1. Purpose
This Data Processing Addendum (the “Addendum”) forms part of and is incorporated into the Contract between REAC Consulting Ltd trading as M365 Chap (the “Processor”) and the Customer (the “Controller”) where the Processor processes Personal Data on behalf of the Controller.
Capitalised terms not defined in this Addendum have the meanings given in the M365 Chap Terms of Business or the applicable Contract. References to Data Protection Laws include the UK GDPR, the Data Protection Act 2018 and other data protection legislation applicable to the processing.
This Addendum sets out the parties’ obligations relating to the processing of Personal Data by the Processor on behalf of the Controller.
If this Addendum conflicts with another contractual document, this Addendum prevails to the extent of the conflict in relation to Personal Data processing.
2. Roles of the Parties
The Controller determines the purposes and lawful basis of processing and remains responsible for compliance with applicable Data Protection Laws.
The Processor processes Personal Data only on documented instructions from the Controller, assists the Controller as described in this Addendum, and implements appropriate technical and organisational measures.
Nothing in this Addendum transfers the Controller’s legal responsibilities to the Processor. If the Processor is required by law to process Personal Data other than on the Controller’s instructions, the Processor shall inform the Controller before processing unless the law prohibits that notification.
3. Processor Obligations
The Processor shall:
- process Personal Data only on documented instructions from the Controller, including instructions contained in the Contract and support requests;
- ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations and receive appropriate training;
- take reasonable steps to ensure that authorised personnel access Personal Data only where required to provide the Services;
- maintain appropriate technical and organisational measures to protect the confidentiality, integrity and availability of Personal Data;
- provide reasonable assistance to the Controller with Data Subject rights, security obligations, breach assessments, data protection impact assessments and prior consultation with a supervisory authority, taking account of the nature of processing and information available to the Processor; and
- inform the Controller if, in the Processor’s reasonable opinion, an instruction infringes applicable Data Protection Laws.
4. Security Measures
The Processor shall maintain security measures appropriate to the nature of the Services, the Personal Data processed and the risks to individuals. The measures described in Schedule A are illustrative and apply where appropriate to the relevant Services.
Where required by law, the Processor shall maintain registration with the Information Commissioner’s Office.
The Controller acknowledges that no security measure can eliminate all risk. The Processor does not warrant that cyber incidents will never occur.
5. Subprocessors
The Controller gives general authorisation for the Processor to engage subprocessors reasonably required to provide the Services. Applicable categories are described in Schedule A.
The Processor may add, remove or replace subprocessors where reasonably necessary. The Processor shall make a current subprocessor list available on reasonable request and, where required by Data Protection Laws, provide information concerning intended changes so that the Controller may raise reasonable data-protection objections.
The Processor shall impose data-protection obligations on each subprocessor that provide an appropriate level of protection for the processing undertaken. The Processor remains responsible to the Controller for the performance of the subprocessor’s data-protection obligations to the extent required by law.
6. International Transfers
The Processor shall not transfer Personal Data outside the United Kingdom, or permit such a transfer by a subprocessor, unless the transfer complies with applicable Data Protection Laws.
Lawful safeguards may include United Kingdom adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another recognised transfer mechanism. Further processing details are set out in Schedule A.
7. Data Subject Requests
If the Processor receives a request from a Data Subject relating to Personal Data processed on the Controller’s behalf, the Processor shall notify the Controller without undue delay and shall not respond except on the Controller’s documented instructions or where required by law.
Taking account of the nature of processing, the Processor shall provide reasonable assistance to enable the Controller to respond to Data Subject requests.
The Processor may recover reasonable costs where assistance requested by the Controller exceeds normal contractual support obligations.
8. Personal Data Breaches
Upon becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller, the Processor shall notify the Controller without undue delay.
The Processor shall provide the information reasonably available to it concerning the nature of the breach, affected data and individuals, likely consequences, and measures taken or proposed. Information may be provided in phases where it is not available at the same time.
The Processor shall take reasonable steps to contain, investigate and remediate the incident. The Controller remains responsible for determining whether notification to a supervisory authority, Data Subjects or another third party is required.
9. Audit Rights
The Processor shall make available information reasonably necessary to demonstrate compliance with this Addendum. The Processor may ordinarily satisfy requests through policies, certifications, security summaries, audit reports or similar compliance material.
If that information is insufficient, the Controller may conduct an audit itself or through an independent auditor bound by confidentiality, subject to reasonable written notice, appropriate scope and timing, and controls to protect other customers and the Processor’s security and confidential information.
On-site audits shall be permitted only where reasonably necessary or legally required and must not unreasonably disrupt operations. The Processor may recover reasonable costs associated with assistance or audits that exceed normal contractual support obligations.
10. Retention and Deletion
On termination or expiry of the relevant Services, and at the Controller’s choice where reasonably practicable, the Processor shall return or delete Personal Data processed on the Controller’s behalf, unless applicable law requires retention.
Personal Data may remain in routine backup systems until the applicable backup retention cycle expires, provided that the Personal Data remains protected under this Addendum and is not restored or otherwise processed except for recovery, security or legal purposes.
The Controller is responsible for exporting or requesting the return of Personal Data before service access ends where the applicable Service permits customer-controlled export.
11. Liability
Liability arising under this Addendum is subject to the exclusions and limitations of liability in the M365 Chap Terms of Business and the applicable Contract, except to the extent that such limitation is prohibited by law.
Nothing in this Addendum increases the Processor’s liability beyond the limits agreed in the Contract.
12. Contact Details
Data protection enquiries may be directed to [email protected] or to any replacement address notified by the Processor.
13. Legal Disclosure Requests
Where the Processor receives a court order, regulatory notice, law-enforcement request or other legally binding demand relating to Personal Data processed on behalf of the Controller, the Processor shall, where legally permitted, notify the Controller without undue delay and reasonably cooperate with the Controller in responding.
Nothing in this clause requires the Processor to breach a legal obligation or restriction.
14. Term
This Addendum takes effect when the Contract commences or when the Processor first processes Personal Data on behalf of the Controller, whichever is earlier. It remains in force for so long as the Processor processes that Personal Data.
Processing Details
A1. Subject Matter of Processing
Provision of technology consultancy, managed services, project services, technical support, cyber security services, licensing services, backup services and related technology services.
A2. Duration of Processing
Personal Data may be processed:
- for the duration of the Contract;
- during any applicable notice or transition period;
- during legally required retention periods;
- during normal backup retention periods; and
- for any further period reasonably required to resolve disputes, investigations or legal claims.
A3. Nature of Processing
Processing may occur manually or by automated means and may include:
- collection;
- recording;
- organisation;
- storage;
- consultation;
- access;
- retrieval;
- transmission;
- backup;
- restoration;
- restriction;
- deletion; and
- destruction.
A4. Purpose of Processing
Personal Data may be processed for:
- administration and support of customer technology systems and cloud services;
- provisioning and management of user accounts and access rights;
- technical support, troubleshooting and service desk operations;
- project delivery, migrations and professional services;
- cyber security, monitoring and incident response services;
- backup, recovery and business continuity services;
- licensing, subscription and supplier management;
- documentation and maintenance of customer environments;
- contract administration; and
- provision of managed services.
The Processor may access stored content, communications, files, logs and user data solely where reasonably necessary to investigate incidents, troubleshoot faults, secure systems, perform migrations, provide support, perform backups, restore services or otherwise deliver Services requested by the Controller.
A5. Categories of Data Subjects
| Category | Examples |
|---|---|
| Employees | Permanent and temporary employees, contractors and consultants. |
| Customer personnel | Directors, managers, administrators and support contacts. |
| Guest users and external collaborators | Guest users, external collaborators, supplier representatives, partner organisation personnel, auditors, customer representatives and other third parties authorised to access customer systems, services or data. |
| Third parties | Suppliers, business partners and service providers. |
| Customer contacts and end users | Customers, prospects, website contacts, email correspondents, service users and other individuals whose Personal Data is contained in systems administered by the Controller. |
A6. Categories of Personal Data
| Category | Examples |
|---|---|
| Identity data | Names, usernames, employee identifiers, guest account identifiers, external directory identifiers, organisation names associated with user accounts and job titles. |
| Contact data | Email addresses, telephone numbers and postal addresses. |
| Technical data | IP addresses, device identifiers, operating system and browser information, sign-in records and technical logs. |
| Authentication data | Usernames, authentication records and multi-factor authentication-related information. Passwords and secrets should be handled only through approved secure systems. |
| Business data | Documents, emails, calendars, contacts, support tickets, notes and files. |
| Financial data | Invoicing contact information and payment references. |
| Usage data | Service usage records, audit trails, activity logs, access history and device-management records. |
A7. Special Category and Criminal Offence Data
The Services are not intended routinely to process Special Category Data or criminal offence data. Such data may nevertheless be present within systems, communications or content administered on behalf of the Controller.
The Controller is responsible for ensuring an appropriate lawful basis and any additional condition for processing. The Processor shall apply the protections in this Addendum to such data and shall access it only where reasonably necessary to provide the Services.
A8. Categories of Approved Subprocessors
The Processor may engage subprocessors in the following categories:
- cloud infrastructure, productivity and collaboration providers;
- identity and access management providers;
- backup and recovery providers;
- documentation, knowledge and configuration management providers;
- service management, ticketing and automation providers;
- remote support, monitoring and device-management providers;
- security, filtering and vulnerability-management providers;
- software licensing, procurement and distribution providers;
- communications and connectivity providers; and
- professional advisers and specialist technology contractors where required to provide the Services.
A9. International Transfers
Personal Data may be accessed or transferred outside the United Kingdom where required to provide the Services, but only in accordance with clause 6 and applicable Data Protection Laws.
A10. Technical and Organisational Measures
Measures appropriate to the relevant Services and risk may include:
Access controls
- least-privilege access;
- role-based permissions;
- joiner, mover and leaver processes;
- periodic review of privileged access.
Authentication controls
- multi-factor authentication;
- password and secure credential-management controls;
- privileged access controls.
Data protection controls
- encryption in transit;
- encryption at rest where supported;
- secure disposal and retention procedures.
Security controls
- endpoint protection;
- vulnerability and patch management;
- security monitoring and audit logging;
- incident-management and breach-response procedures.
Organisational and governance controls
- staff training and confidentiality obligations;
- documented operational and security procedures;
- supplier risk-management processes;
- business continuity and recovery arrangements appropriate to the Services.



