Legal

    Data Processing Addendum

    1. BACKGROUND

    1.1 This Data Processing Addendum ("DPA") forms part of the agreement between Gateway Product Solutions Ltd, trading as Gateway AI ("Processor", "we", "us", "our") and the customer ("Controller", "you", "your") for the provision of the Gateway CRM software-as-a-service platform and associated services (the "Services").

    1.2 This DPA sets out the terms that apply when we process personal data on your behalf in the course of providing the Services.

    2. DEFINITIONS

    2.1 For the purposes of this DPA:

    • Data Protection Laws means all applicable data protection and privacy legislation in force from time to time in the UK, including the UK GDPR, the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended.
    • UK GDPR has the meaning given to it in section 3(10) (as supplemented by section 2054) of the Data Protection Act 2018.
    • The terms controller, processor, data subject, personal data, personal data breach, processing, and appropriate technical and organisational measures shall have the meaning given to them in the UK GDPR.

    3. ROLES AND RESPONSIBILITIES

    3.1 Both parties will comply with all applicable requirements of the Data Protection Laws. This DPA is in addition to, and does not relieve, remove, or replace, a party's obligations or rights under the Data Protection Laws.

    3.2 The parties acknowledge that for the purposes of the Data Protection Laws, you are the controller and we are the processor of the personal data processed in connection with the Services.

    4. PROCESSING OF PERSONAL DATA

    4.1 We shall only process personal data on your documented written instructions, unless required by domestic law to otherwise process that personal data. Where we are relying on domestic law as the basis for processing personal data, we shall promptly notify you of this before performing the processing required by the domestic law unless the domestic law prohibits us from so notifying you.

    4.2 The types of personal data and categories of data subjects processed under this DPA include the contact details, communications, and CRM records of your customers, leads, and staff, as determined by your use of the Services.

    5. PERSONNEL AND SECURITY

    5.1 We shall ensure that all personnel who have access to and/or process personal data are obliged to keep the personal data confidential.

    5.2 We shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

    6. SUB-PROCESSORS

    6.1 You consent to us appointing third-party sub-processors to process personal data in connection with the Services. We will ensure that any sub-processor is subject to a written agreement fulfilling the requirements of Article 28(3) of the UK GDPR.

    6.2 We shall remain fully liable to you for the performance of the sub-processor's data protection obligations.

    7. ASSISTANCE AND AUDITS

    7.1 We shall assist you, at your cost, in responding to any request from a data subject and in ensuring compliance with your obligations under the Data Protection Laws with respect to security, breach notifications, impact assessments, and consultations with supervisory authorities or regulators.

    7.2 We shall notify you without undue delay on becoming aware of a personal data breach.

    7.3 At your written direction, we shall delete or return personal data and copies thereof to you on termination of the agreement unless required by domestic law to store the personal data.

    7.4 We shall make available to you all information necessary to demonstrate our compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or your designated auditor.

    8. INTERNATIONAL TRANSFERS

    8.1 We may transfer personal data outside of the UK as necessary to provide the Services, provided that we ensure such transfers comply with the Data Protection Laws (for example, by relying on an adequacy decision or standard contractual clauses).