This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Main Agreement”) governing the Client’s access to and use of the Services.
This DPA is entered into between Routeon and the legal entity on whose behalf the Terms of Service and this DPA are accepted (the “Client”).
Each is a “Party” and together the “Parties”. This DPA becomes effective when the Main Agreement takes effect or when the Client first submits Customer Personal Data to the Services, whichever occurs first.
1. Definitions
1.1. “Account Data” means personal data relating to the Client, its personnel, representatives, authorised users, beneficial owners, payment contacts and other business contacts that Routeon processes for account administration, contracting, verification, billing, support, business communications, security, compliance and relationship management in Routeon’s own capacity as controller, data user, business or equivalent responsible party.
1.2. “Applicable Data Protection Law” means any privacy, data-protection, data-security, breach-notification, or similar law that applies to a Party’s Processing under the Main Agreement.
1.3. “Controller” means the party that determines the purposes and essential means of Processing and includes a controller, data user, business, organisation, covered entity or equivalent term under Applicable Data Protection Law.
1.5. “Customer Personal Data” means Personal Data Processed by Routeon on behalf of the Client through the Services, as described in Annex 1. It excludes Account Data, Routeon’s corporate records, and De-identified Data.
1.6. “Customer Personal Data Breach” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data Processed by Routeon. It excludes unsuccessful attempts or activities that do not compromise Customer Personal Data, such as scans, pings, blocked attacks, unsuccessful login attempts and denial-of-service attempts that do not result in unauthorised access.
1.7. “De-identified Data” means information that has been aggregated, anonymised or de-identified so that no individual or Client can reasonably be identified, taking account of the means reasonably likely to be used. De-identified Data does not include data that Applicable Data Protection Law continues to treat as Personal Data.
1.8. “Independent Network Provider” means a telecommunications carrier, mobile network operator, SMS aggregator, internet service provider, email or mailbox provider, domain or DNS provider, anti-abuse network, payment network, or similar recipient that independently determines material purposes or essential means of Processing, or Processes data under its own legal, regulatory, network-security or interoperability obligations.
1.9. “Personal Data” means information relating to an identified or identifiable individual, household or device, or any equivalent protected information under Applicable Data Protection Law.
1.10. “Process” and “Processing” have the meanings given under Applicable Data Protection Law and include collection, access, use, transmission, storage, disclosure, deletion and other handling of Personal Data.
1.11. “Processor” means a party that Processes Personal Data on behalf of and under the instructions of a Controller and includes a processor, service provider, contractor, operator or equivalent term under Applicable Data Protection Law.
1.12. “Regulated Data” means data subject to sector-specific, professional-secrecy, localisation, licensing or heightened-security requirements, including protected health information, payment-card data, financial-account credentials, biometric identifiers, government identification numbers, precise geolocation, children’s data, criminal-offence data and data protected by banking, telecom, employment, education or professional-confidentiality rules.
1.13. “Sensitive Data” means special-category, sensitive or highly sensitive Personal Data under Applicable Data Protection Law, including data revealing health, genetics, biometrics used for identification, race or ethnicity, religion, political or philosophical beliefs, trade-union membership, sex life or sexual orientation, and any equivalent category under applicable law.
1.14. “Service Data” means limited technical, operational, routing, delivery, usage, security, fraud, abuse, billing and diagnostic information generated through use of the Services. Service Data may contain Personal Data. Routeon processes Service Data as Processor where it is used solely to provide the Services on the Client’s behalf, and in Routeon’s own responsible capacity where Routeon determines the purpose of Processing for security, fraud and abuse prevention, billing, legal compliance, network integrity, enforcement and legal claims.
1.15. “Services” means Routeon’s URL-shortening, custom-link, link-management, link-in-bio, QR-code, analytics, SMS-routing and messaging, transactional and bulk-email routing and transmission, dashboards, application programming interfaces and related support services described in the Main Agreement.
1.16. “Subprocessor” means a third party engaged by Routeon to Process Customer Personal Data on behalf of the Client. An Independent Network Provider is not a Subprocessor to the extent it acts independently rather than on Routeon’s instructions.
2. Scope, application and order of precedence
2.1. This DPA applies only to Processing of Customer Personal Data by Routeon as Processor. It does not govern Account Data or other Personal Data for which Routeon acts in its own responsible capacity, which is governed by Routeon’s Privacy Notice and Applicable Data Protection Law.
2.2. The subject matter, duration, nature, purpose, categories of Personal Data and categories of individuals are set out in Annex 1 and the Main Agreement.
2.3. If a provision of this DPA conflicts with the Main Agreement regarding Processing of Customer Personal Data, this DPA prevails. The Main Agreement prevails for commercial matters, including fees, warranty disclaimers, suspension, indemnities, exclusions and limitations of liability, unless this DPA expressly states otherwise. Mandatory transfer clauses prevail to the extent of an irreconcilable conflict.
2.4. No provision of this DPA changes the factual role of either Party. A Party is a Controller or Processor according to its actual Processing activities and Applicable Data Protection Law, regardless of contractual labels.
3. Roles and compliance
3.1. For Customer Personal Data, the Client is the Controller and Routeon is the Processor. If the Client acts as a Processor for another Controller, Routeon acts as the Client’s Subprocessor, and the Client confirms that it is authorised to appoint Routeon and give the instructions in this DPA.
3.2. Each Party shall comply with the obligations directly applicable to it under Applicable Data Protection Law. Routeon is not responsible for the Client’s compliance obligations as Controller, sender, advertiser, website operator, employer, telecommunications user or electronic-marketing operator.
3.3. Where Applicable Data Protection Law uses different terminology, the terms of this DPA shall be interpreted to provide the closest legally recognised allocation of roles and obligations.
4. Client instructions
4.1. Routeon shall Process Customer Personal Data only on documented instructions from the Client, unless Processing is required by law. The Main Agreement, this DPA, the Client’s configuration of the Services, API calls, dashboard settings, support requests and other written directions consistent with the Main Agreement constitute the Client’s documented instructions.
4.2 The Client instructs Routeon to Process Customer Personal Data only as necessary to provide the Services selected, used or configured by the Client, including to:
a. host, transmit, organise, retrieve, maintain, troubleshoot, secure and support Customer Personal Data in connection with the Services;
b. create, shorten, redirect, manage and provide analytics for links and QR codes;
c. queue, route, transmit and deliver SMS, email and other communications submitted by or on behalf of the Client;
d. provide delivery, traffic and engagement reporting, including processing delivery failures, bounces, unsubscribe signals, complaints, opens and link interactions, where the relevant functionality is enabled by the Client; and
e. return, export or delete Customer Personal Data in accordance with this DPA, the Main Agreement, the Client’s account configuration.
4.3. Routeon may refuse, suspend or limit an instruction where Routeon reasonably believes that it: (a) violates Applicable Data Protection Law, the Main Agreement or the Acceptable Use Policy; (b) creates a material security, fraud, abuse, network-integrity or legal risk; (c) is technically infeasible; or (d) would materially change the Services. Routeon will inform the Client unless prohibited by law or where doing so would compromise security or an investigation.
4.4. If Routeon is legally required to Process Customer Personal Data other than on the Client’s instructions, Routeon shall inform the Client before the Processing unless the law prohibits notice for important public-interest reasons.
4.5. Any instruction outside the standard functionality or scope of the Services requires Routeon’s written agreement and may be subject to additional fees, technical assessment and modified terms.
5. Client obligations, warranties and restrictions
5.1. The Client is solely responsible for the lawfulness, fairness, transparency, accuracy, quality and proportionality of Customer Personal Data and the Client’s instructions. The Client warrants on an ongoing basis that:
- it has all rights, notices, consents, permissions, licences and other lawful authority required to collect, use and disclose Customer Personal Data to Routeon and to instruct the Processing;
- its use of the Services and each campaign complies with all applicable privacy, telecom, electronic-communications, direct-marketing, anti-spam, consumer-protection, advertising, sanctions, export-control and platform rules;
- recipient lists, telephone numbers, email addresses, device identifiers and contact details were obtained and are used lawfully and are not acquired through unlawful scraping, credential abuse, deception or purchased lists prohibited by law;
- it will provide every required notice and opt-out mechanism and promptly honour objections, unsubscribe requests, suppression requests and complaints;
- it determines and is responsible for message content, sender identity, subject lines, domains, destinations, timing, frequency and recipients;
- it has authority to use each sender ID, phone number, short code, brand, URL, domain and email domain used through the Services;
- it will not use the Services for unlawful surveillance, phishing, malware, deceptive redirects, impersonation, discriminatory targeting, harassment, prohibited content or other abuse;
- its instructions do not require Routeon to violate law, third-party rights, network requirements or the Main Agreement; and
- where it is a Processor, its Controller has authorised the Client to appoint Routeon and to provide the instructions in this DPA.
5.2. The Client shall maintain appropriate security for its accounts, credentials, API keys, tokens, domains, devices, systems and integrations; apply least-privilege permissions; promptly remove former users; and notify Routeon without undue delay of suspected compromise.
5.3. The Client shall not submit Sensitive Data or Regulated Data unless Routeon has expressly approved the specific Processing in a signed writing and the Parties have agreed any required security, localisation, transfer, sectoral or pricing terms. Approval for one category or use does not approve another.
5.4. Without Routeon’s prior written approval, the Client shall not use the Services to Process: payment-card authentication data; bank-account passwords; medical records subject to health-sector laws; biometric templates; precise geolocation for tracking; government identity documents in message content; data of children directed to them; criminal-offence files; or data subject to secrecy, localisation or licensing requirements that the Services are not designed to satisfy.
5.5. If Routeon reasonably suspects prohibited or unlawful data or activity, Routeon may suspend affected Processing, quarantine or delete data where necessary to prevent harm, require information from the Client, or terminate affected Services, without prejudice to other rights under the Main Agreement. Routeon will use reasonable efforts to minimise disruption where circumstances permit.
5.6. The Client shall not disclose Routeon’s security materials, audit evidence or Subprocessor confidential information except to personnel and advisers who need it for compliance and are bound by confidentiality.
6. Routeon Processing and use limitations
6.1. Routeon shall not: (a) sell or share Customer Personal Data for cross-context behavioural advertising; (b) use Client recipient lists or Client-created message content for Routeon’s own marketing; (c) build advertising profiles about recipients; or (d) disclose Customer Personal Data for a third party’s own direct marketing, except where expressly instructed by the Client and lawful.
6.2. Routeon may Process the minimum Service Data reasonably necessary in its own responsible capacity for account and platform security, fraud and abuse prevention, billing and usage calculation, network performance and integrity, compliance with law and provider requirements, investigation and enforcement, and establishment, exercise or defence of legal claims. Such Processing does not permit Routeon to repurpose recipient lists or message content for advertising or unrelated commercial profiling.
6.3. Routeon may create and use De-identified Data for security analytics, service reporting, capacity planning, benchmarking and improvement of the Services, provided Routeon: (a) takes reasonable measures to prevent re-identification; (b) does not attempt to re-identify it; and (c) does not disclose it in a manner that identifies the Client or an individual.
6.4. Routeon may access message content or Customer Personal Data only where reasonably necessary for delivery, troubleshooting, support requested by the Client, security, abuse investigation, legal compliance or enforcement. Access may be automated where practicable and human access shall be limited to authorised personnel with a need to know.
7. Confidentiality and personnel
7.1. Routeon shall ensure that personnel authorised to Process Customer Personal Data are subject to binding confidentiality obligations or an appropriate statutory duty of confidentiality and receive relevant privacy and security awareness training.
7.2. Routeon shall limit access to Customer Personal Data according to role, least privilege and business need, subject to operational and security requirements.
7.3. The confidentiality provisions of the Main Agreement apply to Customer Personal Data and security information disclosed under this DPA.
8. Security measures
8.1. Taking account of the state of the art, implementation costs, nature, scope, context and purposes of Processing, and the risk to individuals, Routeon shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
8.2. The current baseline measures are described in Annex 2. Routeon may update them to reflect technological, operational or legal developments, provided that the overall level of protection is not materially reduced during the term of the Main Agreement.
8.3. The Client acknowledges that the Services operate over public and third-party communications networks and that no system can guarantee absolute security or delivery. Routeon is not responsible for security failures caused by the Client, its users, its systems, compromised credentials, unlawful instructions, or Independent Network Providers outside Routeon’s reasonable control, except to the extent required by mandatory law.
8.4. The Client is responsible for evaluating whether the Services and available configurations are appropriate for the nature and risk of its Processing. Routeon’s security documentation is not a certification of the Client’s compliance.
9. Customer Personal Data Breach
9.1. Routeon shall notify the Client as soon as reasonably practicable and, unless a shorter period is required by applicable Data Protection Law. Notice may be delivered to the account owner, security contact or other notice address designated by the Client. Notice may be delivered to the account owner, security contact or other notice address designated by the Client.
9.2. To the extent reasonably available and legally permitted, Routeon’s notice will describe: (a) the nature of the breach; (b) affected systems and categories of data; (c) known or reasonably estimated scope; (d) likely consequences; (e) containment and remediation steps; and (f) a contact point for follow-up. Routeon may provide information in phases as the investigation develops.
9.3. Routeon shall take reasonable steps to contain, investigate and remediate the breach and preserve relevant evidence. Routeon is not required to disclose information that would compromise security, legal privilege, confidential information of another client, or an active investigation.
9.4. The Client is responsible for determining whether to notify regulators, individuals or third parties and for the content of those notices. Routeon shall provide reasonable assistance where required by Applicable Data Protection Law, taking account of the nature of Processing and information available to Routeon.
9.5. A breach notice is not an admission of fault, liability or violation. The Client shall not name Routeon in a public statement, regulatory notice or communication about a breach without prior consultation, unless legally required, in which case the Client shall provide advance notice where permitted.
9.6. Where the breach results from the Client’s systems, credentials, content, instructions or violation of the Main Agreement, Routeon may charge reasonable costs for extraordinary investigation, remediation or support, subject to the Main Agreement.
10. Individual rights requests and complaints
10.1. The Client is responsible for receiving, verifying and responding to requests and complaints from individuals concerning Customer Personal Data.
10.2. If Routeon receives a request relating to Customer Personal Data, Routeon may direct the individual to the Client, ask the individual to identify the Client, and notify the Client. Routeon shall not respond substantively except on the Client’s instructions or where required by law.
10.3. Taking account of the nature of the Processing, Routeon shall provide reasonable technical and organisational assistance through available Service functionality or other reasonable measures to enable the Client to respond to applicable requests for access, correction, deletion, restriction, objection, portability, opt-out or limitation.
10.4. The Client shall not instruct Routeon to disclose Customer Personal Data where disclosure would adversely affect another person, compromise security, breach confidentiality, or violate law. Routeon may require identity, authority and scope information reasonably necessary to implement a request safely.
11. Compliance assistance
11.1. Taking account of the nature of Processing and information available to Routeon, Routeon shall provide reasonable assistance with the Client’s legally required security assessments, data-protection impact assessments, prior consultations relating specifically to Routeon’s Processing of Customer Personal Data.
11.2. The Client shall first use Routeon’s generally available documentation. Routeon is not required to provide legal advice, complete the Client’s controller obligations, disclose information about other clients, reveal source code or trade secrets, or create documents not normally maintained.
11.3. Routeon may charge reasonable fees for assistance that is repetitive, customised, urgent, disproportionate, caused by the Client’s non-compliance, or not required by law, subject to advance notice where practicable.
12. Subprocessors and network providers
12.1. The Client grants Routeon general written authorisation to appoint Subprocessors. Routeon shall maintain a current list or other reasonable disclosure mechanism identifying material Subprocessors and their Processing locations or functions.
12.2. Routeon shall impose written data-protection obligations on each Subprocessor that provide a level of protection materially equivalent to the obligations applicable to Routeon for the relevant Processing.
12.3. The Client acknowledges that communications and link services require transmission through Independent Network Providers. Such providers may receive destination identifiers, routing metadata, message or email content, IP addresses, domain information, delivery information and similar data necessary for interoperability, delivery, security and legal compliance.
12.4. Where an Independent Network Provider acts as an independent Controller or equivalent party, its Processing is not performed on Routeon’s instructions and is not governed by the Subprocessor provisions. Routeon shall use reasonable commercial diligence in selecting direct providers, but is not responsible for independent Processing outside Routeon’s reasonable control, except as required by mandatory law.
13. International data transfers
13.1. The Client authorises Routeon and its Subprocessors to Process Customer Personal Data in any country reasonably required to provide the Services, subject to this DPA, the disclosed Processing locations and Applicable Data Protection Law.
13.2. Where the Processing of Customer Personal Data involves a transfer to a country or recipient that is not recognised as providing an adequate level of protection under applicable Data Protection Law, the Parties shall apply the legally required data transfer mechanism and any supplementary safeguards necessary for that transfer.
13.3. The Client is responsible for determining whether its use of the Services triggers localisation, registration, government approval or sector-specific transfer restrictions. The Client shall not submit data subject to such restrictions without Routeon’s prior written approval.
14. Government and legal requests
14.1. Routeon may disclose Customer Personal Data where legally required or where reasonably necessary to protect rights, safety, security, networks or legal claims. Routeon shall assess the validity and scope of requests and, where reasonably appropriate, challenge unlawful, overbroad or disproportionate requests.
15. Return, deletion and retention
15.1. During the term, the Client may access, export or delete Customer Personal Data using available Service functionality and subject to the Main Agreement, technical limitations and applicable retention settings.
15.2. After termination or expiry of the affected Services, Routeon shall, at the Client’s choice and where required by Applicable Data Protection Law, delete or return Customer Personal Data within a commercially reasonable period, unless law requires retention. If the Client does not make a choice, Routeon may delete the data according to its standard retention schedule.
15.3. Deletion from active systems does not require immediate deletion from encrypted or segregated backups, disaster-recovery systems, immutable security logs, carrier records or data retained for legal claims. Such data shall remain protected, shall not be used for other purposes, and shall be deleted or overwritten through ordinary retention cycles unless longer retention is legally required.
15.4. Routeon may retain limited Service Data in its own responsible capacity for billing, fraud and abuse prevention, security, compliance, dispute resolution and legal claims, provided the retention is lawful, proportionate, access-restricted and subject to Routeon’s retention controls.
15.5. Routeon is not required to retain Customer Personal Data after the applicable retention period. The Client is responsible for maintaining its own copies and records required for business, legal, consent, suppression and compliance purposes.
16. Audit and verification
16.1. Routeon shall make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, certifications, summaries, completed questionnaires and independent audit reports.
16.2. If the information in clause 16.1 is insufficient to satisfy a specific mandatory requirement, the Client may request an audit not more than once in any twelve-month period, except following a confirmed material breach or where a regulator requires a more frequent audit.
16.3. Audits shall: (a) be limited to Processing of the Client’s Customer Personal Data; (b) occur during normal business hours on at least thirty (30) days’ notice; (c) not unreasonably disrupt operations; (d) be conducted remotely (e) comply with Routeon’s security and confidentiality rules; and (f) not access data of other clients, source code, vulnerability details, privileged material or trade secrets beyond what is strictly necessary.
16.4. An auditor must be independent, appropriately qualified, not a competitor of Routeon, and bound by confidentiality. Routeon may object to an auditor on reasonable security, confidentiality or conflict grounds.
16.5. The Client bears its own audit costs and shall reimburse Routeon’s reasonable costs for on-site, repetitive or extraordinary audits.
16.6. Any audit findings are Routeon Confidential Information.
17. Liability, allocation of risk and indemnity
17.1. The exclusions, limitations of liability, disclaimers, claim procedures and indemnities in the Main Agreement apply to this DPA to the maximum extent permitted by law. Nothing in this DPA creates unlimited liability or a separate aggregate liability cap unless the Main Agreement expressly states otherwise.
17.2. Each Party remains responsible for obligations and liabilities imposed directly on it by mandatory law. Nothing in this DPA limits liability that cannot lawfully be limited.
17.3. Routeon is not liable for delay, non-delivery, blocking, filtering, modification, retention or independent Processing by Independent Network Providers, recipients, mailbox providers, carriers or authorities outside Routeon’s reasonable control, except to the extent required by mandatory law.
18. Term, suspension and termination
18.1. This DPA remains in effect for as long as Routeon Processes Customer Personal Data under the Main Agreement.
18.2. Routeon may suspend affected Processing where reasonably necessary to address a security incident, unlawful Processing, prohibited data, sanctions risk, network abuse, regulatory requirement or material breach, subject to the Main Agreement.
19. Changes to this DPA
19.1. Routeon may update this DPA where reasonably necessary to reflect changes in law, regulatory guidance, transfer mechanisms, Services, security practices or Subprocessors, provided an update does not materially reduce the protection of Customer Personal Data or the Client’s mandatory rights.
19.2. Routeon shall provide reasonable notice of a material change. If a material change is required by law or a regulator, it may take effect on the date required. The Client’s continued use of the Services after the effective date constitutes acceptance to the extent permitted by the Main Agreement and applicable law.
19.3. This DPA constitutes an integral part of the Terms of Service and is offered for acceptance on an accession basis. By accepting the Terms of Service, creating an account, or accessing or using the Services, the Client accedes to this DPA and agrees to be bound by its terms without the need for a separate signature, to the extent permitted by applicable law.
ANNEX 1 – DETAILS OF PROCESSING
This Annex describes the default Processing. The applicable Client configuration and written instructions may further specify or narrow it.
| Element | Description |
|---|---|
| Subject matter | Provision, operation, security and support of Routeon’s URL/link, QR-code, SMS-routing, messaging, email-routing, delivery, analytics, dashboard and API Services. |
| Duration | For the term of the Main Agreement and the limited post-termination periods described in clause 15. |
| Frequency | Continuous, intermittent or event-driven, according to the Client’s use of the Services. |
| Nature of Processing | Collection, receipt, validation, formatting, hosting, storage, queueing, routing, transmission, delivery, redirection, retrieval, display, analysis, logging, aggregation, troubleshooting, security monitoring, suppression, export and deletion. |
| Purposes | Providing the Services; routing and delivering communications; link and QR functionality; reporting and analytics; technical support; usage calculation; security, fraud and abuse prevention; compliance with Client instructions and applicable law. |
| Categories of individuals | Client customers; end users; SMS and email recipients; subscribers; website visitors; link and QR users; senders; campaign contacts; complainants; persons who unsubscribe or object; and other individuals whose data the Client submits or generates through the Services. |
| General data categories | Names; business and personal contact details; telephone numbers; email addresses; sender and recipient identifiers; account or customer identifiers; IP addresses; device, browser and network data; message identifiers; routing and delivery metadata; timestamps; location inferred from IP or routing; link and QR interaction data; campaign and configuration data; suppression, bounce, complaint and opt-out data; and support information. |
| URL, link and QR Services | Original and shortened URLs; branded domains; link aliases; QR content; destination data; click/scan timestamps; IP address; browser/device and referrer data; approximate location derived from network information; campaign parameters; and Client-selected analytics attributes. |
| SMS Services | Telephone numbers; sender IDs; message content; message identifiers; timestamps; routing paths; delivery status; error codes; opt-out and complaint signals; carrier/network data; and traffic statistics. |
| Email Services | Recipient email addresses; sender information; subject lines and content; message identifiers; sending domain; SPF/DKIM/DMARC status; delivery, bounce and complaint information; unsubscribe data; and email opens and link clicks where enabled. |
| Controller instructions | The Main Agreement, this DPA, dashboard and API configuration, support requests, and other written instructions accepted by Routeon. |
ANNEX 2 – TECHNICAL AND ORGANISATIONAL MEASURES
Routeon shall maintain measures appropriate to the actual Services and risk. The following is a contractual baseline and must be validated against Routeon’s implemented controls before signature.
Security governance
- Defined responsibility for information security and privacy compliance.
- Documented security, access-control, incident-response, business-continuity and vendor-management procedures appropriate to Routeon’s size and risk.
- Periodic review of material risks and controls.
Access control
- Role-based access and least-privilege principles for systems containing Customer Personal Data.
- Authentication controls appropriate to account risk, including multi-factor authentication for privileged or administrative access where technically supported.
- Joiner, mover and leaver processes and periodic access review for privileged accounts.
- Unique user accounts and prohibition of unnecessary shared administrative credentials.
Encryption and communications security
- Encryption in transit using current, generally accepted protocols for supported web, API and administrative interfaces.
- Encryption at rest where appropriate to the system, data and risk, or equivalent compensating controls.
- Secure management of secrets, API keys, credentials and cryptographic material.
- Network protections and segmentation appropriate to the architecture.
System and application security
- Secure configuration and change-management practices.
- Vulnerability identification, prioritisation and remediation based on risk.
- Malware, abuse, spam, phishing and anomalous-activity controls appropriate to the Services.
- Security testing and code-review practices proportionate to material changes and risk.
- Logging and monitoring of relevant administrative, authentication, security and service events.
Availability and resilience
- Backup, restoration and disaster-recovery measures appropriate to critical systems.
- Capacity and availability monitoring for material services.
- Business-continuity and incident-response procedures, with periodic exercises or reviews.
Data minimisation and lifecycle
- Collection and retention limited to data reasonably necessary for the Services, security, billing and legal requirements.
- Service-specific retention settings or schedules where technically available.
- Secure deletion or irreversible de-identification when data is no longer required, subject to backup cycles and legal retention.
Personnel security
- Confidentiality obligations for authorised personnel.
- Security and privacy awareness training appropriate to role.
- Disciplinary or access-removal measures for violations of security requirements.
Subprocessor and supplier security
- Risk-based diligence before appointment of material Subprocessors.
- Written security, confidentiality and data-protection obligations.
- Ongoing review or monitoring proportionate to provider risk.
Incident management
- Documented channels for identification, escalation, containment, investigation and remediation of security incidents.
- Preservation of relevant evidence and post-incident review where appropriate.
- Customer notification process consistent with clause 9.
Client-facing safeguards
- Account permissions, API credentials and security features made available according to the selected Service.
- Reasonable security documentation and contact channel.
- Controls to detect and restrict prohibited use, fraud, spam, phishing and abuse.