Data Processing Addendum
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between AvdControl ("Processor", "we", "us") and the customer organisation ("Customer", "Controller") and applies whenever we process personal data on the Customer's behalf through AvdControl.
By accepting the Terms you accept this DPA, so no signature is needed for it to take effect. If your procurement process requires a countersigned copy, or your own template, email [email protected] and we will arrange it.
"Data Protection Law" means all laws applicable to the processing, including the UK GDPR and Data Protection Act 2018, the EU GDPR where applicable, and UAE Federal Decree-Law No. 45 of 2021. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in that law.
1. Roles of the parties
The Customer is the controller and AvdControl is the processor in respect of personal data within the Customer's tenant, including data about the Customer's staff, contractors and Azure Virtual Desktop end users. The Customer determines the purposes and means of that processing, is responsible for the lawfulness of its instructions, and confirms it has provided all notices and has a lawful basis for the processing, including any monitoring of its personnel.
AvdControl is an independent controller for the limited data described in the Privacy Policy as controller data, such as billing contacts, website visitors, sales enquiries, and the security and service logs it needs to run and protect the platform.
2. Subject matter and details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the AvdControl hosted console for Azure Virtual Desktop, and related support |
| Duration | For the term of the Terms, plus the deletion period in section 10 |
| Nature and purpose | Hosting, storing, transmitting, displaying, backing up, collecting from the Customer's Azure environment, logging, and supporting — solely to provide, secure and support the service |
| Categories of data subject | The Customer's administrators, service desk agents and other portal users; Azure Virtual Desktop end users whose sessions appear in the console; the Customer's support requesters |
| Categories of personal data | Names, work email addresses, roles, authentication and multi-factor data, single sign-on identifiers, user principal names, session metadata (host, state, idle and input times), audit records including IP addresses, and support ticket content and attachments |
| Special category data | None. The service is not designed for it and the Customer must not submit it |
| Frequency | Continuous for the duration of the service |
3. Processing only on instructions
AvdControl will process personal data only in accordance with the Terms, this DPA, the Customer's use of the service, and any other documented instruction the parties agree. AvdControl will not process personal data for its own purposes, will not sell it, and will not use it to train generally available machine learning models. AvdControl may process personal data where required by law, and will inform the Customer of that requirement unless legally prohibited.
If AvdControl considers an instruction to infringe Data Protection Law, it will tell the Customer without undue delay and may suspend performance of that instruction. AvdControl may generate and use aggregated or de-identified information about use of the service as described in the Terms.
4. Personnel and confidentiality
AvdControl limits access to personal data to those personnel who need it to provide or support the service, ensures they are bound by confidentiality obligations that survive the end of their engagement, requires multi-factor authentication for privileged access, and records privileged actions taken inside a tenant in that tenant's audit trail.
5. Security measures
AvdControl implements technical and organisational measures appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. Current measures include:
- Encryption. TLS for data in transit. Azure application secrets, identity provider client secrets, multi-factor secrets and backup codes encrypted at rest with versioned, rotatable keys. Passwords stored as salted slow hashes. SCIM tokens stored only as hashes.
- Tenant isolation. Every data access path is scoped to a single tenant, and that scoping is verified automatically as part of our build pipeline.
- Access control. Role-based access within tenants, separate operator accounts for AvdControl staff, least-privilege production access, mandatory multi-factor authentication for owners, administrators and operators, and configurable enforcement for all tenant users.
- Authentication resilience. Rate limiting per account and per network address, short-lived operator sessions, HTTP-only and secure session cookies, and support for the Customer's own single sign-on and SCIM provisioning.
- Auditability. Append-only audit records covering privileged and session actions, including actor, action, before and after values, IP address, and whether a AvdControl operator was acting.
- Data minimisation. Session records are purged automatically 14 days after collection; support attachments are limited in number, size and type.
- Operational security. Segregated environments, dependency and vulnerability management, secrets held outside source control, and Cyber Essentials certification.
AvdControl may update these measures as the service and the threat landscape change, provided it does not materially reduce the level of protection. A current security overview is available under NDA on request.
6. Sub-processors
The Customer gives general authorisation for AvdControl to engage sub-processors. The current list is published on the sub-processors page. AvdControl imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable to the Customer for their performance.
AvdControl will give at least 30 days' notice of a planned addition or replacement, or notice as soon as practical where the change is urgently needed for security or continuity. The Customer may object on reasonable, documented data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected subscription and receive a refund of prepaid fees covering the unused period.
7. International transfers
Personal data is hosted in United Kingdom (London). AvdControl is established in the United Arab Emirates, and some sub-processors and personnel are outside the United Kingdom and the EEA.
Where a restricted transfer occurs, the parties agree that the UK International Data Transfer Agreement, or the European Commission's Standard Contractual Clauses (Module Two, controller to processor) together with the UK Addendum where the UK GDPR applies, are incorporated into this DPA and completed as follows: the Customer is the data exporter and AvdControl the data importer; the details in section 2 populate Annex I; the measures in section 5 populate Annex II; the sub-processors page populates Annex III; the optional docking clause applies; and the supervisory authority and governing law are those of the Customer's place of establishment, or England and Wales where the UK Addendum applies. Where those clauses conflict with the rest of this DPA, the clauses prevail. AvdControl carries out transfer risk assessments and applies supplementary technical measures, including encryption.
If AvdControl adds a hosting region, it will update the sub-processors page and, where the change affects where the Customer's data rests, notify the Customer in advance.
8. Assistance with data subject requests and compliance
The service gives the Customer the ability to access, correct, export and delete personal data in its tenant. Where the Customer cannot act by itself, AvdControl will provide reasonable assistance, at the Customer's cost where the assistance is substantial. If AvdControl receives a request directly from a data subject relating to a Customer tenant, it will not respond substantively, and will refer the individual to the Customer without undue delay.
AvdControl will provide reasonable assistance with data protection impact assessments, prior consultations with supervisory authorities, and security questionnaires, in each case limited to the processing carried out by AvdControl and to information AvdControl holds.
9. Personal data breach
AvdControl will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting personal data it processes for the Customer. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. AvdControl will provide further information as the investigation progresses, take reasonable steps to contain and remediate, and cooperate with the Customer's own regulatory notifications. Notification is not an admission of fault. The Customer is responsible for notifying its own supervisory authority and data subjects where required.
10. Return and deletion
While the tenant is accessible, the Customer can export its data from the service, and AvdControl will provide a reasonable export on request. On termination, AvdControl will archive and then delete personal data in the tenant, normally within 30 days of the effective date of termination, except where retention is required by law or is necessary for billing, tax, security investigation or the defence of legal claims, in which case AvdControl will keep it only for as long as needed and continue to protect it under this DPA. Backups age out on their own cycle. AvdControl will confirm deletion in writing on request.
11. Audit and information rights
On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, AvdControl will provide information reasonably necessary to demonstrate compliance with this DPA, including its security overview and responses to a reasonable questionnaire. Where that is not sufficient to satisfy a mandatory audit obligation, the parties will agree the scope, timing and cost of an audit in advance, conducted during business hours, subject to confidentiality, without disrupting the service or accessing other customers' data, and at the Customer's expense.
12. Liability, precedence and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Law does not permit that. This DPA prevails over the rest of the Terms on matters of personal data processing, and is otherwise subject to them, including the governing law and jurisdiction provisions. It takes effect when the Customer accepts the Terms and continues for as long as AvdControl processes personal data on the Customer's behalf.
Questions, countersignature requests, and copies of transfer safeguards: [email protected].