This Data Protection Addendum (including its Annex) (“DPA”) forms part of the Terms of Service between Tax Systems and the Client. It governs the processing of personal data in connection with Tax Systems’ provision of the Services.
In the event of any conflict between the terms of this DPA and the main body of this Agreement, the terms of this DPA will prevail to the extent such conflict, but only in relation to the processing of personal data.
Tax Systems’ Privacy Policy, available at https://www.alphatax.com/privacy-policy/, describes how Tax Systems collects and may use personal data as a controller (for example, Client Contact Information, website interactions and marketing communications). The Privacy Policy does not apply to Client Data processed by Tax Systems as a processor under this DPA.
Both parties acknowledge that the Terms of Service and this DPA are intended to comply with applicable privacy and data protection requirements in the United Kingdom, the European Union, and other jurisdictions in which Tax Systems provides services or the Client operates.
Definitions #
Defined terms from the Terms of Service shall carry the same meaning in this DPA. In addition, the following terms shall bear the following meanings:
Applicable Data Protection Law means all data protection and privacy laws applicable to the processing of personal data under the Agreement, including the UK GDPR, EU GDPR, the Data Protection Act 2018 and any other applicable global privacy legislation.
Client Contact Information means personal business contact details of identified Client employees used for the purposes of Services, such as sales, marketing, Professional Services, and support.
Information Security Incident means an occurrence that results in actual or potential jeopardy to the confidentiality, integrity, or availability of an information system or the information system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or Acceptable Use Policies.
The terms Data Controller, Data Processor, Data Subject, Personal Data and processing shall have the same meanings given in the Applicable Data Protection Law.
Relationship and Roles #
(a) Tax Systems acts as a Data Controller of Client Contact Information for legitimate business purposes such as account administration, billing and customer support.
(b) Tax Systems acts as a Data Processor (or Subprocessor, as applicable) of Client Data processed in connection with hosted or cloud Services.
(c) For self-hosted Services, the Client is solely responsible for the processing and security of any Client Data stored or processed within its own environment.
(d) Annex 1 sets out the scope, nature and purpose of processing by Tax Systems, the duration of the processing and the types of personal data and categories of data subject.
(e) Personal Data may be transferred or stored outside the UK or EEA or the country where the Client and the Consumers are located in order to carry out the Services and Tax Systems’ other obligations under this Agreement.
Categories of Data and Processing #
(a) Tax Systems does not require or intend to process any special category data such as health, biometric, racial or ethnic origin data under this Agreement.
Data Protection Obligations #
(a) Both parties will comply with the requirements of the Applicable Data Protection Law as applicable to the provision and use of the Services.
(b) The Client, as Data Controller, shall ensure that it has in place all necessary and appropriate consents, notices or other lawful bases to enable the lawful transfer of Personal Data to Tax Systems for processing under the Agreement.
(c) Tax Systems will:
(i) Process Personal Data only on the documented instructions of the Client;
(ii) In processing Personal Data, Tax Systems shall comply with its Privacy Policy available on the Website;
(iii) Ensure that persons authorised to process Personal Data are under confidentiality obligations;
(iv) Implement appropriate technical and organisational measures to protect Personal Data in accordance with Article 32 UK/ EU GDPR (or equivalent);
(v) Assist the Client, insofar as possible and at the Client’s cost, with fulfilling its obligations regarding Data Subject rights, data breach notifications and DPIAs;
(vi) promptly (and in any event, within 72 hours), notify the Client upon becoming aware of any actual or suspected personal data breach or Information Security Incident and provide sufficient information to assist the Client in meeting its legal obligations;
(vii) Delete (or otherwise put beyond use) Personal Data upon termination of the Agreement, except as required by Applicable Data Protection Law to sore such Client Data; and
(viii) Not transfer Client Data outside the UK/ EEA unless in compliance with Applicable Data Protection Law (e.g. adequacy decisions or approved SCCs) and the following conditions are fulfilled: (i) provided appropriate safeguards in relation to the transfer which for the avoidance of doubt can include third party software-as-a-service applications; (ii) the data subject has enforceable rights and effective legal remedies; (iii) Tax Systems complies with its obligations under the Applicable Data Protection Law by providing an adequate level of protection to any Personal Data that is transferred; and (iv) Tax Systems complies with reasonable instructions notified to it in advance by the Client with respect to the processing of the Personal Data.
(d) Tax Systems shall follow its backup procedures for Client Data as set out in https://www.alphatax.com/legal-policies or such other website address as may be notified to the Client from time to time, as such document may be amended by Tax Systems in its sole discretion from time to time (“Backups”). In the event of any loss or damage to Client Data, the Client’s sole and exclusive remedy against Tax Systems shall be for Tax Systems to use reasonable commercial endeavours to restore the lost or damaged Client Data from the latest backup of such Client Data maintained by Tax Systems in accordance with the archiving procedure described in its Backups procedure as set out in https://www.alphatax.com/legal-policies. Tax Systems shall not be responsible for any loss, destruction, alteration or disclosure of Client Data caused by any third party (except those third parties sub-contracted by Tax Systems to perform services related to Client Data maintenance and backups for which it shall remain fully liable under section 5 of this DPA).
(e) Tax Systems will be responsible for the safe storage, security, use and disposal of the Client Data, subject to the following limitations: (i) The terms of UK/ EU GDPR will be used to determine the classification of Client Data held, the procedures regarding storage and disposal; (ii) Re-use of Client Data will be limited to the provision of tax benchmarks and risk metrics and Tax Systems may use the Client Data held, suitably redacted, to support analytical processes that benefit Tax Systems’ whole client base; and (iii) The option to prohibit the use of Client Data for analytical and statistical purposes may be enacted within certain Services, this will remove the option to benefit from the analytical capabilities of Tax Systems’ data set.
Subprocessors #
(a) Tax Systems may engage Subprocessors to support the provision of the Services.
(b) A current list of Subprocessors is available on the Website at https://www.alphatax.com/security/.
(c) Tax Systems will ensure that Subprocessors are bound by written terms offering at least the same level of protection as required by this DPA.
(d) Tax Systems will notify the Client of material changes to Subprocessors, giving the Client an opportunity to object on reasonable grounds, such objection shall not be unreasonably withheld.
(e) The Client consents to (and authorises) Tax Systems appointing the third-party processors listed on the Website in its sole discretion as third-party processors of Personal Data under this Agreement.
(f) As between the Client and Tax Systems, Tax Systems shall remain fully liable for all acts or omissions of any third-party processor appointed by it.
Security #
See Tax Systems Information Security Policy.
Assistance with DORA and the EU Data Act #
(a) Tax Systems recognizes the applicability of the EU Digital Operational Resilience Act (DORA) and the (EU) Data Act and commits to:
(i) Operational resilience. Implementing and maintaining resilient systems and incident response mechanisms aligned with DORA requirements relevant to our supply chain.
(ii) Cooperation. Providing reasonable assistance to regulated clients to support their compliance with DORA obligations, including data availability and reporting requirements.
(iii) Data Portability and Access. Tax Systems solutions allow clients to extract their own information.
(iv) Transparency. Maintaining clear documentation on data locations and subprocessors.
Audits and Compliance #
See Tax Systems Information Security Policy.
Liability and Indemnity #
Liability for breaches of this DPA shall be subject to the limitations and exclusions set out in the Agreement, except where prohibited by Applicable Data Protection Law.
Governing Law #
This DPA shall be governed by and construed in accordance with the governing law set out in the Agreement, provided that such law shall not restrict the rights or remedies of data subjects under Applicable Data Protection Law.
Annex 1: Processing, Personal Data and Data Subjects #
Subject matter of Processing
Tax Systems shall process Personal Data in order to provide the Services under the Agreement. This will include any information that may be contained within tax records that the Client chooses to upload to the Platform in order for Tax Systems to support the Client in using the Services.
A basic level of Personal Data is required for Tax Systems’ products and services, including name, business email address and phone number of the User. Personal Data may also be supplied if the Client requests support.
Data processing around any AI Functionality, if any, is conducted by the third-party AI providers selected by Tax Systems.
Duration of the Processing
Tax Systems shall process the Personal Data in accordance with DPA.
Nature and purpose of the Processing
Tax Systems will process Personal Data for the purposes of providing the Services to the Client in accordance with the Agreement.
Categories of Personal Data
Data relating to Data Subjects provided to Tax Systems in the course of the Services, by (or at the direction of) the Client, another third party or by Data Subjects, where the processing is to be undertaken on the Client’s behalf. Examples of Personal Data include personally identifiable information specified in a corporate tax return.
Categories of Data Subjects
Data Subjects include the individuals about whom data is provided to Tax Systems in the course of the Services, by (or at the direction of) the Client, another third party or by Data Subjects, where the processing is to be undertaking on the Client’s behalf.
Locations of Processing
A current list of Subprocessors is available on the Website at https://www.alphatax.com/security/.