1. Parties and background
This Data Processing Agreement ("DPA") is between Mayne Consulting Ltd (trading as ISOvault), registered in England and Wales, company number 14618424, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ (the "Processor"), and the customer that accepts the ISOvault Terms & Conditions (the "Controller").
The Controller uses ISOvault to store and manage information security management system records. Some of those records contain personal data. This DPA governs the Processor's processing of that personal data on the Controller's behalf.
This DPA is incorporated into and forms part of the Terms & Conditions. It takes effect on the date the Controller creates an ISOvault account and continues for as long as the Processor processes personal data on the Controller's behalf.
2. Definitions
"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any legislation that amends or replaces them. "Personal data", "processing", "data subject", "personal data breach" and related terms have the meanings given in the Data Protection Legislation. "Customer Personal Data" means personal data contained in Customer Data that the Processor processes on behalf of the Controller.
3. Details of processing
| Subject matter | Provision of the ISOvault document and evidence management service. |
| Duration | The subscription term, plus the export and deletion period described in clause 10. |
| Nature and purpose | Hosting, storage, organisation, retrieval, display, analysis (including AI-assisted gap analysis), document generation, backup and deletion of Customer Data, solely to provide the service. |
| Categories of data subjects | The Controller's employees, contractors and officers; contacts at the Controller's suppliers and customers; other individuals whose personal data the Controller includes in its ISMS records. |
| Categories of personal data | Names, job titles, work contact details, user account records, access and permission records, training and acknowledgement records, and any other personal data the Controller chooses to include in its documents and registers. |
| Special category data | Not intended or required for the service. The Controller agrees not to upload special category data unless strictly necessary, and does so as controller of that decision. |
4. Processor obligations
The Processor shall:
- process Customer Personal Data only on the Controller's documented instructions, including as set out in the Terms & Conditions and this DPA, unless required to do otherwise by law, in which case the Processor will inform the Controller unless prohibited from doing so;
- ensure that everyone authorised to process Customer Personal Data is bound by confidentiality obligations;
- implement and maintain the technical and organisational measures set out in Annex 1, and not materially reduce them during the subscription term;
- notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, providing sufficient information for the Controller to meet its own notification obligations;
- taking into account the nature of the processing, assist the Controller with responses to data subject rights requests, and with the Controller's obligations regarding security, breach notification, data protection impact assessments and prior consultation;
- maintain records of its processing activities as required by Article 30 UK GDPR.
5. Sub-processors
- The Controller gives general written authorisation for the Processor to engage sub-processors to provide the service.
- The current list is published at isovault.co.uk/sub-processors, including each sub-processor's purpose, processing location and transfer safeguard.
- The Processor will update the register and notify account holders by email at least 30 days before adding or replacing a sub-processor that processes Customer Personal Data.
- The Controller may object on reasonable data protection grounds within that notice period. If the objection cannot be resolved, the Controller may terminate the subscription and receive a pro-rata refund of any prepaid fees for the unused period.
- The Processor imposes data protection obligations on each sub-processor equivalent to those in this DPA, and remains liable for its sub-processors' performance.
6. International transfers
Customer Data, documents and backups are hosted in the United Kingdom (London, AWS eu-west-2). Where a sub-processor processes personal data outside the UK, the Processor ensures a valid transfer mechanism is in place: UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, as recorded in the sub-processor register.
7. Security
The Processor implements the technical and organisational measures set out in Annex 1, which the parties agree provide a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.
8. Audit and information rights
- The Processor will make available on request the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures, penetration test attestations and completed security questionnaires.
- Where that information is insufficient, the Controller may conduct an audit, at its own cost, no more than once in any 12-month period, on at least 30 days' written notice, during business hours, without disrupting the service, and subject to confidentiality obligations. Audits do not extend to other customers' data or to sub-processors' facilities; for sub-processors, the Processor will pass through audit reports and certifications it receives.
9. Data subject requests
If the Processor receives a request from a data subject relating to Customer Personal Data, it will not respond except to direct the data subject to the Controller, and will notify the Controller promptly. The service's export, search and correction features are the primary means by which the Controller can fulfil requests itself.
10. Return and deletion
- The Controller can export Customer Data at any time during the subscription in standard formats (Word, CSV).
- Following termination or expiry, the Controller has 30 days to export Customer Data.
- The Processor will then delete Customer Personal Data from production systems within 90 days of termination, and from backups as those backups expire in the normal rotation cycle (no later than a further 35 days), unless retention is required by law.
- On written request, the Processor will confirm deletion in writing.
11. Liability and general
- Each party's liability under this DPA is subject to the limitations and exclusions in the Terms & Conditions, except where Data Protection Legislation does not permit liability to be limited.
- If there is a conflict between this DPA and the Terms & Conditions regarding the processing of personal data, this DPA prevails.
- This DPA is governed by the laws of England and Wales.
Annex 1: Technical and organisational security measures
Hosting and physical security
- All Customer Data, documents and backups are hosted in AWS data centres in London (eu-west-2), which maintain ISO 27001, SOC 2 and equivalent physical and environmental certifications.
Encryption
- Data encrypted in transit using TLS 1.2 or higher.
- Data encrypted at rest using AES-256 across databases, document storage and backups.
Tenant isolation
- Each customer's records are held in an isolated database schema; customer documents are held in isolated, tenant-namespaced storage.
- Documents are accessed only through short-lived, signed URLs; storage is never publicly accessible.
Access control
- Authentication via a dedicated identity provider, with support for single sign-on and multi-factor authentication.
- Role-based access within customer workspaces, controlled by the customer's administrators.
- Administrative access to production systems is restricted to authorised personnel, protected by multi-factor authentication, and logged.
Resilience and backups
- Automated backups with point-in-time recovery for customer databases.
- Backup restoration tested on a scheduled basis.
Operational security
- Error and security event monitoring on production systems.
- Documented incident management process, feeding the breach notification commitment in clause 4.
- Segregated development, staging and production environments; customer data is not used in development or testing.
- AI processing is performed within the Processor's AWS environment in London (Claude models via Amazon Bedrock). Customer Data is not sent to the model provider and is not used to train AI models.
Signable copy. This DPA applies automatically to all customers through the Terms & Conditions. If your procurement or compliance process requires a countersigned copy, email hello.isovault@agentmail.to and we will provide a Word version for signature by both parties.