1. Roles and scope
For personal data that Cwlwm Systems processes on Client's behalf to provide contracted services (“Client Personal Data”), Client determines the business purpose and permitted use of the data, and Cwlwm Systems processes the data only as reasonably necessary to provide the contracted services and follow Client's documented instructions.
These terms do not apply to ordinary business contact information that Cwlwm Systems processes for its own account-management, invoicing, security, or legal purposes; that information is handled under the Privacy Policy.
2. Processing instructions
The applicable SOW, Client configuration choices, authorized support requests, and written project instructions form the documented processing instructions. Cwlwm Systems will not materially expand the purpose of processing Client Personal Data without Client authorization unless required by law.
3. Client responsibilities
Client is responsible for determining that it has a lawful basis and appropriate notices, permissions, consents, and authority to provide Client Personal Data for the agreed processing. Client will not instruct Cwlwm Systems to process data in a manner that Client knows violates applicable law.
4. Confidentiality
People authorized to process Client Personal Data for Cwlwm Systems will be subject to confidentiality obligations appropriate to their role. Access will be limited to what is reasonably necessary to provide or support the contracted service.
5. Security measures
Cwlwm Systems will apply reasonable technical and organizational measures appropriate to the nature of the project and data, which may include access controls, encrypted transport, credential and secret management, environment separation, logging, backups where in scope, and vulnerability or dependency maintenance. General security principles are described on the Security page; project-specific requirements must be stated in the SOW when they are material to the engagement.
6. Subprocessors
Client authorizes Cwlwm Systems to use third-party service providers reasonably necessary to deliver the contracted service, subject to appropriate data-protection obligations. Depending on the project, these may include cloud hosting, database, email, monitoring, source-control, AI, analytics, or other infrastructure providers.
For the public website, current infrastructure is designed around Vercel for hosting and may use Resend for contact-form email delivery when enabled. Project-specific subprocessors and data flows should be identified during project scoping when they materially process Client Personal Data.
7. Assistance with individual rights
Taking into account the nature of the processing, Cwlwm Systems will provide reasonable assistance when Client needs information or technical action to respond to a valid request from an individual concerning Client Personal Data. Client remains responsible for evaluating and responding to the request unless applicable law assigns a different responsibility.
8. Security incidents
If Cwlwm Systems confirms unauthorized access to or acquisition, alteration, loss, or disclosure of Client Personal Data within Cwlwm Systems' responsibility that reasonably constitutes a reportable personal-data incident, Cwlwm Systems will notify Client without undue delay and provide reasonably available information needed to understand the nature and scope of the incident.
Notice of an incident is not an admission of fault or liability. Client is responsible for determining any notification obligations that apply to Client unless the parties agree otherwise.
9. Deletion and return
At the end of the applicable services, Cwlwm Systems will, upon reasonable request and subject to the technical design of the project, return or delete Client Personal Data within Cwlwm Systems' control unless retention is required by law, necessary for legitimate dispute or security records, or temporarily present in protected backups that are not reasonably accessible for ordinary use and will expire under normal retention cycles.
10. Audits and information requests
Cwlwm Systems will provide information reasonably necessary to demonstrate compliance with these terms. If a Client has a legal requirement for additional assessment, the parties will first try to satisfy it through existing documentation, architecture information, or written responses. Any on-site or intrusive audit must be reasonably scoped, protect other clients and confidential systems, occur no more than once annually absent a verified incident or legal requirement, and be scheduled with reasonable advance notice.
11. International transfers
Project infrastructure may process data in the United States or other locations supported by the selected service providers. If applicable law requires a particular cross-border transfer mechanism or data-residency commitment, that requirement must be identified and agreed before the relevant processing begins.
12. Conflicts
For data-protection matters, a separately signed DPA or data-protection provision in an SOW controls over these published terms to the extent of a direct conflict. The remainder of the Service Agreement continues to apply.
Questions
Questions about this document can be sent to kasey@cwlwmsystems.com.
