Data Processing Agreement
1. Definitions
For the purposes of this Agreement:
- Controller, Processor, Personal Data, Processing, Data Subject have the meanings given in UK GDPR.
- Customer means any user or organisation using the Service.
- BonafideCheck means the operator of bonafidecheck.co.uk.
2. Scope and Applicability
This Data Processing Agreement ("DPA") applies where BonafideCheck processes Personal Data on behalf of the Customer in the course of providing the Service.
This DPA forms part of, and is incorporated into, the Terms of Service.
3. Roles of the Parties
- The Customer acts as Data Controller
- BonafideCheck acts as Data Processor, except where BonafideCheck acts as an independent Controller for its own operational, legal, or security purposes
4. Processing Details
4.1 Subject Matter
Provision of due diligence, verification, and compliance-support services.
4.2 Duration
Processing continues for the duration of the Customer's use of the Service and any legally required retention period.
4.3 Nature and Purpose
- Collection, aggregation, structuring, analysis, and presentation of data
- Compliance support and risk assessment activities
4.4 Categories of Data
May include:
- Business identifiers
- Contact details
- Public regulatory information
- User-submitted data
Special category data is not intended to be processed unless expressly agreed in writing.
5. Customer Obligations
The Customer warrants that:
- It has a lawful basis for processing
- Data submitted is accurate and lawful
- Required notices and consents have been obtained
- It complies with all applicable data protection laws
The Customer remains solely responsible for determining legality of processing and use.
6. BonafideCheck Obligations
BonafideCheck shall:
- Process data only on documented instructions
- Implement appropriate technical and organisational security measures
- Ensure personnel are subject to confidentiality obligations
- Assist with data subject requests where legally required
7. Sub-Processors
BonafideCheck may engage sub-processors.
The Customer provides general authorisation for such use.
BonafideCheck remains responsible for sub-processor compliance.
8. International Transfers
Where data is transferred outside the UK, appropriate safeguards (including adequacy decisions or contractual protections) will be applied.
9. Data Breaches
BonafideCheck will notify the Customer without undue delay upon becoming aware of a personal data breach, where legally required.
10. Deletion and Return
Upon termination, data will be deleted or anonymised unless retention is required by law.
11. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service.