Between:
Data Controller: ExcluServ Client as defined in Contract for Services
(“Controller”, or “Client”)
Data Processor: ExcluServ Limited
Address: 133 Deepcut Bridge Road, Camberley, Surrey, UK GU16 6SD
Registration: 05633814
(“Processor”, or “Supplier”)
Table of Contents
Data Controller to Data Processor, Data Processing Agreement (DPA)
- Definitions
- Scope of Processing
- Obligations of the Processor
- Obligations of the Controller
1. Definitions
In this Agreement:
Contract for Services
means the master Contract for Services, Terms of Service, Subscription Agreement, or other principal contract governing the provision of services by the Processor to the Controller. This Data Processing Agreement may be incorporated into the Contract for Services by reference or included within it in full.
UK GDPR
means the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) as incorporated into UK law.
Data Protection Legislation
means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (as amended), and any other applicable data protection or privacy laws in force in the United Kingdom.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Personal Data Breach” have the meanings given in Article 4 of the UK GDPR.
Sub-processor
means any third party or separate legal entity engaged by the Processor to process Personal Data on behalf of the Controller, and for the avoidance of doubt includes affiliated companies and independent contractors acting as separate data processing entities.
Restricted Transfer
means a transfer of Personal Data to a country or organisation outside the United Kingdom that is not subject to UK adequacy regulations.
Security Measures
means the technical and organisational measures implemented by the Processor to protect Personal Data as described in Schedule 2 (Security Measures).
2. Scope of Processing
2.1 Processing on Documented Instructions
The Processor shall process Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by applicable law.
Where processing is required by law, the Processor shall inform the Controller of that legal requirement before processing.
The documented instructions for processing are set out in:
- this Agreement
- Schedule 1(Details of Processing)
- the Contract for Services
- any further written instructions issued by the Controller
2.2 Unlawful Instructions
The Processor shall immediately inform the Controller if, in its opinion, any instruction from the Controller infringes Data Protection Legislation.
2.3 Limitation of Processing
The Processor shall not process Personal Data for any purpose other than those specified in this Agreement and Schedule 1 unless otherwise instructed in writing by the Controller.
3. Obligations of the Processor
3.1 Confidentiality and Authorised Persons
The Processor shall ensure that any person authorised by it to process Personal Data, including employees, agency workers, temporary staff, individual contractors and consultants, is:
- subject to a binding duty of confidentiality;
- subject to appropriate contractual obligations regarding data protection and information security;
- permitted to process Personal Data only to the extent necessary for the performance of the Contract for Services and in accordance with the Controller’s documented instructions.
The Processor shall remain responsible for all acts and omissions of such authorised persons in connection with the processing of Personal Data.
3.2 Appropriate Security Measures
The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk in accordance with Article 32 UK GDPR.
Such measures shall include, where appropriate:
- encryption of personal data in transit and at rest
- access controls based on the principle of least privilege
- multi-factor authentication for privileged system access
- logging and monitoring of system access when required
- vulnerability management and patch management processes
- business continuity and disaster recovery capabilities
- regular testing and evaluation of security measures
Further details are set out in Schedule 2 (Security Measures).
The Processor shall not materially reduce the level of security during the term of the Agreement.
3.3 Assisting the Controller
Taking into account the nature of the processing and the information available to the Processor, the Processor shall provide reasonable assistance to the Controller in ensuring compliance with its obligations under Data Protection Legislation, including:
- responding to requests from Data Subjects exercising their rights
- assisting with security obligations under Articles 32 to 36 UK GDPR
- assisting with Data Protection Impact Assessments (DPIAs)
- assisting with consultations with the Information Commissioner’s Office (ICO) where required
3.4 Data Subject Requests
If the Processor receives a request from a Data Subject relating to Personal Data processed under this Agreement, the Processor shall:
- within 48 hours, notify the Controller
- not respond directly to the Data Subject unless authorised to do so by the Controller or required by law
- provide reasonable assistance to enable the Controller to respond
3.5 Personal Data Breaches
The Processor shall notify the Controller without undue delay and in any event without undue delay and, where feasible, within 24 hours of becoming aware of a suspected Personal Data Breach affecting Personal Data processed under this Agreement, or any incident reasonably likely to have resulted in unauthorised access, loss, destruction, alteration or disclosure..
The notification shall include, where available:
- the nature of the breach
- categories and approximate numbers of Data Subjects affected
- categories and approximate number of data records concerned
- likely consequences of the breach
- measures taken or proposed to address the breach
The Processor shall:
- take reasonable steps to contain, investigate and remediate the breach
- cooperate with the Controller in responding to regulatory authorities and Data Subjects
- provide ongoing updates as further information becomes available
- include the Controller in incident response as appropriate
The Processor shall not notify regulators or Data Subjects without the Controller’s prior written authorisation unless required by law.
3.6 Sub-processors
The Controller provides general written authorisation for the Processor to engage Sub-processors.
For the purposes of this Agreement, where the Processor engages any separate legal entity to process Personal Data on behalf of the Controller, that entity shall be treated as a Sub-processor.
The Processor shall notify the Controller in writing, by email, of any intended addition or replacement of a Sub-processor at least 30 days in advance of such change. In unforeseen circumstances where critical operational requirements necessitate a shorter timeframe, the Processor may provide reduced notice, and shall in such cases notify the Controller as soon as reasonably practicable.
The Controller may object to the appointment of a new Sub-processor on reasonable data protection grounds by notifying the Processor in writing within that notice period.
If the Controller objects, the parties shall work in good faith to resolve the objection. If the objection cannot be resolved, the Controller may terminate the affected Services on written notice without penalty.
The Processor shall not permit any Sub-processor to process Personal Data unless the Processor has first entered into a written contract with that Sub-processor which:
- imposes data protection obligations equivalent to those set out in this Agreement
- requires the Sub-processor to provide sufficient guarantees to implement appropriate technical and organisational measures
- prohibits the Sub-processor from engaging another processor without prior specific or general written authorisation
The Processor shall remain fully liable to the Controller for the performance of each Sub-processor’s obligations.
3.7 International Transfers
The Processor will routinely make Restricted Transfers of Personal Data, reflecting the nature of the core ExcluServ partner and sub-processor (ExcluServ Pty) being based in South Africa:
- This is directly authorised by the Controller in entering into this Contract for Services and DPA1.
- Where International transfers are required, the processor will ensure these are carried out in accordance with Data Protection Legislation using an appropriate safeguard such as an International Data Transfer Agreement (IDTA) or the UK addendum to EU Standard Contractual Clauses (SCC) may be used.
- A Transfer Risk Assessment has been carried out where required.
3.8 Audits and Demonstration of Compliance
The Processor shall make available to the Controller information necessary to demonstrate compliance with this Agreement.
The Controller shall bear its own audit costs. The Processor may satisfy its audit and information obligations by providing up-to-date third-party certifications, summaries of audit reports, or other reasonably requested compliance documentation, to the extent sufficient to demonstrate compliance.
Where such information is insufficient, the Controller may conduct or commission an audit.
3.9 Records and Cooperation with Authorities
The Processor shall:
- maintain records of processing activities (ROPA) as required under Article 30 UK GDPR
- cooperate with the Information Commissioner’s Office (ICO) where required by law
- provide reasonable assistance to the Controller in responding to regulatory enquiries relating to the processing of Personal Data under this Agreement
3.10 End-of-Contract Data Handling
Upon termination or expiry of the Contract for Services, the Processor shall, at the Controller’s choice:
- place data into a SharePoint archive fully ring-fenced from normal operations
- return all Personal Data to the Controller
- securely delete all Personal Data
It is generally recommended by ExcluServ that option 1 is selected as this enables queries and investigations to be fulfilled where the Controller requests it.
Unless retention is required by law, where deletion is requested, this will occur within 90 days of termination.
As a bookkeeping and accounting services provider, the Processor and Sub-Processor are required to retain certain financial and accounting records in accordance with applicable UK statutory and regulatory requirements, including but not limited to requirements under HMRC legislation, anti-money laundering regulations and company record keeping obligations. Such records may therefore be retained for up to 7 years, or longer where legally required.
The Processor shall, upon request, provide written confirmation of deletion.
Backup copies containing Personal Data shall be securely deleted in accordance with the Processor’s backup retention schedule, provided that such backups are overwritten in the ordinary course of business and in any event no later than 90 days.
4. Obligations of the Controller
The Controller shall:
- ensure that its instructions comply with Data Protection Legislation
- ensure it has a lawful basis for processing Personal Data
- provide Data Subjects with appropriate privacy information
- ensure it has authority to appoint the Processor
Schedule 1. Details of Processing
| Item | Description |
| Subject Matter | Processing of accounting data including personal data necessary to provide the services described in the Contract for Services |
| Duration | For the duration of the Contract for Services and any agreed post-termination data retention period |
| Nature of Processing | All elements of bookkeeping/payroll, submissions, reconciliations and reporting as laid out within the Contract for Services. The associated collection, storage, organisation, retrieval, consultation and deletion of personal data as necessary to provide such services |
| Purpose of Processing | To enable the Processor to provide the services to the Controller |
| Categories of Data Subjects | Customers, donors, users, employees, or other individuals whose data is submitted by the Controller |
| Types of Personal Data | Contact information, account identifiers, bank details, payroll and employment details, and other personal data submitted by the Controller |
| Special Category Data | Only where submitted by the Controller and where permitted under the Contract for Services |
| Data Transfers | As described in this Agreement |
| Sub-processors | The Processor may appoint sub-processors, including affiliated entities, trusted companies and individual consultants, to process Personal Data on its behalf in connection with the Services. The Processor shall ensure that any such sub-processor is subject to written contractual obligations which are no less onerous than those set out in this Agreement, including obligations relating to confidentiality, data protection and appropriate technical and organisational security measures. The transfer mechanism for all is in line with the IDTA. |
| Third party systems |
The Processor utilises a range of established third-party software providers (“SaaS Providers”) to deliver its services. The Processor confirms that it undertakes appropriate due diligence on such providers, including reviewing their data protection terms and Data Processing Agreements, and ensuring that such providers maintain appropriate technical and organisational measures to protect Personal Data. Where such SaaS Providers act as independent controllers or processors, they do so under their own data protection terms. The Processor ensures that Personal Data is only processed through providers that meet appropriate data protection standards and that data is processed securely at all times. |
Schedule 2. Security Measures
The Processor shall implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data transmitted, stored or otherwise processed.
These measures take into account the current accepted practice, implementation costs, the nature, scope, context and purposes of processing, and the risks posed to Data Subjects.
| Item | Description of Measures |
| Information Security Governance | The Processor maintains documented information security policies and procedures, assigns security responsibilities, conducts periodic policy reviews, and operates a risk management process to identify and mitigate information security risks. |
| Access Control | Access to systems processing Personal Data is restricted to authorised personnel based on role-based access control and the principle of least privilege. Access rights are granted, reviewed and revoked through defined access management procedures. |
| Authentication | Systems require authentication mechanisms appropriate to the sensitivity of the data processed. Privileged or administrative access is protected using stronger authentication mechanisms such as multi-factor authentication where appropriate. |
| Personnel Security | Personnel and authorised contractors with access to Personal Data are subject to confidentiality obligations and receive security awareness training. Access is revoked promptly when personnel leave the organisation. |
| Network and Infrastructure Security | Network security controls such as firewalls, traffic filtering, segmentation where appropriate, and monitoring of network activity are implemented to protect processing environments. |
| Encryption and Data Protection | Personal Data is protected in transit using secure communication protocols. Encryption or other protective measures may be applied to Personal Data at rest where appropriate. Key management practices are implemented where encryption is used. |
| Logging and Monitoring | Systems processing Personal Data generate logs to support the detection and investigation of security events. Monitoring mechanisms are used to identify unauthorised or anomalous activity. |
| Vulnerability Management | Processes are implemented to identify and remediate vulnerabilities, including vulnerability scanning or security testing, monitoring of publicly disclosed vulnerabilities, and timely application of security patches. |
| Secure Development | Where software used to process Personal Data is developed by the Processor, secure development practices are followed, including code review, change management procedures, and remediation of identified security issues. |
| Incident Management | The Processor maintains incident response procedures to detect, respond to, and manage security incidents, including escalation and investigation procedures and breach notification processes. |
| Backup and Recovery | Systems supporting the processing of Personal Data are subject to backup procedures designed to ensure availability and resilience. Disaster recovery or business continuity processes are maintained where appropriate. |
| Physical Security | Facilities used to process Personal Data implement physical access controls such as restricted entry, visitor management procedures, and environmental protections. Where infrastructure is hosted by third-party providers, the Processor relies on the provider’s physical security controls. |
| Sub-processor Security | The Processor conducts due diligence before engaging Sub-processors and requires them to implement appropriate technical and organisational security measures through written contractual obligations. |
| Security Testing and Evaluation | The Processor periodically evaluates the effectiveness of its security measures through security reviews, vulnerability assessments, penetration testing where appropriate, and review of security incidents. |
The Processor may update these Security Measures from time to time provided that such updates do not materially reduce the level of protection for Personal Data during the term of the Agreement.
Approved and adopted by ExcluServ Limited for use in connection with its Contracts for Services and related data processing activities.