proposals and subscription information;
- technical identifiers and logs;
- documents and correspondence;
- attachments; and
- other Personal Data uploaded or entered by the Customer.
7. Special Category Personal Data
Depending upon the Customer's use of the Services, this may include health information, sickness and absence information revealing health data, disability information, occupational-health information, accident/injury information, workplace-adjustment information, racial or ethnic origin, religious or philosophical beliefs, trade union membership and other Special Category Personal Data entered by the Customer.
Biometric data would only be included if functionality is expressly introduced and used for identification purposes.
8. Criminal Offence Data
Criminal offence information may be processed only where lawfully entered by the Customer, for example in recruitment or HR documentation.
9. Frequency
Processing may occur continuously or intermittently according to the Customer's use of the Services.
10. Controller's Rights and Obligations
The Customer retains the rights and obligations of Controller under Applicable Data Protection Law, including responsibility for determining purposes, lawful bases, transparency, Data Subject rights, retention decisions, data minimisation, accuracy, access authorisation, DPIAs where required, regulatory notifications and giving lawful documented instructions to WICL.
Schedule 2 — Technical and Organisational Measures
This Schedule records technical and organisational measures currently verified or sufficiently established. Additional detail will be incorporated as the technical review of the CompCheck.IO environment is completed.
A. Privileged Administrative Access
Access to the highest level of administrative functionality within CompCheck.IO is restricted to a limited number of authorised persons.
At the date of this DPA, Super Administrator access is restricted to:
- an authorised representative of Waris International Consulting Ltd; and
- the authorised freelance software developer responsible for the development and technical maintenance of CompCheck.IO.
No other persons currently have Super Administrator access.
Privileged access is intended to be limited to persons requiring such access for administration, development, maintenance, security or support of the Services.
B. Hosting
CompCheck.IO infrastructure and Customer Data are hosted using services supplied to Waris International Consulting Ltd by Hetzner Online GmbH.
The relevant hosting environment is currently understood to be located in Germany, subject to final technical confirmation.
C. Backups and Recovery
CompCheck.IO Customer and application data is backed up daily.
Backups are maintained for business continuity, recovery and restoration purposes in the event of data loss, system failure or other relevant incidents.
Details concerning backup retention periods, encryption, backup storage location, restoration procedures and testing are undergoing technical verification.
D. Access Control
WICL intends to maintain access controls appropriate to user roles and authorisations. Further technical details concerning authentication, password controls, role-based permissions and access logging will be incorporated following technical verification.
E. Data Security
Details concerning encryption in transit, encryption at rest, database security, file storage and customer-data segregation are undergoing technical verification and will be documented when confirmed.
F. Infrastructure Security
Technical details concerning network controls, patching, vulnerability management and infrastructure security are undergoing technical verification.
G. Monitoring and Logging
Logging, monitoring and security-event controls will be described more specifically following technical verification of the live environment.
H. Personnel
Privileged access is restricted to authorised persons. Persons granted access to Customer Personal Data are expected to be subject to appropriate confidentiality and data-processing obligations and to access data only where required for authorised functions.
I. Incident Management
WICL maintains obligations under this DPA to identify, assess, respond to and notify Customers of relevant Personal Data Breaches without undue delay. Detailed operational incident procedures will be documented further following technical verification.
J. Development and Change Management
Development, deployment and environment-management controls are undergoing technical verification and will be incorporated into this Schedule when confirmed.
K. Data Lifecycle
Customer Data is subject to the return and deletion provisions in clause 17. Further technical retention and deletion periods will be documented when confirmed.
Schedule 3 — Authorised Sub-processors
WICL maintains this Schedule to identify material third-party providers which process Customer Personal Data on WICL's behalf in connection with CompCheck.IO.
| Sub-processor | Purpose | Data processed | Location | Transfer basis / safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting and infrastructure supporting CompCheck.IO | Customer and application data hosted or processed within the CompCheck.IO environment | Germany — subject to final technical confirmation | UK adequacy arrangements applicable to EEA processing, subject to confirmation of processing location and applicable contractual arrangements |
| Additional provider(s) | To be added following technical verification | To be confirmed | To be confirmed | To be confirmed where applicable |
Contact
Company number: 09531683
Registered office: C/O Hr Accountants, 222 Branston Road,
Burton On Trent, England, DE14 3BT
Email:
compcheck@warisconsulting.co.uk