Data processing agreement
This section is the agreement required by Article 28 of the UK GDPR between you (the controller) and Polarize Ltd (the processor) for the personal data we process on your behalf. If anything else in these terms conflicts with it on that subject, this section wins.
What we process. Subject matter and purpose: providing subba to you (your booking page, website chat, contact and quote forms, AI phone line, messages, payment links, shop and customer records). Duration: while your account is open, then until the data is deleted as described below. Nature: collecting, storing, organising, sending messages about, and deleting. Types of data: names, email addresses, phone numbers, booking, order and quote details, messages and chats, call recordings and transcripts, delivery addresses, payment status (never card numbers), and anything you add in notes. Data subjects: your customers and prospective customers, people who contact or call you, and your team members.
Your instructions. We process the data only on your documented instructions: these terms, and how you set up and use subba, are those instructions. If the law requires us to process it otherwise, we will tell you first unless the law forbids that. We will tell you if we think an instruction breaks data protection law.
Confidentiality and security. Everyone at Polarize Ltd, and every contractor, who can access the data is bound to keep it confidential. We take appropriate technical and organisational measures to protect it, including encryption in transit, encryption of customer contact details at rest, access controls, signed sessions, rate limiting and a security log.
Sub-processors. You give general authorisation for the sub-processors listed in our Privacy Policy. We will email you at least 14 days before adding or replacing one, and you may object; if we cannot resolve the objection, you may end the service. Each sub-processor is bound by data protection terms that give the protection this section requires, and we remain responsible to you for them.
Helping you. Your dashboard lets you download a customer’s data and delete a customer, so you can answer their requests; we will help with anything else they ask of you. We will also help you meet your security, breach notification, impact assessment and regulator consultation duties, as far as our part of the processing allows.
Breaches. We will tell you without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting your data, with what we know and what we are doing about it, and keep you updated.
Deletion. When you close your account (Settings, Your account) we delete the data we hold for you, except where the law requires us to keep it. Before that you can download your customer list and any customer’s data. Records that are only needed for a while are deleted sooner, on the timetable in our Privacy Policy.
Audits. We will give you the information you need to show that we meet this section, and allow for and contribute to audits, including inspections, by you or an auditor you appoint, on reasonable notice, at your cost and not more than once a year unless a breach or a regulator requires it.
International transfers. We transfer the data outside the UK only with the safeguards UK law requires, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
Your part. You are responsible for having a lawful basis for the processing, for telling your customers how their data is used (you can link your own privacy notice in your booking settings, and subba links its own notice for customers too), and for the instructions you give us.