Data Protection Addendum

Data Protection Addendum & Processor Terms under UK GDPR Article 28 for Recept IO.

This Data Protection Addendum (DPA) applies to the processing of personal data by 4TH PARTNER LIMITED trading as Recept IO (Recept IO, processor, we, us) on behalf of our law firm customer (Customer, controller, you) in connection with the Recept IO platform and website intake agent (the Platform).

1. Definitions

1.1 Controller, Processor, Personal Data, Data Subject, Personal Data Breach, Processing and Supervisory Authority have the meanings given in UK Data Protection Law.

1.2 UK Data Protection Law means UK GDPR (Data Protection Act 2018), Privacy and Electronic Communications Regulations (PECR), and related rules.

1.3 Customer Personal Data means Personal Data processed by Recept IO on behalf of the Customer through the Platform as specified in Annex 1.

2. Roles of the parties

2.1 The parties acknowledge that Customer is the Controller and Recept IO is the Processor of Customer Personal Data. Customer is responsible for establishing a lawful basis for processing, providing privacy notices to prospective clients, and ensuring instructions given to Recept IO comply with applicable data protection laws.

3. Processing instructions

3.1 Recept IO shall process Customer Personal Data only on the Customer's documented instructions (including as necessary for the performance of the service under our Platform Terms and Conditions), unless required to do so by applicable laws, in which case Recept IO shall inform Customer unless prohibited from doing so on public interest grounds.

3.2 Customer's documented instructions are defined by the Platform features and settings chosen by Customer.

4. Confidentiality of personnel

4.1 Recept IO ensures that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security measures

5.1 Recept IO shall implement technical and organizational measures appropriate to ensure a level of security appropriate to the risk, including encryption in transit and at rest, access controls, and regular vulnerability monitoring.

6. Sub-processors

6.1 Customer grants general authorization for Recept IO to engage sub-processors (such as cloud host infrastructure, database providers, and API communication services). A list of current sub-processors is available upon request.

6.2 Recept IO shall impose data protection obligations on any sub-processor that are no less protective than those set out in this DPA, and shall remain liable for sub-processor compliance.

7. Incident management and assistance

7.1 Recept IO shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and shall provide reasonable assistance to Customer in responding to data subject requests and regulatory notifications.

8. Deletion or return of data

8.1 Upon termination of the agreement or upon request, Recept IO shall delete or return Customer Personal Data, except to the extent required by applicable law to retain copies.