Data processing addendum
Terms that apply when Castis processes personal data on a customer's behalf.
1. Roles and scope
This addendum applies where Castis processes personal data on behalf of a customer in providing the platform. The customer is the controller; Castis is the processor. Where the customer is itself a processor for a third party, Castis is a sub-processor and this addendum applies accordingly.
This addendum forms part of the agreement between the parties. In the event of conflict on data protection matters, this addendum prevails.
2. Subject matter, duration, nature and purpose
Subject matter. Provision of the Castis platform products subscribed to by the customer.
Duration. The term of the subscription, plus any agreed export period.
Nature and purpose. Hosting, storage, transmission, display, analysis and support necessary to deliver the products.
Categories of data subject. Customer personnel, hotel and venue guests, ticket holders, viewers, and business contacts, as applicable to the products in use.
Types of personal data. Identification and contact data, employment and shift data, account and authentication data, service request and task records, transaction references, device identifiers, and playback and delivery telemetry.
3. Processor obligations
Castis will process personal data only on the customer's documented instructions, including the agreement, this addendum and the configuration of the products, unless required otherwise by law, in which case Castis will inform the customer before processing unless the law prohibits it.
Castis will inform the customer if, in its opinion, an instruction infringes applicable data protection law.
4. Confidentiality and personnel
Castis will ensure that personnel authorised to process personal data are bound by confidentiality obligations, receive appropriate training, and are granted access on a least-privilege basis subject to periodic review.
5. Security measures
Castis will implement and maintain appropriate technical and organisational measures, including encryption in transit and at rest, tenant isolation enforced at the data layer, multi-factor authentication for administrative access, network segmentation, logging of consequential actions, secure development practices, vulnerability management, backup and recovery, and physical security at hosting facilities. Current measures are described on the Security page and form Annex B.
6. Sub-processing
The customer gives general authorisation for Castis to engage sub-processors. The current list is published on the Subprocessors page, which forms Annex C.
Castis will give at least thirty days' notice of any intended addition or replacement. The customer may object on reasonable data protection grounds within that period, and the parties will work in good faith to resolve the objection. If it cannot be resolved, the customer may terminate the affected subscription without penalty for the remainder of the term.
Castis imposes on each sub-processor obligations no less protective than those in this addendum and remains liable for their performance.
7. Assistance to the controller
Taking into account the nature of processing, Castis will assist the customer by appropriate technical and organisational measures in responding to data subject requests for access, correction, deletion, restriction, portability and objection. Where a request is made directly to Castis, it will be referred to the customer unless the law requires otherwise.
Castis will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority.
8. Personal data breach
Castis will notify the customer without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting the customer's personal data, and will provide the information reasonably available to enable the customer to meet its own notification obligations.
Castis will take reasonable steps to contain and remediate the breach and will keep the customer informed of material developments.
9. Deletion and return
On expiry or termination, Castis will make personal data available for export for thirty days, and thereafter will delete it and existing copies within ninety days, unless retention is required by law. Backup copies are removed on the ordinary backup expiry cycle.
10. Audit and information
Castis will make available the information reasonably necessary to demonstrate compliance with this addendum, and will allow and contribute to audits, including inspections, conducted by the customer or an auditor it mandates, no more than once in any twelve-month period unless a breach or a regulator requires otherwise, on reasonable notice, during business hours, subject to confidentiality and without unreasonable disruption to Castis operations.
11. International transfers
Where personal data is transferred across borders, the parties will put in place the transfer mechanism required by the exporting jurisdiction, including any standard contractual clauses, adequacy determination, certification or explicit consent, and will keep records of those transfers.
Annex A lists the countries in which personal data is processed. [To be completed to match the deployment profile of each customer.]
12. Annexes
Annex A — Details of processing and processing locations. Annex B — Technical and organisational measures. Annex C — Approved sub-processors.
Signature version available on request to partner@castis.io.