Data Processing Terms
How we handle personal data when we work inside your systems.
These terms apply where 64TEQ processes personal data on the Customer's behalf under an Order. They are also published at 64teq.com and apply where the Terms of Business say they do. Terms defined in the UK GDPR have the same meaning here.
Data Processing Terms
1. Roles and details of processing
1.1The Customer is the controller and 64TEQ is the processor of the personal data 64TEQ processes in performing the Services. The details of the processing are set out below and may be supplemented in an Order.
| Subject | Details |
|---|---|
| Subject matter | Provision of the Services, including administration, monitoring, support and maintenance of the Customer's systems |
| Duration | The duration of the relevant Order, plus the period in paragraph 7.1 |
| Nature and purpose | Accessing, storing, monitoring, backing up, restoring, configuring and supporting systems that contain personal data, so as to provide the Services |
| Types of personal data | Names, contact details, user identifiers, credentials, device and usage data, email and file content and any other personal data held in the Customer's systems |
| Categories of data subject | The Customer's staff, contractors, customers, suppliers and other people whose data is held in the Customer's systems |
Two entries in this table, the remote monitoring tool and the service desk tool used by Next2IT, are being confirmed and will be named here. Paragraph 4.2 applies to any change to this list.
2. 64TEQ's obligations
2.164TEQ will:
- 2.1.1process the personal data only on the Customer's documented instructions, which include the Order and this agreement, unless the law requires otherwise, in which case 64TEQ will tell the Customer before processing unless the law prevents it;
- 2.1.2tell the Customer if, in its opinion, an instruction infringes data protection law;
- 2.1.3ensure that the people it authorises to process the personal data are bound by confidentiality;
- 2.1.4implement the technical and organisational measures in paragraph 3.1 and any others agreed in an Order;
- 2.1.5engage sub processors only in accordance with paragraph 4.1;
- 2.1.6transfer personal data outside the United Kingdom only in accordance with paragraph 5.1;
- 2.1.7taking into account the nature of the processing, assist the Customer with appropriate measures to respond to requests from data subjects;
- 2.1.8assist the Customer in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner, taking into account the nature of the processing and the information available to 64TEQ;
- 2.1.9tell the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the personal data, and give the Customer the information it reasonably needs to meet its own obligations;
- 2.1.10delete or return the personal data in accordance with paragraph 7.1; and
- 2.1.11make available to the Customer the information needed to demonstrate compliance with this Schedule and allow for audits under paragraph 6.1.
2.2Assistance under this paragraph beyond what 64TEQ can reasonably provide within the Charges is chargeable at 64TEQ's standard rates.
3. Security measures
3.164TEQ will maintain measures appropriate to the risk, including: access control based on least privilege, with multi factor authentication on administrative access; unique accounts for its people and logging of administrative activity; encryption of personal data in transit and, where its tools allow, at rest; secure handling and storage of credentials; vetting and security training of its people; endpoint protection and patching of its own systems; documented incident response; and any certification stated in an Order.
4. Sub processors
4.1The Customer gives 64TEQ general authorisation to engage sub processors. The sub processors engaged at the date of this agreement are:
| Sub processor | Purpose | Location |
|---|---|---|
| Next2IT | Delivery of managed services and technical support | United Kingdom |
| Microsoft | Cloud services, email and productivity tools used to deliver the Services, and the Customer's own Microsoft cloud subscriptions | United Kingdom and European Union, with Microsoft's standard safeguards |
| To be confirmed | Monitoring and management of the Customer's systems | To be confirmed |
| To be confirmed | Logging and managing incidents and requests | To be confirmed |
4.264TEQ will tell the Customer in writing at least 30 days before it adds or replaces a sub processor. The Customer may object on reasonable grounds relating to data protection within that period. If the parties cannot resolve the objection, the Customer may end the affected Order by written notice without paying an early termination charge, and 64TEQ may not use the new sub processor for that Customer before then.
4.364TEQ will impose on each sub processor data protection obligations that are no less protective than those in this Schedule, and remains responsible to the Customer for the sub processor's performance.
5. International transfers
5.164TEQ will not transfer personal data outside the United Kingdom, or allow a sub processor to, unless: the destination is covered by adequacy regulations under the UK GDPR; the transfer is made under the International Data Transfer Agreement or the Addendum to the EU standard contractual clauses issued by the Information Commissioner; or the transfer is made under another mechanism the UK GDPR allows. In each case 64TEQ will carry out any risk assessment the law requires.
6. Audit
6.1The Customer may audit 64TEQ's compliance with this Schedule once in any 12 month period, on at least 30 days' written notice, during Working Hours and in a way that does not disrupt 64TEQ's business or expose other customers' data. 64TEQ may satisfy an audit request by providing a written response, a recent independent audit report or relevant certifications. Audits beyond one a year, or following a personal data breach, are at the Customer's cost.
7. Deletion and return
7.1When an Order ends, 64TEQ will, at the Customer's choice, return or delete the personal data it holds for that Order within 30 days, and will delete remaining copies, unless the law requires it to keep them. Personal data in backups is deleted in the ordinary cycle of backup rotation and is not accessed in the meantime.
8. Liability
8.1Each party's liability under this Schedule is subject to clause 16 of the agreement.
64TEQ Limited is registered in England and Wales under company number 08353020. Registered office: Berkeley Square House, Second Floor, Berkeley Square, London W1J 6BD. VAT number GB 153 7421 19. 64TEQ® is a registered trade mark.

