Legal & privacy
Data Processing Terms
These terms form the data-processing agreement between Simplify and a customer where Simplify processes personal data on that customer’s behalf.
1. Scope and roles
These Data Processing Terms (“DPT”) apply where a Simplify customer (“Customer”) is a controller of personal data and Simplify Online (“Simplify”) processes that personal data on the Customer’s behalf in providing Simplify Online.
The Customer is the controller and Simplify is the processor for that processing. Each party must comply with the data-protection obligations that apply to it.
2. Processing details
| Subject matter | Provision, hosting, maintenance, support and security of Simplify Online and the features the Customer chooses to use. |
|---|---|
| Duration | For the term of the Customer’s account/subscription plus any documented retention, deletion and backup period that applies after the service ends. |
| Nature and purpose | Storage, organisation, retrieval, display, transmission, backup, deletion and other processing reasonably necessary to provide the service and follow the Customer’s use/instructions. |
| Types of personal data | Names, addresses, telephone numbers, email addresses, customer/contact details, staff information, notes, quotes, job and scheduling information, invoice/payment records, expense/receipt information, attachments and other business records the Customer chooses to enter. |
| Categories of data subjects | The Customer’s users, customers/clients, prospective customers, suppliers, subcontractors, contacts and other individuals whose information the Customer lawfully enters into Simplify. |
3. Customer instructions
Simplify will process Customer personal data only on the Customer’s documented instructions, including instructions given through use and configuration of the service, these DPT and the Terms of Service, unless UK law requires Simplify to process the data otherwise.
If applicable law requires processing outside the Customer’s instructions, Simplify will inform the Customer before processing unless the law prohibits that notification.
If Simplify believes an instruction infringes applicable data-protection law, Simplify will inform the Customer and may pause the affected processing while the issue is considered.
4. Customer responsibilities
The Customer is responsible for the lawfulness, accuracy and quality of Customer Data, for providing required privacy information to data subjects, for establishing an appropriate lawful basis and for ensuring its instructions to Simplify comply with applicable law.
5. Confidentiality
Simplify will ensure that people it authorises to process Customer personal data are subject to an appropriate duty of confidentiality, whether contractual or statutory.
6. Security
Simplify will implement and maintain technical and organisational measures appropriate to the risk of the processing, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing and the risks to individuals.
Measures may include, where appropriate, access controls, authentication, encryption in transit, secure development and deployment practices, logging/monitoring, backup/recovery arrangements, vulnerability management and procedures for responding to security incidents.
7. Subprocessors
The Customer gives Simplify general written authorisation to use subprocessors reasonably necessary to provide the service.
Simplify will impose data-protection obligations on each subprocessor that provide an equivalent level of protection for the relevant processing as required by applicable law. Simplify remains responsible to the Customer for the subprocessor’s performance of those obligations to the extent required by law.
Where required, Simplify will make a current list of material subprocessors available and provide reasonable notice of an intended new or replacement subprocessor so the Customer can raise a reasonable data-protection objection.
8. Data-subject requests
Taking into account the nature of the processing, Simplify will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests by individuals to exercise their data-protection rights.
If Simplify receives a request relating solely to Customer-controlled data, Simplify may refer the requester to the Customer unless Simplify is legally required to respond directly.
9. Assistance with compliance
Taking into account the nature of processing and information available to Simplify, Simplify will provide reasonable assistance to the Customer with its applicable obligations concerning security, personal-data breach notifications, data-protection impact assessments and prior consultation with the ICO where required.
10. Personal-data breaches
Simplify will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data. Simplify will provide information reasonably available to it about the nature and likely consequences of the incident, affected information/data subjects and measures taken or proposed, to support the Customer’s legal obligations.
11. International transfers
Simplify will not make a restricted transfer of Customer personal data outside the United Kingdom unless the transfer is permitted by applicable UK data-protection law. Where a safeguard is required, Simplify will use an appropriate lawful transfer mechanism and take any supplementary steps required by law.
12. Return and deletion
At the end of the service and at the Customer’s choice where reasonably supported by the service, Simplify will delete or return Customer personal data, and delete remaining copies, unless applicable law requires continued retention.
Deletion from active systems may be followed by deletion through normal backup cycles. Data retained solely in backups will remain protected and will not be returned to ordinary use except where needed for legitimate recovery, security or legal purposes.
13. Audit and compliance information
Simplify will make available information reasonably necessary to demonstrate compliance with its applicable processor obligations and will allow for and contribute to proportionate audits or inspections by the Customer or its appointed auditor where required by applicable law.
Audits must, where legally permissible, be arranged on reasonable notice, avoid unnecessary disruption, protect the security/confidentiality of other customers and use existing independent reports or documentation where these reasonably satisfy the request.
14. Relationship with the Terms of Service
These DPT form part of the Terms of Service. If there is a conflict about the processing of Customer personal data, these DPT prevail to the extent of that conflict.