1. Subject matter and duration
The subject matter is the personal data processed by Processor to deliver the services described in the main agreement. Processing continues for the term of that agreement and for any short return/deletion period defined below.
2. Nature and purpose
Processing is limited to what is necessary to provide cybersecurity, IT, and data protection services to the Controller, including detection, response, configuration, monitoring, and reporting.
3. Types of personal data and categories of data subjects
Unless agreed otherwise in writing, processing is limited to business-context data such as names, business email addresses, job titles, device and log data of the Controller's personnel and end users. Special categories of data are not in scope without a separate written instruction.
4. Processor obligations (GDPR Art. 28)
- Process personal data only on documented instructions from the Controller.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures, including encryption in transit, access control, logging, and least-privilege administration.
- Assist the Controller in responding to data subject requests.
- Assist the Controller with security, breach notification, DPIAs, and prior consultations.
- Notify the Controller without undue delay (and no later than 72 hours where feasible) after becoming aware of a personal data breach.
- At the end of the services, delete or return all personal data, unless retention is required by law.
5. Sub-processors
The Controller grants general authorisation for Processor to engage sub-processors, subject to written terms providing equivalent data protection obligations. A current list of sub-processors is available on request. Processor will give reasonable advance notice of changes and an opportunity to object on reasonable grounds.
6. International transfers
Where personal data is transferred outside Ghana, the EEA, or the UK, the parties rely on appropriate safeguards including the EU Standard Contractual Clauses (Modules 2 and 3 as applicable) and the UK International Data Transfer Addendum, with supplementary technical and organisational measures.
7. Audits
Processor will make available information necessary to demonstrate compliance with this Addendum and will allow audits, including inspections, on reasonable notice, conducted during business hours, no more than once per year (except where required by a supervisory authority or following a confirmed breach), and subject to confidentiality.
8. Liability and conflicts
The limitations of liability set out in the main agreement apply to this Addendum. In the event of conflict between this Addendum and the main agreement, this Addendum prevails with respect to data protection matters.
9. Executable version
Clients may request an executable version of this Addendum (including SCCs) by emailing privacy@yanutek.com.
