The Enquiry 360 software runs inside your own Microsoft tenant. Enquiry records, transcripts and reporting data are created there and stay there. The software transmits none of it to us, and we hold no copy of it. For that processing you are the controller and we are not a processor at all.
These terms exist for the narrower case: you ask us to help with a configuration change, a support question or a diagnosis, and you grant us access to an environment that contains personal data. For that activity, and only that activity, we act as your processor.
1. When these terms apply
These terms apply where all of the following are true: you have licensed the Software under the End User Licence Agreement; you have granted us access to a Microsoft environment of yours; and in exercising that access we process personal data on your behalf.
They do not apply to the ordinary operation of the Software, because that involves no processing by us. They do not apply to personal data you send us directly, for example when you email us about a contract, which is covered by our Privacy Notice.
2. Roles
You are the controller. Maya Information Systems Ltd is the processor. These terms are the written contract required by Article 28(3) of the UK GDPR, and by Article 28(3) of the EU GDPR where that applies to you.
3. Details of the processing
Subject matter. Configuration, support and diagnostic assistance with the Software.
Duration. For the period of each access you grant, and no longer.
Nature and purpose. Viewing configuration and, where you ask us to, records and transcripts, in order to change a configuration, answer a support question, or diagnose a fault. We do not extract, copy, export or retain personal data except where you specifically ask us to in order to resolve an issue.
Types of personal data. Whatever your configuration captures. Typically name, contact details, address, the substance of an enquiry, and where call recording is enabled, call audio and transcripts. Your configuration may include special category data or data about criminal offences; if it does, you should tell us before granting access.
Categories of data subject. The people who contact your service, and your own personnel who use the Software.
4. Our obligations
We will:
- process personal data only on your documented instructions, including as to international transfers, unless we are required to do otherwise by law, in which case we will tell you before processing unless the law prohibits that. Your instructions are the request under which you granted us access, together with these terms and the Licence Agreement;
- tell you promptly if, in our opinion, an instruction infringes data protection law;
- ensure that our personnel authorised to process personal data are subject to an appropriate duty of confidence;
- keep access to the minimum necessary, for the minimum period, and use named individual accounts rather than shared credentials; and
- notify you without undue delay, and in any event within 24 hours, on becoming aware of a personal data breach affecting personal data we process on your behalf, with the information you reasonably need to meet your own obligations.
5. Security
We will implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. Those measures include multi-factor authentication on accounts used to access your environment, least-privilege access, encryption in transit, device security controls, and access granted and removed on a per-engagement basis.
The security of the environment itself, including its access controls, roles, retention and backup, is yours to configure and maintain.
6. Sub-processors
You give us general authorisation to engage sub-processors. We currently engage none for this activity. Microsoft is not a sub-processor of ours for this purpose: it is your own platform provider, engaged by you under your own agreement with Microsoft.
If we propose to engage a sub-processor, we will tell you at least 30 days beforehand and you may object on reasonable data protection grounds. If we cannot resolve your objection, you may terminate the affected access arrangement without penalty. We remain fully liable to you for any sub-processor's performance.
7. Assistance to you
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, in responding to requests from data subjects exercising their rights. In practice you can usually answer those yourself, because the data is in your own tenant and under your own control.
We will also assist you, taking into account the nature of the processing and the information available to us, in complying with your obligations under Articles 32 to 36, which cover security, breach notification and data protection impact assessments.
8. International transfers
We are established in the United Kingdom and our personnel access your environment from the United Kingdom. We will not transfer personal data processed on your behalf outside the United Kingdom without your prior written instruction and an appropriate transfer mechanism.
9. End of access
At the end of each access, and in any event on termination of the Licence Agreement, we will delete any personal data we hold as a result of that access, unless we are required by law to retain it. In the normal case there is nothing to delete, because the data stayed in your tenant and we took no copy. We will confirm deletion in writing if you ask.
10. Demonstrating compliance
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will respond to a reasonable written request for that information no more than once in any twelve months, or more often following a personal data breach affecting your data or where a regulator requires it.
Because we hold no copy of your data and operate no service that stores it, an inspection of our premises or systems would show nothing relevant to your processing. Where your own regulatory obligations require an audit, we will agree a proportionate approach with you in good faith.
11. Your obligations
You confirm that you have a lawful basis for the processing carried out through the Software, that you have given data subjects the information they are entitled to, that your configuration collects only what you need, and that your instructions to us comply with data protection law. You are responsible for the retention policy applied to Your Data and for deciding whether call recording is enabled and what callers are told about it. See the Product Terms & Governance.
12. Contact us
Maya Information Systems Ltd
Prime Apartments, 483 Green Lanes, London, N13 4FG, United Kingdom
Company number 09055019
info@enquiry360.com