This Data Protection Addendum together with its Schedules ("DPA") is part of Breww's Terms of Service, or other written or electronic agreement between Breww and the Customer ("You"), as amended or supplemented from time to time, all together forming the "Agreement".

In this DPA, references to "Services" shall have the same meaning as set out in the Terms of Service.

Where there is any conflict between the terms of this DPA and any other part of the Agreement, the following order of precedence shall apply: (1) this DPA; and (2) any other part of the Agreement.

Agreement

Definitions

  1. In this DPA, the following words are defined:
    1. Addendum: The International Data Transfer Addendum to the New Standard Contractual Clauses (as amended or updated from time to time).
    2. Affiliate: Any entity that directly or indirectly controls, or is controlled by, or is under common control with the subject entity. "Control" for the purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
    3. Data Protection Law:
      1. All laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland and the United Kingdom applicable to the Processing of Personal Data under the Agreement, including, but not limited to EU Directive 95 /46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR; and
      2. to the extent applicable, the data protection or privacy laws of any other country.
    4. GDPR:
      1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the EU GDPR); and
      2. the EU GDPR as implemented or adopted under the laws of the United Kingdom (UK GDPR) (General Data Protection Regulation).
    5. New Standard Contractual Clauses: Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (Text with EEA relevance), as may be replaced or superseded by the European Commission.
    6. Personnel: In relation to a party, those of its employees, workers, agents, consultants, contractors, sub-contractors, representatives or other persons employed or engaged by that party on whatever terms.
    7. Sub-processor: Any entity (whether or not an Affiliate of Breww Ltd, but excluding Breww Ltd’s Personnel) appointed by or on behalf of Breww Ltd to process Personal Data on behalf of the Customer under this DPA.
    8. Working Day: Any day, other than a Saturday, Sunday, or public holiday in England and Wales.
  2. Terms such as “Data Subject”, “Processing”, “Personal Data”, “Controller”, and “Processor”, "Supervisory Authority" and "Personal Data Breach" shall have the same meaning as ascribed to them in the Data Protection Law.
  3. In this DPA unless the context requires a different interpretation:
    1. the singular includes the plural and vice versa;
    2. references to sub-clauses, clauses, schedules or appendices are to sub-clauses, clauses, schedules or appendices of this DPA;
    3. a reference to a person includes firms, companies, government entities, trusts ad partnerships;
    4. "including" is understood to mean "including without limitation";
    5. reference to any statutory provision includes any modification or amendment of it;
    6. the headings and sub-headings do not form part of this DPA; and
    7. "writing" or "written" will include fax and email unless otherwise stated.

Processing Customer Personal Data

  1. For the purpose of Data Protection Law, the Customer shall be the Controller and Breww Ltd (the Supplier) shall be the Processor.
  2. Breww Ltd and each Supplier Affiliate shall:
    1. comply with all applicable Data Protection Law in the Processing of Customer Personal Data; and
    2. only Process Personal Data on the Customer's documented instructions, unless Processing is required by any applicable law to which Breww Ltd is subject (in which case, Breww Ltd shall, to the extent permitted by applicable law, inform the Customer of such legal requirement before undertaking the Processing).
  3. Breww Ltd and each Supplier Affiliate shall take reasonable steps to ensure the reliability of Personnel who have access to the Personal Data, ensuring in each case that such Personnel is subject to a strict duty of confidentiality (whether a contractual or statutory duty) and that they Process the Personal Data in compliance with all applicable law and only for the purpose of delivering the Services under the Agreement.

Security

  1. Breww Ltd will establish data security in relation to the Processing of Personal Data under this DPA. The measures to be taken must guarantee a protection level appropriate to the risk concerning confidentiality, integrity, availability and resilience of the systems. The state of the art, implementation costs, the nature, scope and purposes of the Processing, as well as the probability of occurrence and the severity of the risk to the rights and freedoms of natural persons must be taken into account. Such measures may include, as appropriate:
    1. the pseudonymisation and encryption of Personal Data;
    2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
    3. the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and
    4. a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the Processing.
  2. In assessing the appropriate level of security, Breww Ltd shall take into account any risks that are presented by the Processing, in particular, from a Personal Data Breach.
  3. Breww Ltd has laid down the technical and organisational measures in Schedule 2 of this DPA. Technical and organisational measures are subject to technical progress and further development. In this respect, the Processor may implement alternative adequate measures from time to time and shall notify the Customer in writing where it has done so.

Sub-Processors

  1. The Customer authorises Breww Ltd and each Supplier Affiliate to appoint the Sub-processors listed in Schedule 3 (if any) and any new Sub-processors in accordance with the subsequent provisions.
  2. With respect to each Sub-processor, Breww Ltd, or the Supplier Affiliate shall:
    1. carry out appropriate due diligence prior to the Processing by such Sub-processor to ensure that the Sub-processor is capable of providing the level of protection for Personal Data required by the terms of the Agreement and this DPA; and
    2. enter into a written agreement with the Sub-processor incorporating terms which are substantially similar (and no less onerous) than those set out in this DPA and which meet the requirements of Article 28(3) of UK GDPR.
  3. Breww Ltd and each Supplier Affiliate may continue to use Sub-processors already engaged by Breww Ltd or Supplier Affiliate as at the date of this DPA subject to Breww Ltd or Supplier Affiliate meeting the obligations set forth in the preceding clause as soon as reasonably practicable.

Data Subject Rights

  1. Taking into account the nature of the Processing, Breww Ltd and each Supplier Affiliate shall assist the Customer in implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising Data Subjects" rights under the Data Protection Law.
  2. Breww Ltd shall:
    1. promptly notify the Customer if it (or any of its Sub-processors) receives a request from a Data Subject; and
    2. fully cooperate with and assist the Customer in relation to any request made by a Data Subject, under the Data Protection Law in respect of Personal Data Processed by Breww Ltd under the terms of the Agreement or this DPA.

Personal Data Breaches

  1. Breww Ltd shall:
    1. notify the Customer without undue delay upon becoming aware of any Personal Data Breach affecting the Personal Data Processed by Breww Ltd under this DPA;
    2. provide sufficient information to enable the Customer to evaluate the impact of such Personal Data Breach and to meet any obligations on the Customer to report the Personal Data Breach to a Supervisory Authority and/or notify the affected Data Subjects in accordance with the Data Protection Law;
    3. provide the Customer with such assistance as the Customer may reasonably request; and
    4. cooperate with the Customer and take such reasonable commercial steps (as directed by the Customer) to assist in the evaluation, investigation, mitigation and remediation of each such Personal Data Breach.

Data Protection Impact Assessment and Prior Consultation

  1. Breww Ltd and each Supplier Affiliate shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities or other competent authorities which the Customer considers necessary pursuant to Articles 35 and 36 of the UK GDPR.
  2. Such assistance from Breww Ltd shall be limited, in each case, to the Processing of Personal Data under this DPA.

Return and Deletion of Personal Data

  1. Breww Ltd (and its Sub-processors) may retain Personal Data Processed under this DPA to the extent required by any applicable law to which Breww Ltd (or any Sub-processor) is subject and only to the extent and for such period as required by applicable law. Where applicable, Breww Ltd shall notify the Customer of any such requirement and ensure the confidentiality of such Personal Data. Any Personal Data Processed under this DPA and retained by Breww Ltd (or any Sub-processor) in accordance with this clause shall be not Processed for any other purpose other than the purpose specified in the applicable laws.
  2. The Customer may require Breww Ltd to provide written certification confirming that it has complied in full with its obligations under this section entitled "Return and deletion of personal data."

Restricted Transfers

  1. For the purposes of this section entitled "Restricted transfers", a "Restricted Transfer" is an onward transfer of Personal Data from Breww Ltd (or a Sub-Processor) to a Sub-Processor, in each case, where such transfer would be prohibited by Data Protection Law in the absence of the New Standard Contractual Clauses and the Addendum.
  2. Subject to the subsequent clause, Breww Ltd (the "data exporter") and/or each Sub-processor as appropriate (the "data importer"), will enter into module 3 of the New Standard Contractual Clauses and the Addendum in respect of any Restricted Transfer.
  3. The preceding clause shall not apply to a Restricted Transfer unless its effect, together with other reasonably practical compliance steps (which do not include obtaining consent from Data Subjects) is to allow the Restricted Transfer to take place without breach of applicable Data Protection Law.

Liability

  1. The total liability of either party to the other for any non-compliance with this DPA shall be subject to any limitation regarding monetary damages set forth in the Agreement.

General Terms

  1. Except in respect of any provision of this DPA that expressly or by implication is intended to come into or continue in force on or after the expiry or termination of the Agreement, this DPA shall be coterminous with the Agreement.
  2. No party may assign, transfer or sub-contract to any third party the benefit and/or burden of the DPA without the prior written consent (not to be unreasonably withheld) of the other party.
  3. No variation of the DPA will be valid or binding unless it is recorded in writing and agreed by or on behalf of both parties.
  4. No variation of the Agreement will be valid or binding unless it is recorded in writing and agreed by or on behalf of both parties.
  5. The Contracts (Rights of Third Parties) Act 1999 does not apply to the DPA and no third party has any right to enforce or rely on any provision of the DPA.
  6. Unless otherwise agreed, no delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of that, or any other, right or remedy.
  7. If any court or competent authority finds that any provision (or part) of the DPA is invalid, illegal or unenforceable, that provision or part-provision will, to the extent required, be deemed to be deleted, and the validity and enforceability of the other provisions of the DPA will not be affected.
  8. Any notice (other than in legal proceedings) to be delivered under the DPA must be in writing and delivered by pre-paid first class post to or left by hand delivery at the other party’s registered address or place of business. Notices:
    1. sent by post will be deemed to have been received, where posted from and to addresses in the United Kingdom, on the second Working Day and, where posted from or to addresses outside the United Kingdom, on the tenth Working Day following the date of posting;
    2. delivered by hand will be deemed to have been received at the time the notice is left at the proper address; and

Governing Law and Jurisdiction

  1. This DPA will be governed by and interpreted according to the law of England and Wales and all disputes arising under the DPA (including non-contractual disputes or claims) shall be subject to the exclusive jurisdiction of the English and Welsh courts.

Schedule 1 - Processing Activities

This Schedule 1 includes certain details of the Processing of Personal Data as required by Article 28(3) UK GDPR. The subject matter and duration of the Processing of the Personal Data are set out in the Agreement and this DPA.

The nature and purpose of the Processing of Personal Data

Breww Ltd will Process Personal Data as necessary to provide the Services pursuant to the Agreement, and as further instructed by the Customer in its use of the Services.

The types of Personal Data to be Processed

The Customer may submit Personal Data to the Services, the extent of which, is determined and controlled by the Customer in its sole discretion, and which may include, but is not limited to the following types of Personal Data:

  • Personal details

The categories of Data Subject to whom the Personal Data relates

The Customer may submit Personal Data to the Services, the extent of which is determined and controlled by the Customer in its sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of Data Subjects:

  • Staff, including volunteers, temporary and casual workers Customers (including their staff)
  • Clients (including their staff)
  • Suppliers (including their staff)

The obligations and rights of Customer and Customer Affiliates

The obligations and rights of the Customer (and any Customer Affiliates) are set out in the Agreement and this DPA.

Schedule 2 - Technical and Organisational Measures

Breww Ltd will conduct the activities covered by this DPA in compliance with its Information Security Policy, available from the Data Protection Officer or another person responsible for data protection compliance and online at https://breww.com/legals/security-policy, and relevant data protection policies and guidance, available from the Data Protection Officer or another person responsible for data protection compliance.

Schedule 3 - Sub-Processors

The Customer agrees that Breww Ltd may sub-contract certain obligations under this DPA to the following Sub-processors:

Name Website Sub-contracted activities
DigitalOcean https://www.digitalocean.com Data storage and provision of cloud servers
Google Cloud https://cloud.google.com Data storage and provision of cloud servers
Cloudflare https://www.cloudflare.com Data storage and proxying of traffic
Stripe https://www.stripe.com Payment processing
Despatch Cloud https://despatchcloud.com Courier label generation
Twilio https://www.twilio.com SMS message sending partner
HubSpot https://www.hubspot.com CRM platform used by Breww for our own sales team activities