Paperlink Legal Center
Data Processing Addendum
A processing framework for eligible business customers that require documented commitments for personal-data processing.
1. Scope
This Data Processing Addendum (DPA) is intended for eligible business customers where Paperlink processes personal data on the customer's documented instructions. It supplements the Paperlink Terms of Service and Privacy Policy where the parties agree that a processor relationship applies.
2. Roles and instructions
The customer determines the purposes and means of processing customer-controlled personal data. Paperlink processes that data only to provide, secure, support and improve the contracted services, or as otherwise required by applicable law. The customer is responsible for providing lawful instructions and required notices to data subjects.
3. Security
- Access controls and authentication for authorised personnel.
- Reasonable technical safeguards for data in transit and at rest where applicable.
- Security monitoring and incident response processes appropriate to the service.
- Confidentiality obligations for personnel who may access customer data.
4. Subprocessors
Paperlink may use service providers to host, secure, deliver or support the service. Where required by applicable data-protection law, we will provide appropriate information about material subprocessors and maintain contractual requirements appropriate to their role.
5. Data-subject requests
Where Paperlink processes personal data on behalf of a customer, we will provide reasonable assistance for data-subject requests and compliance obligations that are applicable to the service, subject to the customer's instructions and the technical nature of the request.
6. Security incidents
If we become aware of a confirmed security incident affecting customer-controlled personal data in our systems, we will follow our incident-response procedures and provide notice and cooperation as required by applicable law and the parties' agreement.
7. Return and deletion
After termination, customer data is handled according to the service's deletion and retention processes, subject to legal retention requirements, backups, security logs and other legitimate operational needs.