Last updated: 23 July 2026. View change log.
This Schedule sets out the data protection terms that apply where we process personal data on your behalf in connection with services provided under the Partner Agreement. It applies to all partners and all services unless a Partner Order expressly states otherwise.
1. Definitions and Interpretation
- In this Schedule:
- Data Protection Laws means all applicable data protection and privacy legislation, including the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR.
- Personal Data, Processing, Controller, Processor, Data Subject and Personal Data Breach have the meanings given in Data Protection Laws.
- Partner Data means any Personal Data we process on your behalf in connection with the services.
- Sub-processor means any third party we appoint to process Partner Data on your behalf.
- If Data Protection Laws require additional obligations that this Schedule does not expressly state, we will both act reasonably to comply with them.
2. Roles of the Parties
- For Partner Data processed in connection with services delivered to End Customers:
- you act as Controller; and
- we act as Processor.
- Where we contract directly with an End Customer, the roles of the parties are as set out in our applicable terms with that End Customer.
3. Details of Processing
- Subject matter. The provision, operation and support of IT, Cloud and Web services.
- Duration. For the duration of the services and any reasonable post-termination period required for offboarding, data return or deletion, or as required by law.
- Nature and purpose. Processing necessary to deliver services, provide support, maintain security, perform monitoring and backups (where applicable), and manage incidents and requests.
- Types of Personal Data. May include names, business contact details, user identifiers, authentication data, access and audit logs, device and system identifiers, support communications and service usage data.
- Categories of Data Subjects. End Customer employees, contractors and other authorised users.
4. Partner Obligations
- You must:
- make sure you have a lawful basis for Processing Partner Data;
- provide appropriate privacy information to Data Subjects;
- make sure you are entitled to appoint us as a Processor and to permit the use of Sub-processors;
- make sure any instructions you give us are lawful and documented; and
- not provide Partner Data to us unless it is reasonably necessary for service delivery.
- You are responsible for the accuracy, quality and legality of Partner Data.
5. Cultrix Obligations
- We will:
- process Partner Data only on your documented instructions, unless the law requires otherwise;
- make sure people authorised to process Partner Data are subject to appropriate confidentiality obligations;
- put in place appropriate technical and organisational measures to protect Partner Data; and
- tell you where an instruction would, in our reasonable opinion, infringe Data Protection Laws.
- We may use aggregated and anonymised information derived from the services – which does not identify any individual or customer – to monitor, maintain, improve and develop our services. We do not otherwise use your personal data for our own purposes; personal data is processed only on your documented instructions.
6. Security Measures
- We will maintain appropriate technical and organisational security measures designed to protect Partner Data against unauthorised or unlawful Processing and against accidental loss, destruction or damage.
- Measures may include access controls, least-privilege principles, encryption in transit where appropriate, logging and monitoring, and supplier security controls.
- You acknowledge that security is a shared responsibility and that no measures eliminate all risk.
7. Sub-processing
- You authorise us to appoint Sub-processors for the purpose of delivering services.
- We will make sure Sub-processors are subject to written obligations that are no less protective than those set out in this Schedule, to the extent required by Data Protection Laws.
- We may update our Sub-processor arrangements from time to time, and we will give reasonable notice of material changes where practical.
8. International Transfers
- Partner Data may be processed outside the UK and/or EEA where required by the service delivery model or Vendors.
- Where international transfers apply, we will make sure appropriate safeguards are in place in accordance with Data Protection Laws.
- You are responsible for making sure your privacy information reflects any such international processing.
9. Personal Data Breaches
- We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Partner Data.
- We will provide the information reasonably required to help you meet your breach notification obligations.
- You are responsible for deciding whether notification to supervisory authorities or Data Subjects is required.
10. Data Subject Requests
- If we receive a request from a Data Subject relating to Partner Data, we will, where permitted, refer the request to you.
- We will provide reasonable assistance to you in responding to Data Subject requests, taking into account the nature of the Processing.
- Assistance may be chargeable where it requires material time or effort beyond standard service delivery.
11. Audits and Information
- We will make available the information reasonably necessary to demonstrate compliance with this Schedule, subject to confidentiality and security considerations.
- Any audit must be carried out on reasonable written notice, during normal business hours, and in a way that does not unreasonably disrupt our operations or compromise other customers’ data.
12. Data Return and Deletion
- When services end, we will, where practicable and subject to legal and Vendor constraints, return or delete Partner Data after completing reasonable offboarding steps.
- We may keep Partner Data where required by law or for legitimate record-keeping purposes.
13. Order of Priority
- If there is a conflict between this Schedule and the Partner Agreement, this Schedule prevails for data protection matters.
- If there is a conflict between this Schedule and a Partner Order, the Partner Order prevails.