This Data Processing Agreement ("DPA") forms part of and is incorporated into the EasyPeasy Sales Terms of Service. It sets out the terms under which TKC Consulting LLC, operator of EasyPeasy Sales ("Processor") processes personal data on behalf of its customers ("Controller") in accordance with the UK GDPR, EU GDPR, and the Data Protection Act 2018.
1. Definitions
- "Controller", "Processor", "Data Subject", "Personal Data", "Special Category Data", "Processing", "Sub-processor", and "Personal Data Breach" have the meanings given in the GDPR.
- "Customer Data" means personal data processed by the Processor on behalf of the Controller through the Service.
- "Applicable Law" means the UK GDPR, EU GDPR, Data Protection Act 2018, and any other applicable data protection legislation.
2. Roles and Scope
- Roles: The Controller is the data controller. The Processor is the data processor. Each party complies with its obligations under Applicable Law in its respective role.
- Scope: This DPA applies to the Processor's processing of Customer Data in connection with the provision of the Service.
- Details of processing: The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are described in the Service itself and in our Privacy Policy. The Service processes contact data, company data, usage data, and communication data for the purpose of providing CRM, AI coaching, email campaign, and market intelligence features.
3. Processor Obligations
The Processor shall:
- Process Customer Data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required by law.
- Not process Customer Data for any purpose other than providing the Service as described in the Terms of Service.
- Not sell, rent, or lease Customer Data to any third party.
- Not use Customer Data for the Processor's own marketing or commercial purposes.
- Not use Customer Data to train AI or machine learning models.
- Ensure that persons authorised to process Customer Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures as described in Section 5.
- Assist the Controller in responding to data subject rights requests as described in Section 6.
- Notify the Controller of any personal data breach without undue delay, as described in Section 7.
- At the Controller's choice, delete or return Customer Data after the end of the service, as described in Section 9.
- Make available information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 8.
4. Sub-Processors
- General authorisation: The Controller grants general authorisation for the Processor to use the sub-processors listed in the Privacy Policy (Section 6 — Data Sharing & Sub-Processors).
- Sub-processor obligations: The Processor shall enter into a written agreement with each sub-processor imposing data protection obligations equivalent to those in this DPA.
- Liability: The Processor remains fully liable to the Controller for the performance of each sub-processor's data protection obligations.
- New sub-processors: The Processor shall give the Controller the opportunity to object to the engagement of a new sub-processor. The Processor will notify the Controller of intended changes by updating the Privacy Policy. The Controller may object within 30 days of the notice by contacting privacy@easypeasysales.co.uk. If the Controller objects, the Processor may (a) cease using the sub-processor, or (b) the Controller may terminate the affected portion of the Service.
5. Security Measures
The Processor implements the following technical and organisational measures:
- Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest
- Access control: Role-based access control, least-privilege principle, unique user IDs
- Authentication: Secure password hashing, session management, optional multi-factor authentication
- Network security: Firewalls, intrusion detection, secure API endpoints
- Data segregation: Logical separation of Customer Data between accounts
- Logging & monitoring: Audit logs for access and processing activities, regular security monitoring
- Backups: Regular encrypted backups with tested disaster recovery procedures
- Personnel security: Confidentiality agreements, security awareness training
- Vendor management: Security review of sub-processors, contractual data protection terms
6. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights under the GDPR (access, rectification, erasure, portability, objection, restriction). Specifically:
- If the Processor receives a request from a data subject, the Processor shall promptly forward it to the Controller and not respond directly.
- The Processor shall provide the Controller with the ability to correct, delete, or export Customer Data through the Service's built-in features.
- The Processor shall assist the Controller with data subject requests where technically feasible.
7. Personal Data Breach
- The Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting Customer Data.
- The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
- The Processor shall cooperate with the Controller in investigating and mitigating the breach and in notifying the supervisory authority and data subjects where required.
- The Processor shall document all personal data breaches, including facts, effects, and remedial action taken.
8. Audits and Information
- The Processor shall maintain records of its processing activities as required by Article 30 of the GDPR.
- The Processor shall make available to the Controller information necessary to demonstrate compliance with this DPA.
- The Controller may audit the Processor's compliance with this DPA, subject to: (a) providing at least 14 days' written notice, (b) conducting the audit during business hours, (c) minimising disruption to the Service, and (d) maintaining confidentiality of the Processor's confidential information.
- Alternatively, the Processor may provide a third-party audit report (e.g., SOC 2 Type II or ISO 27001 certificate) to demonstrate compliance.
9. International Data Transfers
- The Processor may transfer Customer Data outside the UK/EEA only with appropriate safeguards in place.
- Such transfers shall be governed by the Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner and/or the European Commission, as applicable.
- The Processor shall ensure that sub-processors transferring data outside the UK/EEA are also bound by equivalent safeguards.
- The Processor shall conduct transfer impact assessments where required and implement supplementary measures if the assessment identifies risks.
10. Deletion or Return of Data
- Upon termination of the Service, the Processor shall, at the Controller's choice, delete or return Customer Data.
- The Controller may export their Customer Data at any time during the subscription term using the Service's export features.
- The Processor shall delete all Customer Data within 30 days of termination, unless legally required to retain it.
- Backup copies of Customer Data shall be overwritten or deleted within 60 days of termination.
11. Cooperation with Authorities
The Processor shall cooperate with the Controller in relation to the Controller's obligations under Articles 32–36 of the GDPR, including data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to the Processor.
12. Term and Termination
This DPA takes effect on the date the Controller accepts the Terms of Service and remains in effect for as long as the Processor processes Customer Data on behalf of the Controller. The obligations regarding data security, confidentiality, breach notification, and data deletion survive termination of the Service.
13. Contact
For any questions about this DPA, please contact our Data Protection Officer at privacy@easypeasysales.co.uk.