Data processing · GDPR Article 28
Data Processing Addendum
This addendum governs personal data processed on a client behalf during an engagement. It is written to satisfy GDPR Article 28, the UK GDPR and the equivalent requirements a procurement team asks about before a vendor is approved.
Need a signed copy for procurement? This addendum is incorporated into every engagement agreement automatically. For a signed PDF, email [email protected] with "DPA" and your company name in the subject. Ця сторінка українською.
1Definitions
In this Data Processing Addendum, the following terms carry the meanings below.
- Controller, the client, who determines the purposes and means of processing.
- Processor, Solutions4sf, operated by Serhii Skrypnyk, a sole trader registered in Ukraine as an individual entrepreneur, who processes personal data on the controller’s behalf.
- Personal Data, any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
- Processing, any operation performed on personal data, including collection, storage, modification, retrieval, transmission or deletion.
- Sub-Processor, any third party engaged to process personal data in connection with the services.
- Data Subject, the person to whom the personal data relates.
- GDPR, Regulation (EU) 2016/679, and where applicable the UK GDPR and the Data Protection Act 2018.
- Services, the consulting, implementation, audit, training and support services provided under the master services agreement or statement of work.
2Scope and roles
This addendum applies whenever personal data is processed on the client’s behalf in the course of providing the services.
- The client is the controller of all personal data reached during the engagement.
- Solutions4sf is the processor under GDPR Article 28.
- This addendum is incorporated by reference into the master services agreement or statement of work.
- Where this addendum conflicts with another agreement, this addendum prevails on data protection matters.
3Subject matter and duration
Subject matter. Processing personal data as necessary to provide Salesforce, Account Engagement, RevOps consulting, audit, implementation, integration and related services.
Duration. For the length of the engagement defined in the statement of work, plus any reasonable period needed for handover, knowledge transfer or required record retention.
Nature and purpose. Configuring, auditing, integrating and migrating Salesforce and Account Engagement environments. Reading, structuring and, where instructed, modifying lead, contact, account and engagement data.
4Categories of data subject
Personal data processed under this addendum may relate to:
- The client’s employees and contractors, such as Salesforce users and marketing operations staff.
- The client’s prospects, leads and customers held in Salesforce or Account Engagement.
- The client’s website visitors whose data arrives through forms, tracking or campaign parameters.
- Any other individual whose data sits in the client’s CRM or marketing automation platform.
5Categories of personal data
Depending on the client’s configuration, this typically includes:
- Identifiers. Name, email address, telephone number, job title, company.
- Engagement data. Email opens, clicks, form submissions, page views, campaign responses.
- Lead and account attributes. Industry, company size, revenue band, source, score, grade.
- Communication content. Email content, automated message logs, conversation history where applicable.
- System data. Audit logs and configuration history, limited to what the work requires.
Special category data as defined in GDPR Article 9 is not intentionally processed, unless the statement of work requires it and enhanced safeguards accompany it. The client must give advance notice if such data may be present.
6Obligations as processor
6.1 Documented instructions
Personal data is processed only on the client’s documented instructions, including on international transfers, unless required otherwise by law, in which case the client is told of that requirement before processing unless the law forbids it.
6.2 Confidentiality
Anyone authorised to process personal data is bound by confidentiality, by contract or by statutory duty.
6.3 Security measures, Article 32
- Access control. Two factor authentication on every account handling client data, least privilege, and credentials held in a password manager.
- Encryption. Client systems reached over HTTPS only; credentials never stored in plain text.
- Endpoint security. Encrypted disks, current operating systems and security patches.
- Logging. Activity logs retained for incident investigation and audit.
- Network. No client work over public wireless networks.
- Backup. Periodic encrypted backups with tested recovery.
- Incident response. A defined procedure for security incidents and breach notification.
6.4 Sub-processors
Sub-processors may be engaged to support the services. The client gives general written authorisation, subject to clause 7.
6.5 Assistance with data subject rights
Reasonable technical and organisational assistance is given to the client in responding to requests under GDPR Articles 15 to 22.
6.6 Breach notification
The client is notified without undue delay and in any event within seventy two hours of becoming aware of a personal data breach affecting their data. The notice describes the nature of the breach, the approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point.
6.7 Impact assessments
Reasonable assistance is given with data protection impact assessments and prior consultation with supervisory authorities under GDPR Articles 35 and 36.
6.8 Audit
All information necessary to demonstrate compliance with this addendum is made available, and audits including inspections are supported. Four conditions apply:
- Thirty days written notice, except where a regulator or a breach makes it urgent.
- Conducted during normal business hours.
- Reasonable confidentiality protection for other clients.
- The client bears the reasonable cost of the audit.
6.9 Return or deletion
On termination, personal data is returned or deleted at the client’s choice, except where law requires retention. Written confirmation of deletion is provided within thirty days of the request.
7Sub-processors
The client authorises the sub-processors listed in the privacy policy, which currently cover hosting, content delivery, the customer relationship platform, analytics and email.
At least thirty days notice is given before a sub-processor that touches client personal data is added or replaced. The client may object on reasonable data protection grounds, and if the objection cannot be resolved within thirty days the client may terminate the affected services.
Each sub-processor is bound by written obligations no less protective than those in this addendum.
8International transfers
Solutions4sf is based in Ukraine. The client may be in the EU, the UK, the United States or elsewhere, so international transfers may occur.
For transfers from the EEA, the UK or Switzerland, the following are relied on:
- Standard Contractual Clauses as adopted by the European Commission in Decision 2021/914, incorporated into this addendum where applicable.
- The UK International Data Transfer Addendum for transfers from the United Kingdom.
- Adequacy decisions where they apply.
- Supplementary measures including encryption in transit and at rest.
9Liability
Liability under this addendum is subject to the limits set out in the master services agreement or statement of work, except where data protection law provides otherwise, including GDPR Article 82 on compensation.
10Term and termination
This addendum takes effect when the underlying services agreement is executed and remains in force for as long as personal data is processed on the client’s behalf. Clauses 6.9, 7, 8 and 9 survive termination.
11Conflict and severability
If any provision is invalid or unenforceable the rest remains in force, and the invalid provision is replaced by one achieving the same intent within the law. This addendum is the complete agreement on data processing and supersedes any earlier data processing terms unless explicitly retained.
12Contact
For data protection enquiries, a signed copy, breach notification or audit coordination, email [email protected] with "DPA" and your company name in the subject.
Solutions4sf is operated by Serhii Skrypnyk, sole trader, registered in Ukraine as an individual entrepreneur.