This is a general template. The scope, systems, data categories and subprocessors are specified for each client.
1. Roles and duration
The client is the controller and Adam El Hadidy / HadidyLabs is the processor to the extent it processes personal data on the client’s behalf. Processing lasts for the underlying service and only for its documented purposes.
2. Instructions and confidentiality
HadidyLabs processes data only on documented client instructions unless law requires otherwise. People with access are bound by confidentiality and receive access only when needed.
3. Nature, purpose and categories
Processing may include hosting, storage, backups, maintenance, security, support and troubleshooting. Data subjects and data categories are specified per client, such as visitors, leads, users, contact details, account data, content and logs.
4. Security
HadidyLabs applies measures appropriate to risk, including access controls, encrypted connections, updates, backups, monitoring and incident procedures. The client remains responsible for lawful instructions and internal permissions.
5. Subprocessors
HadidyLabs may use subprocessors for hosting, backups and technical services. The client is informed of material changes and may object on reasonable data protection grounds. Equivalent obligations are imposed on subprocessors.
6. Assistance
HadidyLabs assists with data-subject requests, security obligations, breaches, DPIAs and regulator consultation, taking the nature of processing into account. Additional work outside regular management may be charged.
7. Breaches
HadidyLabs notifies the client without undue delay after becoming aware of a personal data breach and supplies reasonably available information. The client decides whether notification to authorities or data subjects is required.
8. End of service
At the client’s choice, personal data is returned or deleted after service, where technically possible and unless legal retention applies. Data may remain in protected backups for the ordinary rotation period.
9. Information and audit
HadidyLabs provides information reasonably necessary to demonstrate Article 28 GDPR compliance. Audits are agreed in advance, minimise disruption and cost, and protect confidential information.
Questions about this document can be sent to info@hadidylabs.com.