This Data Processing Addendum (“DPA”) forms part of the Terms of Service or any other written agreement (the “Agreement”) between PartnerBridge Ltd (“PartnerBridge”, “Processor”, “we”, “our” or “us”) and the customer identified in the Agreement (“Customer”, “Controller”, “you” or “your”).
This DPA governs the Processing of Personal Data by PartnerBridge on behalf of the Customer when providing the PartnerBridge Services.
Where there is any conflict between this DPA and the Agreement in relation to the Processing of Personal Data, this DPA shall prevail to the extent of that conflict.
Parties
Data Processor
PartnerBridge Ltd
Registered in Scotland
Company Number: SC856320
Registered Office:
Clyde Offices, 2nd Floor
48 West George Street
Glasgow
G2 1BP
United Kingdom
ICO Registration Number
ZB944221
Contact
Data Controller
The Customer identified within the applicable Agreement.
The Customer determines the purposes and means of Processing Customer Personal Data submitted to the PartnerBridge Services.
Purpose
The purpose of this DPA is to establish the parties’ respective obligations regarding the Processing of Personal Data and to ensure compliance with applicable Data Protection Laws, including:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- EU General Data Protection Regulation (EU GDPR), where applicable
- California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), where applicable
- Any other applicable data protection or privacy legislation governing the Processing of Personal Data under the Agreement.
Scope
This DPA applies whenever PartnerBridge Processes Personal Data on behalf of the Customer in connection with the Services, including but not limited to:
- RelateIQ
- Precision Insights
- Activate
- PartnerBridge APIs
- Customer portals
- Customer support services
- Professional services provided under the Agreement
- Any associated PartnerBridge platform or application.
This DPA does not apply where PartnerBridge acts as an independent Data Controller, including when Processing Personal Data relating to:
- prospective customers;
- marketing activities;
- website visitors;
- event registrations;
- recruitment activities;
- business administration; or
- legal and regulatory compliance.
Such Processing is governed by the PartnerBridge Privacy Policy.
Definitions
Unless otherwise defined in the Agreement, the following definitions apply throughout this DPA.
“Agreement” means the Terms of Service, Master Services Agreement or other principal services agreement between the parties, together with any applicable Order Form.
“Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under this DPA, including the UK GDPR, Data Protection Act 2018, EU GDPR where applicable, CCPA/CPRA where applicable, and any successor legislation.
“Applicable Law” means any law, regulation, court order or legally binding governmental requirement applicable to a party or the Services.
“Controller” means the natural or legal person that determines the purposes and means of Processing Personal Data.
“Customer Data” means all information submitted to the Services by or on behalf of the Customer.
“Customer Personal Data” means Personal Data contained within Customer Data.
“Data Subject” means an identified or identifiable natural person.
“Personal Data” has the meaning given under Applicable Data Protection Laws.
“Personal Data Breach” means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
“Process”, “Processing”, “Processed” and similar expressions shall have the meanings given under Applicable Data Protection Laws.
“Processor” means a person or organisation that Processes Personal Data on behalf of a Controller.
“Services” means the products and services supplied by PartnerBridge under the Agreement.
“Sub-processor” means any third party appointed by PartnerBridge to Process Customer Personal Data on behalf of the Customer.
Roles of the Parties
Except where expressly agreed otherwise in writing:
- where the Customer determines the purposes and means of Processing Customer Personal Data, the Customer acts as the Controller and PartnerBridge acts as the Processor;
- where the Customer Processes Customer Personal Data on behalf of another Controller, the Customer acts as a Processor and appoints PartnerBridge as its Sub-processor;
- the Customer is responsible for ensuring that it has authority to appoint PartnerBridge and for communicating any relevant Controller instructions to PartnerBridge;
- PartnerBridge shall Process Customer Personal Data only in accordance with the Customer’s documented instructions, the Agreement and this DPA.
Where PartnerBridge independently determines the purposes and means of Processing Personal Data, PartnerBridge acts as a separate Controller in accordance with its Privacy Policy.
Order of Precedence
If there is any inconsistency between:
- this DPA;
- the Agreement;
- any Order Form; or
- any other document governing the Services,
the documents shall prevail in the above order solely in relation to the Processing of Personal Data.
Processing of Customer Personal Data
7.1Customer Instructions
PartnerBridge shall Process Customer Personal Data only:
- in accordance with the Customer’s documented instructions;
- as necessary to provide the Services under the Agreement;
- as required to comply with applicable law; or
- where otherwise expressly authorised by this DPA or the Agreement.
If PartnerBridge is required by law to Process Customer Personal Data in a manner not authorised by the Customer, PartnerBridge shall, unless prohibited by law, notify the Customer before carrying out such Processing.
PartnerBridge shall immediately notify the Customer if, in its opinion, any documented instruction infringes Applicable Data Protection Laws.
7.2Nature of Processing
PartnerBridge Processes Customer Personal Data solely for the purpose of providing the Services.
Processing activities may include:
- collection;
- recording;
- organisation;
- structuring;
- storage;
- retrieval;
- consultation;
- analysis;
- classification;
- transmission;
- generation of reports;
- AI-assisted analysis;
- customer support;
- backup and disaster recovery;
- deletion; and
- secure disposal.
PartnerBridge shall not Process Customer Personal Data for any purpose incompatible with the Agreement.
7.3Customer Responsibilities
The Customer represents and warrants that:
- it has all necessary rights, permissions and lawful bases to provide Customer Personal Data to PartnerBridge;
- it has provided any notices required under Applicable Data Protection Laws;
- its instructions comply with Applicable Data Protection Laws;
- Customer Personal Data has been collected lawfully; and
- the Processing requested under the Agreement is lawful.
The Customer remains solely responsible for:
- determining the lawful basis for Processing;
- responding to Data Subject requests unless otherwise agreed;
- determining retention requirements for Customer Data;
- the accuracy of Customer Personal Data submitted to the Services; and
- ensuring that no unlawful or prohibited content is uploaded.
7.4Confidentiality
PartnerBridge shall ensure that all personnel authorised to Process Customer Personal Data:
- are subject to appropriate confidentiality obligations;
- receive appropriate privacy and security training;
- access Customer Personal Data only where necessary to perform their duties; and
- remain bound by confidentiality obligations after their engagement ends.
PartnerBridge shall implement appropriate access controls to ensure Customer Personal Data is accessible only by authorised personnel.
7.5Security Measures
PartnerBridge shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful:
- destruction;
- loss;
- alteration;
- unauthorised disclosure; or
- unauthorised access.
The specific security measures implemented by PartnerBridge are described in Annex D (Technical and Organisational Measures).
PartnerBridge may update its security measures from time to time provided such changes do not materially reduce the overall level of protection provided to Customer Personal Data.
7.6Personal Data Breaches
If PartnerBridge becomes aware of a Personal Data Breach affecting Customer Personal Data, PartnerBridge shall:
- notify the Customer without undue delay after becoming aware of the breach;
- provide available information regarding the nature of the breach;
- describe the categories of Personal Data affected, where known;
- describe the likely consequences of the breach, where reasonably possible;
- describe measures taken or proposed to mitigate the breach; and
- provide additional information as it becomes available.
PartnerBridge shall cooperate with the Customer to enable the Customer to comply with its legal obligations relating to Personal Data Breaches.
PartnerBridge’s notification of a Personal Data Breach shall not be construed as an admission of liability or fault.
7.7Assistance with Data Subject Rights
Taking into account the nature of the Processing, PartnerBridge shall provide reasonable assistance to enable the Customer to fulfil its obligations in responding to requests from Data Subjects, including requests relating to:
- access;
- rectification;
- erasure;
- restriction of Processing;
- portability;
- objection to Processing; and
- withdrawal of consent where applicable.
Where PartnerBridge receives a request directly from a Data Subject concerning Customer Personal Data, PartnerBridge shall:
- promptly notify the Customer unless prohibited by law;
- not respond directly except where legally required; and
- provide reasonable assistance to enable the Customer to respond.
7.8Regulatory Assistance
Taking into account the nature of the Processing and the information available to PartnerBridge, PartnerBridge shall provide reasonable assistance to the Customer in relation to:
- Data Protection Impact Assessments (DPIAs);
- prior consultations with supervisory authorities;
- regulatory investigations relating to the Services; and
- compliance with Articles 32 to 36 of the UK GDPR and equivalent provisions of other Applicable Data Protection Laws.
PartnerBridge reserves the right to charge reasonable fees where assistance extends beyond standard support obligations or requires substantial additional work.
7.9Audit Rights
Upon reasonable written request, PartnerBridge shall make available information reasonably necessary to demonstrate compliance with this DPA.
Except where required by a supervisory authority, following a Personal Data Breach affecting Customer Personal Data, or where the Customer has reasonable grounds to suspect material non-compliance, an audit may be requested no more than once in any twelve-month period.
Where the information provided is insufficient to satisfy the Customer’s reasonable compliance requirements, the Customer may conduct, or appoint an independent auditor to conduct, a proportionate further audit in accordance with this Section.
Any audit shall:
- occur during normal business hours;
- be subject to reasonable confidentiality obligations;
- avoid disruption to PartnerBridge’s operations;
- not compromise the confidentiality, security or privacy of other customers;
- be conducted by an independent auditor approved by PartnerBridge, such approval not to be unreasonably withheld; and
- be undertaken at the Customer’s expense unless otherwise required by law.
PartnerBridge may satisfy audit obligations by providing independent third-party certifications, audit reports or equivalent compliance documentation where appropriate.
7.10Return and Deletion of Customer Personal Data
Upon termination or expiry of the Agreement, the Customer may request return of Customer Personal Data during any export period specified in the Agreement or, where no period is specified, within thirty (30) days after termination.
Following expiry of that period, PartnerBridge shall securely delete Customer Personal Data within sixty (60) days, unless:
- the Customer requests earlier deletion and such deletion is technically and legally practicable;
- retention is required by applicable law; or
- the data remains temporarily within routine backup systems as described below.
PartnerBridge may retain Customer Personal Data where required:
- by applicable law;
- for the establishment, exercise or defence of legal claims;
- to comply with regulatory obligations; or
- within routine encrypted backup systems until overwritten in accordance with standard backup retention practices.
Following expiry of any applicable retention period, retained Customer Personal Data shall be securely deleted or irreversibly anonymised.
7.11Records of Processing
PartnerBridge shall maintain records of Processing activities where required by Applicable Data Protection Laws.
Such records shall include, where applicable:
- categories of Processing activities;
- categories of Customer Personal Data;
- categories of recipients;
- international transfers;
- retention practices; and
- general descriptions of technical and organisational security measures.
Sub-processors
8.1General Authorisation
The Customer provides PartnerBridge with general authorisation to engage Sub-processors to Process Customer Personal Data on the Customer’s behalf, provided that PartnerBridge remains responsible for the performance of its Sub-processors in accordance with this DPA.
PartnerBridge shall ensure that each Sub-processor is bound by written contractual obligations that provide a level of protection for Customer Personal Data substantially equivalent to those set out in this DPA, including appropriate obligations relating to confidentiality, security, international transfers and compliance with Applicable Data Protection Laws.
8.2Current Sub-processors
As of the Effective Date of this DPA, PartnerBridge uses the following categories of Sub-processors:
- Google Workspace – business email, collaboration and document management.
- HubSpot – customer relationship management and customer communications.
- OpenAI – AI-assisted analysis and platform functionality.
- FullStory – website and application analytics and user experience diagnostics.
- Google Analytics – website analytics and performance measurement.
PartnerBridge may update this list from time to time in accordance with this Section.
A current list of approved Sub-processors is maintained in Annex E of this DPA.
8.3Changes to Sub-processors
PartnerBridge may appoint additional Sub-processors where reasonably necessary for the operation or improvement of the Services.
Where a new Sub-processor is expected to Process Customer Personal Data, PartnerBridge shall provide notice at least thirty (30) days before the new Sub-processor begins Processing.
If the Customer reasonably believes that the appointment of a new Sub-processor would materially increase privacy or security risks, the Customer may notify PartnerBridge in writing within thirty (30) days of the notification.
The parties shall work together in good faith to resolve the Customer’s concerns.
Where the parties cannot resolve the Customer’s reasonable objection, the Customer may terminate only the portion of the Services that cannot reasonably be provided without the disputed Sub-processor by giving written notice before that Sub-processor begins Processing Customer Personal Data.
Any prepaid fees attributable to the terminated portion of the Services for the period after termination shall be refunded on a pro rata basis, unless the Agreement expressly provides otherwise.
8.4Sub-processor Liability
PartnerBridge remains responsible for the performance of its Sub-processors to the same extent as if the relevant Processing activities had been performed directly by PartnerBridge, except where otherwise permitted under Applicable Data Protection Laws.
International Transfers
9.1Transfers Outside the United Kingdom
Customer Personal Data may be transferred outside the United Kingdom where necessary to provide the Services.
Where such transfers occur, PartnerBridge shall ensure that appropriate safeguards are implemented in accordance with Applicable Data Protection Laws.
These safeguards may include:
- UK International Data Transfer Agreements (IDTAs);
- the UK Addendum to the EU Standard Contractual Clauses;
- adequacy regulations issued by the UK Government;
- European Commission adequacy decisions where applicable; or
- any other lawful transfer mechanism recognised under Applicable Data Protection Laws.
9.2Transfer Impact Assessments
Where required by Applicable Data Protection Laws, PartnerBridge shall undertake appropriate assessments of international transfers and implement supplementary technical, contractual or organisational safeguards where reasonably necessary.
9.3Onward Transfers
PartnerBridge shall ensure that any onward transfer of Customer Personal Data by a Sub-processor is subject to contractual safeguards that provide a level of protection substantially equivalent to those required under this DPA.
9.4Transfer Mechanisms
Where a restricted transfer of Customer Personal Data between the parties requires contractual safeguards:
- the parties shall enter into or incorporate the applicable UK International Data Transfer Agreement, UK Addendum to the European Commission Standard Contractual Clauses, or other legally recognised transfer mechanism;
- the applicable transfer mechanism shall be deemed incorporated into this DPA upon execution or electronic acceptance by the parties where legally permitted; and
- if the relevant transfer mechanism conflicts with this DPA, the transfer mechanism shall prevail solely in relation to the restricted transfer.
PartnerBridge shall ensure that restricted onward transfers by its Sub-processors are governed by an appropriate transfer mechanism where required by Applicable Data Protection Laws.
California Privacy Rights
This Section applies only where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), applies to the Processing of Customer Personal Data.
10.1Service Provider Status
To the extent that Customer Personal Data includes Personal Information regulated by the CCPA, PartnerBridge acts as a Service Provider or Contractor, as those terms are defined under the CCPA.
PartnerBridge shall Process such Personal Information solely:
- for the Business Purposes described in the Agreement;
- in accordance with the Customer’s documented instructions; and
- as otherwise permitted under applicable law.
10.2No Sale or Sharing
PartnerBridge shall not:
- sell Customer Personal Information;
- share Customer Personal Information for cross-context behavioural advertising;
- retain, use or disclose Customer Personal Information for any purpose other than providing the Services, except where permitted by law; or
- combine Customer Personal Information received from one Customer with information obtained from another source except where permitted by the CCPA.
10.3Additional CCPA Commitments
PartnerBridge shall:
- Process Customer Personal Information only for the limited and specific Business Purposes described in Annex A and the applicable Order Form;
- not retain, use or disclose Customer Personal Information outside the direct business relationship between PartnerBridge and the Customer, except as permitted by the CCPA;
- comply with all applicable provisions of the CCPA and provide the same level of privacy protection required of the Customer in respect of Customer Personal Information;
- implement reasonable security procedures and practices appropriate to the nature of the Customer Personal Information;
- notify the Customer without undue delay if PartnerBridge determines that it can no longer meet its obligations under the CCPA;
- permit the Customer to take reasonable and appropriate steps to verify that PartnerBridge uses Customer Personal Information consistently with the Customer’s obligations under the CCPA; and
- cooperate with reasonable steps taken by the Customer to stop and remediate any unauthorised use of Customer Personal Information.
PartnerBridge certifies that it understands and will comply with the restrictions and obligations set out in this Section 10.
10.4Consumer Requests
PartnerBridge shall provide reasonable assistance to enable the Customer to respond to verified consumer requests relating to:
- access;
- deletion;
- correction;
- portability;
- restriction of processing where applicable; and
- any other rights available under applicable privacy legislation.
10.5Compliance Assistance
Upon reasonable request, PartnerBridge shall provide information reasonably necessary for the Customer to demonstrate compliance with applicable privacy legislation relating to the Services.
Liability
Nothing in this DPA shall:
- limit either party’s liability where such limitation is prohibited by Applicable Data Protection Laws; or
- modify the liability provisions contained in the Agreement except to the extent expressly required by Applicable Data Protection Laws.
Term and Termination
This DPA shall become effective on the Effective Date of the Agreement and shall remain in force for so long as PartnerBridge Processes Customer Personal Data on behalf of the Customer.
The obligations contained in this DPA relating to confidentiality, security, deletion, international transfers and compliance with Applicable Data Protection Laws shall survive termination of the Agreement for so long as PartnerBridge retains Customer Personal Data.
Annex A – Details of Processing
This Annex forms part of the Data Processing Addendum.
A.1Subject Matter of Processing
PartnerBridge Processes Customer Personal Data solely for the purpose of providing the Services described in the Agreement, including the provision of technology partnership analysis, evidence generation, customer support, platform administration, security, maintenance and related functionality.
A.2Duration of Processing
Processing shall continue for the duration of the Agreement and for any additional period during which PartnerBridge is required to retain Customer Personal Data in accordance with applicable law or the Agreement.
A.3Nature of Processing
Processing activities may include:
- collection;
- recording;
- organisation;
- structuring;
- storage;
- adaptation;
- retrieval;
- consultation;
- analysis;
- AI-assisted classification;
- evidence generation;
- reporting;
- transmission;
- hosting;
- backup;
- restoration;
- deletion; and
- secure destruction.
A.4Purpose of Processing
Customer Personal Data is Processed solely for purposes authorised by the Customer, including:
- providing access to the Services;
- authenticating authorised users;
- analysing customer-submitted business information;
- generating technology partnership recommendations;
- producing reports and evidence bundles;
- storing customer documents;
- responding to support requests;
- maintaining platform security;
- preventing fraud and abuse;
- performing system maintenance; and
- complying with legal obligations.
PartnerBridge shall not Process Customer Personal Data for advertising, profiling unrelated to the Services, or any other independent commercial purpose.
Annex B – Categories of Personal Data
Depending upon how the Customer uses the Services, Customer Personal Data may include:
Customer Account Information
- names;
- business email addresses;
- usernames;
- passwords (stored only as cryptographic hashes);
- job titles;
- company names;
- telephone numbers.
Customer Content
Information uploaded by Customers, including:
- documents;
- presentations;
- spreadsheets;
- reports;
- strategic planning materials;
- technology partner information;
- customer-provided datasets;
- business contact information contained within uploaded files.
Technical Information
- IP addresses;
- browser information;
- operating system;
- device identifiers;
- authentication logs;
- session identifiers;
- timestamps;
- API request metadata;
- audit logs.
Support Information
- emails;
- support requests;
- attachments;
- meeting notes;
- troubleshooting information;
- communications with PartnerBridge.
Usage Information
- feature usage;
- navigation behaviour;
- application events;
- diagnostic information;
- performance metrics;
- crash reports;
- analytics events.
Annex C – Categories of Data Subjects
Depending upon the Customer’s use of the Services, Customer Personal Data may relate to:
- Customer employees;
- Customer contractors;
- authorised users;
- prospective customers;
- business contacts;
- technology partners;
- suppliers;
- consultants;
- advisors;
- individuals whose information is contained within Customer-uploaded documents; and
- other individuals whose Personal Data the Customer lawfully submits to the Services.
PartnerBridge does not intentionally collect special category Personal Data unless expressly authorised by the Customer.
The Services are not designed for the Processing of Special Category Personal Data, criminal offence data, protected health information or payment card data. The Customer shall not submit such data unless the parties expressly agree in writing to the relevant Processing and any additional safeguards required.
Annex D – Technical and Organisational Measures
PartnerBridge implements and maintains the following measures to the extent applicable to the Services and the nature of the Customer Personal Data being Processed. Only measures actually deployed within the relevant production environment shall be represented as operational controls.
These measures include, where appropriate:
Information Security Governance
- documented security policies;
- defined access management procedures;
- security awareness training;
- confidentiality obligations for personnel;
- least privilege principles;
- role-based access controls.
Authentication
- authenticated user access;
- strong password requirements;
- secure credential storage;
- session management;
- authentication logging.
Encryption
- TLS encryption for data transmitted over public networks;
- encryption of Personal Data at rest where appropriate;
- encrypted backups where supported by the hosting environment.
Infrastructure Security
- secure hosting environments;
- operating system security updates;
- network firewalls;
- infrastructure monitoring;
- vulnerability management;
- malware protection where appropriate.
Application Security
- input validation;
- access control enforcement;
- audit logging;
- secure development practices;
- dependency management;
- vulnerability remediation;
- change management procedures.
Availability and Resilience
- routine backups;
- disaster recovery procedures;
- monitoring of critical services;
- redundancy where appropriate;
- restoration testing where appropriate.
Personnel Security
PartnerBridge ensures that personnel with access to Customer Personal Data:
- are authorised to access such data;
- receive appropriate privacy and security training;
- are subject to confidentiality obligations; and
- access Customer Personal Data only where necessary to perform their responsibilities.
Incident Management
PartnerBridge maintains procedures for:
- identifying security incidents;
- investigating incidents;
- mitigating security risks;
- notifying Customers where required;
- documenting incidents; and
- implementing corrective actions.
Data Minimisation
PartnerBridge designs its Services to minimise the collection and retention of Personal Data where reasonably possible.
Customer Personal Data is accessed only where necessary for providing the Services or complying with legal obligations.
AI Processing Safeguards
Where Customer Content is processed using AI-assisted functionality:
- Processing is performed solely to provide the Services requested by the Customer.
- PartnerBridge does not use Customer Content to train general-purpose, publicly available or shared foundation models. Where a third-party AI provider Processes Customer Content, PartnerBridge shall configure and contract for the relevant service so that Customer Content is not used to train such models, except where the Customer expressly instructs otherwise in writing.
- AI-generated outputs are provided as decision-support tools and remain subject to Customer review.
- PartnerBridge retains appropriate controls over AI-assisted processing consistent with applicable privacy obligations.
Continuous Improvement
PartnerBridge periodically reviews and updates its technical and organisational measures to reflect:
- evolving security risks;
- changes in technology;
- regulatory developments;
- industry best practices; and
- changes to the Services.
Annex E – Approved Sub-processors
Annex E identifies third parties that PartnerBridge engages to Process Customer Personal Data on behalf of the Customer.
Providers used solely for PartnerBridge’s independent controller activities, including general sales, marketing or public-website analytics, are not Sub-processors for the purposes of this DPA and are described separately in the PartnerBridge Privacy Policy.
The Customer provides general authorisation for PartnerBridge to engage the following Sub-processors in accordance with Section 8 of this DPA.
PartnerBridge may update this list from time to time as described in this DPA.
Google Workspace
Purpose
Business email, calendar, document collaboration and operational administration.
Data Processed
- Business contact information
- Emails
- Support communications
- Documents
- Calendar information where applicable
HubSpot
Purpose
Customer relationship management, sales communications and customer support.
Data Processed
- Contact details
- Company information
- Sales communications
- Customer interaction history
OpenAI
Purpose
AI-assisted analysis and platform functionality.
Data Processed
- Customer prompts
- Customer-provided business information submitted for AI-assisted analysis
- Generated outputs
PartnerBridge does not intentionally use Customer Content to train publicly available foundation models.
FullStory
Purpose
Website and application analytics, diagnostics and user experience improvement.
Data Processed
- Device information
- Browser information
- Session activity
- User interaction events
- Technical diagnostics
Google Analytics
Purpose
Website traffic analysis and performance measurement.
Data Processed
- IP address (where applicable)
- Browser information
- Device information
- Website usage information
- Analytics events
PartnerBridge shall maintain appropriate contractual safeguards with each Sub-processor and remains responsible for their compliance with this DPA to the extent required by Applicable Data Protection Laws.
Annex F – Contact Information
Questions relating to this DPA may be directed to:
PartnerBridge Ltd
Clyde Offices, 2nd Floor
48 West George Street
Glasgow
G2 1BP
United Kingdom
Email:
Annex G – Order of Documents
The order of precedence is governed exclusively by Section 6.
General Provisions
Governing Law
This DPA shall be governed by and construed in accordance with the laws of Scotland.
The Scottish courts shall have exclusive jurisdiction except where Applicable Data Protection Laws require otherwise.
Severability
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
The parties shall replace any invalid provision with a valid provision that most closely reflects the original commercial intention.
Entire Agreement
This DPA, together with the Agreement, any applicable Order Form, any executed international transfer mechanism and any expressly incorporated security schedule, constitutes the agreement between the parties regarding the Processing of Customer Personal Data.
This DPA supersedes prior proposals or discussions concerning the same subject matter, but does not supersede any separately executed transfer mechanism, security addendum or written amendment unless expressly stated.
Nothing in this DPA modifies the Agreement except as expressly provided.
Amendments
PartnerBridge may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Laws or binding regulatory requirements, provided that no update materially reduces the protection afforded to Customer Personal Data.
Changes to Sub-processors shall be governed by Section 8.3.
Any other material amendment to this DPA shall take effect only:
- by written agreement between the parties;
- in accordance with an amendment mechanism expressly contained in the Agreement; or
- following reasonable prior notice where the Agreement validly permits online contractual updates.
If an amendment materially reduces Customer rights or materially increases Customer obligations, it shall not apply to an existing fixed contractual term without the Customer’s agreement, except where required by Applicable Data Protection Laws.
Survival
The provisions relating to:
- confidentiality;
- security;
- international transfers;
- audit rights;
- deletion or return of Customer Personal Data;
- liability; and
- Applicable Data Protection Laws,
shall survive termination of the Agreement for so long as PartnerBridge retains Customer Personal Data.
Execution
This DPA forms part of the Agreement between PartnerBridge and the Customer.
Execution of the Agreement, acceptance of the Terms of Service, or continued use of the Services following the Effective Date constitutes acceptance of this DPA unless the parties execute a separate written version.
Schedule 1 – Processing Summary
For ease of reference, the parties acknowledge the following.
Customer Role
Controller or Processor, as applicable to the relevant Processing.
PartnerBridge Role
Processor or Sub-processor, as applicable to the relevant Processing.
Purpose of Processing
Provision of the PartnerBridge Services.
Categories of Data Subjects
As described in Annex C.
Categories of Personal Data
As described in Annex B.
Nature of Processing
As described in Annex A.
Duration of Processing
For the duration of the Agreement and any lawful retention period.
Sub-processors
As described in Annex E.
International Transfers
Subject to Section 9 of this DPA.
Security Measures
As described in Annex D.
Email help@partnerbridge.io and our team will respond as soon as reasonably possible.