Legal
Data Processing Addendum
Terms for processing personal data on behalf of customers.
Roles
Where Farqad Cloud processes personal data on behalf of a customer in providing services, the customer is the controller (or processor) and Farqad Cloud is the processor (or subprocessor). Website visitor data is typically controlled by Farqad Cloud as described in the Privacy Policy.
Instructions
We process personal data only on documented customer instructions, including this DPA, the SOW, and product configuration, unless required by law. We will promptly inform the customer if, in our reasonable view, an instruction infringes applicable data-protection law, unless the law prohibits that notice. We will not transfer personal data to a third country except on documented instructions or as required by law.
Processing details
Unless the SOW states more specific details:
- Subject matter: professional cloud, software-delivery, security, support, and related services described in the SOW.
- Duration: the engagement term plus the limited retention and deletion period stated in the SOW or Data Retention and Deletion Policy.
- Nature and purpose: access, review, organization, storage, transmission, troubleshooting, development, testing, security, support, deletion, and other operations necessary to deliver the documented services.
- Data types: business contact and account information, identifiers, technical and usage data, communications, system records, and other personal data the customer lawfully provides or makes accessible.
- Data subjects: customer personnel, contractors, authorized users, customers, prospects, suppliers, and other individuals whose data the customer places in scope.
The customer must identify special-category, criminal-offence, children’s, health, financial, or other highly regulated data before providing access. Such data is out of scope unless expressly authorized in the SOW with appropriate safeguards.
Confidentiality and security
Personnel authorized to process personal data are bound by confidentiality. We implement measures appropriate to the risk and consistent with our Security Policy, including access control, authentication, encryption in transit for systems we control, vulnerability management, logging where in scope, incident handling, and restoration measures appropriate to the service.
Subprocessors
Customer gives general written authorization for the subprocessors listed at /legal/subprocessors. We will provide advance notice of intended additions or replacements for active processing engagements and allow a reasonable opportunity to object on documented data-protection grounds. We impose materially equivalent data-protection obligations on subprocessors and remain responsible for their performance to the extent required by applicable law.
Assistance
Taking into account the nature of processing and information available to us, we assist with data-subject requests, security obligations, personal-data-breach notifications, data-protection impact assessments, and regulator consultations as required by applicable law. We notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer data and provide available information reasonably needed for the customer’s response.
International transfers
Where transfers occur from the EEA/UK/Switzerland to third countries, we implement appropriate safeguards (for example SCCs) with relevant parties.
Return and deletion
Upon engagement end and at the customer’s choice, we delete or return customer personal data within the timelines in the Data Retention and Deletion Policy, and delete existing copies, except where retention is legally required. Legally retained data remains protected and is used only for the required purpose.
Audits
Customers may request information reasonably necessary to demonstrate compliance, including via the Trust Center request-access workflow. We will contribute to reasonable audits and inspections by the customer or an independent auditor. Audits require reasonable notice, confidentiality, minimal operational disruption, and proportionate scope, unless a regulator or applicable law requires otherwise.
Customer obligations
The customer is responsible for the lawfulness, accuracy, transparency, and documented instructions for personal data it places in scope, including any required notices, legal bases, and rights handling.
Change notification
We may update this policy to reflect legal, operational, or service changes. Material changes will be communicated on this page or through another appropriate notice. Where required by law or contract, we will provide additional notice. Where affirmative consent or a contractual amendment is required, continued use alone will not replace that process.