This Data Processing Agreement ("DPA") forms part of the agreement between the tenant company ("Controller") and Vilmak Ltd (company number 17425133, registered office: Bowen Suite, The Globe Centre, 1 St. James Square, Accrington, BB5 0RE) ("Processor"), for the provision of The Logical Auditor platform (the "Service"), and applies whenever Vilmak processes personal data on the Controller's behalf. It is incorporated by reference into our Terms of Service.
This DPA applies for the duration of the Controller's use of the Service under the Terms of Service, and for so long afterwards as Vilmak retains any personal data processed on the Controller's behalf.
Vilmak processes personal data solely to provide the Service: operating the platform, storing and displaying account and activity data, generating reports, sending transactional notifications, and maintaining backups, all as instructed by and configured by the Controller through its use of the Service.
Personal data processed may include: name and email address of Authorised Users; hashed passwords; role and department assignments; shift check-in and check-out timestamps; walkaround (quality-check) records; machine/production log entries and calculated scrap data; and Quality Lock breach records linking a station, a worker, and a timestamp.
The Controller's employees, contractors, and other individuals authorised by the Controller to use the Service (including factory workers and tenant administrators).
Vilmak will process personal data only on the Controller's documented instructions, which are given by the Controller's configuration and use of the Service, and as otherwise agreed in writing, unless required to do otherwise by law — in which case Vilmak will inform the Controller before processing, unless prohibited from doing so.
Vilmak will ensure that any personnel authorised to process personal data are subject to a duty of confidentiality.
Vilmak implements appropriate technical and organisational measures, including:
The Controller authorises Vilmak to engage the following sub-processors:
Vilmak will inform the Controller of any intended changes to sub-processors, giving the Controller a reasonable opportunity to object on reasonable data-protection grounds. Vilmak remains responsible for the acts and omissions of its sub-processors as if they were its own.
Personal data is stored primarily within the United Kingdom, with off-site backups stored within the European Economic Area (Berlin, Germany). The UK's data protection framework recognises the EEA as providing an adequate level of protection, so no additional transfer safeguards are currently required. If Vilmak engages a sub-processor outside the UK or EEA in a jurisdiction not covered by adequacy regulations, Vilmak will put in place an appropriate transfer mechanism (such as the UK's International Data Transfer Addendum) before doing so.
Vilmak will, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to respond to requests from data subjects exercising their rights under data protection law. Where a data subject contacts Vilmak directly, Vilmak will refer the request to the Controller and provide reasonable assistance as required.
Vilmak will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide reasonably available information to help the Controller meet its own breach-notification obligations.
Vilmak will provide reasonable assistance to the Controller, taking into account the nature of processing and information available to Vilmak, where the Controller is required to carry out a data protection impact assessment or consult with a supervisory authority.
On reasonable written notice, and no more than once per year (except following a security incident), Vilmak will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA. Audits will in the first instance be conducted remotely, through documentation and written responses to reasonable questions; an on-site or physical inspection will only be arranged where reasonably necessary and by mutual agreement on timing. Any audit must be conducted in a manner that does not provide the Controller with access to any other tenant's data or systems, is subject to reasonable confidentiality safeguards, and is at the Controller's own cost unless the audit identifies a material breach of this DPA by Vilmak.
On termination of the Service, Vilmak will, at the Controller's choice, delete or return all personal data processed on the Controller's behalf, and will delete existing copies, within the timeframe set out in the Terms of Service, except to the extent retention is required by applicable law.
Liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
This DPA is governed by the laws of England and Wales. In the event of any conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.