In short: when we handle personal data on your behalf during an engagement, we act as your processor. This addendum forms part of your engagement letter and sets out what we will and will not do with that data under Article 28 of the UK GDPR.
This Data Processing Addendum forms part of the engagement letter between you (the controller) and Unavoidable Studio Ltd, trading as Unavoidably Secure (the processor). It applies to full audit, standards readiness and ongoing assurance engagements, and to any other work where we process personal data on your behalf. If your engagement could involve health or care records, the extra terms in our healthcare data agreement also apply.
1. Scope of processing
- Subject matter
- Compliance and web risk auditing, including documentation review, evidence collection, remediation planning and re-testing.
- Duration
- The term of the engagement, plus the retention period in our privacy notice.
- Nature and purpose
- Analysing publicly visible technical information and the documents you give us, to find security and compliance gaps against the standards that apply to your organisation.
- Types of personal data
- Contact details of your staff (name, work email, work phone), and personal data that happens to appear in documents you give us. We do not need special category or health data. If any is shared by mistake, we will redact it or return it on request.
- Data subjects
- Your staff and contractors, and occasionally people named in documents you share with us.
2. Our obligations as processor
We will:
- process personal data only on your documented instructions, including those in the engagement letter and this addendum;
- make sure everyone who processes it for us is bound by written confidentiality obligations;
- apply appropriate technical and organisational security measures (see Annex A);
- help you respond to requests from individuals, and meet your own security, breach notification and data protection impact assessment obligations;
- tell you without undue delay, and within 48 hours, when we become aware of a personal data breach affecting your data;
- return or delete your personal data at the end of the engagement, as you choose, unless the law requires us to keep it;
- give you the information you need to show we meet these obligations, and allow audits on reasonable notice.
3. Sub-processors
- BitHoarders Ltd (UK): hosting and storage. Data: engagement data. Location: UK.
- Postmark (ActiveCampaign, LLC, US): transactional email delivery. Data: contact email address and message content. Location: US, with transfer safeguards (see section 4).
We will tell you at least 30 days before we add or replace a sub-processor. You may object, and if we cannot resolve your objection reasonably, you may end the engagement.
4. International transfers
Where personal data is transferred outside the UK, we rely on a lawful safeguard, such as the UK-US data bridge for certified organisations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
5. Requests from individuals
We will pass on any request we receive about your data within 5 working days, and help you respond within the time the law allows.
6. Breach notification
If we become aware of a personal data breach affecting your data, we will tell you within 48 hours, including the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the steps we have taken or propose to take.
7. Return or deletion
When the engagement ends, and at your choice, within 30 days we will either return all personal data we hold for you in a common machine-readable format, or delete it securely and confirm the deletion in writing. Where the law requires us to keep audit records or engagement details, for example to defend a claim, we keep the minimum necessary for the shortest necessary time, and it stays protected under this addendum.
8. Audits
With at least 30 days' notice, you may audit our compliance with this addendum. Audits must not disrupt our operations or those of other clients. We will make available our current security documentation and audit log summaries.
Annex A. Security measures
- Audit evidence and stored reports encrypted at rest with libsodium (XSalsa20-Poly1305), using a key held outside the web root.
- Reports delivered as AES-256 encrypted PDFs through a one-time link, with the passphrase sent separately by a different channel.
- HTTPS for all data in transit, with HSTS.
- Two-factor authentication required on owner and auditor accounts, with account lockout after repeated failed sign-ins.
- A tamper-evident audit log: every action is recorded in a hash chain that is checked each time the dashboard loads.
- Role-based access, limited to the people working on your engagement.
- Physical security of servers provided by our UK hosting provider.
Contact
Questions about this addendum: support@unavoidablysecure.com.