01Application and particulars
This schedule applies only when incorporated into an accepted order and completed with the processing particulars. The Customer is the controller, or a processor authorised by its controller; Huberway acts as processor or subprocessor for the contracted processing. Each party must comply with the data-protection law applicable to its role.
Before processing starts, the parties must record the subject matter and duration; nature and purpose; categories of individuals and personal data; permitted instructions; processing and backup countries; security measures; authorised subprocessors; deletion and return periods; and any international-transfer arrangement. Special-category data is excluded unless expressly agreed with the necessary safeguards. An unsigned or incomplete schedule does not represent that these deployment details have been settled.
02Instructions and confidentiality
Huberway shall process personal data only on documented lawful instructions, including for international transfers, unless applicable law requires otherwise. In that case Huberway shall inform the Customer before processing unless the law prohibits notice. Huberway shall promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.
Huberway shall restrict access to authorised persons bound by confidentiality and implement documented technical and organisational measures appropriate to the processing risk. The signed security schedule must describe access control, encryption where applicable, resilience, restoration, monitoring and testing; these general terms do not substitute for that schedule.
03Subprocessor authorisation
Subprocessors require the Customer’s specific written authorisation or general written authorisation with advance notice of changes and an opportunity to object on reasonable data-protection grounds. Huberway shall impose equivalent relevant obligations and remain responsible for the subprocessor’s performance of those obligations. The parties must resolve an objection before the disputed processing proceeds.
04Assistance and incidents
Huberway shall assist the Customer, taking account of the processing and available information, with data-subject requests, security obligations, incident response, impact assessments and supervisory-authority consultations. It shall notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, provide available relevant details and supplement them as investigations progress. This does not replace the Customer’s own statutory reporting deadlines.
05Accountability and audits
Huberway shall make available information necessary to demonstrate compliance and allow audits by the Customer or an independent auditor subject to reasonable confidentiality and security arrangements. Routine audits should use existing evidence where sufficient; restrictions must not prevent an audit required by applicable law or a competent authority. Costs for unusual assistance may be agreed where lawful, without delaying mandatory cooperation.
06Return, deletion and transfers
At the Customer’s choice, Huberway shall return or delete the personal data at the end of the service and delete existing copies unless applicable law requires retention. The completed schedule must address export format, active-system deletion, backup cycles and legal holds. Retained copies remain protected and may not be used for unrelated purposes.
Where GDPR Article 28 applies, this schedule must be interpreted consistently with that Article. For restricted international transfers, the parties must execute the appropriate approved clauses with completed annexes and any necessary supplementary measures. This page does not itself constitute executed Standard Contractual Clauses or a UK transfer addendum.