Trust
Data protection
Roles, responsibilities and the controls that apply when we process data on behalf of an agency.
Who is responsible for what
In most programs the agency or association is the party that decides why and how data is processed, and we process it on their instructions under a written agreement. That agreement states the purposes, the retention window, the access roles and what happens to the data when the contract ends.
Controls that apply in every case
The controls that apply to a given deployment are set out in the contract and its security schedule, and are described there in specific terms rather than as general claims. We provide that documentation on request before any agreement is signed.
Questions about this page
Write to us and we will answer.