1.1 This Data Processing Addendum ("DPA") forms part of the agreement between Gateway Product Solutions Ltd, trading as Gateway AI ("Processor", "we", "us", "our") and the customer ("Controller", "you", "your") for the provision of the Gateway CRM software-as-a-service platform and associated services (the "Services").
1.2 This DPA sets out the terms that apply when we process personal data on your behalf in the course of providing the Services.
2.1 For the purposes of this DPA:
3.1 Both parties will comply with all applicable requirements of the Data Protection Laws. This DPA is in addition to, and does not relieve, remove, or replace, a party's obligations or rights under the Data Protection Laws.
3.2 The parties acknowledge that for the purposes of the Data Protection Laws, you are the controller and we are the processor of the personal data processed in connection with the Services.
4.1 We shall only process personal data on your documented written instructions, unless required by domestic law to otherwise process that personal data. Where we are relying on domestic law as the basis for processing personal data, we shall promptly notify you of this before performing the processing required by the domestic law unless the domestic law prohibits us from so notifying you.
4.2 The types of personal data and categories of data subjects processed under this DPA include the contact details, communications, and CRM records of your customers, leads, and staff, as determined by your use of the Services.
5.1 We shall ensure that all personnel who have access to and/or process personal data are obliged to keep the personal data confidential.
5.2 We shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
6.1 You consent to us appointing third-party sub-processors to process personal data in connection with the Services. We will ensure that any sub-processor is subject to a written agreement fulfilling the requirements of Article 28(3) of the UK GDPR.
6.2 We shall remain fully liable to you for the performance of the sub-processor's data protection obligations.
7.1 We shall assist you, at your cost, in responding to any request from a data subject and in ensuring compliance with your obligations under the Data Protection Laws with respect to security, breach notifications, impact assessments, and consultations with supervisory authorities or regulators.
7.2 We shall notify you without undue delay on becoming aware of a personal data breach.
7.3 At your written direction, we shall delete or return personal data and copies thereof to you on termination of the agreement unless required by domestic law to store the personal data.
7.4 We shall make available to you all information necessary to demonstrate our compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or your designated auditor.
8.1 We may transfer personal data outside of the UK as necessary to provide the Services, provided that we ensure such transfers comply with the Data Protection Laws (for example, by relying on an adequacy decision or standard contractual clauses).