Draft pending review. This document is being reviewed by the Northline admins and is not yet in force. Items in [brackets] are still to be decided.
Roles
For personal data you put into the Service, you are the controller and we are the processor. For account and billing data about you, we are the controller as described in our Privacy Policy.
Processing on your instructions
We process personal data only to provide the Service and on your documented instructions, including this addendum and your use of the product's features. We will tell you if we think an instruction breaks data-protection law.
Confidentiality and security
People with access to personal data are bound by confidentiality. We apply the technical and organisational measures described on our Security page, appropriate to the risk.
Subprocessors
You authorise us to use the subprocessors listed on our Subprocessors page. We will give at least [30] days' notice of changes so you can object on reasonable data-protection grounds.
International transfers
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as standard contractual clauses with our providers.
Assistance and breaches
We will help you respond to data-subject requests and carry out data-protection assessments where reasonably needed, and notify you without undue delay (target: within [72] hours) after becoming aware of a personal-data breach affecting your data.
Return and deletion
On termination we will let you export your data and then delete or anonymise it after [30] days, unless the law requires us to keep it.
Audits
On reasonable request and not more than once a year, we will provide information needed to show compliance with this addendum. [Admin to confirm audit terms.]