1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Agreement between Customer and Sanmarris where Sanmarris processes personal data on behalf of Customer in providing the Service. Customer acts as controller/business or equivalent decision-maker for Customer Personal Data, and Sanmarris acts as processor/service provider where those concepts apply. Each party remains responsible for processing it performs as an independent controller.
2. Processing details
Subject matter: provision, support, security and administration of the subscribed Sanmarris Service.
Duration: the Agreement term plus the period reasonably required for return, deletion, backup expiry or legal retention.
Nature and purpose: hosting, storing, organising, transmitting, retrieving, securing, supporting and otherwise processing Customer Personal Data as required to provide the Service and documented instructions.
Data subjects: may include Customer employees, contractors, users, customers, suppliers, visitors, community members or other individuals whose information Customer submits to the Service.
Data types: depend on Customer configuration and may include identifiers, contact/business details, account information, workforce or operational records, location/site relationships, asset/work records, safety or incident-related information, communications and technical usage data. Customer must not submit special-category/sensitive data unless the Service and Agreement expressly support that processing.
3. Documented instructions
Sanmarris will process Customer Personal Data only on Customer’s documented instructions, including the Agreement, Orders, configuration choices and lawful written instructions, unless applicable law requires otherwise. Sanmarris will inform Customer if it believes an instruction infringes applicable data-protection law, where permitted.
4. Confidentiality and security
Sanmarris will ensure personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and will maintain technical and organisational measures appropriate to the risk. Measures may include access controls, authentication, encryption in transit, logging, backup/recovery, secure development and vulnerability-management practices as applicable to the Service.
5. Subprocessors
Customer provides general authorisation for Sanmarris to engage subprocessors necessary to provide the Service. Sanmarris will maintain a current Subprocessors page and impose data-protection obligations on subprocessors appropriate to their processing. For material new subprocessors that process Customer Personal Data, Sanmarris will provide reasonable notice where required by applicable law or contract, allowing Customer to raise reasonable data-protection objections.
6. Data-subject requests
Taking into account the nature of processing, Sanmarris will provide reasonable assistance to Customer with requests by individuals to exercise applicable data-protection rights. If Sanmarris receives a request relating to Customer Personal Data, it may direct the requester to Customer unless law requires Sanmarris to respond directly.
7. Personal data breaches
Sanmarris will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data where notification is required under applicable processor obligations. Sanmarris will provide information reasonably available to assist Customer with its assessment and notification duties. Notification does not constitute an admission of fault or liability.
8. Compliance assistance
Taking into account the nature of processing and information available to Sanmarris, Sanmarris will provide reasonable assistance with Customer’s applicable security, breach-notification, data-protection impact assessment and regulator-consultation obligations relating to the Service.
9. International transfers
Customer authorises processing in the countries identified through the Subprocessors page and applicable service documentation, subject to applicable transfer requirements. Where GDPR applies to a restricted transfer requiring safeguards, the parties will incorporate the applicable European Commission Standard Contractual Clauses using the module appropriate to their roles. Where UK GDPR requires a transfer mechanism, the parties will use the applicable UK transfer mechanism. Australian cross-border handling remains subject to applicable Privacy Act obligations.
The parties will reasonably cooperate with transfer assessments and supplementary safeguards where legally required.
10. Information and audits
Sanmarris will make information reasonably necessary to demonstrate compliance with applicable processor obligations available to Customer. Where required by applicable law and reasonable documentary evidence is insufficient, Customer may request an audit subject to reasonable advance notice, confidentiality, security controls, non-disruption requirements and limitations designed to protect other customers. The parties may agree reasonable costs for audits beyond ordinary compliance support.
11. Return and deletion
At Customer’s choice and subject to Service functionality, Sanmarris will return or delete Customer Personal Data after termination when required by applicable law, except information Sanmarris must retain by law. Residual backup copies may remain until overwritten under normal backup cycles and remain protected by this DPA while retained.
12. Order of precedence
If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA controls to the extent of that conflict. Mandatory data-protection terms and incorporated transfer clauses prevail where required by law.