This Data Processing Agreement (“DPA”) forms part of the agreement between GROWKINS (“Processor”) and the client (“Controller”) where GROWKINS processes personal data on behalf of the Controller in connection with the services provided.
This DPA is intended to support compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable privacy legislation where relevant.
The purpose of this Agreement is to define the responsibilities of both parties regarding the processing of personal data while GROWKINS delivers its services.
This DPA applies whenever GROWKINS processes personal data on behalf of a client.
For the purposes of this Agreement:
Controller means the organization that determines the purposes and means of processing personal data.
Processor means GROWKINS, which processes personal data on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable natural person.
Processing includes collecting, storing, organizing, accessing, using, transferring, or deleting personal data.
Data Subject means the individual whose personal data is processed.
GROWKINS processes personal data solely for the purpose of delivering the agreed services, which may include:
Processing activities are limited to those necessary to perform contractual obligations.
Depending on the services provided, GROWKINS may process business-related personal data including:
GROWKINS does not intentionally collect special categories of personal data unless expressly agreed in writing and permitted by applicable law.
Personal data processed under this Agreement may relate to:
GROWKINS agrees to:
The Controller is responsible for:
The Controller remains responsible for determining the purposes and legal basis of processing.
GROWKINS may engage trusted third-party service providers to support service delivery, including providers of:
GROWKINS remains responsible for ensuring that subprocessors are contractually required to provide appropriate data protection safeguards.
GROWKINS may engage trusted third-party service providers to support service delivery, including providers of:
GROWKINS remains responsible for ensuring that subprocessors are contractually required to provide appropriate data protection safeguards.
Where personal data is transferred internationally, GROWKINS will implement appropriate safeguards as required by applicable law, including contractual protections where appropriate.
Where applicable, GROWKINS will reasonably assist the Controller in responding to requests relating to:
GROWKINS will promptly notify the Controller if it receives a request directly from a data subject concerning data processed on the Controller’s behalf, unless prohibited by law.
If GROWKINS becomes aware of a confirmed personal data breach affecting personal data processed under this Agreement, GROWKINS will notify the Controller without undue delay and provide available information reasonably necessary to support the Controller’s response obligations.
GROWKINS retains personal data only for as long as necessary to:
Upon termination of services and subject to legal or contractual retention requirements, GROWKINS will delete or return personal data as agreed with the Controller.
GROWKINS will ensure that employees, contractors, and authorized personnel with access to personal data are bound by appropriate confidentiality obligations.
Access to personal data is limited to individuals who require it to perform their duties.
Where reasonably required and subject to appropriate confidentiality protections, GROWKINS will provide information necessary to demonstrate compliance with this Agreement.
Any audits shall be conducted at mutually agreed times in a manner that minimizes disruption to business operations.
Each party remains responsible for its own compliance with applicable data protection laws.
Liability relating to data processing is governed by the applicable service agreement unless otherwise required by law.
This DPA remains in effect for as long as GROWKINS processes personal data on behalf of the Controller under the applicable service agreement.
Termination of the underlying agreement automatically terminates this DPA, except for obligations that survive by law or by their nature.
Questions regarding this Data Processing Agreement or GROWKINS’ data processing practices may be directed through the contact information provided on our Contact page.
GROWKINS is committed to processing personal data responsibly, securely, and transparently.
We recognize that trust is essential to every business relationship and continually work to maintain high standards of privacy, information security, and regulatory compliance while delivering exceptional revenue growth services.