1. Roles
You are the controller (or a processor acting for your own client) and I, MD Morsalin, am your processor (or sub-processor). For clients in California, I’m your service provider under the CCPA. “Client personal data” means personal data I process for you under our agreement.
2. What the processing is
| Subject matter | The services in your proposals, change requests and plans. |
|---|---|
| Duration | For as long as I provide the services, and until the data is deleted or returned under section 9. |
| Nature and purpose | Access to, and viewing, storing, changing, migrating, backing up, testing with and deleting data, only as needed to build, fix, run and support your systems. |
| Types of data | What your systems hold, typically: names, contact details, account and login data, order and transaction data, messages, technical logs and IP addresses. Special-category data only if your system holds it and we’ve agreed on it in writing first. |
| Data subjects | Your customers, users, staff, contacts and website visitors. |
3. Your instructions
I process client personal data only on your documented instructions: the proposal, change requests, portal requests and written messages. The exception is where the law requires otherwise, and then I tell you first unless the law forbids it. If I think an instruction breaks data-protection law, I tell you. I don’t sell client personal data, share it for advertising, use it for my own purposes, or combine it with other data, and I don’t keep it longer than the work needs.
4. Confidentiality
I do the work myself. I keep client personal data confidential, and anyone I bring in with your written permission is bound to the same confidentiality.
5. Security
I apply the technical and organizational measures in Annex II, which are appropriate to the risk. I work in your systems where I can, rather than copying data out. Where a copy is needed (for example to debug or migrate), I keep it encrypted and only for as long as the task needs.
6. Sub-processors
You give general authorization for the sub-processors in Annex III. I tell you by email at least 14 days before adding or replacing one, and you can object on reasonable data-protection grounds. If we can’t resolve it, you can end the affected services without penalty. I impose the same data-protection obligations on each sub-processor and remain responsible for them. Your own providers, such as your hosting, email and payment services, are your processors, not mine.
7. Helping you
I help you, as far as I reasonably can:
- answer requests from people exercising their rights, forwarding any I receive directly without replying to them myself;
- with security, data protection impact assessments and consultations with authorities.
Help beyond a small amount of time is charged at the rate we agree.
8. Personal data breaches
If I become aware of a personal data breach affecting client personal data, I tell you without undue delay and within 48 hours. I include what I know then, such as what happened, the data and people affected, likely consequences and what I’ve done or propose to do, and I add details as I learn them. I help you meet your own obligations to notify authorities and people. I keep a record of breaches.
9. At the end
When the services end, I delete client personal data I hold and remove my access to your systems, unless you ask me within 30 days to return it first or the law requires me to keep it. I confirm the deletion in writing on request. Data that only ever lived in your systems stays with you.
10. Information and audits
I give you the information you reasonably need to show that this agreement is being followed, and answer written questions within 30 days. You may audit, or have an independent auditor audit, compliance once a year, or after a breach, with 30 days’ notice, in working hours, remotely where possible and at your cost. Findings are confidential.
11. International transfers
I work from Bangladesh. The European Commission and the UK haven’t made an adequacy decision for Bangladesh, so where client personal data comes from the EEA, the UK or Switzerland, these apply and are part of this agreement:
- EEA: the standard contractual clauses in Commission Implementing Decision (EU) 2021/914. Module Two applies where you’re a controller, and Module Three where you’re a processor. You are the data exporter and I am the data importer. Clause 7 (docking) applies. Under Clause 9(a), Option 2 applies (general authorization, with 14 days’ notice as in section 6). The optional wording in Clause 11 doesn’t apply. Clauses 17 and 18: the law and courts of Ireland. Annexes I to III of the clauses are completed by sections 2 and 5, Annex II and Annex III here, and the competent supervisory authority is the one that applies to you under Clause 13.
- UK: the UK Information Commissioner’s International Data Transfer Addendum to those clauses (version B1.0), with the details in this agreement. Either of us may end it as its Section 19 allows.
- Switzerland: the same clauses, with the Swiss Federal Data Protection and Information Commissioner as the authority, and references to the GDPR read as references to the Swiss Federal Act on Data Protection.
If the clauses conflict with this agreement or the Terms, the clauses win.
12. Liability and precedence
Liability under this agreement follows the Terms of Service, except where the standard contractual clauses or data-protection law don’t allow it to be limited. On data protection, this agreement takes priority over the Terms.
Annex I: parties
Data exporter / controller: the client named in the accepted proposal, with the contact in its client account. Data importer / processor: MD Morsalin, sole trader, Dhaka, Bangladesh, [email protected]. The processing is described in section 2, and happens continuously while the services last.
Annex II: security measures
- Encrypted connections (TLS or SSH) for all access to your systems and data.
- Full-disk encryption, a screen lock and current security updates on the devices I work from.
- Two-step verification on the accounts I use for your work, where the service supports it, and unique passwords in a password manager.
- Least privilege: the narrowest access the task needs, in accounts you control, removed when the work ends.
- Credentials exchanged through the portal’s one-time encrypted notes or your own secrets manager, never by plain email or chat.
- Production data isn’t used for testing unless you agree. Copies are encrypted, minimized and deleted after the task.
- No client personal data in AI or other tools that use it to train their models.
- Backups and restore checks as agreed for the service. Changes to production go through version control and are logged.
- A breach-response routine in line with section 8.
Annex III: sub-processors
| Sub-processor | What for | Where |
|---|---|---|
| Google Cloud (Google LLC / Google Ireland) | Hosting the client portal: files, messages and notes you share there | London, United Kingdom |
| Resend | Sending portal emails, which can include request titles and names | United States |
I’ll add others here, with the notice in section 6, before using them for client personal data.