Standard DPA: This Data Processing Agreement ("DPA") forms part of the Terms of Service between PICMS and the Customer. It governs the processing of personal data in accordance with UK GDPR requirements.

1. Parties

Data Controller ("Customer")

The organisation that has subscribed to PICMS services and determines the purposes and means of processing personal data.

Data Processor ("PICMS")

PICMS Ltd, registered in England and Wales, providing compliance management services and processing personal data on behalf of the Customer.

2. Definitions

"Personal Data"
Any information relating to an identified or identifiable natural person as defined in UK GDPR Article 4(1).
"Processing"
Any operation performed on personal data, including collection, recording, storage, adaptation, retrieval, use, disclosure, or deletion.
"Data Subject"
An identified or identifiable natural person whose personal data is processed.
"Sub-processor"
Any third party engaged by PICMS to process personal data on behalf of the Customer.
"UK GDPR"
The UK General Data Protection Regulation as incorporated into UK law by the Data Protection Act 2018.

3. Subject Matter and Duration

3.1 Subject Matter

This DPA governs the processing of personal data by PICMS when providing compliance management services to the Customer, including:

3.2 Duration

This DPA shall remain in effect for the duration of the Customer's subscription to PICMS services and for as long as PICMS processes personal data on behalf of the Customer.

4. Nature and Purpose of Processing

PICMS processes personal data for the following purposes:

5. Categories of Data Subjects

Personal data processed under this DPA may relate to:

6. Types of Personal Data

Categories of personal data processed may include:

7. Processor Obligations

PICMS shall:

7.1 Processing Instructions

7.2 Confidentiality

7.3 Security Measures

7.4 Sub-processing

7.5 Data Subject Rights

7.6 Data Breach Notification

8. Controller Obligations

The Customer shall:

9. International Transfers

Personal data is primarily processed within the UK (AWS EU-West-2, London). If international transfers are necessary:

10. Approved Sub-processors

The Customer authorises the use of the following sub-processors:

Sub-processor Purpose Location
Amazon Web Services (AWS) Cloud infrastructure and hosting EU-West-2 (London, UK)
Auth0 (Okta) Authentication services EU Region
Stripe Payment processing UK/EU
SendGrid (Twilio) Email delivery EU Region

PICMS will notify the Customer at least 30 days before engaging any new sub-processor, allowing the Customer to object.

11. Audit Rights

The Customer has the right to:

PICMS will provide SOC 2 Type II reports and security documentation upon request.

12. Data Retention and Deletion

12.1 During Subscription

PICMS will retain personal data for the duration of the Customer's subscription as necessary to provide the services.

12.2 Upon Termination

12.3 Exceptions

Data may be retained longer where required by law or for legitimate legal purposes (e.g., regulatory compliance records).

13. Liability

Each party's liability under this DPA shall be subject to the limitations set forth in the main Terms of Service, except that neither party excludes liability for:

14. Amendments

This DPA may be amended:

Annex A: Technical and Organisational Measures

Measure Implementation
Encryption in Transit TLS 1.2/1.3 with 256-bit encryption
Encryption at Rest AES-256 encryption for all stored data
Access Control Role-based access control (RBAC), MFA available
Network Security Firewalls, VPC isolation, DDoS protection
Monitoring 24/7 security monitoring, intrusion detection
Backups Daily encrypted backups, tested recovery procedures
Physical Security AWS data centres with SOC 2 Type II certification
Incident Response Documented incident response procedures

Data Protection Contact

For questions regarding this DPA or to exercise your rights:

Email: dpo@picms.com

Data Subject Requests: dsar@picms.com

Address: PICMS Ltd, London, United Kingdom