This Data Processing Agreement ("DPA") is incorporated into and forms part of the Terms of Service, Commercial Agreement, or Master Services Agreement (the "Agreement") between AH Technology Ltd (trading as Klyk), a company registered in England and Wales with company number 11773440, whose registered office is at Unit A12 Eldon Way, Park Royal Industrial Estate, London, NW10 7QQ ("Processor" or "Klyk") and the entity or person accepting the Agreement ("Controller" or "Customer").
This DPA governs Klyk’s processing of Personal Data on behalf of the Customer when the Customer uses the Resolver by Klyk service (the "Service").
Capitalized terms not defined herein shall have the meaning set forth in the Agreement.
2.1 Relationship of the Parties: For the purposes of processing Customer Data under this DPA, the Customer is the Data Controller, and Klyk is the Data Processor.
2.2 Scope of Processing: Klyk shall process Customer Data only as necessary to provide the Service in accordance with the Agreement and this DPA. The specific subject-matter, duration, nature, and purpose of the processing, as well as the types of Personal Data and categories of Data Subjects, are described in Annex 1 (Details of Processing).
3.1 Documented Instructions: Klyk shall only process Customer Data on the documented instructions of the Customer, unless required to do so by UK law to which Klyk is subject. In such a case, Klyk shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Agreement, this DPA, and the Customer's configuration and use of the Service (e.g., executing commands via Slack/Teams) constitute the Customer's complete and final documented instructions.
3.2 Lawfulness of Processing: The Customer warrants that it has all necessary rights, consents, and lawful bases under Applicable Data Protection Laws to provide the Customer Data to Klyk for processing.
3.3 Notice of Infringement: Klyk shall immediately inform the Customer if, in Klyk’s opinion, an instruction infringes Applicable Data Protection Laws.
4.1 Personnel Confidentiality: Klyk shall ensure that all employees, contractors, and agents authorized to process Customer Data are subject to a strict duty of confidentiality (whether contractual or statutory).
4.2 Reliability: Klyk shall take reasonable steps to ensure the reliability of any personnel who have access to the Customer Data, ensuring access is strictly limited to those individuals who need to know or access the relevant Customer Data for the purposes of the Agreement.
5.1 Technical and Organisational Measures (TOMs): Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Klyk shall implement and maintain appropriate technical and organisational security measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.