Data processing addendum
Article 28 processor terms, subprocessor list, security measures, and transfer mechanisms for engagements where Geist Labs processes personal data on a client's behalf.
- Effective
- Last updated
This addendum applies where Geist Labs processes personal data on behalf of a client in the course of an engagement. It is designed to satisfy Article 28 of the EU and UK GDPR, and to give a procurement team the document it asks for without a three-week negotiation.
It forms part of the Workshop and engagement terms, or of any signed agreement between us, and takes precedence over those terms on data protection matters. Where we act as controller — our own website, marketing, and direct sales — the Privacy policy applies instead.
A Client who needs a signed copy can request one through the contact form. We will return this document executed, or sign the Client's own processor terms where their procurement process requires their paper — we do not insist on ours.
01
Roles
For personal data the Client makes available in the course of an engagement, the Client is the controller and Geist Labs is the processor. Where the Client is itself a processor for another controller, Geist Labs is a subprocessor and these terms apply accordingly.
02
Our starting position
We ask clients not to give us production personal data at all. Workshops and reviews can nearly always run against anonymised, synthetic, or non-production data, and that is what we will propose. The best data protection posture available to an engagement like ours is not to hold the data.
This addendum covers the cases where that is not possible.
03
Details of processing
Subject matter. Delivery of the workshop, training, or advisory services described in the engagement confirmation.
Duration. The term of the engagement, plus the return or deletion period below.
Nature and purpose. Reviewing, configuring, and advising on the Client's engineering systems and workflows; delivering training; and producing engagement deliverables. Processing is incidental to those services — we do not process personal data as a service in its own right.
Types of personal data. Typically limited to business contact details of attendees and Client personnel. Where the Client grants access to its systems, it may incidentally include personal data present in the Client's repositories, logs, tickets, or documentation.
Categories of data subject. Client personnel, attendees, contractors, and — where present in Client systems — the Client's own customers or users.
Special category data. None is requested and none should be provided. If an engagement requires it, that must be agreed in writing in advance with additional safeguards.
04
Our obligations
We will:
- Process only on documented instructions from the Client, including on international transfers, unless required otherwise by law — in which case we will inform the Client first, unless the law prohibits it. The engagement agreement and this addendum are the Client's initial documented instructions.
- Tell the Client if, in our opinion, an instruction infringes data protection law.
- Ensure confidentiality — everyone we authorise to process the data is bound by a written confidentiality obligation, and access is limited to those who need it to deliver the engagement.
- Implement appropriate technical and organisational measures, as set out below.
- Engage subprocessors only on the terms below.
- Assist the Client in responding to data subject requests, by appropriate technical and organisational measures and taking into account the nature of the processing.
- Assist the Client with data protection impact assessments, prior consultation, breach notification, and security obligations under Articles 32 to 36, taking into account the information available to us.
- Delete or return the data at the end of the engagement, as set out below.
- Make available the information necessary to demonstrate compliance, and allow for audits as set out below.
05
Security measures
Our technical and organisational measures reflect the fact that we are a small, deliberately low-surface operation. That is a control, not a shortcut.
| Area | Measure |
|---|---|
| Access control | Individual named accounts, multi-factor authentication on every account with access to Client material, and least privilege by default |
| Device security | Full-disk encryption, automatic screen lock, current OS and security patches, remote wipe capability |
| Encryption | TLS 1.2 or higher in transit; encryption at rest on all storage holding Client material |
| Data minimisation | Anonymised or synthetic data requested by default; Client production data avoided wherever the engagement allows |
| Segregation | Client material kept in per-engagement storage, not commingled across clients |
| Credentials | Client-provided credentials held in a password manager, never in plaintext, never in a repository, and revoked at the end of the engagement |
| Personnel | Confidentiality obligations in every contract; access removed when it is no longer needed |
| Retention | Deletion at the end of the engagement, per the schedule below |
| Incident response | Documented process for detecting, assessing, and notifying a personal data breach |
| Subprocessors | Written terms with equivalent obligations before any personal data is shared |
This table is the Annex II description of technical and organisational measures for the purposes of the Standard Contractual Clauses. It describes what is actually in place, not an aspiration, and it is updated when the practice changes rather than when a questionnaire asks.
06
Subprocessors
The Client gives general written authorisation for us to engage subprocessors. Our standing subprocessor for engagement work is:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Email delivery via Amazon SES, and supporting infrastructure | United States, us-east-1 |
That is the whole list, and it is short for a reason: an engagement that follows our starting position above involves no Client personal data reaching a third party at all.
Delivery tooling is agreed per engagement, not assumed. Video conferencing, screen sharing, and any file exchange for a given engagement are named in the engagement confirmation before the engagement starts, and where the Client has its own approved tooling we will use the Client's rather than introduce our own. A tool named in a confirmation and accepted by the Client is an authorised subprocessor for that engagement.
We will give the Client at least 30 days' notice before adding or replacing a standing subprocessor. If the Client reasonably objects on data protection grounds within that period, we will work to find an alternative, and if none is workable either party may terminate the affected part of the engagement without penalty, with a pro-rata refund of fees paid for undelivered work.
Every subprocessor is engaged under written terms imposing obligations equivalent to those in this addendum, and we remain fully liable to the Client for their performance.
07
Personal data breaches
We will notify the Client without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Client personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed.
We will cooperate with the Client and take reasonable steps to assist in investigating, mitigating, and remediating the breach. We will not notify a supervisory authority or a data subject about a breach affecting Client personal data without the Client's prior agreement, unless we are legally required to.
08
Data subject requests
If we receive a request from a data subject relating to Client personal data, we will not respond to it directly unless legally required or the Client instructs us to. We will inform the Client without undue delay and provide reasonable assistance in responding.
09
Audits
We will make available the information reasonably necessary to demonstrate compliance with this addendum, and respond to reasonable written security questionnaires, no more than once a year unless a breach or a regulator requires otherwise.
Where a documentary response is genuinely insufficient, the Client may audit on 30 days' written notice, no more than once a year, during business hours, subject to confidentiality, in a manner that does not disrupt our other clients, and at the Client's cost. Both parties will use existing documentation first.
10
Deletion and return
Within 30 days of the end of an engagement, we will delete Client personal data and any credentials we hold, or return it if the Client asks in writing before that period expires. Deletion includes copies in working storage, and access to Client systems is revoked.
We may retain data where law requires, and where we do it stays subject to this addendum for as long as we hold it. Anonymised or aggregated material that cannot identify a data subject is not affected.
11
International transfers
Geist Labs operates from the United States. Where the Client is in the EEA, the UK, or Switzerland and the engagement involves a transfer of personal data to us or to a subprocessor outside those regions:
- The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated into this addendum by reference and are completed with the details of processing above. In Clause 17 the governing law is that of Ireland, and in Clause 18 the forum is the courts of Ireland, unless the Client's own establishment makes another Member State appropriate.
- The UK International Data Transfer Addendum (version B1.0) applies to UK transfers, with the tables completed by reference to this document.
- For Switzerland, references to the GDPR are read as references to the FADP and the competent authority as the Swiss FDPIC.
Where a subprocessor is certified under the EU-US Data Privacy Framework, transfers to it may instead rely on that framework.
12
United States privacy laws
Where the Client is subject to the California Consumer Privacy Act or an equivalent US state law, Geist Labs is a service provider or processor as those laws define it. We will not sell or share Client personal information, will not retain, use, or disclose it for any purpose other than performing the engagement, will not combine it with personal information from other sources except as permitted, and will not use it outside the direct business relationship. We certify that we understand and will comply with these restrictions.
13
Liability
Liability under this addendum is subject to the limitations in the Workshop and engagement terms or in any signed agreement between the parties, except where those limitations are not permitted by applicable data protection law.
14
Order of precedence
On data protection matters this addendum prevails over the engagement terms. The Standard Contractual Clauses prevail over this addendum where they conflict. A signed agreement between the parties prevails over all of them where it says so expressly.
15
Contact
Data protection questions on an engagement go through the contact form or the privacy inbox in the Legal notice.