Last Updated: 31st July 2026, version number 13.0
This Data Processing Agreement ("Agreement") is between Datalive Limited T/A Allsorter, a limited liability company having its registered office at Westmoreland House, Westmoreland Park, Ranelagh, Dublin 6, Dublin, Ireland (“Allsorter” or “Service Provider”) and the Customer, each a “Party” and together the “Parties”.
For good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree as follows:
RECITALS
A. The Customer has engaged Allsorter to Process the Relevant Personal Data (as defined below) under the terms of a Master Subscription Agreement dated and executed by the Parties (the “MSA”) for the provision of effective CV automation software solutions (the “Services”). This DPA shall form part of the MSA.
B. Customer will use the Services under the terms of the MSA for the purpose of CV automation software solutions.
C. This Agreement sets out the obligations of the Parties with respect to the Processing of the Relevant Personal Data.
1. Definitions and Interpretation
1.1 In this Agreement, unless the context otherwise requires:
“Affiliate” means any entity which directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control," for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
“Agreement” means this data processing agreement.
"Commercial Confidential Data" means any information disclosed by the Disclosing Party to the Receiving Party that is not Personal Data but is proprietary or commercially sensitive in nature, the unauthorised disclosure of which could reasonably be expected to result in commercial, competitive or financial harm to the Disclosing Party or any third party to whom the Disclosing Party owes a duty of confidence.
“Commercial Confidential Data Breach” means any accidental, unauthorised or unlawful access to, disclosure of, alteration, loss, destruction or compromise of Commercial Confidential Data.
“Controller” has the meaning given to it in the Data Protection Laws.
“Customer” means the customer named above and its Affiliates.
“Data Protection Authority” means a Supervisory Authority, as that term is defined in the Data Protection Laws.
“Data Protection Impact Assessment” means a data protection impact assessment, as described in Article 35 of the GDPR.
“Data Protection Laws” means all applicable legislation relating to data protection and privacy, including the EU GDPR and related applicable data protection and privacy laws of the EEA member states, the UK GDPR and related applicable data protection laws of the United Kingdom, and/or the related applicable data protection laws of the United States, as the case may be, each as amended, repealed, consolidated or replaced from time to time, and any applicable guidance, rules, requirements and directions issued by a data protection authority in respect of such legislation.
“Data Subject” has the meaning given to it in the Data Protection Laws.
“EEA” means the European Economic Area.
“EU GDPR” means Regulation (EU) 2016/679, as amended, consolidated or replaced from time to time.
“GDPR” means the EU GDPR or the UK GDPR, whichever is relevant.
“Personal Data” has the meaning given to it in the Data Protection Laws.
“Personal Data Breach” has the meaning given to it in the Data Protection Laws.
“Personnel” means any current, former or prospective employee, consultant, temporary contractor, agency worker, intern, other non-permanent employee, contractor, secondee or other personnel.
“Process”, “Processing” or “Processed” each have the meanings given to them in the Data Protection Laws.
“Processor” has the meaning given to it in the Data Protection Laws.
“Relevant Personal Data” means the categories of Personal Data that are set out in Schedule 1 and that are Processed under, or in connection with the provision of the Services.
“Subprocessor” means any party engaged by Service Provider to Process Relevant Personal Data. An up-to-date list of approved Subprocessors is maintained by the Service Provider and set out in Schedule 1.
“Term” has the meaning given to "Subscription Term" in the MSA.
“UK GDPR” means the United Kingdom General Data Protection Regulation, which is the EU GDPR as incorporated into UK domestic law by virtue of section 3 of the European Union (Withdrawal) Act 2018 and amended by The Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.
2. Subject Matter and Scope
2.1 This Agreement applies only to the Processing of Relevant Personal Data.
2.2 The purpose of this Agreement is to help ensure adequate protection of Relevant Personal Data as may be processed by Service Provider while providing Services under the MSA. To the extent that there is any conflict between this Agreement and the MSA in relation to that purpose, this Agreement shall govern.
3. Obligations of Service Provider
3.1 With respect to the Processing of Relevant Personal Data, Service Provider shall, and shall procure that each of its Personnel, agents and Subprocessors shall, comply with Data Protection Laws, to the extent applicable; and only Process Relevant Personal Data on behalf of and in accordance with Customer’s prior written instructions (including as set out in this Agreement and the MSA) and for no other purpose.
3.2 The Service Provider shall implement appropriate technical and organisational measures (detailed in Schedule 2) to protect the Relevant Personal Data, in accordance with applicable Data Protection Laws. The Service Provider shall ensure that such technical and organisational measures are appropriate to the particular risks that are presented by its Processing activities, in particular to protect the Relevant Personal Data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access. The Service Provider shall perform internal inspections on a regular basis, to confirm that it is complying with its obligations under this Agreement and, where appropriate, the Service Provider shall amend its Processing activities to satisfy its obligations under this Agreement.
3.3 Where the Processing of Relevant Personal Data involves a transfer by the Service Provider from the European Economic Area to a recipient in a third country that is not subject to an adequacy decision under applicable Data Protection Laws, the Service Provider shall ensure that the transfer is subject to an appropriate transfer mechanism under Chapter V of the EU GDPR. Where the applicable transfer mechanism is the Standard Contractual Clauses, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 shall apply in the appropriate module. With respect to transfers to OpenAI Inc. in the United States, the Service Provider confirms that:
(a) such transfers are governed by the Standard Contractual Clauses referred to above, as incorporated into the agreement between the Service Provider and OpenAI;
(b) a Transfer Impact Assessment has been conducted in respect of such transfers, and the Service Provider shall make a summary of such assessment available to the Customer upon request;
(c) the Service Provider shall review and update the Transfer Impact Assessment at least annually, or promptly upon any material change in the legal framework applicable to such transfers; and
(d)the Service Provider shall promptly notify the Customer if it becomes aware of any change in circumstances that would affect the adequacy of the transfer mechanism in place.
3.4 The Parties hereby acknowledge and agree that the Customer is a Controller and the Service Provider is a Processor with respect to the Processing of the Relevant Personal Data. In addition to, and notwithstanding, any other right or obligation arising under this Agreement or the MSA, the Service Provider shall, in relation to such Processing:
(a) comply with the express instructions or directions of the Customer given from time to time in connection with the Processing of the Relevant Personal Data, and the requirements of any Data Protection Laws; and
(b) only Process the Relevant Personal Data strictly and solely: (I) to the extent necessary in connection with this Agreement, in particular as described in Schedule 1 below; and (ii) in accordance with the documented instructions received from the Customer from time to time. If at any point, the Service Provider becomes legally unable to comply with the Customer's instructions regarding the Processing of the Relevant Personal Data (whether as a result of a change in applicable law, or a change in the Customer's instructions), the Service Provider shall promptly:
(i) notify the Customer of such inability, providing a reasonable level of detail as to the instructions with which it cannot comply and the reasons why it cannot comply, to the greatest extent permitted by applicable law; and
(ii) cease all Processing of the affected Relevant Personal Data (other than merely storing and maintaining the security of the affected Relevant Personal Data) until such time as the Customer issues new instructions with which the Service Provider is able to comply.
3.5 In addition, the Service Provider, and where applicable the Service Provider’s representative, shall, in relation to the Processing of the Relevant Personal Data:
(a) (i) create; (ii) keep up to date for the duration of the Processing; and (iii) maintain for seven (7) years thereafter; complete and accurate records in writing (including in electronic form) of its Processing activities, as listed in Schedule 1, in relation to the Relevant Personal Data, and disclose such records to the Customer, or any Data Protection Authority, promptly upon demand;
(b) (i) ensure the Relevant Personal Data are kept confidential; (ii) take all reasonable steps to ensure the reliability and trustworthiness of the Service Provider’s Personnel and any Subprocessors; and (iii) ensure that all relevant Service Provider Personnel, and any relevant Subprocessors, have committed themselves to ensuring the confidentiality of all the Relevant Personal Data that they Process;
(c) ensure that, in each instance in which it engages a Subprocessor to Process any Relevant Personal Data, it shall: (i) only appoint such Subprocessor in accordance with the process outlined in clause 3.6; (ii) keep the Customer informed of any change to the role or status of the Subprocessor; and (iii) enter into a binding written agreement with the Subprocessor that imposes on the Subprocessor the same obligations that apply to the Service Provider under this Agreement with respect to the Processing of the Relevant Personal Data;
(d) at the Customer’s request and expense, promptly provide the Customer with all reasonable technical and organisational assistance necessary to respond appropriately to requests from Data Subjects to exercise their rights;
(e) at the Customer’s request and expense, promptly provide the Customer with all reasonable assistance necessary to enable the Customer to: (i) notify relevant breaches of the GDPR and/or any domestic Data Protection Lawsto the relevant Data Protection Authority and/or affected Data Subjects; (ii) conduct Data Protection Impact Assessments; and (iii) obtain any necessary authorisations from the Data Protection Authority, to the extent such breaches did not occur as a result of any error, omission or negligence on behalf of Service Provider or its Personnel;
(f) permanently and securely delete (or, at the election of the Customer, return) all Relevant Personal Data in the possession or control of Service Provider or any of its Subprocessors, within thirty (30) days after the end of the Term, unless applicable Data Protection Laws require otherwise, and procure that its Subprocessors shall do likewise;
(g) at the Customer’s request and expense, and to the extent Service Provider can do so taking into account the nature and extent of the Processing and the Relevant Personal Data stored by Service Provider, Service Provider shall (i) promptly provide the Customer with all information reasonably necessary to enable the Customer to demonstrate compliance with its obligations pursuant to Data Protection Laws; and (ii) allow for and contribute to audits, including inspections, conducted by the Customer or an auditor appointed by the Customer, provided that: (i) the Customer shall give the Service Provider not less than thirty (30) days' prior written notice of any audit, except where a suspected Personal Data Breach requires shorter notice, in which case reasonable notice shall be given; (ii) audits shall be conducted no more than once per calendar year, unless a confirmed Personal Data Breach or material breach of this Agreement has occurred in that year; (iii) any third-party auditor appointed by the Customer shall enter into a confidentiality agreement with the Service Provider on reasonable terms before commencing the audit; and (iv) audits shall be conducted during normal business hours and in a manner that minimises disruption to the Service Provider's operations. If the scope of a requested audit is addressed in an ISO 27001 or similar audit report performed by a qualified third-party auditor within the previous twelve (12) months, and the Service Provider's data protection contact certifies in writing that there are no known material changes in the controls audited, the Customer may accept those reports in lieu of requesting an audit of the controls covered by the report;
(h) notify the Customer promptly, and in any event within twenty-four (24) hours, of: (i) becoming aware of a confirmed Personal Data Breach affecting the Relevant Personal Data; (ii) becoming aware of any material breach of this Clause 3; or (iii) receipt of any correspondence or communication from any Data Subject, the Data Protection Authority or third party regarding the Processing of the Relevant Personal Data; and
(i) notify the Customer promptly, and in any event within forty-eight (48) hours, of becoming aware of any Commercial Confidential Data Breach or incident.
3.6 The Customer acknowledges and confirms its prior general consent to sub-contracting of the data processing by Allsorter to its vetted Subprocessors. An up-to-date list of approved Subprocessors is set out in Schedule 1 and may be updated by Service Provider from time to time. Service Provider shall notify Customer in advance of any intended addition or replacement of a Subprocessor, thereby giving Customer a reasonable opportunity to object to such change on reasonable data protection grounds. Customer must submit any objection in writing without undue delay after receiving notice and must set out reasonable data protection grounds for its objection. If Customer objects on reasonable data protection grounds, the Parties shall discuss in good faith a commercially reasonable resolution. Any Subprocessors utilised by the Service Provider shall be bound by data protection terms that are no less protective than the obligations set out in this Agreement, including standard contractual clauses where required under applicable Data Protection Laws. As between the Customer and the Service Provider, the Service Provider shall remain fully liable for all acts or omissions of any Subprocessor appointed by it.
3.7 Service Provider shall indemnify and hold harmless the Customer from and against any and all third-party claims, suits, demands and actions, and resulting damages, awards, direct losses, costs and expenses (including reasonable legal and professional fees) incurred by the Customer that directly result from a material breach by the Service Provider of its obligations under this Agreement and/or applicable Data Protection Laws. Service Provider’s liability under this clause 3.7 shall be on a comparative fault basis for the portion of those damages directly attributable to its breach and shall in all cases be subject to the limitations of liability set out in the MSA.
3.8 If any third party makes a claim against the Customer, or notifies an intention to make a claim against the Customer, arising out of a matter for which the Service Provider may be obliged to indemnify the Customer under clause 3.7, the Customer shall: (i) give written notice of the claim to the Service Provider as soon as reasonably practicable; (ii) not make any admission of liability in relation to the claim without the prior written consent of the Service Provider (not to be unreasonably withheld); (iii) at the Service Provider’s request and expense, allow the Service Provider to conduct the defence of the claim, including any settlement, provided that the Service Provider shall not settle any claim in a manner that admits liability on behalf of the Customer without the Customer’s prior written consent; and (iv) at the Service Provider’s expense, co-operate and assist to a reasonable extent with the Service Provider’s defence of the claim.
3.9 Service Provider shall not use Relevant Personal Data submitted to or generated through the Services to train, fine-tune or otherwise improve any AI model, or to build, improve or commercialise any candidate database, analytics product or unrelated product or service for Service Provider’s own independent purposes, except: (a) to the extent strictly necessary to provide the Services to Customer in accordance with Customer’s documented instructions, the MSA, any applicable AI Addendum and this Agreement; or (b) with Customer’s prior written consent. This clause does not restrict Service Provider’s collection and use of data that has been irreversibly anonymised in accordance with Data Protection Laws, including anonymised statistical data relating to outcomes, usage and operation of the Services, which shall no longer be considered Relevant Personal Data under Data Protection Laws.
4. Obligations of Customer
4.1 The Customer represents and warrants that: (i) it has a valid legal basis under applicable Data Protection Laws for all Processing of Relevant Personal Data under or in connection with this Agreement, including where required, obtaining any necessary consents and providing any necessary notices to Data Subjects; (ii) all data processing instructions given to the Service Provider comply with applicable Data Protection Laws; (iii) it shall have sole responsibility for the accuracy, quality and legality of the Relevant Personal Data and the means by which it acquired the Relevant Personal Data; and (iv) it shall not, by act or omission, cause the Service Provider to violate applicable Data Protection Laws as a result of the Service Provider Processing the Relevant Personal Data in accordance with this Agreement.
5. Termination
5.1 This Agreement shall terminate automatically upon the termination or expiry of the MSA. Notwithstanding termination of this Agreement, nor any other provision of this Agreement or the MSA, the Service Provider’s obligations under Clauses 3 shall continue in full force and effect for the duration of the period in which the Service Provider Processes any Relevant Personal Data.
5.2 Termination of this Agreement shall be governed by the termination provisions of the MSA. For the avoidance of doubt, the Customer’s right to terminate the MSA for material breach in accordance with the MSA shall extend to a material breach of this Agreement by the Service Provider.
6. General
6.1 This Agreement shall be governed by, and construed in accordance with, the laws of the Republic of Ireland and each Party irrevocably submits to the exclusive jurisdiction of the courts of the Republic of Ireland.
6.2 Service Provider may propose variations to this Agreement which it reasonably considers necessary to address requirements of any Data Protection Laws. The parties shall discuss and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified as soon as reasonably practicable. Customer shall not unreasonably withhold or delay agreement to any consequential variations proposed by Service Provider to comply with Data Protection Laws.
Schedule 1: Data Processing Activities
Data Subjects
The Relevant Personal Data concern the following categories of Data Subjects:
- Potential job candidates and applicants whose resumes/CVs, profiles or related candidate information are Processed through the Services;
- Customer personnel, recruiters and other Customer-authorised users of the Services.
Categories of Relevant Personal Data
The following Relevant Personal Data may be Processed by Service Provider:
- Information in a standard curriculum vitae/resume or candidate profile, including name, address and other contact information including personal telephone numbers and email addresses, social media profile links, educational history, employment history, degree(s) and other qualifications, languages, skills, projects, publications and similar candidate-provided or sourced candidate information;
- Age/date of birth;
- Nationality and citizenship;
- Government-issued identification information, passport or visa information;
- Job title and role / function;
- Salary and compensation data, including non-salary benefits, bonuses and incentives and other financial information;
- To the extent permitted or required by applicable law marital status, and family situation;
- Work and/or personal references;
- Customer personnel and authorised user information, including names, business contact details, login credentials, calendar events, social media profile links, access permissions, session identifiers, audit logs and related operational metadata; and
- User prompts, task history, system responses and AI-assisted outputs generated through the Services, to the extent such information contains Personal Data.
Special Categories of Data
It is not anticipated that any categories of Sensitive or Special Category Personal Data will be Processed by Service Provider. The Services are not designed to identify, extract or highlight Sensitive or Special Category Personal Data for use in the formatted output. Where such data appears in resumes/CVs, ATS fields or other Customer-provided materials, it may be incidentally processed only to the extent included by Customer or otherwise present in the materials processed through the Services. Such data will not be intentionally extracted into the formatted output unless Customer manually adds it, copies it, types it, maps it from an ATS field, or otherwise instructs the Services to include it. Customer is responsible for ensuring that it does not submit Sensitive or Special Category Personal Data to the Services unless permitted by applicable law and necessary for Customer’s lawful use of the Services. To the extent Sensitive or Special Category Personal Data is included in the Services, Customer may delete such data through the functionality made available in the Services or otherwise request deletion in accordance with this Agreement.
Data Processing Purposes
The Purposes for which the Relevant Personal Data are Processed are as follows:
- Provision, operation, maintenance and support of the Services;
- Identity verification, account authentication, access management, device access and account administration;
- Enabling access to services on multiple devices and transfer of accounts to new devices;
- Enabling users to find other users on the Services;
- Enabling Customer to upload, import, parse, format, review, edit, export and otherwise process resumes/CVs, candidate profiles and related recruitment information;
- Monitoring, detecting and deterring unauthorised or fraudulent use of, or abuse of, theServices;
- Providing customer support and responding to inquiries;
- Providing users with information regarding the Services, including feature updates and important service notices;
- Notifying users of any other important information regarding the Services;
- Aggregating anonymised statistical data regarding the Services, including for the purpose of improving and/or optimising the Services; and
- Complying with applicable laws or legal obligations.
Record of Categories of Processing Activities
A written record of these Processing Activities will be maintained:
- The name and the contact information of Customer on whose behalf it acts,
- List of Subprocessors used,
- The categories of Processing carried out on behalf of Customer,
- Where applicable, transfers of Personal Data to a non-EEA country, including identification of that third country,
- A general description of technical and organisational security measures implemented.
Processing Locations and Encryption
Connecting to Allsorter
Allsorter uses AWS Cognito for identity services.
Data Location
Allsorter partners with AWS for all core platform infrastructure and all data resides in the Europe region of AWS.
Encryption
All Customer Data is encrypted in transit using TLS 1.3 and at rest using AES-256.
Third-Party Subprocessors
Personal data retention
The Relevant Personal Data shall be retained as per the written instructions of the Customer at the time of the Agreement, with the retention period measured from the date it is imported into the Allsorter system. In case of no specific instructions, the Service Provider shall retain the Personal Data in the system for seven (7) days from the date it was uploaded into the system, after which it will be marked for deletion in the next automated deletion job.
Schedule 2: Technical and Organisational Security Measures
These describe the technical and organisational measures taken by Allsorter to ensure an appropriate level of security of Personal Data, taking into account its role as a Data Processor.
(A) Controls to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services
Technical and organisational measures to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services:
The Customer retains the original copy of any uploaded resume/CV or candidate profile, and the Service Provider accesses a copy for processing. The Customer's personnel can reformat, edit and export processed candidate information. In this flow, the Customer retains control over the original Personal Data and the Service Provider acts solely as Processor in accordance with Customer's instructions.
- Appropriate measures are taken to protect Personal Data against accidental or unlawful destruction, accidental loss, unauthorised access, alteration, transfer or processing outside the scope of data processing activities described in the data processing agreement (“DPA”). The measures are described in their respective sections below.
- These measures take into consideration the Service Provider’s role as a data processor, evaluation of potential risks and the sensitive nature of Personal Data.
- The measures ensure an adequate level of resilience of the data processing systems and centres.
- Allsorter employs a “data privacy and protection by design and default” approach.
(B) Control of physical access to premises and data processing centres
Technical and organisational measures to control physical access to premises and facilities, particularly to identify permitted Personnel at entry:
The core platform architecture is provided by AWS and the data stored in AWS data centres in the Republic of Ireland. AWS uses state-of-the-art security-in-depth to restrict access.
The Allsorter staff primarily works remotely, and the head office has all the requisite physical security measures in place:
- Locked doors on all entrances / exits (e.g., electronic locks; physical locks; etc.)
- Presence of Personnel at the front desk during business hours
- Visitor logs
- Access control systems (e.g., access card security; etc.)
- CCTV systems
- Intruder alarm systems
- Fire alarms
(C) Control to ensure anonymisation and encryption of Personal Data
Technical and organisational security measures designed to ensure anonymisation and encryption of Personal Data:
- State-of-the art encryption applied to all personal data ‘in transit’
- State-of-the art encryption applied to all personally identifiable information ‘at rest’
- Secure anonymisation or deletion of Personal Data that are no longer required for lawful Processing purposes
- Access to Personal Data is controlled as per the measures outlined in section (E) below
- Data retention timespans are outlined in section (J) below
(D) Control of access to IT systems (data processing systems)
Technical and organisational security measures designed to ensure that users with access to the relevant IT systems are identified and authenticated:
- IT security systems requiring individual users to log in using unique usernames
- IT security systems requiring the use of strong / complex passwords
- IT security systems requiring the use of multi-factor authentication
- Additional system log-in requirements for particular applications
- Automatic locking of IT terminals and devices after periods of non-use, with passwords required to ‘wake’ the terminal or device
- Regular audits of security procedures: Allsorter has been certified against the ISO27001 standard by a UKAS-accredited certification body. It has also been certified against the Cyber Essentials Plus standard.
- Annual mandatory training for all employees regarding access to IT systems and information security, with records of completion maintained and available for audit
(E) Control of access to Personal Data
Technical and organisational security measures designed to ensure that users with access to the Relevant Personal Data are identified and authenticated:
Personal Data is not accessed by Service Provider’s Personnel unless they are expressly requested by the Customer to help them troubleshoot an issue.
- ‘Read’ rights for systems containing Personal Data restricted to specified Personnel roles
- ‘Edit’ rights for systems containing Personal Data restricted to specified Personnel roles or profiles
- Logging of all attempts to access systems containing Personal Data
- System settings to ensure that only Personal Data necessary for each specific instance of processing is processed
- State-of-the art encryption on drives and media containing Personal Data
- Annual mandatory training for all employees regarding data privacy and data protection obligations, with records of completion maintained and available for audit
- Access by Service Provider personnel to Personal Data is removed upon termination of contractual relationship or a change in job status that results in the personnel no longer requiring access to Personal Data
- Segregation of environments with personal data (Allsorter system)
(F) Control of disclosure of Personal Data
Technical and organisational measures to transport, transmit and communicate or store data on data media and for subsequent checking:
- Restrictions on transfer rights for systems containing Personal Data
- Secure data networks (e.g., encrypted VPNs, VPCs)
- Logging of all transfers of data across the network
- TLS encryption for all internet access portals
- Enforced encryption of all drives that are used to take data off the network (Policy exists for encryption, check-in and check-out of data; however, data is not transported on removable or physical media)
(G) Control of input mechanisms
Technical and organisational security measures to permit the recording and later analysis of information about when input to data systems (e.g., editing, adding, deleting, etc.) occurred and who was responsible for such input:
- Logging who inputs and exports resumes/CVs containing Personal Data
- ‘Edit’ rights for systems containing Personal Data restricted to specified Personnel roles
- Binding agreements in writing with all employees who Process Personal Data, imposing strict confidentiality obligations
- Regular reviews of compliance with the relevant agreements
(H) Control of workflows between Processors and Sub-Processors
Technical and organisational measures to segregate the responsibilities between Processors and Sub-Processors Processing the Relevant Personal Data:
- Binding agreements in writing governing the appointment and responsibilities of Sub-Processors with access to the Relevant Personal Data
- Working only with the Sub-Processors capable of appropriately protecting the privacy, confidentiality and security of Personal Data
- Regular reviews and assessments of compliance with the relevant agreements
(I) Control mechanisms to ensure availability and access to the Relevant Personal Data in the event of a physical or technical incident
Technical and organisational measures in place to ensure the physical and electronic availability and accessibility of the Relevant Personal Data:
- Documented incident response procedures that are periodically reviewed
- Documented business continuity plans and disaster recovery procedures
- Secure backup procedures in place, with full backups run regularly
- Disaster Recovery and Business Continuity Plans tested at least annually, with results documented and made available to the Customer upon request
- All physical, power and security requirements to store Personal Data are managed by AWS
- Uninterruptible power supplies at backup facilities
- Physical security of backup facilities (e.g., secure premises; security Personnel; etc.).
- Security alarm systems at backup facilities
- Electronic security of backup facilities (e.g., firewalls; antivirus software; etc.)
- Environmental controls at backup facilities (e.g., cooling; humidity controls; etc.)
- Fire protection at backup facilities (e.g., sprinkler systems; fireproof doors; etc.)
- Training for employees regarding backups and disaster recovery
(J) Control mechanisms for Personal Data retention
Data retention is enabled only for seven (7) days from the date the Personal Data is input to the system, with the flexibility to enable shorter data retention spans based on Allsorter’s agreement with the Customer. Once the data retention time elapses, it will be marked for deletion in the next automated deletion job.
(K) Control mechanisms to ensure separation of the Relevant Personal Data from other data
Technical and organisational measures to ensure that the Relevant Personal Data are stored and processed separately from other data:
- Logical separation of live or production data from backup data and development or test data
- Logical separation of storage containing Relevant Personal Data from systems containing other data
- Separation of Personnel with access to Production Personal Data from other Personnel
- Training for employees regarding data separation
(L) Control mechanisms to test, assess and evaluate technical measures for IT Security
Technical and organisational measures to ensure that the IT environments are secure:
- Use of firewalls/ACLs to control traffic
- End-point security (antivirus, firewalls, encryption, secure device policies, automatic security updates)
- Least privilege access model applied, with user access given on a need-to-know basis and based on business needs
- Periodic access review meetings
- Periodic IT security meetings
- Periodic penetration tests, both internal and external, with risks mitigated
- Periodic vulnerability scans, both internal and external, with vulnerabilities mitigated
- Security and governance programme with policies communicated to staff on onboarding and each time they are reviewed, assessed and evaluated
- Periodic reviews of the effectiveness of the security and governance programme and adjustments as needed
(M) Certification
Allsorter has been certified against the ISO27001 standard by a UKAS-accredited certification body. It has also been certified against the Cyber Essentials Plus standard.
Contact for data protection inquiries
dataprotection@allsorter.com
Datalive Ltd.
NexusUCD
Belfield Innovation Park
Dublin 4, Dublin, Ireland