Legal

Data Processing Addendum

The terms on which Codeaex processes personal data on behalf of organizations using AMS.

Last updated 24 August 2026

1. Scope

This addendum forms part of the agreement between Codeaex ("Processor") and your organization ("Controller") for use of AMS. It applies wherever we process personal data on your behalf.

A signed copy for your records is available on request from corp@codeaex.com.

2. Subject matter and duration

Subject matter: provision of the accreditation lifecycle platform. Duration: the term of the agreement, plus any return or deletion period specified in it.

Nature and purpose: hosting, storage, retrieval and processing of records required to operate an accreditation program.

3. Data subjects and data categories

Data subjects may include:

  • Your staff and administrators
  • Assessors and trainers on your registers
  • Contacts at applicant and certified organizations

Categories of personal data may include names, contact details, professional qualifications, competence and assessment records, employment history contained in submitted CVs, and platform activity records.

4. Our obligations

We will:

  • Process personal data only on your documented instructions, including as set out in the agreement.
  • Ensure that personnel with access are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Assist you, taking account of the nature of processing, in responding to data subject requests.
  • Assist you with security, breach notification and impact assessment obligations.
  • Delete or return personal data at the end of the agreement, as you elect.
  • Make available the information necessary to demonstrate compliance with this addendum.

5. Security measures

Measures include workspace isolation between organizations, role-based access control, invite-based onboarding without shared credentials, hashed credential storage, encrypted transport, and an audit trail of actions across the platform.

Measures are reviewed as the platform develops and may be updated provided the level of protection is not reduced.

6. Subprocessors

You give general authorisation for us to engage subprocessors for hosting, storage and communication. Each is engaged under written terms imposing obligations no less protective than those in this addendum.

A current list is available from corp@codeaex.com. We will give notice of intended changes so you may object on reasonable data protection grounds.

7. International transfers

Where personal data is transferred outside its jurisdiction of origin, we put in place an appropriate transfer mechanism recognised under applicable law, such as standard contractual clauses.

Specific data residency requirements can be agreed as part of an Enterprise engagement.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide the information reasonably available to us to support your own notification obligations.

9. Audits

On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, we will respond to reasonable audit enquiries and provide documentation demonstrating compliance with this addendum.

10. Return and deletion

On termination, and at your election, we will return your personal data or delete it, save where retention is required by law. Backups are purged in the ordinary course of their rotation cycle.

11. Contact

Data protection enquiries and signed-copy requests: corp@codeaex.com.