A clear processing agreement for customer data.
This Data Processing Addendum is intended to apply when Accagrity processes personal data in customer-controlled documents or workspaces on behalf of a business, institution, or other organisation. It is a working template and must be completed and reviewed for the contracting entity, service scope, and applicable law before signature.
1. Parties and roles
The customer is the controller or business responsible for personal data submitted to an organisation-controlled workspace. Accagrity is the processor or service provider for that data, except where Accagrity determines purposes for account administration, security, billing, legal compliance, and service integrity as described in the Privacy Policy. The contracting Accagrity entity is: [INSERT LEGAL ENTITY NAME, REGISTRATION NUMBER, AND ADDRESS].
2. Documented instructions
Accagrity will process customer data only to provide, secure, support, and maintain the contracted service, and on documented instructions from the customer. The service may host, retrieve, analyse, compare, transform, export, preserve revision history, validate uploads, and maintain provenance records when those operations are requested through the product. The customer is responsible for the lawfulness of its instructions and for providing required notices to individuals.
3. Confidentiality and security
Persons authorised to process customer data will be subject to confidentiality obligations. Accagrity will maintain appropriate technical and organisational measures, including access control, authentication, encryption in transit, protected storage, upload validation, rate limiting, logging, workspace isolation, and secure deletion processes appropriate to the risk. The customer remains responsible for account configuration, member permissions, lawful content, and backups of critical work.
4. Subprocessors and transfers
The customer generally authorises the subprocessors listed in the Subprocessor Register. Accagrity will impose written data-protection obligations on subprocessors and remains responsible for their processing as required by applicable law. Processing may occur outside the EEA, UK, or customer country. The parties will use an applicable lawful transfer mechanism, such as an adequacy decision, EU Standard Contractual Clauses, UK Addendum, or another lawful safeguard, with supplementary measures where required.
5. Assistance and rights requests
Taking into account the nature of processing, Accagrity will provide reasonable assistance with access, correction, deletion, restriction, portability, security, and regulatory requests. Customers should direct individual requests to their organisation first. Accagrity will not respond independently to a request concerning customer-controlled content unless instructed or legally required.
6. Incidents, deletion, and audit
Accagrity will notify the customer without undue delay after confirming a personal-data breach affecting customer-controlled data, provide available relevant information, and cooperate on reasonable response steps. At the end of the service, Accagrity will delete or return customer data according to the customer’s instructions, subject to legal retention, active legal holds, restricted backups, and documented retention windows. Customer audits may be satisfied through current security documentation, certifications when available, questionnaires, and reasonable additional information. Audit scope must protect other customers and Accagrity’s confidential information.
7. Priority and governing documents
If this Addendum conflicts with the Terms for processing of personal data, this Addendum controls. The contracting parties should insert the applicable governing law, supervisory authority, notice contacts, and signed order details here: [INSERT CONTRACT-SPECIFIC DETAILS].
Template effective date: 3 September 2026. This document is not legal advice and requires completion by the contracting parties.