LEGAL

ARUGA DATA PROCESSING AGREEMENT

This Data Processing Agreement (this "DPA") records the terms on which Aruga Cyber Ltd (company number 15583748) of 18 School Road, Sale, Greater Manchester, M33 7XP ("Aruga") processes Customer Personal Data on behalf of the Customer in connection with the Services.

This DPA is the "Aruga Data Processing Agreement" referred to in clause 14 of the Master Services Agreement between Aruga and the Customer (the "MSA"). It is made available at [insert URL of the Aruga Data Processing Agreement], forms part of the Agreement, and applies whenever Aruga processes Customer Personal Data. This DPA is entered into on the same basis as, and is subject to, the Agreement (including the limitation and exclusion of liability provisions in clause 16 of the MSA). No separate signature is required; the parties are bound by this DPA through their acceptance of the Agreement.

1. INTERPRETATION

1.1. In this DPA, the following definitions apply:

"Agreement"
has the meaning given in the MSA;
"Applicable Data Protection Laws"
means all laws and regulations applicable to the processing of personal data under the Agreement, including the UK GDPR, the Data Protection Act 2018, and (where applicable) the EU GDPR, in each case as amended or replaced;
"Customer Personal Data"
means any personal data that Aruga processes on behalf of the Customer under the Agreement, as described in Schedule 1 (Processing Particulars);
"EU GDPR"
means Regulation (EU) 2016/679;
"International Transfer Mechanism"
means the UK International Data Transfer Agreement or Addendum, the EU standard contractual clauses, or any other lawful transfer mechanism recognised under Applicable Data Protection Laws;
"Sub-processor"
means any third party (including any Aruga Affiliate or Third Party Supplier) engaged by Aruga to process Customer Personal Data;
"TOMs"
means the technical and organisational measures set out in Schedule 2 (Technical and Organisational Measures);
"UK GDPR"
has the meaning given in the Data Protection Act 2018.

1.2. The terms "controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in the UK GDPR.

1.3. Terms used but not defined in this DPA have the meanings given in the MSA. In the event of conflict between this DPA and the body of the MSA in respect of the processing of Customer Personal Data, this DPA prevails, save that clause 16 of the MSA (Limitation of Liability) prevails over any inconsistent term of this DPA.

2. ROLES OF THE PARTIES

2.1. The parties acknowledge that, in respect of the processing of Customer Personal Data, the Customer is the controller and Aruga is the processor.

2.2. The Customer warrants and undertakes that it has, and shall maintain at all times, a valid lawful basis and all necessary consents, notices, authorisations and records required to enable the lawful processing of Customer Personal Data by Aruga and its Sub-processors in accordance with the Agreement, and that its instructions to Aruga shall at all times comply with Applicable Data Protection Laws.

2.3. The Customer shall indemnify and keep Aruga (and its Affiliates and Sub-processors) indemnified in full and on demand against all losses, liabilities, damages, fines, penalties, claims, costs and expenses (including legal costs on a full indemnity basis) arising out of or in connection with (a) any breach by the Customer of clause 2.2 or of its obligations as controller under Applicable Data Protection Laws, (b) any instruction given by the Customer, and (c) any claim by a data subject or third party to the extent arising from the Customer's acts or omissions. This indemnity is not subject to any limitation or exclusion of liability in the Agreement.

3. PROCESSING ON INSTRUCTIONS

3.1. Aruga shall process Customer Personal Data only on the Customer's documented instructions, being the instructions set out in the Agreement and in Schedule 1 (Processing Particulars), unless required to process otherwise by applicable law, in which case Aruga shall (to the extent permitted by law) inform the Customer of that legal requirement before processing.

3.2. Aruga has no obligation to review, monitor or verify the lawfulness of any instruction, the Customer Personal Data, or the Customer's compliance with Applicable Data Protection Laws, and Aruga shall have no liability whatsoever for processing carried out in accordance with the Customer's instructions. If Aruga notifies the Customer that in its opinion an instruction may infringe Applicable Data Protection Laws, Aruga may suspend performance of the relevant instruction, without liability, until the Customer confirms or amends it in writing.

4. ARUGA'S OBLIGATIONS

4.1. Aruga shall, in relation to Customer Personal Data:

  1. implement and maintain the TOMs;
  2. ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality;
  3. taking into account the nature of the processing, use reasonable endeavours to assist the Customer, to the extent required by Applicable Data Protection Laws and against the Customer's prior written agreement to pay Aruga's reasonable charges (at Aruga's then-current time-and-materials rates) and reasonable costs, by appropriate technical and organisational measures insofar as is reasonably possible, in responding to requests from data subjects exercising their rights under Applicable Data Protection Laws. For the avoidance of doubt, Aruga's assistance under this clause does not transfer to Aruga any of the Customer's obligations as controller, and Aruga shall not be responsible for the Customer's decisions, notifications or filings;
  4. use reasonable endeavours to assist the Customer, to the extent required by Applicable Data Protection Laws and against the Customer's prior written agreement to pay Aruga's reasonable charges (at Aruga's then-current time-and-materials rates) and reasonable costs, in ensuring compliance with its obligations relating to security of processing, personal data breach notification, data protection impact assessments and prior consultation with supervisory authorities. For the avoidance of doubt, Aruga's assistance under this clause does not transfer to Aruga any of the Customer's obligations as controller, and Aruga shall not be responsible for the Customer's decisions, notifications or filings; and
  5. at the Customer's direction, delete or return all Customer Personal Data on termination or expiry of the Agreement, unless retention is required by applicable law.
  6. Aruga shall maintain records demonstrating its compliance with this DPA and shall make those records available to the Customer in accordance with clause 7.

5. SUB-PROCESSING

5.1. The Customer grants Aruga general authorisation to engage Sub-processors to process Customer Personal Data.

5.2. Aruga shall, on the Customer's reasonable written request, make available a list of its current Sub-processors. Aruga shall give notice (which may be given by updating a webpage) of the intended addition or replacement of any Sub-processor.

5.3. The Customer may object to a new Sub-processor only on reasonable, documented data protection grounds, by written notice within [10] days of Aruga's notice. Absent such objection, the appointment is deemed approved. Where the Customer objects, Aruga shall use reasonable endeavours to make available a commercially reasonable alternative; if Aruga does not do so, the Customer's sole and exclusive remedy is to terminate the affected Services or Order Form on [30] days written notice, remaining liable for all Charges up to the date of termination. An objection does not relieve the Customer of any payment obligation or suspend performance.

5.4. Aruga shall impose on each Sub-processor, by written contract, data protection obligations that are in substance materially equivalent to those in this DPA to the extent relevant to the services provided by that Sub-processor. Aruga's liability for the acts and omissions of its Sub-processors is subject to, and shall not exceed, the limitations and exclusions of liability in clause 16 of the MSA, and Aruga shall have no liability for any Sub-processor that is engaged, required or approved by the Customer.

6. INTERNATIONAL TRANSFERS

6.1. Aruga (and its Sub-processors) may transfer Customer Personal Data to, or process it in, a country outside the United Kingdom (or, where the EU GDPR applies, outside the European Economic Area) provided that the transfer is made subject to an appropriate International Transfer Mechanism or another lawful basis for transfer under Applicable Data Protection Laws.

6.2. The Customer authorises Aruga to enter into any applicable International Transfer Mechanism on the Customer's behalf, and to procure that its Sub-processors enter into equivalent mechanisms, where required to give effect to clause 6.1.

7. AUDIT

7.1. Aruga shall make available to the Customer, on reasonable written request and not more than once in any twelve (12) month period (save where required by a supervisory authority or where there are reasonable grounds to suspect a material breach), such information as is reasonably necessary to demonstrate Aruga's compliance with this DPA.

7.2. The Customer's audit right under clause 7.1 shall be satisfied, wherever possible, by Aruga providing a copy of any relevant third-party audit report, certification or attestation. Any further audit shall be at the Customer's cost, on reasonable prior written notice, during business hours, subject to Aruga's confidentiality and security requirements, and conducted so as to minimise disruption to Aruga's business.

8. PERSONAL DATA BREACH

8.1. Aruga shall notify the Customer without undue delay after Aruga confirms a personal data breach affecting Customer Personal Data, and shall provide such information as Aruga then reasonably has available and is not legally or contractually restricted from disclosing, to assist the Customer in meeting its own obligations. Aruga's obligation is limited to notification and reasonable assistance at the Customer's cost; Aruga is not required to take remediation, forensic or recovery steps under this DPA (such work being chargeable under the Agreement).

8.2. Aruga's notification of, or response to, a personal data breach shall not be construed as an acknowledgement by Aruga of any fault or liability.

8.3. The Customer is solely responsible for making any notification to a supervisory authority (including the Information Commissioner's Office) or to affected data subjects, and for any regulatory or contractual notification arising from a personal data breach.

9. DELETION AND RETURN

9.1. On termination or expiry of the Agreement, or on the Customer's earlier written instruction, Aruga shall (at Aruga's election) delete or return all Customer Personal Data, and delete existing copies. Deletion to standard commercial standards (including where Customer Personal Data is retained in routine backups, which shall be deleted in the ordinary course of backup rotation) is sufficient to satisfy Aruga's obligations under this clause. Any return of Customer Personal Data, or work relating to the deletion of Customer Personal Data beyond secure deletion, shall be chargeable at Aruga's then-current professional services rates. Aruga may retain Customer Personal Data where required by applicable law or where retention is reasonably necessary for the establishment, exercise or defence of legal claims, and shall continue to protect any retained Customer Personal Data in accordance with this DPA.

10. LIABILITY

10.1. The total aggregate liability of Aruga arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to, forms part of, and shall in no circumstances increase, the aggregate cap and the exclusions of liability set out in clause 16 of the MSA. Nothing in this DPA creates any separate or additional liability for Aruga beyond that cap. For the avoidance of doubt, the Customer's indemnities in this DPA are not subject to that cap.

11. GENERAL

11.1. This DPA takes effect on the date the Customer accepts the Agreement and continues for so long as Aruga processes Customer Personal Data.

11.2. Aruga may update this DPA from time to time by publishing an updated version at the URL referred to above, provided that no update shall materially reduce the protection afforded to Customer Personal Data.

11.3. This DPA and any dispute or claim arising out of or in connection with it are governed by, and construed in accordance with, the law of England and Wales, and are subject to the exclusive jurisdiction of the courts of England and Wales, in accordance with clause 31 of the MSA.

Schedule 1 (Processing Particulars)

  1. Subject matter of processing: [the provision of the Services under the Agreement].
  2. Duration of processing: [the term of the Agreement and any retention period required by law].
  3. Nature and purpose of processing: [detection, triage, containment, incident response and related security services, and such other processing as is necessary to provide the Services].
  4. Types of Customer Personal Data: [insert, e.g. names, contact details, job titles, account and authentication data, IP addresses, device and log data, security telemetry, and any personal data contained within monitored systems and log sources].
  5. Categories of data subjects: [insert, e.g. the Customer's employees, contractors, administrators and users, and any individuals whose personal data is contained within the in-scope environment].
  6. Sub-processors: as notified in accordance with clause 5, including any Third Party Suppliers used in the delivery of the Services.

Schedule 2 (Technical and Organisational Measures)

  1. Aruga shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, including, as appropriate:
  2. access controls, including least-privilege access, multi-factor authentication and just-in-time / privileged access management;
  3. encryption of Customer Personal Data in transit and, where appropriate, at rest;
  4. measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  5. measures to restore the availability of and access to Customer Personal Data in a timely manner in the event of an incident;
  6. logging, monitoring and a process for regularly testing, assessing and evaluating the effectiveness of the measures; and
  7. staff confidentiality undertakings and data protection awareness training.
  8. [Insert any additional or service-specific measures agreed with the Customer.]

Cookies on this website

We use essential cookies to make this website work. With your permission, we also use analytics and marketing cookies to understand how the site is used and improve our communications.

Read our cookie policy