Third Party Index

Snapshot 65025

Document
Data processing addendum
URL
https://www.itcinfotech.com/wp-content/uploads/2024/10/ITCI-Data-Processing-Terms-Eng.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
203455 bytes
SHA-256 (raw)
8e888ba74121965a2e4aa7a7f48d683304715e80a9e85c93086aaa142bdcb804
SHA-256 (normalized text)
139e5951a7290431f9bc36f143821d9ada342f36e92ea86c44baf3ac8bc73e97

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                        ITCI Data Processing Terms & Conditions
 In the provision of certain services under the terms of the Principal Agreement(s) as defined below, Customer,
 as controller will require ITCI to process certain personal data received from Customer.
 The parties agree that these terms and conditions shall apply to all such processing undertaken by ITCI on
 behalf of Customer and shall be supplemental to the terms of the Principal Agreement.

1. Appointment                                                 that has executed standard contractual
   Customer as controller of certain personal data             clauses adopted or approved by the European
   appoints ITCI as processor to process the                   Commission.
   personal data listed in Schedule 1 (the “Data")
   for the purposes also described in the                  4. Confidentiality of processing
   Schedule1 (or as otherwise agreed in writing by            ITCI shall ensure that any person it authorizes to
   the parties) (the "Permitted Purpose"). Each               process the personal data (an "Authorized
   party shall comply with the obligations that               Person") have committed themselves to
   apply to it under Applicable Data Protection               preserve the confidentiality of such personal
   Law.                                                       data.

2. Definitions                                             5. Security
   In these terms and conditions, the following               ITCI shall implement the technical and
   terms shall have the following meanings:                   organizational measures as set out in the
   (a) “Principal Agreements”: Any agreement                  Schedule 1 to protect the personal data (i) from
       between ITCI and Customer under the                    accidental or unlawful destruction, and (ii) loss,
       terms of which ITCI provides services                  alteration, unauthorized disclosure of, or access
       Customer;                                              to the personal data.

   (b) "controller", "processor", "data subject",          6. Subcontracting
       "personal data", “personal data breach”                Customer as controller consents to ITCI
       "processing" (and "process") and "special              engaging third party subprocessors mentioned
       categories of personal data" and                       in Schedule 2 to process the Data for the
       “supervisory authority” shall have the                 Permitted Purpose. The list of subprocessors
       meanings given in Applicable Data                      mentioned in Schedule 2 shall be updated with
       Protection Law; and                                    details of any change in subprocessors at least
                                                              10 days' prior to any such change taking effect;
   (c) "Applicable        Data Protection Law"                (ii) ITCI imposes data protection terms on any
       shall mean, where personal data of EU                  subprocessor it appoints that require it to
       residents is processed (i) prior to 25 May             protect the personal data to the standard
       2018, the EU Data Protection Directive                 required by Applicable Data Protection Law;
       (Directive 95/46/EC); (ii) on and after 25             and (iii) ITCI remains liable for any breach of this
       May 2018, the EU General Data Protection               Clause that is caused by an act, error or
       Regulation (Regulation 2016/679), and (iii)            omission of its subprocessor. Customer may
       where personal data of non-EU residents is             object to ITCI’s appointment or replacement of
       processed any applicable privacy law in                a subprocessor prior to its appointment or
       the relevant jurisdiction.                             replacement, provided such objection is based
                                                              on reasonable grounds relating to data
   All other terms shall be as defined in the                 protection. In such event, Customer may
   applicable Principal Agreement.                            require ITCI to suspend or terminate all
3. International transfers                                    processing activities (without prejudice to any
   As a global company ITCI may need to transfer              fees incurred by or committed to by Customer
   personal data out of the country that the                  under the terms of the Principal Agreement
   Customer or the data subjects are located. All             prior to suspension or termination).
   such transfers shall be in accordance with
   measures that permit the lawful transfer of             7. Cooperation and data subjects' rights
   personal data out of the EEA such as                       ITCI shall provide reasonable and timely
   transferring the personal data to a recipient              assistance to Customer (at Customer's

                                                 Page 1 of 5
   expense) to enable Customer to respond to: (i)                 any further processing except to the extent
   any request from a data subject to exercise any                required by such law.
   of its rights under Applicable Data Protection
   Law (including its rights of access, correction,          10. Audit
   objection, erasure and data portability, as                   Customer acknowledges that ITCI is regularly
   applicable);      and      (ii)   any     other               audited     for    compliance      with  various
   correspondence,       enquiry   or   complaint                internationally recognized standards as more
   received from a data subject, regulator or                    specifically detailed in the Schedule(s) by
   other third party in connection with the                      independent third party auditors.           Upon
   processing of the Data. In the event that any                 request, ITCI shall supply a summary / redacted
   such request, correspondence, enquiry or                      copy of its audit report(s) to Customer, which
   complaint is made directly to ITCI, ITCI shall                reports shall be subject to the confidentiality
   promptly inform Customer providing full details               provisions these terms and conditions. ITCI shall
   of the same.                                                  also respond to any written audit questions
                                                                 submitted to it by Customer, provided that
8. Personal Data Breach                                          Customer shall not exercise this right more than
   If it becomes aware of a confirmed personal                   once per year. Notwithstanding the foregoing,
   data breach, ITCI shall inform Customer without               in the event of an audit request directly from a
   undue delay and shall provide reasonable                      Supervisory Authority, ITCI shall always assist
   information and cooperation to Customer so                    Customer in answering the request and
   that Customer can fulfil any data breach                      organizing an audit.
   reporting obligations it may have under (and in
   accordance with the timescales required by)               11. Liability
   Applicable Data Protection Law. ITCI shall                    Each party's liability to the other in respect of
   further take such any reasonably necessary                    any individual claim for breach of contract,
   measures and actions to remedy or mitigate                    negligence, breach of statutory duty or
   the effects of the personal data breach and                   otherwise in relation to these terms and
   shall keep Customer informed of all material                  conditions will be limited in accordance with
   developments in connection with the personal                  the terms of the Principal Agreement.
   data breach.
9. Deletion or return of Personal Data                       12. General
   Upon termination or expiry of the Principal                   The laws governing the Principal Agreement
   Agreement, ITCI shall (at Customer's election)                shall apply to these terms and conditions
   destroy or return to Customer all personal data               except in the case where personal data of EU
   in its possession or control. This requirement shall          citizens is being processed and the jurisdiction
   not apply to the extent that ITCI is required by              of the Principal Agreement is not that of a
   applicable law to retain some or all of the                   member state of the EU, in which case the laws
   personal data, or to personal data it has                     of the Republic of Ireland shall apply in default.
   archived on backup systems, which personal                    These terms and conditions and the terms of the
   data ITCI shall securely isolate and protect from             Principal Agreement referred to herein
                                                                 embody the whole agreement of the parties
                                                                 with respect to its subject matter.

                                                    Page 2 of 5
                                              Schedule 1

Security Measures

Description of the technical and organizational security measures implemented by ITCI as processor:

    1.   Secure user authentication protocols including:
            • Control user IDs and other identifiers
            • Provide a reasonably secure method of assigning and selecting passwords (or use an
                 alternative authentication technology such as biometrics or Multifactor authentication)
            • Control data security passwords to ensure that such passwords are kept in a location
                 and/or format that does not compromise the security of the data they protect
            • Restrict access to active users and active user accounts only
            • Block access to user identification after multiple unsuccessful attempts to gain access
                 or the limitation placed on access for the particular system
            • Restrict access to records and files containing personal information to those who need
                 such information to perform their job duties
            • Assign unique identifications plus passwords, which are not vendor supplied default
                 passwords, to each person with customer access, that are reasonably designed to
                 maintain the integrity of the security of the access controls

    2.   Encrypt (to the extent technically feasible) all transmitted records and files containing personal
         information that will travel across public networks, and encryption of all data to be transmitted
         wirelessly

    3.   Implement reasonable monitoring of systems, for unauthorized use of or access to personal
         information

    4.   Encrypt all personal information stored on laptops or other portable devices

    5.   Provide reasonably up-to-date operating system security patches for files containing personal
         information on a system that is connected to the Internet, designed to maintain the integrity of
         the personal information

    6.   Provide reasonably up-to-date versions of endpoint detection and response agent software for
         malware protection and reasonably up-to-date sensor versions, or a version of such a software
         that can still be supported with up-to-date sensor versions, and is set to receive the most current
         sensor updates on a regular basis

    7.   Educate and train employees on the proper use of the computer security system and the
         importance of personal information security

    8.   Ensure that any third party that may have access to the systems by way of providing services to
         ITCI, but which are not providing data processing services, guarantee an equivalent level of
         security.

Security Certifications:
ISO 27001:2013

                                                Page 3 of 5
DATA:

Data subjects

The Personal Data relating to the following categories of data subjects:

  •     Individuals who are authorized by Customer to use access ITCI services being Customer’s
        employees, consultants, subcontractors, suppliers, business partners and customers.
  •     Other individuals whose personal data may be uploaded by Customer to ITCI services.

Personal Data Categories
Name, Company, organization, business contact details, interactions with ITCI’s services such as logfiles
and incident reports, training records and other personal data that an individual may share with ITCI.
IP addresses, cookie data, device identifiers and similar device-related information.

Permitted Purpose:
To DELIVER ITCI SERVICES to Customer in accordance with the terms of the Principal Agreement and
Customer’s instructions.

                                              Page 4 of 5
                                            Schedule 2

ITC Infotech India Ltd. group entities/affiliates may also act as sub‐processors.
Refer to ITCI affiliates list at www.itcinfotech.com/dxp-services/resources/legal-documents

                                              Page 5 of 5