Data Processing and Assessment Terms
The terms on which SecureEdge Advisory processes personal data on behalf of a customer, and the terms governing evidence submitted for assessment.
Scope and roles
These terms apply where SecureEdge Advisory processes personal data on behalf of a customer in the course of an engagement. For that data the customer is the controller and we are the processor, and we process it only on the customer's documented instructions.
This agreement is distinct from our Privacy Policy. The Privacy Policy concerns personal data for which we are the controller, such as the data of a visitor to this website. These terms concern personal data that a customer places into our care.
Subject matter, nature and duration
The subject matter of the processing is the performance of the engagement. Its nature and purpose are the collection, review, analysis, storage and reporting of information necessary to assess the customer's security posture and to prepare deliverables. Processing continues for the duration of the engagement and for the retention period thereafter.
The categories of data subject are the customer's personnel and, where the customer provides it, the personnel of the customer's own suppliers. The categories of personal data are business contact details, employment role, and any personal data incidentally contained in evidence the customer submits.
Our obligations as processor
- To process personal data only on the customer's documented instructions, including in respect of transfer outside the UAE, unless we are required to do otherwise by law.
- To ensure that persons authorised to process the personal data are bound by an obligation of confidentiality.
- To implement technical and organisational measures appropriate to the risk, taking account of the state of the art and the nature of the data.
- To assist the customer, so far as is reasonable, in responding to a request from a data subject and in meeting the customer's own obligations of security, breach notification and impact assessment.
- To notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data.
- To make available the information reasonably necessary to demonstrate compliance with these terms, and to permit an audit conducted on reasonable notice, during business hours, and no more than once a year unless a breach or a regulator requires otherwise.
- On termination, and at the customer's election, to delete or return the personal data, save where retention is required by law.
Sub-processors
We engage the sub-processors listed on our Sub-processors page, presently Vercel, Supabase, Zoho and Resend. The customer authorises their engagement. Where we intend to engage a further sub-processor we shall give the customer notice, and the customer may object on reasonable grounds relating to data protection.
We remain liable to the customer for the performance of a sub-processor's obligations, and we impose on each sub-processor obligations no less protective than those in these terms.
International transfer
The sub-processors named on our Sub-processors page host data outside the United Arab Emirates. The hosting region and the basis relied upon for each transfer are stated on that page. The customer instructs us to transfer personal data on that basis.
Evidence submitted for assessment
Evidence that a customer submits for assessment remains the property of the customer. We use it solely to conduct the assessment and to prepare the deliverables, and we do not use it to train a model, to benchmark another customer, or for any purpose beyond the engagement.
Where an assessment record is retained for audit purposes, it is retained in a form that preserves its integrity, so that the record of what was assessed, when, and on what evidence, cannot be altered after the fact. That property protects the customer as much as it protects us.
Security measures
- Access to customer data is restricted to personnel who require it to perform the engagement, and is granted on the principle of least privilege.
- Data is encrypted in transit, and at rest by the storage provider.
- Credentials are stored using a one-way function designed for password storage. They are never stored in a form from which the original may be recovered.
- Actions taken on customer records are logged, and the log is protected against modification and deletion.
- Access rights are reviewed on a defined cycle and revoked when a person's role no longer requires them.
Breach notification
Where we become aware of a personal data breach affecting the customer's personal data, we shall notify the customer without undue delay and shall provide the information reasonably available to us concerning the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We shall cooperate with the customer in its own notification obligations.
Order of precedence
Where these terms conflict with the Terms of Service in respect of the processing of personal data on the customer's behalf, these terms prevail. Where an executed engagement letter addresses a matter covered here, the engagement letter prevails for that engagement.
Contact
Questions concerning these terms, and any documented instruction under them, should be sent to privacy@secureedgeadvisory.com, copying legal@secureedgeadvisory.com.