Third Party Index

Snapshot 79424

Document
Data processing addendum
URL
https://www.zen.co.uk/resources/docs/default-source/document-library/global-documents/customer-data-processing-agreement_final.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
377607 bytes
SHA-256 (raw)
0c29b3077702af29f1125f24ee730e4ef47530f1338e41dc5bf37e1d8eeb7fc4
SHA-256 (normalized text)
f9fc26907979dcc75b0e34eab44b750ad1061c35d4da5bfe63e2ce7eac88916f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Customer Data
Processing Agreement
Customer Data Processing Agreement

                                               DATA PROCESSING AGREEMENT

   Each Party confirms that it has read this Data Processing Agreement and agrees to be bound by it.

   BACKGROUND

   (A)       The Data Protection Laws requires that Processing by a Processor be governed by a contract that
             stipulates certain contractual obligations.

   (B)       The terms of this Data Processing Agreement only apply to the extent that Zen is Processing Personal
             Data on behalf of the Customer.

   1.        EFFECTIVE DATE

   1.1.      The terms of this Data Processing Agreement shall apply with effect from the date on which Zen
             commences Processing of Personal Data on behalf of Customer.

   2.        DEFINITIONS AND INTERPRETATION

    Adequacy Regulation                  means any valid adequacy regulation as referred to in Article 45 of the UK GDPR

    Customer                             the party contracting with Zen under the Services Agreement

    Controller                           as defined in the applicable Data Protection Laws from time to time

    Processor                            as defined in the applicable Data Protection Laws from time to time

    Data Subject                         as defined in the applicable Data Protection Laws from time to time

    Personal Data                        as defined in the applicable Data Protection Laws from time to time

    Personal Data Breach                 as defined in the applicable Data Protection Laws from time to time

    Processing                           as defined in the applicable Data Protection Laws from time to time and (and
                                         related expressions, including process, processed and processes shall be
                                         construed accordingly)

    Data Protection Laws                  the:

                                         (a)       the EU GDPR;

                                         (b)       the UK GDPR and the UK DPA 2018;

                                         (c)       any laws which implement or supplement any such laws; and

                                         any laws that replace, extend, re-enact, consolidate or amend any of the foregoing

    Data Protection Regulator            any local, national or multinational agency, department, official, parliament,
                                         public or statutory person or any government or professional body, regulatory or

   © Zen Internet Limited
   Dated: 25.11.2022
Customer Data Processing Agreement

                                         supervisory authority, board or other body responsible for administering Data
                                         Protection Laws

    EU GDPR                              the General Data Protection Regulation, Regulation (EU) 2016/679)

    GDPR                                 the EU GDPR and UK GDPR (as applicable in the circumstances)

    Lawful Safeguards                    means such legally enforceable mechanism(s) for Transfers of Personal Data as
                                         may be permitted under Data Protection Laws from time to time

    Products                             Any services and/or equipment provided by Zen to the Customer

    Services Agreement                   any agreement under which Zen provides Products to the Customer

    Sub-Processor                        any Processor engaged by Zen (or by any other Sub-Processor) for carrying out
                                         any Processing activities in respect of the Personal Data on behalf of the Customer

    Transfer                             has the same meaning as the word ‘transfer’ in Article 44 of the GDPR. Related
                                         expressions such as Transfers, Transferred and Transferring shall be construed
                                         accordingly

    UK DPA 2018                          the United Kingdom’s Data Protection Act 2018

    UK GDPR                              the meaning given to that term in the UK DPA 2018

    UK Personal Data                     means any Personal Data to which the UK GDPR and UK DPA 2018 apply

   3.        Compliance with Law

   3.1.      The Customer shall, at all times, comply with all Data Protection Laws in connection with the Processing
             of Personal Data. The Customer shall ensure all instructions given by it to Zen in respect of Personal
             Data (including the terms of the Services Agreement) shall at all times be in accordance with all
             applicable law.

   3.2.      Zen acts as a Processor, and Customers and those entities (e.g., a customer of the Customer) that it
             permits to use the Products, act as Controllers under this Data Processing Agreement.

   4.        CHANGES TO THE CONTRACT

   4.1.      From the Effective Date, the provisions of this Data Processing Agreement shall apply in respect of all
             Personal Data processed by Zen as a Processor for the Customer.

   4.2.      The terms of the Services Agreement which apply to the Processing of Personal Data shall remain in
             force, however if these conflict with the provisions of this Data Processing Agreement, the provisions of
             the Data Processing Agreement shall prevail.

   © Zen Internet Limited
   Dated: 25.11.2022
Customer Data Processing Agreement

   4.3.      Other than as set out in this Clause 4, all other provisions of the Services Agreement shall remain in full
             force and effect.

   5.         INSTRUCTIONS

   5.1.      Schedule 1 sets out the scope, nature and purpose of Processing by Zen, the duration of Processing, the
             types of Personal Data and categories of Data Subject.

   5.2.      Zen shall not Process Personal Data other than on the Customer’s documented instructions (including
             the Services Agreement) unless Zen must do so to comply with any applicable law, in which case Zen
             will inform the Customer before Processing unless prohibited by applicable law from doing so.
   5.3.      The Customer shall ensure that it has all the necessary appropriate consents and notices in place to
             enable the lawful transfer of Personal Data to Zen for the purposes of the Services Agreement.
   5.4.      The Customer retains control of the Personal Data and remains responsible for its compliance
             obligations under the applicable Data Protection Laws, and for the Processing instructions it gives to
             Zen.

   6.        SUB-PROCESSING AND PERSONNEL

   6.1.      Subject to Clause 6.2, Zen shall not subcontract any Processing of Personal Data which Zen processes as
             a Processor on behalf of the Customer as a Controller within the scope of this Data Processing
             Agreement without the Customer’s prior consent.

   6.2.      The Customer hereby consents to Zen engaging (and/or dismissing) Sub-Processors listed on this page
             https://www.zen.co.uk/resources/docs/default-source/document-library/global-documents/personal-
             data-shared-with-third-parties.pdf?sfvrsn=af6df82d_4 to Process the Personal Data, provided that Zen
             shall:

             (a)        Provide Customer with notice in advance of any intended additions or replacements to the list
                        of Sub-Processors including full details regarding such Sub-Processor;

             (b)        Customer may object to the new Sub-Processor appointed by Zen if the Customer, in its
                        reasonable discretion, believes that such new Sub-Processor in Processing the Personal Data
                        would not comply with applicable Data Protection Laws, in which case the parties agree to
                        negotiate in good faith a mutually agreeable alternative; and

             (c)        If the objection is valid and no such alternative is agreed within 30 days of the objection, the
                        Customer will have the right to terminate, without penalty, any Products or services for which
                        Personal Data would be Processed by the new Sub-Processor against which the objection was
                        raised. If the Customer does not terminate within this 30 day period, Customer is deemed to
                        have accepted the new Sub-Processor.

   © Zen Internet Limited
   Dated: 25.11.2022
Customer Data Processing Agreement

   6.3.       Zen shall enter into a written contract with each Sub-Processor that:

             (a)        contains terms materially the same terms as those set out in this Data Processing Agreement,
                        in particular, in relation to requiring appropriate technical and organisational data security
                        measures, and, upon the Customer’s written request, provides the Customer with copies of
                        such contracts;

             (b)        remain fully liable to the Customer under this Data Processing Agreement for all the acts and
                        omissions of each Sub-Processor as if they were its own; and

             (c)        ensure that all persons authorised by Zen or any Sub-Processor to process Personal Data are
                        subject to a binding written contractual obligation to keep the Personal Data confidential.

   7.        International Transfers

   7.1.      The Customer consents to the Transfer and Processing of Personal Data by Zen outside the European
             Economic Area (EEA) and in the case of UK Personal Data, outside the United Kingdom provided that:

             (a)        Zen, or its approved Sub-Processor, is Processing Personal Data in a territory which is subject
                        to a current finding by the European Commission that the territory provides adequate
                        protection for the privacy rights of individuals;

             (b)        In the case of UK Personal Data, Zen, or its approved Sub-Processor, is Processing UK Personal
                        Data in a territory which is subject to any valid Adequacy Regulation; or

             (c)        Zen, or its approved Sub-Processor, Transfers Personal Data by way of Lawful Safeguards.

   8.        SECURITY

   8.1.      Zen shall adopt and maintain appropriate technical and organisational measures to ensure Personal
             Data is kept secure in accordance with our independently validated ISO 27001 (“Security Policy”).
             Customer is responsible for reviewing the information made available by Zen relating to data security
             and making an independent determination as to whether the Products meet Customer’s requirements
             and legal obligations under Data Protection Laws. Zen may review and update its Security Policy from
             time to time, provided that any such updates shall not materially diminish the overall security of the
             Products or Personal Data.

   © Zen Internet Limited
   Dated: 25.11.2022
Customer Data Processing Agreement

   8.2.      Zen shall ensure that all personnel authorised by Zen or a Sub-Processor to Process Personal Data are:

                        (i)       informed of the confidential nature of the Personal Data and are bound by
                                  confidentiality obligations and use restrictions in respect of the Personal Data;

                        (ii)      are aware both of Zen’s duties and their personal duties and obligations under the
                                  Data Protection Laws and this Data Processing Agreement.

   9.        ASSISTANCE

   9.1.       Zen shall on request;

             (a)        provide all information and assistance reasonably required by the Customer to enable it to
                        comply with the Data Protection Laws in relation to Personal Data, including but not limited
                        to the exercise of the rights of Data Subjects;

             (b)        provide reasonable assistance (taking into account the nature of the Processing and
                        information available to Zen) to the Customer in ensuring compliance with the Customer’s
                        obligations under Data Protection Laws with respect to:

                        (i)       security of Processing;

                        (ii)       any data privacy impact assessments (as such term is defined in Data Protection
                                  Laws);

                        (iii)     prior consultation with a Data Protection Regulator; and

                        (iv)      notifications to the Data Protection Regulator and/or communications to Data
                                  Subjects by the Customer in response to any Personal Data Breach,

                        provided the Customer shall pay Zen’s reasonable costs for the work, time, and expenses

                        incurred by Zen or any Sub-Processor(s) in connection with providing the assistance in this

                        Clause 9.1 at the rates set out in Zen’s standard rates that are available upon request.

             (c)        ensure that it has adequate processes and systems in place to comply with its obligations
                        under this Clause 9.1;

             (d)        as soon as reasonably possible, and in any event without undue delay, notify the Customer
                        with full details if it:

                        (i)       becomes aware of any Personal Data Breach in relation to the Services Agreement;

                        (ii)      believes that instructions provided by the Customer in respect of the Processing of
                                  Personal Data are contrary to or would require it to act in a way contrary to the Data
                                  Protection Laws and/or applicable law; or

   © Zen Internet Limited
   Dated: 25.11.2022
Customer Data Processing Agreement

                        (iii)   receives any request (including from an individual or the Data Protection Regulator)
                                to disclose any Customer Personal Data.

   10.        AUDITS

   10.1.     Zen shall, in accordance with Data Protection Laws, make available to the Customer on request such
             information that is in its possession or control as is necessary to demonstrate Zen’s compliance with the
             obligations placed on it under this Data Processing Agreement and to demonstrate compliance with the
             obligations on each party imposed by Article 28 of the GDPR, and allow for and contribute to audits,
             including inspections, by the Customer (or another auditor mandated by the Customer) for this purpose
             (subject to a maximum of one audit request in any 12 month period under this Clause 10). To the extent
             consistent with the forgoing, Zen shall, however, be entitled to withhold information where it is
             commercially sensitive or confidential to it or its other customers.
   10.2.     The Customer will provide at least 30 days’ written notice of an audit, including details on the scope
             and any required evidence. Zen reserves the right to charge for any reasonable costs incurred for its
             preparation and compliance with the audit.

   11.       DELETION OF PERSONAL DATA

   11.1.     Upon Customer’s request or instruction, or on termination of the Services Agreement, amend, transfer,
             delete, or otherwise process the Personal Data, or provide all Customer Personal Data to the Customer
             and/or securely delete that Personal Data, other than where applicable law requires Zen to retain it.

   12.       GENERAL

   12.1.     This Data Processing Agreement shall survive the termination or expiry of the Services Agreement to
             the extent that Zen continues to Process Personal Data on behalf of the Customer.

   © Zen Internet Limited
   Dated: 25.11.2022
Customer Data Processing Agreement

   SCHEDULE 1
   PERSONAL DATA SCHEDULE

    Subject matter of the Processing       As required and further described in the Services Agreement.

    Duration of the Processing             Until the earlier of final termination or final expiry of our
                                           Agreement, except as otherwise expressly stated in relevant
                                           Services Agreement.

    Nature and purpose of the Processing   Processing as reasonably required to provide the Products as
                                           described in the relevant Services Agreement

    Type of Personal Data

                                           Customer Personal Data required to provide the Products in the
                                           Services Agreement, which may include:

                                           Identity and contact information:

                                               •   Full name

                                               •   Email addresses

                                               •   Personal phone number

                                               •   Homeworker IP address

    Categories of Data Subjects            The Data Subjects may include the Customer’s authorised users,
                                           employees, suppliers, customers (“End Users”) and other Data
                                           Subjects as detailed in the Services Agreement.

   © Zen Internet Limited
   Dated: 25.11.2022