Data Processing Addendum
Version 1.0.0.2 · SW11 Software Ltd
Provider: SW11 Software Ltd, company no. 16896573, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("SW11 Software").
Applies when: SW11 Software processes personal data on behalf of a business customer through ZeRaLD and this Addendum is incorporated into the customer's ZeRaLD service agreement.
1. Roles and scope
The customer is controller or processor, as applicable, for Customer Personal Data. SW11 Software acts as processor or subprocessor only to the extent it processes Customer Personal Data on the customer's documented instructions in providing ZeRaLD.
"Customer Personal Data" means personal data contained in customer-controlled project content or other material that the customer instructs ZeRaLD to process on its behalf. It does not include ordinary ZeRaLD account, authentication, security, legal-acceptance or service-administration data for which SW11 Software determines its own purposes as controller.
2. Documented instructions
SW11 Software will process Customer Personal Data only to provide, secure and support the ZeRaLD services in accordance with the service agreement, the customer's use of product controls and other documented lawful instructions, unless law requires otherwise. If legally permitted, SW11 Software will inform the customer before processing required by law.
The customer is responsible for ensuring its instructions and disclosure of Customer Personal Data to ZeRaLD are lawful.
3. Confidentiality
SW11 Software will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and access it only where required for their duties.
4. Security
SW11 Software will maintain technical and organisational measures appropriate to the risk, including access control, credential protection, scoped and expiring Handoff access, privileged administrative controls, logging/audit where appropriate, retention controls, vulnerability/update management and measures intended to prevent unauthorised disclosure or loss.
5. Subprocessors
The customer authorises SW11 Software to use the processors recorded in SW11 Software's maintained subprocessor register for the relevant service. SW11 Software remains responsible for imposing appropriate data-protection obligations on subprocessors it appoints for Customer Personal Data.
Where a customer independently chooses an AI provider or other recipient and instructs ZeRaLD to disclose project material to it, that recipient is not an SW11 Software subprocessor solely because ZeRaLD facilitates the customer's instruction.
SW11 Software will maintain an up-to-date subprocessor record and will provide reasonable notice of a material new SW11-appointed subprocessor where required by applicable law or the service arrangement, allowing the customer to raise a reasoned data-protection objection.
6. International transfers
SW11 Software will not make a restricted transfer of Customer Personal Data for which it is responsible without an applicable lawful transfer mechanism. Current primary ZeRaLD application/database hosting is in Germany (EEA). Customer-directed disclosures to independently selected recipients remain the customer's instruction and must be lawful.
7. Data-subject requests
Taking into account the nature of processing, SW11 Software will provide reasonable assistance to enable the customer to respond to requests from data subjects where Customer Personal Data processed by ZeRaLD is relevant. If SW11 Software receives a request relating solely to Customer Personal Data for which the customer is controller, SW11 Software may direct the requester to the customer unless law requires otherwise.
8. Personal-data breaches
SW11 Software will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed on the customer's behalf and will provide information reasonably available to support the customer's assessment and notification duties.
9. DPIAs and regulatory consultation
Taking into account the nature of processing and information available to it, SW11 Software will provide reasonable assistance with data-protection impact assessments and prior consultation required for the customer's use of ZeRaLD.
10. Deletion and return
On termination or a valid customer instruction, SW11 Software will delete or return Customer Personal Data within its control as applicable to the service, unless law requires retention. Temporary AI Handoff archives are subject to their expiry/revocation deletion lifecycle. Backup copies expire through the controlled backup rotation and remain protected until overwritten or deleted.
11. Audit information
SW11 Software will make available information reasonably necessary to demonstrate compliance with its processor obligations and will support proportionate audits or inspections where required by applicable data-protection law. Audits must protect other customers, security-sensitive information and SW11 Software confidential information and should use existing evidence before intrusive inspection unless that evidence is insufficient.
12. Processing details
Subject matter: provision of ZeRaLD deployment, server-management and customer-directed AI Handoff functionality.
Duration: for the period Customer Personal Data is processed under the service arrangement, including applicable deletion/backup lifecycle.
Nature: hosting, storage, retrieval, transmission when instructed, deployment-related processing, temporary Handoff packaging/access, deletion and security operations.
Purpose: provide the ZeRaLD functionality selected by the customer.
Data subjects: determined by the customer's project and may include the customer's staff, users, clients or other individuals represented in project content.
Personal-data types: determined by customer content; ZeRaLD does not require special-category data for ordinary service operation.
Customer rights and duties: determine lawful purposes and instructions; provide required notices and lawful bases; control project content and recipients; respond to data subjects; avoid uploading data unnecessary for the service.
13. Priority
If this Addendum conflicts with the service agreement on processing Customer Personal Data, this Addendum prevails to the extent of that conflict. Mandatory data-protection law prevails over both.
14. Contact
Data-protection enquiries and complaints can be raised through the account Privacy area or via the contact details in the Privacy Notice.
