Data Protection Addendum.
The processor terms that govern how SandLogic handles personal data on a customer's behalf. It forms part of your agreement with us — this page summarises it and links the full document.
SandLogic Data Protection Addendum
PDF · 13 pages · includes Annex 1 (processing details and security measures) and Annex 2 (sub-processors)
This Addendum applies when SandLogic processes personal data on behalf of a customer as part of delivering a product or service. The customer is the Controller; SandLogic is the Processor. It forms part of the customer’s agreement with us and is not a standalone contract. For how this website handles personal data, see the Privacy Policy instead.
01What this document is
The Data Protection Addendum (“Addendum” or “DPA”) sets out the terms on which SandLogic processes personal data on behalf of a customer when delivering its products and services.
It is not a standalone contract. It forms part of, and is governed by, the written agreement between SandLogic and the customer — typically a master services agreement, IP licence, or order form (the “Agreement”). Where the Addendum and the Agreement conflict on a data protection matter, the Addendum prevails.
If you are looking for how this website handles personal data, that is a different document: see our Privacy Policy.
02Roles of the parties
Under the Addendum:
- the customer is the Controller (GDPR) or Business (CCPA) — it decides what personal data is processed and why;
- SandLogic is the Processor or Service Provider — it processes that data only on the customer’s documented instructions.
SandLogic does not sell or share customer personal data, does not process it for its own commercial purposes, and does not combine it with data obtained from other sources outside the scope of the Agreement.
03Core commitments
- Purpose limitation — processing only for the purposes set out in the Agreement and Annex 1, on documented instructions.
- Confidentiality — personnel with access are bound by confidentiality obligations.
- Security — technical and organisational measures appropriate to the risk, including encryption and pseudonymisation, with regular testing. Set out in full in Annex 1, section 4.
- Sub-processors — 30 days’ advance notice of any change, a right to object on data protection grounds, and SandLogic remains liable for its sub-processors.
- Breach notification — notification to the customer without undue delay, with the information needed to meet its own reporting obligations.
- Data subject requests — reasonable assistance to the customer in responding.
- Audit — assessment responses annually, with inspection rights where those responses are insufficient.
- Return or deletion — on termination, customer personal data is returned or deleted at the customer’s option, subject to retention required by law.
04International transfers
Where a transfer of customer personal data to SandLogic is a restricted transfer under applicable data protection law, it is made subject to the appropriate Controller-to-Processor Standard Contractual Clauses, together with any successor or equivalent clauses adopted by the relevant regulator.
05Sub-processors
The current sub-processor list is maintained in Annex 2 of the Addendum. Customers receive at least 30 days’ notice of any intended addition or change, and may object on reasonable data protection grounds.
To be notified of sub-processor changes, email info@sandlogic.com.
06Exercising data subject rights
Individuals whose personal data SandLogic processes on behalf of a customer should normally direct requests to that customer, which is the Controller and decides how the data is used. Where a request is made to us directly, we will pass it to the relevant customer and assist them in responding. Our Data Protection Officer can be reached at info@sandlogic.com.
07Accepting the Addendum
For most customers the Addendum is incorporated automatically by the Agreement and needs no separate signature. If your procurement process requires a countersigned copy, or if you need us to execute your own DPA template or Standard Contractual Clauses instead, contact sales@sandlogic.com.
The PDF is the authoritative version; this page is a summary for convenience. Questions: info@sandlogic.com. See also our Terms of Use, Privacy Policy, and Trust & Compliance.