Data Protection Addendum
In the event of any conflict between the terms of this DPA and the main body of the Agreement, the terms of this DPA will prevail to the extent of such conflict, but only in relation to the processing of personal data.
Intra Pricing Solutions’ Privacy Policy, available at https://intrapricing.com/legal/privacy-policy/, describes how Intra Pricing Solutions collects and may use personal data as a controller (for example, Client Contact Information, website interactions and marketing communications). The Privacy Policy does not apply to Client Data processed by Intra Pricing Solutions as a processor under this DPA.
Both parties acknowledge that the Terms of Service and this DPA are intended to comply with applicable privacy and data protection requirements in the United Kingdom, the European Union, and other jurisdictions in which Intra Pricing Solutions provides services or the Client operates.
1. Definitions
Defined terms from the Terms of Service shall carry the same meaning in this DPA. In addition, the following terms shall bear the following meanings:
Applicable Data Protection Law means all data protection and privacy laws applicable to the processing of personal data under the Agreement, including the UK GDPR, EU GDPR, the Data Protection Act 2018, the Dutch Uitvoeringswet Algemene verordening gegevensbescherming (UAVG), and any other applicable global privacy legislation, in each case as amended, supplemented or replaced from time to time.
Client Contact Information means personal business contact details of identified Client employees used for the purposes of the Services, such as sales, marketing, Professional Services, and support.
Information Security Incident means an occurrence that results in actual or potential jeopardy to the confidentiality, integrity, or availability of an information system or the information system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or applicable Acceptable Use Policies.
The terms Data Controller, Data Processor, Data Subject, Personal Data and processing shall have the same meanings given in the Applicable Data Protection Law.
2. Relationship and Roles
- Intra Pricing Solutions acts as a Data Controller of Client Contact Information for legitimate business purposes such as account administration, billing and customer support.
- Intra Pricing Solutions acts as a Data Processor (or subprocessor, as applicable) of Client Data processed in connection with hosted or cloud Services.
- For self-hosted Services, the Client is solely responsible for the processing and security of any Client Data stored or processed within its own environment.
- Annex 1 sets out the scope, nature and purpose of processing by Intra Pricing Solutions, the duration of the processing and the types of personal data and categories of data subject.
- Personal Data may be transferred or stored outside the UK or EEA or the country where the Client and the Users are located in order to carry out the Services and Intra Pricing Solutions’ other obligations under the Agreement.
3. Categories of Data and Processing
| Data Type | Intra Pricing Solutions Role | Purpose of Processing | Example of Processing Activities |
| Client Contact Information | Controller | Account management, billing, service notifications | Storing contact details, sending account updates |
| Client Data (input via the applicable Services) | Processor | Provision of hosted and/or cloud Services | Hosting, storage, maintenance and technical support |
Intra Pricing Solutions does not require or intend to process any special category data such as health, biometric, racial or ethnic origin data under the Agreement.
4. Data Protection Obligations
- Both parties will comply with the requirements of the Applicable Data Protection Law as applicable to the provision and use of the Services.
- The Client, as Data Controller, shall ensure that it has in place all necessary and appropriate consents, notices or other lawful bases to enable the lawful transfer of Personal Data to Intra Pricing Solutions for processing under the Agreement.
- Intra Pricing Solutions will:
- Process Personal Data only on the documented instructions of the Client;
- In processing Personal Data, comply with its Privacy Policy available on the Website;
- Ensure that persons authorised to process Personal Data are under confidentiality obligations;
- Implement appropriate technical and organisational measures to protect Personal Data in accordance with Article 32 UK/EU GDPR (or equivalent);
- Assist the Client, insofar as possible and at the Client’s cost, with fulfilling its obligations regarding Data Subject rights, data breach notifications and DPIAs;
- Promptly (and in any event, within 72 hours) notify the Client upon becoming aware of any actual or suspected personal data breach or Information Security Incident and provide sufficient information to assist the Client in meeting its legal obligations;
- Delete (or otherwise put beyond use) Personal Data upon termination of the Agreement, except as required by Applicable Data Protection Law to store such Client Data; and
- Not transfer Client Data outside the UK/EEA unless in compliance with Applicable Data Protection Law (e.g. adequacy decisions or approved SCCs) and the following conditions are fulfilled: (i) Intra Pricing Solutions has provided appropriate safeguards in relation to the transfer which for the avoidance of doubt can include third party software-as-a-service applications; (ii) the data subject has enforceable rights and effective legal remedies; (iii) Intra Pricing Solutions complies with its obligations under the Applicable Data Protection Law by providing an adequate level of protection to any Personal Data that is transferred; and (iv) Intra Pricing Solutions complies with reasonable instructions notified to it in advance by the Client with respect to the processing of the Personal Data.
- Intra Pricing Solutions shall follow its backup procedures for Client Data as set out at https://intrapricing.com/legal/data-security/ or such other web address notified by Intra Pricing Solutions to the Client from time to time, and such document may be amended by Intra Pricing Solutions in its sole discretion from time to time (“Backups”). In the event of any loss or damage to Client Data, the Client’s sole and exclusive remedy against Intra Pricing Solutions shall be for Intra Pricing Solutions to use reasonable commercial endeavours to restore the lost or damaged Client Data from the latest backup of such Client Data maintained by Intra Pricing Solutions in accordance with the archiving procedure described in its Backups procedure as set out in https://intrapricing.com/legal/data-security/ or such other web address notified by Intra Pricing Solutions to the Client from time to time. Intra Pricing Solutions shall not be responsible for any loss, destruction, alteration or disclosure of Client Data caused by any third party (except those third parties sub-contracted by Intra Pricing Solutions to perform services related to Client Data maintenance and backups for which it shall remain fully liable under section 5 of this DPA).
- Intra Pricing Solutions will be responsible for the safe storage, security, use and disposal of the Client Data, subject to the following limitations: (i) The terms of UK/EU GDPR will be used to determine the classification of Client Data held and the procedures regarding its storage and disposal; (ii) Re-use of Client Data will be limited to the provision of tax benchmarks and risk metrics and Intra Pricing Solutions may use the Client Data held, suitably redacted, to support analytical processes that benefit Intra Pricing Solutions’ whole client base; and (iii) The option to prohibit the use of Client Data for analytical and statistical purposes may be enacted within certain Services; this will remove the option to benefit from the analytical capabilities of Intra Pricing Solutions’ data set.
5. Subprocessors
- Intra Pricing Solutions may engage subprocessors to support the provision of the Services.
- A current list of subprocessors is available on the Website at https://intrapricing.com/legal/data-security/.
- Intra Pricing Solutions will ensure that subprocessors are bound by written terms offering at least the same level of protection as required by this DPA.
- Intra Pricing Solutions will notify the Client of material changes to subprocessors giving the Client an opportunity to object on reasonable grounds, such objection shall not be unreasonably withheld.
- The Client consents to (and authorises) Intra Pricing Solutions appointing the third-party processors listed on the Website in its sole discretion as third-party processors of Personal Data under the Agreement.
- As between the Client and Intra Pricing Solutions, Intra Pricing Solutions shall remain fully liable for all acts or omissions of any third-party processor appointed by it.
6. Security
See https://intrapricing.com/legal/data-security/ or such other web address notified by Intra Pricing Solutions to the Client from time to time.
7. Assistance with Regulation (EU) 2022/2554 (DORA) and Regulation (EU) 2023/2854 (Data Act)
- Intra Pricing Solutions recognises the applicability of DORA and the Data Act and commits to:
- Operational resilience. Implementing and maintaining resilient systems and incident response mechanisms aligned with DORA requirements relevant to its supply chain.
- Cooperation. Providing reasonable assistance to regulated clients to support their compliance with DORA obligations, including data availability and reporting requirements.
- Data portability and access. Ensuring that Intra Pricing Solutions’ solutions allow clients to extract their own information.
- Transparency. Maintaining clear documentation on data locations and subprocessors.
8. Audits and Compliance
See https://intrapricing.com/legal/data-security/ or such other web address notified by Intra Pricing Solutions to the Client from time to time.
9. Liability
Liability for breaches of this DPA shall be subject to the limitations and exclusions set out in the Agreement, except where prohibited by Applicable Data Protection Law.
10. Governing Law
This DPA shall be governed by and construed in accordance with the governing law set out in the Agreement, provided that such law shall not restrict the rights or remedies of data subjects under Applicable Data Protection Law.
Annex 1: Processing, Personal Data and Data Subjects
Subject matter of Processing
Intra Pricing Solutions shall process Personal Data in order to provide the Services under the Agreement. This will include any information that may be contained within tax records that the Client chooses to upload to the Platform in order for Intra Pricing Solutions to support the Client in using the Services.
A basic level of Personal Data is required for Intra Pricing Solutions’ products and services, including name, business email address and phone number of the User. Personal Data may also be supplied if the Client requests support.
Data processing around AI Functionality, if any, is conducted by the third-party AI providers selected by Intra Pricing Solutions.
Duration of the Processing
For the duration of the Term and thereafter until deletion in accordance with section 4(c)(vii) of this DPA, Intra Pricing Solutions shall process the Personal Data in accordance with this DPA.
Nature and purpose of the Processing
Intra Pricing Solutions will process Personal Data for the purposes of providing the Services to the Client in accordance with the Agreement.
Categories of Personal Data
Data relating to Data Subjects provided to Intra Pricing Solutions in the course of the Services, by (or at the direction of) the Client, another third party or by Data Subjects, where the processing is to be undertaken on the Client’s behalf. Examples of Personal Data include personally identifiable information specified in a corporate tax return.
Categories of Data Subjects
Data Subjects include the individuals about whom data is provided to Intra Pricing Solutions in the course of the Services, by (or at the direction of) the Client, another third party or by Data Subjects, where the processing is to be undertaken on the Client’s behalf.
Locations of Processing
A current list of subprocessors is available on the Website at https://intrapricing.com/legal/data-security/ or such other web address notified by Intra Pricing Solutions to the Client from time to time.