1. Scope and roles
For Customer Personal Data covered by these terms, the customer is the controller (or a processor acting for another controller) and Xenon Radio Ltdis the processor. Each party will comply with the data-protection law that applies to it.
These terms do not apply to information for which we independently determine the purposes and means of processing, such as our own account, billing, security and compliance records, which are described in our Privacy Notice.
2. Details of the processing
Subject matter: provision, operation, support and security of StationCortex.
Duration: for the customer's use of StationCortex and any agreed or legally required retention period.
Nature and purpose: hosting, organising, retrieving, analysing, transmitting, drafting, automating and otherwise processing data to provide the Cortex functions selected or instructed by the customer.
Types of personal data may include: names, business contact details, customer and prospect records, communications, commercial history, campaign information, contract/invoice references, account activity and other information uploaded by the customer.
Categories of data subjects may include: the customer's staff and users, advertisers, prospects, clients, suppliers, contacts and other individuals whose information the customer lawfully places in Cortex.
3. Documented instructions
We will process Customer Personal Data only on the customer's documented instructions, including instructions inherent in the customer's use and configuration of StationCortex, unless applicable law requires otherwise.
If law requires processing outside those instructions, we will inform the customer before processing unless the law prohibits us from doing so.
We will inform the customer if, in our reasonable opinion, an instruction infringes applicable data-protection law.
4. Confidentiality
We will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where reasonably necessary for their role.
5. Security
Taking account of the state of the art, implementation costs and the nature, scope, context and purposes of processing, as well as risk to individuals, we will maintain appropriate technical and organisational measures designed to protect Customer Personal Data.
Measures may include, where appropriate:
- access controls and authentication;
- role and permission controls;
- secure infrastructure and encrypted transmission where appropriate;
- logging, monitoring and incident response;
- backup, resilience and recovery arrangements;
- processes for reviewing and improving security measures.
6. Sub-processors
The customer gives general authorisation for us to appoint sub-processors reasonably necessary to provide StationCortex, subject to applicable data-protection requirements.
We will impose data-protection obligations on sub-processors that provide materially equivalent protection for Customer Personal Data as required by law. We remain responsible for our sub-processor obligations to the extent required by applicable law.
We will make information about material sub-processors available to customers and provide notice of material changes where required or reasonably practicable.
7. Data-subject rights
Taking account of the nature of the processing, we will provide reasonable assistance through appropriate technical and organisational measures to help the customer respond to requests to exercise data-subject rights.
If we receive a request relating primarily to Customer Personal Data for which the customer is controller, we may direct the requester to the customer and will not independently respond on the merits unless authorised or legally required.
8. Compliance assistance
Taking account of the nature of processing and information available to us, we will provide reasonable assistance with the customer's obligations relating to security, personal-data breaches, data-protection impact assessments and prior consultation with regulators where applicable.
9. Personal-data breaches
We will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data where applicable law requires processor notification.
We will provide information reasonably available to us to assist the customer in meeting its notification and investigation obligations. Notification is not an admission of fault or liability.
10. International transfers
We will not transfer Customer Personal Data internationally in breach of applicable UK data-protection law. Where a restricted transfer requires safeguards, we will use an appropriate lawful transfer mechanism and take supplementary measures where required.
11. Return and deletion
At the end of the services involving processing, and subject to the customer's available export functionality and documented instructions, we will delete or return Customer Personal Data as required by applicable law, unless law requires us to retain particular information.
Data may remain temporarily in secure backups until overwritten through our normal backup lifecycle, provided it remains protected and is not used for another purpose.
12. Information and audits
We will make available information reasonably necessary to demonstrate compliance with our processor obligations. Where that information is not sufficient, we will permit a reasonable audit or inspection as required by law, subject to appropriate confidentiality, security, scope and notice requirements.
Audits must not unreasonably disrupt the Service, compromise other customers' confidentiality or require disclosure of information we are legally prohibited from providing.
13. Customer responsibilities
The customer is responsible for:
- the lawfulness, fairness and transparency of its collection and use of Customer Personal Data;
- providing required privacy information to individuals;
- having an appropriate lawful basis for prospect, customer and marketing data;
- ensuring its instructions to us are lawful;
- configuring user access and permissions appropriately;
- not uploading personal data that is unnecessary or disproportionately sensitive for the intended use.
14. Priority and contact
If these Data Processing Terms conflict with the general Terms of Service on a matter specifically concerning processor obligations, these Data Processing Terms take priority for that matter.
Data-protection enquiries: privacy@stationcortex.com.
