Roles of the parties

[Counsel to complete: identify the client as controller and TryEntitle as processor, and address any scenario where TryEntitle acts as an independent controller.]

Scope, nature, and duration of processing

[Counsel to complete: subject matter, duration, nature and purpose of processing, types of personal data, and categories of data subjects — typically an annex. Note that engagements in healthcare, legal, insurance, and accounting may involve special-category or otherwise regulated data, which must be addressed explicitly.]

Processor obligations

[Counsel to complete: processing only on documented instructions, confidentiality obligations of personnel, and assistance with data subject requests.]

Subprocessors

[Counsel to complete: authorisation for subprocessors, the notification process for changes, and flow-down obligations. The list must stay consistent with the Privacy Policy and Security page.]

Security measures

[Counsel to complete: the technical and organisational measures actually implemented — normally an annex. Must match the Security page exactly; a mismatch between the two is a contractual problem.]

International transfers

[Counsel to complete: the transfer mechanism relied on (for example, Standard Contractual Clauses or the UK addendum) and the countries involved.]

Deletion or return on termination

[Counsel to complete: what happens to personal data at the end of the engagement, the timeframe, and any retention required by law.]

Audit rights

[Counsel to complete: audit and information rights, including notice periods and any limits on frequency.]

Breach notification

[Counsel to complete: the notification timeframe to the controller and the information provided. Must be consistent with the incident response commitment on the Security page.]