1. Subject and duration
This agreement governs BrandGuard's processing of personal data on behalf of the customer under Article 28 GDPR. It applies for the term of the main contract and, where necessary, until commissioned data has been deleted or returned.
2. Nature, purpose and scope
Processing may include hosting, storage, research, crawling, evidence preservation, monitoring, user and case administration and support according to the documented configuration. BrandGuard acts only under the main contract and documented instructions.
3. Data and data subjects
Data may include account and contact information, roles, logs, public website content, names, business contacts, images, documents and customer case information. Data subjects may include users, staff, contacts, providers, traders, rights owners and persons appearing in public sources.
4. Instructions and customer responsibility
The customer remains controller and is responsible for lawfulness, transparency, purpose limitation and instructions. Manifestly unlawful instructions are identified and may be suspended pending clarification.
5. Technical and organizational measures
Measures include access control, tenant and role separation, password hashing, optional two-factor authentication, HTTPS, session and abuse protection, audit logs, backups, hash manifests, recovery tests and incident processes. Measures evolve according to risk.
6. Confidentiality
Persons with access to commissioned data are bound by confidentiality and receive only the permissions required for their tasks.
7. Subprocessors
The published subprocessor list forms part of this agreement. Material changes are announced in advance. Customers may object for an important data-protection reason and the parties will seek a reasonable solution.
8. Assistance
BrandGuard reasonably assists with data subject rights, impact assessments, consultations, security requests and evidence. Work outside the selected plan may be chargeable after prior coordination.
9. Personal data breaches
Known breaches relating to commissioned data are reported without undue delay with the information available. BrandGuard assists with containment, remediation and documentation.
10. Return, deletion and legal hold
After termination, commissioned data is exported or deleted according to choice and technical feasibility unless law or a documented legal hold requires retention. Backup copies are overwritten in the ordinary cycle.
11. Evidence and audits
BrandGuard provides suitable information on measures, subprocessors and reviews. Controls must preserve security, confidentiality and proportionality; documents and existing evidence are used first.
12. International transfers and precedence
International transfers occur only with an appropriate legal basis and documented activation of the relevant service. This agreement and mandatory data-protection law prevail over general terms in case of conflict.