Introduction
This DPA sets out the terms on which StructureFlow may process Customer Personal Data. Terms not defined in this DPA have the meanings given elsewhere in the Platform Service Terms and the terms (data) controller, (data) processor, data subject, personal data breach and process/processes/processing have the meanings given to them in Data Protection Law (as defined in the Platform Service Terms).
Part A – Data Processing Details
| Subject matter of the processing |
|---|
| The provision of a cloud-hosted platform for visualizing and modelling entities and relationships, including the processing of Customer Personal Data uploaded to or generated through Platform Service. |
| Nature and purpose of the processing |
|---|
| Hosting, backup, transmission and processing of Customer Personal Data through automated systems for the purpose of enabling Customer to visualize and model entities and relationships, collaborate with colleagues, and create reports and presentations. |
| Categories of data subjects and personal data |
|---|
| Data subjects include Authorized Users, Collaborators and any individuals referred to within a Project. Categories of Customer Personal Data include Account Administration Data, Customer Usage Data and Project Data (as defined in the Privacy Policy). |
| Duration of processing |
|---|
| The Term and any period during which StructureFlow continues to hold any Customer Personal Data until it is deleted or returned at Customer’s option. |
Part B – StructureFlow’s obligations
1. Relationship of the parties
The parties acknowledge that, as between the parties, Customer is a controller and StructureFlow is a processor when processing Customer Personal Data, except where StructureFlow processes Customer Personal Data as controller in accordance with the Privacy Policy. For the purposes of the CCPA, StructureFlow will process Customer Personal Data as a ‘service provider’ for Customer as a business.
2. Instructions for processing
StructureFlow shall process Customer Personal Data only on documented instructions from Customer, which includes this agreement, unless required to do so by Applicable Law (in which case StructrureFlow shall notify Customer, unless legally prohibited from doing so, before such other processing). StructureFlow shall inform Customer if, in its opinion, an instruction infringes Data Protection Law.
3. Confidentiality obligations of StructureFlow Personnel
StructureFlow shall ensure that those of its Personnel authorized to process Customer Personal Data have agreed to protect Customer Personal Data in accordance with StructureFlow’s confidentiality obligations in this agreement.
4. Security of processing
Considering the state of the art, the costs of implementation and the nature, scope and purposes of processing as set out in Part A above, StructureFlow shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing the Customer Personal Data.
5. Authorisation of sub-processors
Customer hereby provides general authorization for StructureFlow to engage third-party processors (sub-processors) for the onward processing of Customer Personal Data that StructureFlow processes as processor or sub-processor (as applicable, having regard to Customer’s role) on condition that StructureFlow shall: (a) restrict sub-processors’ access to and processing of Customer Personal Data only to what is strictly necessary to provide the Services; (b) impose contractual obligations on sub-processors which are at least as onerous as those set out in this DPA; and (c) remain liable for sub-processors’ acts or omissions. Customer acknowledges that the sub-processors engaged by StructureFlow as at the Effective Date are listed in the Approved Sub-processors List.
6. Additional or replacement sub-processors
StructureFlow may appoint additional or replacement sub-processors on condition that StructureFlow: (a) gives Customer at least 30 days’ prior written notice of the proposed appointment or replacement (Sub-processor Notice Period), including details of the sub-processor’s identity, location and processing activities; and (b) does not proceed to appoint or replace the sub-processor during the Sub-processor Notice Period if Customer objects in good faith to such appointment or replacement. Customer may raise any objections during the Sub-processor Notice Period on giving StructureFlow written notice specifying the grounds of objection. If Customer objects, the parties shall work together in good faith to resolve the grounds of objection within 30 days of StructureFlow’s receipt of the objection notice. If the parties are unable to resolve the objection within such period, Customer may terminate this agreement on giving StructureFlow 30 days’ written notice.
7. Personal data breaches
StructureFlow shall notify Customer without undue delay and in any event within 48 hours upon becoming aware of a personal data breach affecting Customer Personal Data. StructureFlow shall: (a) take all necessary steps to investigate, mitigate the effects of, and remedy the personal data breach; (b) assist Customer with its obligations to notify the personal data breach to any regulatory body, supervisory authority or affected data subjects; and (c) provide such information and assistance as Customer may reasonably request to enable Customer to manage the personal data breach.
8. Rights of data subjects
StructureFlow shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to requests for exercising data subject rights under Data Protection Law. StructureFlow shall notify Customer without undue delay and in any event within 72 hours if it receives a request from a data subject under Data Protection Law in respect of Customer Personal Data.
9. Impact of assessment and consultations
StructureFlow shall provide Customer with reasonable assistance in ensuring compliance with its obligations regarding data protection impact assessments or consultation with many regulatory body or supervisory authority that may be required under Data Protection Law.
10. Deletion or return of Customer Personal Data
Within 60 days from expiry or termination of this agreement, StructureFlow shall, at Customer’s election, delete or return all Customer Personal Data to Customer and delete existing copies, unless Applicable Law requires storage of the Customer Personal Data (in which case StructureFlow shall confirm the same to Customer in writing).
11. Audits and inspections
StructureFlow shall make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Customer shall provide reasonable notice of any audit or inspection and conduct such audit or inspection during StructureFlow’s normal business hours, in a manner that does not unreasonably interfere with StructureFlow’s operations.
Part C – Customer’s obligations
1. Rights of Customer Personal Data
Customer has and shall throughout the Term maintain all necessary rights, consents and authorizations to process Customer Personal Data through the Platform Service and any other instructions given to StructureFlow.
2. Processing on behalf of Authorised Affiliates
Where applicable, Customer enters into this DPA on its own behalf and on behalf of the Authorized Affiliates, unless such Authorized Affiliates enter into their own agreement with StructureFlow regarding the processing of Customer Personal Data.
3. Cooperation with StructureFlow
Customer shall reasonably cooperate with StructureFlow on all matters relating to the processing of Customer Personal Data and compliance with its obligations under Data Protection Law.
4. Backup of Customer Personal Data
Without limiting StructureFlow’s obligations under this DPA and this agreement regarding information security, Customer acknowledges that Customer is responsible for maintaining a backup of all Customer Personal Data.
5. Restricted categories of Personal Data
Customer shall not upload or input to the Platform Service any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.
Part D – International transfers
1. International transfers
Except as set out in this DPA, StructureFlow shall not process Customer Personal Data originating from the Customer (or permit any sub-processor to process Customer Personal Data originating from the Customer) outside the Agreed Hosting Location specified in the Order Form (and for the purposes of Data Protection Law in the UK and EEA, will not transfer Customer Personal Data outside the UK or EEA) without the Customer’s prior written approval.
2. Transfer mechanisms
The parties hereby agree that for transfers of Customer Personal Data subject to: (a) the UK GDPR, the parties shall comply with the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses (UK SCCs); (b) the EU GDPR, the parties shall comply with the Standard Contractual Clauses approved by the European Commission (2021/914) (EU SCCs); and (c) Swiss FADP, the parties shall comply with the Swiss-adapted EU SCCs approved by the Federal Data Protection and Information Commissioner (Swiss SCCs). In each case, the parties agree that the applicable terms are incorporated into this agreement by reference.
3. Variables for Transfer Terms
For the purposes of the IDTA, UK SCCs, EU SCCs and Swiss SCCs (together, the Transfer Terms), the parties agree as follows:
| Parties and roles | The parties’ identities, contact details, and roles (controller, processor, joint controller, or sub-processor) under the Transfer Terms will be the same those set out in this agreement (including the Order Form). |
| Description of the data transfer | The categories of personal data, data subjects, purposes of processing, nature of processing and duration of processing/retention under the Transfer Terms will be those set out in Part A of this DPA). |
| Technical and organisational measures | The technical and organisational measures required under the Transfer Terms (including Annex II to the EU SCCs and corresponding sections of the UK SCCs, Swiss SCCs and IDTA) will be those set out Part E of this DPA or otherwise provided by the data importer in accordance with this agreement and accepted by the data exporter. |
| Sub-processing | The sub-processing provisions, including authorisation mechanisms and details of permitted sub-processors, will be those set out in this agreement. Where the Transfer Terms require a list or description of sub-processors, those list at will apply: structureflow.co/authorized-sub-processors |
| International locations | The territory or territories in which the data importer (and any authorized sub-processors) may process Customer Personal Data under the Transfer Terms will be limited to those locations permitted under this agreement. |
| Governing law and jurisdiction | Where the Transfer Terms require specification of the governing law or competent supervisory authority: (a) under the EU SCCs, the governing law will be that of Ireland and competent supervisory authority will be Irish Data Protection Commission; (b) under the UK SCCs and IDTA, the governing law will that of England and Wales and competent supervisory will be the UK Information Commissioner’s Office; and (c) under the Swiss SCCs, the governing law will be Swiss law and the competent authority will be the Swiss FDPIC. |
| Liability and indemnities | The allocation of liability between the parties under the Transfer Terms will follow the liability provisions of this agreement. Any liability caps or exclusions in this agreement will, to the maximum extent permitted by applicable data protection law, apply also to liabilities arising under or in connection with the Transfer Terms. |
| Optional and alternative modules | Where the Transfer Terms include optional clauses, modules, or selections relating to controller–processor or controller–controller transfers, audit rights, docking clauses, and redress mechanisms, the module(s) corresponding to the parties’ roles under this agreement will apply, and any optional clauses not expressly inconsistent with this agreement will be deemed selected. |
| Additional provisions for IDTA and UK SCCs | Any fields in the IDTA or UK SCCs requiring completion (including tables on data description, importer/exporter details, TIA summary, and linked agreements) shall be deemed populated by the corresponding information in this Agreement. |
4. Compliance with US Privacy Law
To the extent applicable under US Privacy Law, StructureFlow shall comply with its obligations to: (a) only process Customer Personal Data for the purposes set out in this agreement and unless otherwise permitted by Applicable Law; (b) not “sell” or “share” (as defined by CCPA) Customer Personal Data; (c) not retain, use or disclose Customer Personal Data outside of the direct business relationship between StructureFlow and Customer unless otherwise required or permitted by Applicable Law; (d) process Customer Personal Data in a manner that provides no less than the level of privacy protection required by US Privacy Law; (e) not combine any Customer Personal Data with Personal Data that StructureFlow receives from or on behalf of a third party or collected from StructureFlow’s own interactions with individuals (unless permitted under US Privacy Law or as directed by Customer in writing); and (f) not attempt to re-identify any de-identified data provided to StructureFlow, except for the sole purpose of determining whether the de-identification processes complies with US Privacy Law.
5. Conflict of terms
In the event of any ambiguity or inconsistency between the following documents regarding the processing of Customer Personal Data, the order of priority will be: (a) first, the applicable Transfer Terms (as defined in paragraph 3 above, subject to the terms in paragraph 4); (b) second, this DPA; and (c) finally, the other terms of this agreement.
Part E – Minimum Information Security Standards
Security management
1. Information security programme
Without limiting StructureFlow’s obligation under section 6.2 (Information security) of the Platform Service Terms, StructureFlow shall maintain an information security management system (ISMS) including: (a) documented policies covering acceptable use, change management, incident response, and disaster recovery; (b) regular review and approval by senior management; and (c) communication to all Personnel with access to Customer Data.
2. Accountability
StructureFlow shall designate an individual who is accountable for all matters relating to information security.
3. Subcontractors
StructureFlow shall undertake an appropriate level of due diligence on all its subcontractors having regard to the risks associated with the activities conducted by them. To the extent any subcontractor may process Customer Data, StructureFlow shall ensure that such subcontractor has contractually committed to information security obligations at least as onerous as those set out in this Part E.
Access controls
4. User accounts and authentication
StructureFlow shall: (a) assign unique user IDs to Authorized Users (no shared accounts); (b) require all passwords to have a minimum of eight characters; (c) enable multi-factor authentication for systems where technically feasibly; and (d) require multi-factor authentication for privileged accounts where technically feasible.
5. Access management
StructureFlow shall: (a) grant access on a least-privilege basis and need-to-know basis; (b) implement appropriate segregation of duties; (c) review users accounts and privileges regularly; (d) promptly revoke access when no longer required; and (e) maintain a register of privileged accounts.
Data protection
6. Encryption
StructureFlow shall: (a) encrypt Customer Data at rest on all systems, servers, storage media and back-ups using AES-256; (b). encrypt Customer Data in transit using TLS v1.2; and and (c) enable encryption on all removable media, laptop computers and mobile devices used for work purposes.
7. Data retention and destruction
StructureFlow shall: (a) retain Customer Data only as long as necessary for providing the Services or as required by Applicable Law; (b) upon Customer’s request, destroy Customer Data irretrievably within 30 days of such request and provide written confirmation of destruction; (c) dispose of any physical media under its control securely in accordance with NIST SP 800-88 or any equivalent standard.
Technical and physical security
8. Malware protection
StructureFlow shall: (a) deploy malware protection on all endpoints with automatic daily updates; and (b) implement advanced threat detection and prevention measures.
9. Patch management
StructureFlow shall: (a) maintain a formal patch management process; (b) apply critical security patches expeditiously where relevant; and (c) use supported versions of all applications and operating systems.
10. Network security
StructureFlow shall: (a) protect network perimeter with appropriately configured firewalls; (b) implement intrusion detection/prevention systems; (c) restrict ports, protocols, and IP addresses to the minimum necessary; and (d) segment networks appropriately.
11. Vulnerability management
StructureFlow shall: (a) conduct regular vulnerability scans; (b) investigate any identified vulnerabilities and submit an appropriate remediation plan without undue delay; and (c) conduct annual penetration testing accredited by independent third parties.
12. Physical security
StructureFlow shall: (a) maintain a physical access policy; (b) ensure facilities that process Customer Data have appropriate security procedures and controls; (c) escort and supervise office visitors at all times; (d) protect equipment against power failures and environmental hazards; and (e) ensure offices used for its daily operations have appropriate physical access procedures and are secured with alarm systems.
Operational controls
13. Change management
StructureFlow shall: (a) implement documented change management processes; (b) obtain written approval before changes affecting security or Services; and (c) review, test, and deploy changes formally.
14. Logging and monitoring
StructureFlow shall: log all security events, access attempts, and administrative activities; (b) protect logs against unauthorized access or modification; (c) retain logs for at least 90 days; (d) monitor logs for inappropriate activity; and (e) provide logs to Customer upon request.
15. Backups
StructureFlow shall: (a) perform daily encrypted backups of Customer Data; (b) test backup data weekly; (c) store backups securely in Azure-paired locations; (d) encrypt backup data using AES-256 encryption; and (e) restrict database access to approved Personnel only.
16. Business continuity
StructureFlow shall: (a) maintain documented business continuity and disaster recovery plans; (b) test plans at least annually; (c) implement corrective measures identified during testing; and (d) protect against denial-of-service attacks.
Personnel security
17. Background checks
StructureFlow shall conduct background checks on all Personnel with access to Customer Data, including: (a) identity verification; (b) criminal record checks (to the extent permitted by Applicable Law); (c) education and employment verification; (d) immigration and right to work checks; and (e) relevant licence and certification verification (where permitted by law).
18. Training
StructureFlow shall ensure that all Personnel receive: (a) information security awareness training upon engagement or employment; (b) regular updates on security policies and procedures; and (c) role-specific security training as appropriate.
Application security
19. Secure development
StructureFlow shall: (a) follow secure development lifecycle practices; (b) ensure secure coding standards (e.g., OWASP guidelines) are followed; (c) not use Customer Data in development or testing without prior consent; (d) maintain separate environments for development, testing and production; and (e) conduct pre-deployment testing.
20. Internet-facing applications
StructureFlow shall: (a) conduct pre-deployment security assessments; and (b) perform regular security testing.
Incident management
21.Incident response
StructureFlow shall maintain a documented incident response procedure covering detection, assessment, escalation, and resolution of security incidents.
22. Notification
StructureFlow shall notify Customer of any security incident affecting the confidentiality, integrity or availability of Customer Data promptly and in any event without undue delay and comply its obligations under the DPA to the extent any security incident involves Customer Personal Data.
23. Cooperation
StructureFlow shall: (a) provide all relevant information about the incident promptly; (b) cooperate to identify root cause and remediate; (c) assist with any required notifications to regulatory authorities; and (d) document incidents and provide documentation to Customer.
Compliance and audit
24. Regulatory compliance
StructureFlow shall comply with all Applicable Law, including Data Protection Law.
25. Independent audits
StructureFlow shall: (a) engage independent and accredited third parties to audit its information security management system (ISMS) at least annually; (b) implement procedures to resolve identified risks or deficiencies; and (c) provide redacted audit results to Customer upon request.
26. Customer audits
Customer may audit StructureFlow’s information security practices: (a) upon 30 days’ prior written notice; (b) during the hours of 09:30-17:30 (GMT/BST) (as applicable) Monday to Friday, excluding UK public holidays; (c) not more than once per 12-month period (except following Security Incidents); and (d) at Customer’s expense unless material non-compliance is found. StructureFlow shall reasonably cooperate with audits, providing access to those of its Personnel, facilities and documentation as may reasonably be necessary for such purposes.