ACCESS4 DATA PROCESSING ADDENDUM (UK)
1. Scope and roles
1.1. This DPA applies where the Access4 Entity (we, us, our) Processes Personal Data on behalf of the Partner (you, your) in connection with a Service. This DPA is a separate document that is incorporated into, and forms part of, the Contract by reference, and supplements the General Trading Terms. We make it available on our website and may update it as set out in the Variation clause below. Capitalised terms not defined here have the meaning given in the General Trading Terms.
1.2. The parties acknowledge that, in respect of Personal Data Processed through the Services: the relevant Customer (or its own end customer, as applicable) is the Controller; you act as a Processor; we act as a Sub-processor engaged by you; and our Suppliers act as further Sub-processors engaged by us. The parties agree that the actual role of each party is ultimately determined by the circumstances of the Processing.
1.3. This DPA reflects our obligations as a processor under the UK GDPR. To the extent of any conflict on data protection matters, this DPA prevails over the rest of the Contract (including the General Trading Terms) on those matters.
1.4. In this DPA, the terms Controller, Processor, Sub-processor, Processing, data subject, Personal Data Breach and Supervisory Authority have the meanings given in the UK GDPR. Customer means the Partner’s customer or, where the Partner supplies the Services through a reseller or other intermediary, that intermediary’s end customer, in each case being the party on whose behalf Personal Data is Processed through the Services.
2. Processing instructions
2.1. We will Process Personal Data only on your documented instructions (including as set out in the Contract and Annex 1), and as necessary to provide the Services, unless required otherwise by Applicable Laws (in which case we will, where lawful, inform you first).
2.2. You warrant that your instructions, and your and each Customer’s Processing, comply with the Privacy Laws, and that all notices have been given and consents obtained necessary for us and our Suppliers to Process the Personal Data (including for recording, monitoring and processing of communications).
3. Confidentiality
We will ensure that persons authorised to Process the Personal Data are subject to appropriate obligations of confidentiality.
4. Security
We will implement and maintain appropriate technical and organisational measures to protect Personal Data against a Personal Data Breach, appropriate to the risk, consistent with the requirements of the UK GDPR and our Privacy Policy.
5.1. You give us a general authorisation to appoint Sub-processors (including our Suppliers) to Process Personal Data. We will make available to you a list of our current Sub-processors on request.
5.2. We will impose on each Sub-processor data protection obligations that are, in substance, no less protective than those in this DPA, and we remain responsible for each Sub-processor’s acts and omissions.
5.3. We will give you at least 30 days’ notice (by any means permitted for notices under the Contract, including by updating a list we make available) before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, you may terminate the affected Service.
6. Assistance
6.1. Taking into account the nature of the Processing, we will provide reasonable assistance to enable you (and the Controller) to: (a) respond to requests to exercise data subject rights; and (b) comply with your obligations under the UK GDPR relating to security, personal data breach notification, data protection impact assessments and prior consultation, in each case taking into account the information available to us.
6.2. We will promptly notify you if we (or a Sub-processor) receive a request from a data subject to exercise their rights under the Privacy Laws in respect of Personal Data we Process on your behalf. Unless required otherwise by Applicable Laws, we will not respond to any such request directly, and the parties acknowledge that any such request should be directed to, and handled by, the relevant Controller (as between the parties, you or your Customer).
7. Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting the Personal Data, and will provide reasonable information and cooperation to enable you and the Controller to meet any notification obligations under the Privacy Laws, including any obligation to notify the Information Commissioner’s Office within 72 hours (where applicable).
8. Government and law enforcement access
If we receive a legally binding request from a public authority, law enforcement agency or Supervisory Authority to disclose Personal Data we Process on your behalf, we will, where and to the extent legally permitted, notify you (and not the data subject) without undue delay. We will not otherwise be required to handle the request on your behalf. Nothing in this clause requires us to notify you, or prevents any disclosure, where notification or withholding disclosure is prohibited or restricted by Applicable Laws (including the Investigatory Powers Act 2016).
9. Return and deletion
On termination of the relevant Service, we will (at your choice) delete or return the Personal Data, and delete existing copies, unless retention is required by Applicable Laws.
10. Audit
We will make available information reasonably necessary to demonstrate compliance with our obligations under the UK GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, on reasonable prior notice, no more than once in any 12-month period (unless required by a Supervisory Authority or following a Personal Data Breach), subject to reasonable confidentiality and security conditions. We may satisfy this obligation by providing third-party audit reports or certifications.
11. International transfers
We may transfer Personal Data outside the United Kingdom where an adequacy basis applies. Where no adequacy basis applies, the parties will put in place an appropriate transfer mechanism under the UK GDPR, and the International Data Transfer Agreement (IDTA), or the International Data Transfer Addendum to the EU SCCs (UK Addendum), as applicable, is incorporated into this DPA and completed using the information in the Annexes.
12. Governing law
This DPA is governed by the laws of England and Wales.
13. Liability
Each party’s liability arising out of or in connection with this DPA is subject to, and does not increase, the limitations and exclusions of liability set out in the General Trading Terms, which apply to this DPA as if set out in full.
14. Variation
We may vary this DPA from time to time where reasonably necessary to reflect changes in the Privacy Laws or the requirements of a Supervisory Authority, or to give effect to an approved transfer mechanism, provided that any such variation does not materially reduce the protections for Personal Data. We will make the updated DPA available on our website, or by such other means as we may notify.
Annex 1 – Processing details
Subject matter and duration:
Processing of Personal Data for the term of the relevant Service and any wind-down period.
Nature and purpose: providing, operating, supporting, securing and improving the Services, including as described in the applicable Standard Service Terms and Accepted Order.
Types of Personal Data: contact details, account and identity data, communications content and metadata, voice and audio recordings and transcripts, text and interaction content, and other Personal Data contained in Customer Data submitted to or generated by the Services.
Categories of data subjects: your personnel, your Customers and their personnel, and end users interacting with the Services.
Annex 2 – Security measures
The technical and organisational measures maintained by us and our Suppliers, as described in our Privacy Policy and made available on request, and which vary depending on the relevant Service, product, platform and its capabilities, may include: role-based access controls and authentication; use of encryption where appropriate to the relevant Service and platform; logical separation of Customer Data; network and security monitoring and logging; vulnerability management and regular penetration testing; backups; incident detection and response processes; and personnel confidentiality obligations and security awareness training.
Annex 3 – Sub-processors
We engage Sub-processors to Process Personal Data in connection with the Services. A list of our current Sub-processors is available to you on request.
Further Sub-processors may be appointed in accordance with clause REF _Ref237871848 \r \h 5 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F005200650066003200330037003800370031003800340038000000 and notified to you.
Version 1.0 | Effective date: 18 August 2026