Legal
Data Processing Agreement
Last updated: [ dd/mm/yyyy ]
This agreement sets out how Output IQ processes personal data on behalf of its customers, as required by Article 28 of the UK GDPR. It forms part of your Order and applies for as long as we hold your data.
Parties and roles
This agreement is between Output IQ, a trading name of [ Company name ] Ltd, a company registered in England & Wales (company no. [ 00000000 ]), registered office [ address ] ("the Processor"), and the customer named in the Order ("the Controller").
You decide what personal data goes into the platform and why. We process it only on your documented instructions, which include this agreement and your Order.
What we process, and why
We process personal data in order to run the Output IQ platform for you. That means storing, structuring, retrieving, using, transmitting, backing up and deleting it.
The data typically includes:
- Names, job titles and business contact details of your staff.
- Access credentials and authentication data.
- Records of activity in the system, including time bookings, job records and audit logs.
- Names and business contact details of your own customers and suppliers.
- [ Confirm whether payroll or HR data is in scope, since the platform feeds payroll hours. ]
[ Confirm that no special category data under Article 9 is processed. If health, biometric or similar data can be entered anywhere in the platform, this section must say so. ]
Where it is held
All processing takes place in the United Kingdom. Hosting is provided by Fasthosts. Each customer has their own database rather than shared tables.
Backups are taken daily, kept for thirty days, and held in UK cloud storage separate from the live database.
No personal data is transferred outside the United Kingdom, except as set out below.
Sub processors
We use the following sub processors:
- Fasthosts Internet Ltd, for hosting and infrastructure, in the United Kingdom.
- [ AI provider legal name ], to process a question when someone chooses to use the AI assistant, in [ location, and confirm whether the UK or EU endpoint is used ].
- [ Backup storage provider, if it is not Fasthosts. ]
The AI sub processor receives only the content of the question a user submits to the assistant. It does not receive your database.
[ Confirm against that provider's terms whether submitted content is retained, and whether it is used to train models. If it is, this section must say so plainly, and so must the security section on the Platform page. ]
We will give you at least [ 30 ] days notice before adding or replacing a sub processor, and you may object during that period.
How we protect it
- Encrypted in transit and at rest.
- A separate database for each customer, rather than shared tables.
- Role based access control, with multi factor authentication and single sign on available on every plan.
- Audit logging of access and changes.
- Daily backups with a thirty day history, held separately from the live database.
- Penetration testing and security review, carried out internally.
- [ Confirm password policy and session timeout. ]
- [ Confirm who at Output IQ can access customer data, under what approval, and whether that access is logged. ]
Getting your data back, and deletion
You can export your records at any time, in full. If you leave, we help you take a complete copy with you.
We hold your data for ninety days after termination and then delete it. If you want it deleted sooner, ask, and we will do so within [ 30 ] days of the request. Backups containing your data are overwritten on the ordinary thirty day cycle.
Helping you meet your own obligations
We help you respond to data subject requests, carry out data protection impact assessments, and consult the ICO where you need to, taking account of the nature of the processing and what we know.
If a data subject contacts us directly, we pass the request to you without undue delay rather than acting on it ourselves.
If something goes wrong
If there is a personal data breach affecting your data, we will tell you without undue delay and in any event within [ 24 hours ] of becoming aware of it, with the information you need to meet your own reporting duties.
Audit
We will give you the information you need to show that we meet Article 28, and allow audits by you or an auditor you appoint, on reasonable notice and no more than [ once a year ] unless a regulator requires otherwise.
Confidentiality
Everyone authorised to process your data is bound by confidentiality.
How this fits with your Order
This agreement forms part of your Order. Where the two conflict on data protection, this agreement takes precedence. Liability is as set out in your Order.
See also our Privacy Policy and Terms of Service.