Data Processing Agreement
The terms that apply when personal data is processed in connection with a Sterdam engagement.
Roles
Where Sterdam processes personal data on behalf of a client and on that client's documented instructions, the client acts as controller and Sterdam acts as processor, subject to the applicable engagement and to applicable law.
Where Sterdam independently determines the purposes and means of processing, for example in operating the platform, its own accounts and its own business records, Sterdam's role may instead be that of controller. This document does not convert every processing activity into a processor relationship.
Subject matter, duration and scope
The subject matter is the personal data contained in the material a client provides or asks us to work with, for example contact details in a brief, or personal data appearing in supplied reference material.
Processing lasts for the duration of the engagement and for any period afterwards required for record keeping or by law.
The nature and purpose of processing is the production, delivery and support of the commissioned work, and administration of the engagement.
Instructions
As processor, Sterdam processes personal data only on the client's documented instructions, including the instructions contained in the engagement documents, unless required otherwise by law. If we believe an instruction conflicts with applicable law, we will inform the client.
Confidentiality
Personnel with access to client personal data are bound by confidentiality obligations and are given access only as needed to perform the engagement.
Security measures
We apply access controls, authenticated and role restricted data access, server side authorisation of privileged operations, and transport encryption for data in transit.
No certification, audit standard or compliance mark is claimed. Where a client requires evidence for a procurement process, we will respond to a written request with the information we can verify at that time.
Sub-processors
We use subprocessors for hosting and content delivery, database, storage and authentication infrastructure, payment processing, email delivery, and model providers used for generation. On written request we will confirm the subprocessors in use for a stated purpose.
We impose data protection obligations on subprocessors consistent with this document.
Assistance with data subject requests
Where we act as processor and receive a request from a data subject relating to client personal data, we will refer it to the client and will provide reasonable assistance in responding, taking into account the nature of the processing.
Personal data breach
We will notify the client without undue delay after becoming aware of a personal data breach affecting client personal data, and will provide the information reasonably available to us to support the client's own notification obligations.
Return and deletion
On termination of the engagement, and on written request, we will delete or return client personal data, except where retention is required by law or is necessary for records of the engagement.
International transfers
Processing may take place outside the client's country where our infrastructure or subprocessors are located. Where a transfer mechanism is required by applicable law, the parties will put the appropriate mechanism in place.
Client responsibilities
- Ensuring there is a lawful basis for the personal data it provides to us.
- Ensuring supplied material, including reference imagery of identifiable people, may lawfully be used for the requested purpose.
- Providing instructions that are lawful and sufficiently clear.
Term and contact
This document applies for the duration of the engagement to which it relates. Data protection questions can be sent to info@sterdaminc.com.