How Harman AJ Ltd processes personal data on your behalf. This DPA forms part of our Customer Terms and applies automatically; you don't need to sign it.
1.1 This Data Processing Agreement ("DPA") is between Harman AJ Ltd, company number 17412886 ("we", "Processor") and the customer that has accepted our Customer Terms ("you", "Customer"). It forms part of the agreement described in the Customer Terms and applies whenever we process Customer Personal Data.
1.2 This DPA is intended to meet Article 28(3) of the UK GDPR and, where it applies, of the EU GDPR. If you need a countersigned copy, email privacy@safehanded.com.
3.1 You are the controller of Customer Personal Data and we are your processor.
3.2 If you are a managed service provider acting as processor for your own clients, we are your sub-processor. You warrant that your clients have authorised our appointment and that your instructions to us are consistent with theirs. We will deal with you, not your clients, unless you have ceased to exist.
3.3 You are responsible for the lawfulness of the processing you instruct, including having a lawful basis and giving data subjects any notices required.
4.1 We process Customer Personal Data only on your documented instructions, unless the law we are subject to requires otherwise, in which case we will tell you first unless that law forbids it.
4.2 Your instructions are: the Customer Terms and this DPA; your configuration and use of the service, including your policies, integrations and purge settings; and any further written instructions we agree.
4.3 We will tell you promptly if we believe an instruction infringes the Data Protection Laws.
5.1 We ensure that everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality.
5.2 Our authorised personnel can view account and configuration information about your organisation, such as members and integrations, to provide support, operate billing and protect the service. Where they need to see your organisation as a user would, access is: read-only; granted only with a recorded reason; time-limited; and recorded as an event in your organisation's audit log. Our personnel cannot decrypt handover payloads.
6.1 We implement the technical and organisational measures in Annex 2, which we consider appropriate to the risk. We may update them, provided the overall level of security is not reduced.
6.2 You are responsible for the security measures within your control, including your users' passkeys, your organisation recovery key, your identity provider and the credentials you give us for integrations.
7.1 You give general authorisation for us to engage sub-processors. Our current sub-processors are listed on our sub-processors page (Annex 3).
7.2 We will give at least 30 days' notice of any new or replacement sub-processor by updating that page and emailing your organisation's owners. You may object on reasonable data-protection grounds within that period. If we cannot address the objection, you may end the affected subscription and we will refund prepaid fees for the unused period.
7.3 We impose on each sub-processor, by written contract, data-protection obligations that are no less protective than this DPA, and remain liable to you for its performance.
7.4 Services you connect yourself, such as your helpdesk, identity provider, mailbox or SMS account, act on your instructions and are not our sub-processors.
8.1 Customer Personal Data is hosted in the European Union. We are established in the United Kingdom.
8.2 We will not make a Restricted Transfer unless it is covered by a valid transfer mechanism under the Data Protection Laws, such as an adequacy decision or regulation, the EU Standard Contractual Clauses (Commission Decision 2021/914) with, for UK transfers, the ICO's International Data Transfer Addendum, or the ICO's International Data Transfer Agreement.
8.3 Where you are subject to the EU GDPR and the European Commission's adequacy decision for the United Kingdom ceases to cover our processing, the EU Standard Contractual Clauses are incorporated into this DPA as follows. Module Two (controller to processor) applies, or Module Three (processor to processor) where section 3.2 applies. You are the data exporter and we are the data importer. The optional docking clause in Clause 7 applies. Option 2 (general written authorisation, with the notice period in section 7.2) applies in Clause 9. The optional wording in Clause 11 does not apply. Clauses 17 and 18 select the law and courts of Ireland. Annexes 1 to 3 of this DPA complete the appendix, and the competent supervisory authority is the one determined under Clause 13.
9.1 Taking into account the nature of the processing, we will help you, by appropriate technical and organisational measures and so far as possible, to respond to requests from data subjects exercising their rights. The service lets you export your audit log, purge handovers and remove members. If we receive a request directly, we will pass it to you within 5 business days and will not respond to it ourselves except to redirect the requester.
9.2 We will give you reasonable help with your obligations on security, breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking into account the information available to us.
10.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We will notify the email addresses of your organisation's owners.
10.2 The notice will describe, as far as we then know them, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. We will add further information as it becomes available.
10.3 We will take reasonable steps to contain and remedy the breach. Our notification is not an acknowledgement of fault.
11.1 During the subscription, handover payloads are destroyed automatically under your purge settings, and handover records and audit events are deleted at the end of your retention period.
11.2 When the agreement ends, you may export your audit log for 30 days. We then delete Customer Personal Data from the live service, and it is removed from backups within a further 30 days, unless the law requires us to keep it. If we restore a backup, we re-apply these deletions and those in section 11.1 before the service resumes. We will confirm deletion in writing on request.
12.1 We will make available to you the information reasonably necessary to demonstrate compliance with this DPA and Article 28, including answering a reasonable security questionnaire once a year.
12.2 If that information is not sufficient, or a supervisory authority requires it, or after a personal data breach, you may carry out an audit, yourself or through an independent auditor bound by confidentiality. You must give at least 30 days' notice, agree the scope with us in advance, conduct the audit during business hours without disrupting the service or other customers' data, and bear its costs. Except after a breach or at a regulator's request, audits are limited to one per year.
13.1 Each party's liability under this DPA is subject to the limits and exclusions in the Customer Terms, except where the Data Protection Laws do not allow them to apply.
13.2 This DPA lasts as long as we process Customer Personal Data. If it conflicts with the Customer Terms, this DPA prevails on data protection. If the EU Standard Contractual Clauses apply and conflict with this DPA, the Clauses prevail.
13.3 We may update this DPA to reflect changes in the Data Protection Laws or the service, on the notice set out in the Customer Terms. An update will not reduce the protection given to Customer Personal Data.
| Subject matter | Provision of the SafeHanded credential-handover service under the Customer Terms. |
| Duration | The term of the agreement, plus the deletion period in section 11. |
| Nature and purpose | Hosting, storing (as ciphertext for payloads), transmitting, notifying, auditing and deleting data so the Customer can request, receive and send credentials, link them to tickets and keep an audit trail. Sending emails and SMS, and exchanging data with services the Customer connects. |
| Data subjects | The Customer's users (technicians, administrators, auditors); people the Customer sends requests or shares to (its own staff, its clients' staff and others); the Customer's client contacts shown on handover pages. |
| Personal data |
Users: name, email, role, profile photo and extension, passkey public keys, device and session records, IP address and browser. Subjects and recipients: name, email or UPN, directory identifier, phone number where SMS is used, ticket reference and the Customer's stated reason, IP address and browser for actions on the handover page, and the encrypted payload, which the Processor cannot read. Client contacts: name, role, email and phone. |
| Special category data | None intended. Payloads are encrypted and unreadable to the Processor; the Customer must not place special category data in readable fields (Customer Terms section 5.3). |
| Frequency | Continuous. |
| Retention | Payloads: until purged under the Customer's settings, at most 30 days. Handover records and audit events: the Customer's retention period within its plan limit. Everything else: the term plus section 11. |
The sub-processors authorised at the effective date are those on our sub-processors page, which is incorporated into this Annex and updated under section 7.