Data-processing terms for managed services

Version 2026-09-08. These terms apply when SolutionMAX processes personal data on a business customer's documented instructions, after both parties agree the service order and processing schedule. They do not replace the schedule or assert that one has already been signed.

Instructions and scope

The customer is controller and SolutionMAX is processor for the agreed operations. The schedule must identify the parties, purpose, duration, data categories, data subjects, systems, countries, retention and authorised sub-processors. We process only documented lawful instructions, including for transfers, unless law requires otherwise, and inform the customer of such a requirement where permitted. We notify the customer if an instruction appears to infringe data-protection law.

Confidentiality and security

Access is limited to authorised people bound to confidentiality. Before processing, the schedule records the actual Article 32 measures: access control and MFA, secure transport, credentials handling, isolation, backup and recovery, updates and incident response, according to risk. It must specify any encryption at rest and restoration testing that have actually been implemented.

Sub-processors and transfers

Sub-processors require the customer's prior specific or general written authorisation. Under general authorisation we give advance notice of additions or replacements and an opportunity to object before their use. Each receives equivalent data-protection obligations, and we remain responsible for its performance. The schedule identifies locations and any Chapter V transfer safeguards; it must not assume that a US AI API is covered merely because another supplier has an EU office.

Assistance, incidents and oversight

We assist the customer with data-subject requests, security, breaches, impact assessments and regulator consultations, taking account of the processing and information available. We notify the customer without undue delay after becoming aware of a personal-data breach and provide available facts and updates. We provide information needed to demonstrate compliance and allow proportionate audits, including inspections, by the customer or its authorised auditor.

End of processing

At the customer's choice we return or delete personal data after the service ends and delete copies, except where law requires retention. The schedule specifies export format, deletion time and backup expiry. Retained data is restricted to the legal purpose. Financial records for our own obligations follow our privacy notice.

Before a workflow goes live

The agreed schedule must be completed for the particular workflow. Special-category data, medical use, voice recording or decisions with significant effects need explicit scope and assessment before activation. Contact [email protected] to arrange the schedule.

Terms ยท Privacy