Skip to main content

Legal

Data Processing Agreement

Our Article 28 processor terms: scope, security measures, sub-processors, international transfers, audit rights, and deletion on termination.

Version
1.0
Last reviewed
Governing law
England and Wales

This Data Processing Agreement applies whenever we process personal data on your behalf, and satisfies the written-contract requirement in Article 28(3) of the UK and EU GDPR. It is incorporated automatically into our Terms of Service — no separate signature is needed, though we will happily execute a countersigned copy on request.

1. Parties and Roles

You (the Controller) determine the purposes and means of processing. Etraders Group Ltd (the Processor) processes personal data only on your documented instructions. Where we determine purposes ourselves — for example, in relation to our own client records — we act as an independent controller and our Privacy Policy applies instead.

2. Subject Matter, Duration, Nature and Purpose

  • Subject matter: the processing necessary to deliver the services described in the applicable statement of work.
  • Duration: the term of the engagement, plus the return or deletion period in section 11.
  • Nature and purpose: hosting, storage, transmission, analysis, testing, migration, support, and, where the engagement requires it, AI-assisted processing.

3. Types of Personal Data and Categories of Data Subject

These vary by engagement and are specified in the statement of work. Typically:

  • Data subjects: your employees and contractors; your customers and end users; your suppliers; and, for recruitment engagements, candidates.
  • Data types: identity and contact details; account and authentication data; transaction and billing records; support and conversation content; usage and device data; and, for recruitment, CV and assessment data.
  • Special category data: processed only where the statement of work expressly provides for it and additional safeguards are agreed in writing.

4. Our Obligations as Processor

We will:

  1. process personal data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we will tell you first, unless the law prohibits it;
  2. immediately inform you if, in our opinion, an instruction infringes data protection law;
  3. ensure that everyone authorised to process the data is under a binding duty of confidentiality;
  4. implement the technical and organisational measures required by Article 32, as described in section 6;
  5. respect the conditions in section 7 for engaging sub-processors;
  6. assist you, by appropriate measures, in responding to data subject rights requests;
  7. assist you with security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority (Articles 32 to 36);
  8. at your choice, delete or return the personal data at the end of the engagement, as set out in section 11; and
  9. make available the information necessary to demonstrate compliance and allow for audits, as set out in section 10.

5. Your Obligations as Controller

You warrant that you have a lawful basis for the processing you instruct, that you have given the required privacy information to data subjects, and that you have obtained any necessary consents. You are responsible for the accuracy and lawfulness of the data you provide, and for ensuring that instructions to us comply with applicable law. Please do not send us personal data we do not need — particularly production data for development work, where anonymised or synthetic data will usually do.

6. Security Measures

We maintain measures appropriate to the risk, including:

  • encryption of personal data in transit (TLS 1.2 or above) and at rest;
  • role-based, least-privilege access control, with multi-factor authentication on administrative accounts;
  • credentials held in a managed secret store, rotated on a defined schedule and on personnel changes;
  • audit logging of access to systems containing personal data;
  • separated development, staging, and production environments, with anonymised or synthetic data used in non-production wherever feasible;
  • automated dependency and vulnerability scanning in our build pipeline;
  • documented backup and restoration procedures, with restoration tested rather than assumed;
  • written confidentiality agreements and data protection training for all personnel; and
  • a documented incident response procedure.

7. Sub-Processors

You give general authorisation for us to engage sub-processors, subject to the conditions below. Our current sub-processors are listed on the sub-processors page.

  • We will give at least 30 days' notice before adding or replacing a sub-processor.
  • You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected services without penalty and receive a refund of prepaid fees for services not yet delivered.
  • Every sub-processor is bound by a written contract imposing obligations no less protective than this agreement.
  • We remain fully liable to you for the performance of our sub-processors.

8. International Transfers

Where personal data is transferred outside the UK or EEA, we rely on an adequacy decision covering the recipient, or on the UK International Data Transfer Agreement or UK Addendum, or on the EU Standard Contractual Clauses (2021/914) supported by a transfer risk assessment. We maintain Standard Contractual Clauses with every provider as a fallback rather than relying on an adequacy framework alone, so that a change in the status of any framework does not interrupt lawful transfer. Copies of the safeguards in place are available on request.

9. Personal Data Breaches

We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. We will not notify a supervisory authority or data subjects on your behalf unless you instruct us to, since that decision is yours to make as controller.

10. Audit and Information Rights

We will make available the information reasonably necessary to demonstrate compliance with Article 28. You may audit our processing no more than once in any 12-month period, on 30 days' written notice, at your cost, during business hours, subject to confidentiality and without unreasonable disruption to our operations or access to other clients' data. We may satisfy an audit request by providing a current independent assessment or certification where it covers the relevant scope. Where a regulator requires an audit, these restrictions do not apply.

11. Return and Deletion

On termination, and at your choice, we will return the personal data in a commonly used machine-readable format, or delete it. Unless you instruct otherwise in writing, we will delete it within 30 days of termination, and purge it from backups within a further 90 days as those backups expire on their normal cycle. We will confirm deletion in writing on request. We may retain data where required by law, in which case we will tell you what, why, and for how long, and continue to protect it under this agreement.

12. AI Processing

Where an engagement involves AI model providers, we will: name them in the statement of work; configure enterprise endpoints with training on your data disabled and zero or minimal retention; not submit special category data to a model provider without your express written instruction; and ensure that no decision with legal or similarly significant effect on an individual is made by fully automated means. Our AI Transparency Statement sets out the detail.

13. Liability and Precedence

Liability under this agreement is subject to the limitations in our Terms of Service, except where those limits cannot lawfully be applied to data protection obligations. Where this agreement conflicts with any other document, this agreement prevails on matters of data protection.

14. Requesting a Countersigned Copy

This agreement takes effect automatically when we begin processing on your behalf. If your procurement process requires a signed copy, or you need us to execute your own DPA instead, email privacy@etradersgroup.online and we will turn it around within 5 business days.