Legal
Data Processing Addendum
The terms on which Codeaex processes personal data on behalf of organizations using AMS.
1. Scope
This addendum forms part of the agreement between Codeaex ("Processor") and your organization ("Controller") for use of AMS. It applies wherever we process personal data on your behalf.
A signed copy for your records is available on request from corp@codeaex.com.
2. Subject matter and duration
Subject matter: provision of the accreditation lifecycle platform. Duration: the term of the agreement, plus any return or deletion period specified in it.
Nature and purpose: hosting, storage, retrieval and processing of records required to operate an accreditation program.
3. Data subjects and data categories
Data subjects may include:
- Your staff and administrators
- Assessors and trainers on your registers
- Contacts at applicant and certified organizations
Categories of personal data may include names, contact details, professional qualifications, competence and assessment records, employment history contained in submitted CVs, and platform activity records.
4. Our obligations
We will:
- Process personal data only on your documented instructions, including as set out in the agreement.
- Ensure that personnel with access are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures.
- Assist you, taking account of the nature of processing, in responding to data subject requests.
- Assist you with security, breach notification and impact assessment obligations.
- Delete or return personal data at the end of the agreement, as you elect.
- Make available the information necessary to demonstrate compliance with this addendum.
5. Security measures
Measures include workspace isolation between organizations, role-based access control, invite-based onboarding without shared credentials, hashed credential storage, encrypted transport, and an audit trail of actions across the platform.
Measures are reviewed as the platform develops and may be updated provided the level of protection is not reduced.
6. Subprocessors
You give general authorisation for us to engage subprocessors for hosting, storage and communication. Each is engaged under written terms imposing obligations no less protective than those in this addendum.
A current list is available from corp@codeaex.com. We will give notice of intended changes so you may object on reasonable data protection grounds.
7. International transfers
Where personal data is transferred outside its jurisdiction of origin, we put in place an appropriate transfer mechanism recognised under applicable law, such as standard contractual clauses.
Specific data residency requirements can be agreed as part of an Enterprise engagement.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide the information reasonably available to us to support your own notification obligations.
9. Audits
On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, we will respond to reasonable audit enquiries and provide documentation demonstrating compliance with this addendum.
10. Return and deletion
On termination, and at your election, we will return your personal data or delete it, save where retention is required by law. Backups are purged in the ordinary course of their rotation cycle.
11. Contact
Data protection enquiries and signed-copy requests: corp@codeaex.com.
