Draft for review · not legal advice
Data Processing Addendum — outline
Version: draft · Last reviewed: — · Owner: Staffgent
A draft OUTLINE of the processor terms for client personal data. This is a skeleton to be completed and reviewed by a solicitor; it is not a signed agreement.
1. Roles
For the client business data and lead/prospect data inside your workspace, the client is the data controller and Staffgent is the processor, acting on the client’s documented instructions.
2. Scope of processing (to be completed)
- Subject matter: provision of the AI lead-research and CRM service.
- Duration: for the term of the subscription plus the retention grace period.
- Nature & purpose: research, scoring, drafting and CRM management for the controller's approval.
- Types of personal data: business contact details and public professional information of prospects; controller's own users.
- Categories of data subject: the controller's prospects and staff/users.
3. Processor obligations (draft)
- Process only on documented instructions from the controller.
- Ensure confidentiality of personnel with access.
- Implement appropriate technical and organisational security measures (see Security overview).
- Engage subprocessors only under equivalent terms and with notice (see Subprocessor list).
- Assist the controller with data-subject requests and with security/breach obligations.
- Delete or return personal data at the end of the service, subject to legal retention.
- Make available information needed to demonstrate compliance.
4. International transfers
Where a subprocessor processes data outside the UK/EEA, an appropriate transfer mechanism (e.g. standard contractual clauses) is to be identified and referenced here on review.
5. Sub-processing
The current subprocessors are listed on the Subprocessor page. The controller will be notified of intended changes so it may object.
6. Deletion & return
On offboarding, workspace data is retained for the grace period, then deleted or anonymised on explicit confirmation. Billing and audit records are retained where legally required and are never cascade-deleted.
Status
This outline is incomplete by design. A qualified adviser must finalise the annexes, security schedule, liability and transfer mechanisms before execution.