Data processing terms
1. Application and roles
These Data Processing Terms apply when a business customer is controller of personal data processed by FoundBefore on its behalf. The customer is controller and FoundBefore is processor for that customer data. Each party remains independently responsible for data it controls for its own purposes.
2. Instructions and purpose
FoundBefore processes customer personal data only to provide, secure, support and improve the contracted service according to documented customer instructions, the agreement and applicable law. An instruction that appears unlawful may be paused while the parties clarify it.
3. Confidentiality and security
Personnel and subprocessors with access are bound by confidentiality and least-privilege requirements. Technical and organisational measures include authentication, role enforcement, tenant isolation, consent-controlled disclosure, encryption where specified, logging, rate limits, incident handling and recovery procedures.
4. Subprocessors
The customer authorises providers needed for hosting, authentication, storage, transactional email, monitoring and support. Current categories are described in the Privacy Notice and operational documentation. FoundBefore remains responsible for processor obligations delegated to a subprocessor and will provide notice of material changes where required.
5. International transfers
Restricted transfers will use a lawful mechanism appropriate to the destination and parties, including adequacy decisions or approved contractual clauses where applicable. The customer will provide information reasonably needed to assess the transfer.
6. Assistance
Taking account of the processing, FoundBefore will reasonably assist with data-subject requests, security assessments, breach obligations, impact assessments and regulator enquiries. Assistance beyond standard product controls may be chargeable under a B2B order form unless caused by FoundBefore's breach.
7. Incidents
FoundBefore will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will provide available information needed for the customer's legal duties. Notice is not an admission of fault.
8. Return, deletion and audit
During the term, the customer may use available export controls. On termination, customer data is returned or deleted according to the agreement, recovery period and lawful retention duties. FoundBefore will provide reasonable compliance information; audits must protect other customers, security and confidentiality.
9. Contact and precedence
Data-processing questions may be sent to office@foundbefore.com. If these terms conflict with a signed DPA or order form, the signed document controls. These terms are not effective for commercial processing until the operator identity and legal approval are complete.