Data Processing Agreement

Last updated: 5 August 2026

This Data Processing Agreement ("DPA") is made by and between the parties to any Service Agreement or Terms incorporating this DPA by reference, and this DPA shall be in addition to any obligations set out in any Service Agreement or Terms.

This DPA outlines the obligations between the parties where Good Technologies acts as a data processor in providing the GoodSubmissions Services to the Client, insofar as it relates to Applicant and other Protected Data processed via the Service.

Definitions

This DPA is entered into between Good Technologies and the Client under the Good Technologies Admin Terms of Service (Customer Agreement). It is not entered into by, and does not create any obligations owed to, individual Applicants, Co-authors, or Assessors — their own relationship with Good Technologies is governed by the separate Applicant & Co-author Terms of Service and Assessor Terms of Service respectively, each of which links to this DPA and the Privacy Policy for transparency.

All capitalised terms in this DPA shall have the meaning prescribed by the Good Technologies Admin Terms of Service (Customer Agreement), available at goodsubmissions.org, or as otherwise agreed between the parties, unless otherwise specified below.

Applicable Law means, as applicable and binding on the Client, Good Technologies and/or the Services: (a) any law, statute, regulation, byelaw, or subordinate legislation in force from time to time to which a party is subject and/or in any jurisdiction that the Services are provided to or in respect of, as may be specified in Terms; (b) the common law and laws of equity as applicable to the parties from time to time; (c) any binding court order, judgment, or decree; or (d) any applicable direction, policy, rule, or order that is binding on a party and made or given by any regulatory body having jurisdiction over that party or its assets, resources, or business.

Applicant means an individual who submits, or attempts to submit, an application, entry, or nomination through the Services in connection with a Programme run by the Client.

Assessor means an individual appointed by the Client to review and/or score one or more Submissions, whose access to the Services is scoped to the specific Programme(s) and/or stage(s) they are assigned to.

Co-author means an individual invited by an Applicant to collaborate on a specific Submission.

Data Controller means the party determining the processing activities conducted in relation to Personal Data, as further described under applicable Data Protection Laws.

Data Processor means the party conducting processing activities at the instruction of the Data Controller in relation to Personal Data, as further described under applicable Data Protection Laws.

Data Protection Laws means, as applicable and binding on the Client, Good Technologies and/or the Services: (a) for Services supplied by Good Technologies Limited, the General Data Protection Regulation (EU) 2016/679 and the UK GDPR (as it forms part of UK law) and national implementing legislation (including the Data Protection Act 2018), the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 ("DPPEC"), the Privacy and Electronic Communications (EC Directive) Regulations 2003, and/or any corresponding or equivalent national laws or regulations; (b) specifically in relation to the Client, all data protection and/or privacy laws applicable to the jurisdictions in which recipient Data Subjects are located; and (c) any Applicable Laws replacing, amending, extending, re-enacting, or consolidating any of the above from time to time.

Data Protection Losses means: (a) administrative fines, penalties, sanctions, liabilities, or other remedies imposed by a Supervisory Authority; and/or (b) compensation ordered by a Supervisory Authority to be paid to a Data Subject.

Data Subject means the individual to whom Personal Data relates, including, in the context of the Services, Applicants, Co-authors, Assessors, and other individuals about whom data is submitted.

Data Subject Request means a request made by a Data Subject to exercise any rights of Data Subjects under Data Protection Laws.

International Recipient has the meaning given to that term in clause 6.2.

Personal Data has the meaning given to that term in Data Protection Laws, or, where that term is not identically defined in the applicable Data Protection Law, the meaning given to the equivalent defined term in that applicable Data Protection Law.

Personal Data Breach means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, any Protected Data.

Processing has the meaning given to that term in Data Protection Laws (and related terms such as "process" have corresponding meanings).

Processing Instructions has the meaning given to that term in clause 3.2.1.

Programme means an application, entry, recruitment, competition, or other submission process configured and run by the Client using the Services.

Protected Data means Personal Data received from, or on behalf of, the Client (including Personal Data submitted by Applicants) in connection with the performance of Good Technologies' obligations under this DPA.

SCCs means the applicable standard contractual clauses (or, for transfers from the UK, the International Data Transfer Agreement or UK Addendum issued by the ICO, as relevant) governing the transfer of personal data to processors established in third countries.

Sub-Processor means another Data Processor engaged by Good Technologies for carrying out processing activities in respect of the Protected Data on behalf of the Client.

Supervisory Authority means any local, national, or multinational agency, department, official, parliament, public or statutory person, or any government or professional body, regulatory or supervisory authority, board, or other body responsible for administering Data Protection Laws.

References to any Applicable Laws (including the Data Protection Laws) and to terms defined in such Applicable Laws shall be replaced with or incorporate references to any Applicable Laws replacing, amending, extending, re-enacting, or consolidating such Applicable Law (including any new Data Protection Laws from time to time) and the equivalent terms defined therein, once in force and applicable. A reference to a law includes all subordinate legislation made under that law.

1. Interaction with the Agreement

1.1. This DPA will take effect from the date on which the Client accepts the terms of this DPA (or signs a Service Agreement incorporating the terms of this DPA), and shall continue until the end of Good Technologies' provision of the Services (including any period of suspension, where relevant) ("Term").

1.2. Except for the changes made by this DPA, the Terms and Service Agreement remain in full force and effect. To the extent that there is any conflict between this DPA and the Terms, the order of precedence shall be the SCCs (if applicable), the clauses of this DPA, and then the Terms.

2. Data Processor and Data Controller

2.1. The parties agree that, in relation to Protected Data as applicable under Data Protection Laws, the Client shall be the Data Controller and Good Technologies shall be the Data Processor. This includes Protected Data relating to Applicants and other individuals who interact with a Programme run by the Client.

2.2. Good Technologies shall process Protected Data in compliance with: (a) the obligations of Data Processors under Data Protection Laws in respect of the performance of its obligations herein; and (b) the terms of this DPA, the Terms, and the Service Agreement, which set out the Client's instructions in relation to such processing activities.

2.3. The Client shall comply with: (a) all Data Protection Laws in connection with the processing of Protected Data, use of the Services, and the exercise and performance of its respective rights and obligations under this DPA, including maintaining all relevant regulatory registrations and notifications as required under Data Protection Laws; and (b) the terms of this DPA.

2.4. The Client warrants, represents, and undertakes that: (a) all data collected by, or on behalf of, the Client via the Services — including all Programme Data and Applicant Data — shall comply in all respects, including in terms of its collection, storage, and processing (which shall include the Client providing all required fair processing information to, and obtaining all necessary consents or identifying an appropriate lawful basis and, where applicable, Article 9 condition from, Data Subjects, including where special category data such as health, disability, or equality monitoring information is requested as part of a Programme), with Data Protection Laws; and (b) all instructions given by it to Good Technologies in respect of Personal Data shall at all times be in accordance with Data Protection Laws.

2.5. The Client shall not unreasonably withhold, delay, or condition its agreement to any change or amendment requested by Good Technologies in order to ensure the Services and Good Technologies (and each Sub-Processor) can comply with Data Protection Laws.

2.6. The Services do not process payments. The Client shall not configure any Programme, question, form, or file upload to collect financial account details, bank details, or payment card information from any Data Subject via the Services, and Protected Data shall not include any such information. Where a Programme requires the collection of financial details for a legitimate purpose (for example, to pay out a grant or award), the Client shall collect that information by a means other than the Services.

3. Instructions and details of processing

3.1. By entering into this DPA, the Client instructs Good Technologies to process Protected Data only in accordance with Applicable Law: (a) to provide the Services; (b) as further specified by the Client's use of the Services or the Software, including its configuration of Programmes; (c) as documented in the Terms and this DPA; and (d) as further documented in any other written instructions provided by the Client and acknowledged by Good Technologies as being instructions for the purposes of this DPA.

3.2. Insofar as Good Technologies processes Protected Data on behalf of the Client, Good Technologies: (a) unless required to do otherwise by Applicable Law, shall (and shall take steps to ensure each person acting under its authority shall) process the Protected Data only on and in accordance with the Client's documented instructions as set out in this clause, as updated from time to time as agreed between the parties ("Processing Instructions"); (b) if Applicable Law requires it to process Protected Data other than in accordance with the Processing Instructions, shall notify the Client of any such requirement before processing the Protected Data (unless Applicable Law prohibits such information on important grounds of public interest); and (c) shall inform the Client if Good Technologies becomes aware of a Processing Instruction that, in Good Technologies' opinion, infringes Data Protection Laws, provided that: (i) this shall be without prejudice to clauses 3 and 2.4; and (ii) to the maximum extent permitted by mandatory law, Good Technologies shall have no liability howsoever arising for any losses, costs, expenses, or liabilities (including any Data Protection Losses) arising from or in connection with any processing in accordance with the Client's Processing Instructions following the Client's receipt of that information.

3.3. The subject matter and details of the processing of Protected Data to be carried out by Good Technologies under this DPA shall comprise the processing set out in Schedule 1 (Data Processing details), as may be updated from time to time as agreed between the parties.

3.4. Good Technologies acknowledges that its processing of Protected Data is limited to that set out in this DPA in order to supply the Services to the Client, and will not retain, use, or disclose Protected Data other than as specified under this DPA, or (for the purposes of US Data Protection Laws) "sell" Protected Data, as that term is defined under the CCPA.

4. Technical and organisational measures

4.1. Good Technologies shall implement and maintain, at its cost and expense and in relation to the processing of Protected Data by Good Technologies, technical and organisational measures taking into account the nature of the processing — including, where relevant, the heightened sensitivity of any special category data submitted as part of a Programme — to assist the Client insofar as is possible in the fulfilment of the Client's obligations to respond to Data Subject Requests relating to Protected Data.

4.2. Manual data extracts. Where Good Technologies personnel need to take a manual extract of Protected Data (for example, a database export) for an operational purpose such as debugging, migration, or incident response, Good Technologies shall ensure that:

(a) such an extract is taken only where no reasonably practicable alternative exists, and only by personnel authorised for that purpose;

(b) the extract is encrypted at rest and stored only on Good Technologies-managed, access-controlled infrastructure — never on an unmanaged personal device or unencrypted local storage;

(c) the extract is logged, recording who took it, when, and for what purpose;

(d) the extract is securely deleted as soon as it is no longer required for the purpose for which it was taken, and in any event within 7 days of creation, unless a longer period is agreed with the Client in writing; and

(e) the extract is treated as Protected Data and Confidential Information for all purposes of this DPA for as long as it exists, including the breach notification obligations in clause 10.

5. Using Sub-Processors

5.1. Subject to the remainder of this clause 5, Good Technologies shall not engage any Sub-Processor for carrying out any processing activities in respect of the Protected Data where data is hosted outside of the United Kingdom (UK) or European Economic Area (EEA) without express written permission of the Client.

5.2. The Client specifically authorises the engagement of Good Technologies' affiliates and associated group companies as Sub-Processors, and also authorises the appointment of any Sub-Processors Good Technologies chooses. Good Technologies' current Sub-Processors, and the categories of Protected Data and locations relevant to each, are set out in Schedule 3. This list will be kept up to date and an updated version can be provided on request.

5.3. Good Technologies shall ensure: (a) via a written contract that the Sub-Processor only accesses and processes Protected Data to perform the obligations subcontracted to it, and does so in accordance with the measures contained in this DPA, enforceable by Good Technologies; and (b) it remains fully liable for all acts and omissions of each Sub-Processor as if they were its own.

5.4. When any new Sub-Processor outside of the UK or EEA is engaged by Good Technologies during the Term, Good Technologies shall give the Client 30 days' prior notice of the appointment, including details of the Processing to be undertaken by the Sub-Processor, via email.

5.5. The Client may object (on reasonable grounds relating only to data protection) to any such new Sub-Processor appointed per clause 5.4 within 14 days of Good Technologies' notice. If the Client notifies Good Technologies in writing of any objection: (a) Good Technologies shall work with the Client in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Sub-Processor; and (b) where such a change cannot be made within 14 days of Good Technologies' receipt of the Client's notice, the Client may, by written notice with immediate effect, terminate the Service Agreement to the extent it relates to the Services which require use of the proposed Sub-Processor. This termination right is the Client's sole and exclusive remedy for its objection to any Sub-Processor appointed during the Term.

6. International data transfers

6.0. As at the date of this DPA, all of Good Technologies' Sub-Processors are located, and hold Protected Data, in the United Kingdom (see Schedule 3), and Good Technologies does not transfer Protected Data outside the UK or EEA. As transfers between the UK and the EEA are not restricted transfers under Data Protection Laws, no SCCs or other transfer mechanism is currently required. The remainder of this clause 6 applies on a contingent basis, in the event that Good Technologies engages a Sub-Processor located outside the UK or EEA in the future, in accordance with the notice and objection provisions at clauses 5.4 and 5.5.

6.1. Australian Transfers. Where Good Technologies receives Protected Data protected by Australian Data Protection Laws, the Client acknowledges and agrees that Good Technologies may transfer such Personal Data to Sub-Processors located outside of Australia, as contemplated under this DPA, subject to Good Technologies complying with this DPA and applicable Data Protection Laws.

6.2. UK and European Transfers. The Client agrees that Good Technologies may transfer any Protected Data to Sub-Processors located outside the UK or European Economic Area (an "International Recipient"), provided all such transfers shall (to the extent required under Data Protection Laws) be effected under an appropriate transfer mechanism, including the SCCs, the UK's International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, as applicable.

6.3. Where there is a transfer of Protected Data to Good Technologies by a Client established in the European Economic Area, and the location of the relevant Good Technologies entity is a third country under European Data Protection Laws, Good Technologies agrees to abide by and process Protected Data in compliance with the SCCs in the form set out in Schedule 2. For the purposes of the descriptions in the SCCs, Good Technologies is the "data importer" and the Client is the "data exporter" (notwithstanding that the Client may itself be an entity located outside Europe).

6.4. Singapore Transfers. Where Good Technologies receives Protected Data protected by Singaporean Data Protection Laws, the Client acknowledges and agrees that Good Technologies may transfer such Protected Data to Sub-Processors located outside of Singapore, as contemplated under this DPA, subject to Good Technologies complying with the DPA and applicable Data Protection Laws.

Good Technologies has taken appropriate steps to ascertain whether, and to ensure that, any recipient of the Protected Data is bound by legally enforceable obligations to provide the transferred Protected Data a standard of protection at least comparable to that required under the applicable Data Protection Laws.

7. Staff

7.1. Good Technologies shall ensure that all persons authorised by it (or by any Sub-Processor) to process Protected Data are subject to a binding written contractual obligation to keep the Protected Data confidential (except where disclosure is required in accordance with Applicable Law, in which case Good Technologies shall, where practicable and not prohibited by Applicable Law, notify the Client of any such requirement before such disclosure).

8. Assistance with the Client's compliance and Data Subject rights

8.1. Good Technologies shall refer all Data Subject Requests it receives — including any received directly from Applicants — to the Client within ten Business Days of receipt.

8.2. Notwithstanding anything to the contrary in the Terms, Good Technologies reserves the right to disclose the identity of the Client to any relevant Data Subject following any such request from a Data Subject.

8.3. Good Technologies shall provide such reasonable assistance as the Client reasonably requires (taking into account the nature of processing and the information available to Good Technologies) in ensuring compliance with the Client's obligations under Data Protection Laws with respect to: (a) security of processing; (b) data protection impact assessments (as defined in Data Protection Laws) — including in respect of Programmes that involve special category data or children's data; (c) prior consultation with a Supervisory Authority regarding high-risk processing; and (d) notifications to the Supervisory Authority and/or communications to Data Subjects by the Client in response to any Personal Data Breach.

9. Records, information and audit

9.1. Good Technologies shall maintain, in accordance with Data Protection Laws binding on it, written records of all categories of processing activities carried out on behalf of the Client.

9.2. Good Technologies shall, in accordance with Data Protection Laws, make available to the Client such information as is reasonably necessary to demonstrate its compliance with the obligations of Data Processors under Data Protection Laws, and allow for and contribute to audits, including inspections, by the Client (or another auditor mandated by the Client), subject to the Client: (a) giving reasonable prior notice of such information request, audit, and/or inspection; (b) ensuring that all information obtained or generated in connection with such requests, inspections, and audits is kept strictly confidential (save for disclosure to the Supervisory Authority or as otherwise required by Applicable Law); (c) ensuring any such audit or inspection is undertaken during normal business hours, with minimal disruption to Good Technologies' business and that of other Clients; and (d) paying Good Technologies' reasonable costs for assisting with the provision of information and allowing for and contributing to on-site inspections and audits, calculated on a time and materials basis.

10. Breach notification

10.1. In respect of any Personal Data Breach involving Protected Data, Good Technologies shall, without undue delay (but in any event within 24 hours) from becoming aware of the same: (a) notify the Client of the Personal Data Breach; and (b) provide the Client, where possible, with details of the Personal Data Breach.

10.2. Notice of a Personal Data Breach shall include: (a) the nature of the Personal Data Breach (including, where possible, the categories and approximate number of data subjects and data records concerned); (b) the likely consequences of the Personal Data Breach; (c) the measures taken or proposed to be taken to address it, including, where appropriate, measures to mitigate its possible adverse effects; and (d) such other information as may be required by Data Protection Law.

11. Deletion or return of Protected Data and copies

11.1. Good Technologies shall, at the Client's written request, or provide facilities for the Client to either delete or return all the Protected Data to the Client in such form as the Client reasonably requests, within a reasonable time after the earlier of: (a) the end of the provision of the relevant Services related to processing; or (b) once processing by Good Technologies of any Protected Data is no longer required for the purpose of Good Technologies' performance of its relevant obligations under the Service Agreement — and shall delete existing copies (unless storage of any data is required by Applicable Law, in which case Good Technologies shall inform the Client of any such requirement).

12. Liability

12.1. Any claims brought under or in connection with this DPA shall be subject to the terms and conditions, including but not limited to the exclusions and limitations, set out in the Terms.

12.2. Notwithstanding the foregoing, the limitations specified in 12.1 shall not apply to Data Protection Losses. In no event shall any party limit its liability with respect to any individual's data protection rights under this DPA or otherwise.

12.3. Any Data Protection Losses incurred by one party arising from or in connection with the other's failure to comply with its obligations under this DPA or any applicable Data Protection Laws shall be considered a liability to the non-compliant party.

13. Cooperation

13.1. If a party receives a compensation claim from an individual or Supervisory Authority relating to processing of Protected Data, it shall promptly provide the other party with notice and full details of such claim. The party with conduct of the action shall: (a) make no admission of liability nor agree to any settlement or compromise of the relevant claim without the prior written consent of the other party (not to be unreasonably withheld or delayed); and (b) consult fully with the other party in relation to any such action.

14. Government Requests

14.1. Good Technologies does not, as a matter of course, voluntarily supply government authorities, agencies, or law enforcement access to or information relating to Good Technologies Client accounts or Protected Data. If Good Technologies receives a compulsory request (whether via court order, warrant, or other valid legal process) from any government authority, agency, or law enforcement for access to or information relating to a Client account (including Protected Data) belonging to a Client (a "Government Request"), Good Technologies shall take all reasonable steps necessary to confirm the validity of such a request.

14.2. Where Good Technologies satisfies itself that a Government Request is valid, it shall: (a) inform the government authority, agency, or law enforcement that Good Technologies is a processor of the Protected Data; (b) attempt to redirect the requestor to request the data directly from the Client; and (c) notify the Client via email of the Government Request to allow the Client to seek its own appropriate remedy, and may provide the Client's contact information to the requestor.

14.3. Good Technologies shall not be required to comply with clauses 14.1 or 14.2 if: (a) it is legally prohibited from doing so; or (b) it has a reasonable and good-faith belief that urgent access is necessary to prevent an imminent risk of serious harm to any individual, the safety of the public, or Good Technologies' Services or property.


SCHEDULE 1: DATA PROCESSING DETAILS

  1. Subject-matter of processing: Protected Data relating to Good Technologies' provision of the Services to the Client, including hosting and processing of Programme Data submitted by Applicants.

  2. Duration of the processing: The term of any relevant Service Agreement, until deletion of all Protected Data by Good Technologies in accordance with this DPA.

  3. Nature and purpose of the processing: Good Technologies will process Protected Data for the purpose of providing the Services to the Client — including enabling the Client to configure, publish, and administer Programmes; receive, store, and manage Submissions; communicate with Applicants; and export or report on Programme Data — in accordance with this DPA, the Terms, and as initiated by the Client (or its Applicants) in its use of the Services.

  4. Type of Personal Data: Data relating to individuals provided to Good Technologies via the Services by, or at the direction of, the Client, its Applicants, Co-authors, or Assessors. The specific questions and file uploads within a Programme are configured entirely by the Client, so the categories below reflect what the Services are capable of capturing rather than a fixed schema:

    • account data (email address and platform role — no name, phone number, or postal address is captured at account level by the Services; any such data is instead captured as Submission content, below);
    • Submission content, which the Client's question configuration may render as names, contact details, free text, or structured answers, and which may include documents, images, audio recordings, and video recordings (which may in turn identify a Co-author or other third party named or featured in the content);
    • equality and diversity monitoring information, where a Programme requests it;
    • information about access requirements or support needs, where a Programme requests it;
    • conflict-of-interest declarations made by Assessors, including free-text reasons and Client review notes, which may describe an Assessor's relationship to an Applicant;
    • where provided by an Applicant, Co-author, or Assessor as part of a Submission or declaration, special category data within the meaning of Article 9 UK GDPR (for example, health, disability, racial or ethnic origin, or religious belief information) — the Client is responsible for identifying an appropriate condition for processing any such data, and for auditing its own Programme question content to confirm whether this applies.

    Protected Data shall not include financial account, bank, or payment card details — see clause 2.6.

  5. Categories of Data Subjects: Applicants, Co-authors, and Assessors, and other individuals about whom data is provided to Good Technologies via the Services by, or at the direction of, the Client or its Applicants (for example, referees or nominees named within a Submission). Each Client's Programme(s) are hosted on a dedicated subdomain of the Services, and Protected Data relating to one Client's Applicants is not shared with another Client.


SCHEDULE 2: STANDARD CONTRACTUAL CLAUSES (PROCESSORS)

For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection, Good Technologies (whose details are particularised on the relevant Service Agreement and Terms, hereinafter the "data importer") and the Client (whose details are particularised on the relevant Service Agreement and Terms, hereinafter the "data exporter"), each a "party", together "the parties", HAVE AGREED on the following Contractual Clauses (the "Clauses") in order to adduce adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of individuals for the transfer by the data exporter to the data importer of the personal data specified in Appendix 1.

Clause 1 — Definitions

For the purposes of the Clauses: (a) "personal data", "special categories of data", "process/processing", "controller", "processor", "data subject", and "supervisory authority" shall have the same meaning as in Directive 95/46/EC; (b) "the data exporter" means the controller who transfers the personal data; (c) "the data importer" means the processor who agrees to receive from the data exporter personal data intended for processing on their behalf after the transfer, in accordance with their instructions and the terms of the Clauses, and who is not subject to a third country's system ensuring adequate protection within the meaning of Article 25(1) of Directive 95/46/EC; (d) "the subprocessor" means any processor engaged by the data importer or by any other subprocessor of the data importer who agrees to receive personal data exclusively intended for processing activities on behalf of the data exporter after the transfer, in accordance with their instructions, the terms of the Clauses, and the terms of the written subcontract; (e) "the applicable data protection law" means the legislation protecting the fundamental rights and freedoms of individuals, in particular their right to privacy with respect to the processing of personal data, applicable to a data controller in the Member State in which the data exporter is established; (f) "technical and organisational security measures" means measures aimed at protecting personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing.

Clause 2 — Details of the transfer

The details of the transfer, and in particular the special categories of personal data where applicable, are specified in Appendix 1, which forms an integral part of the Clauses.

Clause 3 — Third-party beneficiary clause

  1. The data subject can enforce against the data exporter this Clause, Clause 4(b) to (i), Clause 5(a) to (e) and (g) to (j), Clause 6(1) and (2), Clause 7, Clause 8(2), and Clauses 9 to 12 as third-party beneficiary.
  2. The data subject can enforce against the data importer this Clause, Clause 5(a) to (e) and (g), Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where the data exporter has factually disappeared or ceased to exist in law, unless a successor entity has assumed the entire legal obligations of the data exporter by contract or operation of law, in which case the data subject can enforce them against such entity.
  3. The data subject can enforce against the subprocessor this Clause, Clause 5(a) to (e) and (g), Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where both the data exporter and the data importer have factually disappeared, ceased to exist in law, or become insolvent, unless a successor entity has assumed the entire legal obligations of the data exporter by contract or operation of law. Such third-party liability of the subprocessor shall be limited to its own processing operations under the Clauses.
  4. The parties do not object to a data subject being represented by an association or other body if the data subject so expressly wishes and if permitted by national law.

Clause 4 — Obligations of the data exporter

The data exporter agrees and warrants: (a) that the processing, including the transfer itself, has been and will continue to be carried out in accordance with the relevant provisions of the applicable data protection law and does not violate the relevant provisions of that State; (b) that it has instructed, and will throughout the duration of the processing services instruct, the data importer to process the personal data transferred only on the data exporter's behalf and in accordance with the applicable data protection law and the Clauses; (c) that the data importer will provide sufficient guarantees in respect of the technical and organisational security measures specified in Appendix 2; (d) that, after assessment of the requirements of the applicable data protection law, the security measures are appropriate to protect personal data against accidental or unlawful destruction or loss, alteration, unauthorised disclosure or access, and other unlawful forms of processing, and ensure a level of security appropriate to the risks presented; (e) that it will ensure compliance with the security measures; (f) that, if the transfer involves special categories of data, the data subject has been informed or will be informed before, or as soon as possible after, the transfer that its data could be transmitted to a third country not providing adequate protection; (g) to forward any notification received from the data importer or any subprocessor pursuant to Clause 5(b) and Clause 8(3) to the data protection supervisory authority if the data exporter decides to continue the transfer or lift a suspension; (h) to make available to data subjects upon request a copy of the Clauses (except Appendix 2), a summary description of the security measures, and any subprocessing contract required under the Clauses, subject to removal of commercial information; (i) that, in the event of subprocessing, the processing activity is carried out in accordance with Clause 11 by a subprocessor providing at least the same level of protection as the data importer under the Clauses; and (j) that it will ensure compliance with (a) to (i) above.

Clause 5 — Obligations of the data importer

The data importer agrees and warrants: (a) to process the personal data only on behalf of the data exporter and in compliance with its instructions and the Clauses, and to inform the data exporter promptly if it cannot provide such compliance; (b) that it has no reason to believe the legislation applicable to it prevents it from fulfilling the data exporter's instructions and its obligations under the contract, and to notify the data exporter promptly of any change in that legislation likely to have a substantial adverse effect on the warranties and obligations under the Clauses; (c) that it has implemented the technical and organisational security measures specified in Appendix 2 before processing the personal data transferred; (d) to promptly notify the data exporter about any legally binding request for disclosure by a law enforcement authority, any accidental or unauthorised access, and any request received directly from data subjects, without responding to that request unless authorised to do so; (e) to deal promptly and properly with all inquiries from the data exporter and abide by the advice of the supervisory authority; (f) at the data exporter's request, to submit its data processing facilities for audit of the processing activities covered by the Clauses; (g) to make available to data subjects upon request a copy of the Clauses, or any subprocessing contract, subject to removal of commercial information; (h) that, in the event of subprocessing, it has previously informed the data exporter and obtained its prior written consent; (i) that subprocessing services will be carried out in accordance with Clause 11; and (j) to send promptly a copy of any subprocessor agreement to the data exporter.

Clause 6 — Liability

  1. The parties agree that any data subject who has suffered damage as a result of a breach of the obligations in Clause 3 or Clause 11 by any party or subprocessor is entitled to receive compensation from the data exporter for the damage suffered.
  2. Where a data subject cannot bring a claim against the data exporter because the data exporter has factually disappeared, ceased to exist in law, or become insolvent, the data importer agrees the data subject may claim against it as if it were the data exporter, unless a successor entity has assumed the data exporter's obligations. The data importer may not rely on a breach by a subprocessor to avoid its own liabilities.
  3. Where a data subject cannot bring a claim against either the data exporter or the data importer because both have factually disappeared, ceased to exist in law, or become insolvent, the subprocessor agrees the data subject may claim against it with regard to its own processing operations under the Clauses, unless a successor entity has assumed those obligations. The subprocessor's liability shall be limited to its own processing operations under the Clauses.

Clause 7 — Mediation and jurisdiction

  1. The data importer agrees that, if a data subject invokes third-party beneficiary rights or claims compensation for damages under the Clauses, it will accept the data subject's decision to: (a) refer the dispute to mediation by an independent person or the supervisory authority; or (b) refer the dispute to the courts in the Member State in which the data exporter is established.
  2. This choice does not prejudice the data subject's substantive or procedural rights to seek remedies under other provisions of national or international law.

Clause 8 — Cooperation with supervisory authorities

  1. The data exporter agrees to deposit a copy of this contract with the supervisory authority if requested or required under applicable data protection law.
  2. The supervisory authority has the right to audit the data importer, and any subprocessor, on the same terms as would apply to an audit of the data exporter.
  3. The data importer shall promptly inform the data exporter about the existence of legislation preventing an audit under paragraph 2, in which case the data exporter may take the measures foreseen in Clause 5(b).

Clause 9 — Governing Law

The Clauses shall be governed by the law of the Member State in which the data exporter is established.

Clause 10 — Variation of the contract

The parties undertake not to vary or modify the Clauses, save for adding business-related clauses that do not contradict them.

Clause 11 — Subprocessing

  1. The data importer shall not subcontract its processing operations under the Clauses without the data exporter's prior written consent, and any such subcontract shall impose the same obligations on the subprocessor as apply to the data importer. Where a subprocessor fails to fulfil its obligations, the data importer remains fully liable to the data exporter.
  2. The written agreement between the data importer and subprocessor shall include a third-party beneficiary clause as set out in Clause 3, for cases where the data subject cannot claim against the data exporter or data importer because they have disappeared, ceased to exist, or become insolvent.
  3. Data protection aspects of subprocessing shall be governed by the law of the Member State in which the data exporter is established.
  4. The data exporter shall keep an updated list of subprocessing agreements notified to it, available to its supervisory authority.

Clause 12 — Obligations after termination

  1. On termination of the data processing services, the data importer and subprocessor shall, at the data exporter's choice, return all personal data transferred (and copies) to the data exporter, or destroy it and certify that this has been done, unless legislation prevents this — in which case confidentiality must be guaranteed and no further active processing undertaken.
  2. The data importer and subprocessor warrant that, on request, they will submit their data processing facilities for audit of the measures in paragraph 1.

APPENDIX 1 TO THE STANDARD CONTRACTUAL CLAUSES — Details of the transfer: Please see Schedule 1 to this Data Processing Agreement.

APPENDIX 2 TO THE STANDARD CONTRACTUAL CLAUSES — Description of the technical and organisational security measures implemented by the data importer, available upon request.


SCHEDULE 3: CURRENT SUB-PROCESSORS

The following table sets out Good Technologies' current Sub-Processors as at the date of this DPA. This list is maintained on an ongoing basis; the version provided to the Client on request or on notice of a change under clause 5.4 shall prevail over this Schedule if the two differ.

Sub-Processor Role Data processed Location
DigitalOcean Cloud infrastructure: compute, managed database, managed cache/session store, container registry, and automated infrastructure backups All Protected Data processed via the Services London, UK
Amazon Web Services (S3) File storage for uploaded Submissions (documents, images, audio, and video files) Submission file content London, UK
Amazon Web Services (SES) Delivery of transactional email (registration, password reset, invitations, notifications) Name/email address as needed to address and send the email London, UK

No other third party processes Protected Data on Good Technologies' behalf as at the date of this DPA. Good Technologies does not use any third-party analytics, advertising, payment, or support-desk tool that receives Protected Data.


Good Technologies Limited. Jactin House, 24 Hood St, Manchester M4 6WX. Registered in England: 11189871. VAT GB352267405.

All legal documents

GoodSubmissions
Legal
© Good Technologies Ltd.
Version: 1.1.33