1. Application and roles
This addendum applies where 3NT Solutions LLP processes personal data on documented instructions for a customer under an accepted service contract. The customer is the controller or an authorised processor acting for its controller; 3NT is the processor or subprocessor for that activity. Our separate controller activities, such as billing and security administration, are described in the Privacy Policy.
2. Processing details
The subject matter is provision of the infrastructure and specifically agreed management, storage, backup or support service. Processing continues for the service term and the lawful return, deletion and backup-expiry period agreed in the service schedule. Its nature may include storage, retrieval, transmission, backup, restoration and deletion as necessary for that scope. The purpose is to supply the customer's instructed service.
Data subjects and personal-data categories are determined by the customer's lawful use and documented in the order or processing schedule. The customer must identify special-category or criminal-offence data and other heightened requirements before placing them in a service that has not been agreed for that purpose. These terms are not unrestricted approval to process every data category.
3. Instructions and compliance
We process customer personal data only on documented instructions, including for transfers. For processing governed by UK GDPR, departure from those instructions requires a UK legal obligation. We notify the customer before acting unless that law prohibits notice on important public-interest grounds. Other applicable regimes and their mandatory exceptions must be identified in the agreed processing schedule. An overseas demand does not itself authorise disclosure or a restricted transfer; it is assessed under the Law Enforcement Guidelines. We inform the customer if, in our opinion, an instruction infringes applicable data-protection law and may suspend that particular instruction while it is clarified.
The customer is responsible for a lawful basis, required notices, the authority to issue instructions and configuration within its control. Neither party is relieved of its own statutory responsibilities.
4. Confidentiality and security
Access is limited to authorised personnel subject to confidentiality obligations. Appropriate technical and organisational measures are selected for the service, risks and state of the art. The service-specific security schedule must identify relevant access controls, transmission protection, isolation, resilience, recovery, change management and testing responsibilities before this addendum is adopted.
We do not materially reduce agreed security during the term without lawful justification and appropriate notice. A customer's application-security and independent-backup responsibilities remain as stated in the order. A general reference to security is not a representation that every product has an identical control set.
5. Subprocessors
No other processor may handle customer personal data on our behalf before the customer has authorised that appointment in writing, either specifically or under a documented general authorisation. General authorisation must be documented with the current relevant list and a procedure for notice of additions or replacements. The customer must have a meaningful opportunity to object on reasonable data-protection grounds. We impose appropriate equivalent obligations and remain responsible as required by applicable law. The relevant subprocessor list forms part of the service-specific arrangements.
6. Assistance and incidents
Taking account of the nature of processing and information available, we assist with data-subject requests, security obligations, impact assessments and consultations as required by law. We do not respond substantively to a request about customer-controlled data except on instructions or where required by law.
We notify the customer without undue delay after becoming aware of a personal-data breach affecting data processed under this addendum. Available information is supplied progressively where necessary, including the nature, likely consequences and measures taken or proposed. Notification alone is not an admission of liability.
7. Transfers and legal requests
Restricted transfers require an applicable lawful mechanism and necessary assessments or supplementary measures. The chosen location of a server alone does not resolve every transfer involved in support or a subprocessor. The relevant transfer arrangements must be identified for the actual service.
We assess requests for customer personal data and, where permitted, notify the customer of legally binding requests and seek clarification or challenge where appropriate. We disclose only the information lawfully required or otherwise properly authorised.
8. Evidence and audits
We make available information reasonably necessary to demonstrate compliance and contribute to proportionate audits as required by applicable law. Arrangements protect other customers, confidential information and security, without making a statutory audit right ineffective. Scope, timing and reasonable cost allocation are agreed where permitted by law. An urgent regulatory need is assessed on its circumstances.
9. Return and deletion
At the end of the relevant processing, customer personal data is returned or deleted at the customer's choice according to the agreed service schedule, unless UK law requires retention for processing governed by UK GDPR. Any mandatory retention exception under another applicable regime must be identified in the agreed processing schedule. The schedule identifies export format and timing, live-data deletion, backup expiry and any necessary segregation during a lawful hold. Retained copies remain protected and are not used for unrelated purposes.
10. Adoption and priority
The service-specific processing details, security measures, subprocessors, transfer arrangements and exit timetable must be completed and accepted with this addendum. For personal-data processing, this addendum and applicable transfer instruments prevail over conflicting provisions in an order, SLA or other service terms. Service schedules may supplement these protections consistently. Mandatory law remains unaffected.
3NT Solutions LLP · OC363382