This Data Processing Agreement ("DPA") applies where EagleHQ processes personal data on behalf of a client (the "Controller") in the course of providing the Services, and forms part of our Terms of Service. Where applicable data protection law (including the GDPR and UK GDPR) requires it, this DPA governs that processing.
Roles
For personal data submitted through the sites and tools we host — such as booking and customer details — the client is the Controller and EagleHQ is the Processor. For our own account and billing data, EagleHQ is the Controller (see our Privacy Policy).
Our obligations as processor
- Process personal data only on the client's documented instructions, including for transfers, unless required by law.
- Ensure people authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see our Security statement).
- Assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach notification, and impact-assessment obligations.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the Services, except where retention is required by law.
- Make available information reasonably necessary to demonstrate compliance and allow for audits consistent with applicable law.
Subprocessors
The Controller authorizes EagleHQ to engage the subprocessors listed on our Subprocessors page. We impose data-protection obligations on each subprocessor no less protective than those in this DPA and remain responsible for their performance. We will give notice of intended changes and a chance to object.
International transfers
Where personal data is transferred across borders, we rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses) as required by applicable law.
Contact
To request a countersigned copy of this DPA or ask questions, email hello@eaglehq.us.