DATA PROCESSING TERMS · VERSION 2026-08-31
Data Processing Terms
These terms apply where Brandon Rofe - Entrepreneur individuel processes personal data on behalf of a business customer through Annoying. They form part of the Terms of Service.
Roles and instructions
The customer is the controller (or a processor acting for another controller) for customer-controlled project data and Brandon Rofe - Entrepreneur individuel acts as processor for that data. We process it only on the customer's documented instructions, including the instructions inherent in using Annoying, unless law requires otherwise.
Processing details
- Subject matter: providing scope review, evidence organisation, commercial-impact workflow and change approval features.
- Duration: for the customer's use of the service and applicable deletion/return period.
- Nature: receiving, extracting, storing where selected, organising, comparing, displaying, transmitting and deleting customer-controlled project information.
- Purpose: providing and securing Annoying at the customer's instruction.
- Data subjects: customer personnel, the customer's clients and suppliers, and people referenced in project material.
- Data types: names, business contact information, communications, project/contract information and other personal data the customer chooses to submit. Customers should not submit special-category or highly sensitive personal data unless genuinely necessary and lawful.
Confidentiality and security
People authorised to process customer personal data are subject to appropriate confidentiality obligations. We maintain technical and organisational measures appropriate to the service risk, including access controls, transport security, secure password hashing, request forgery protection, rate limiting and controlled upload handling.
Sub-processors
The customer authorises use of sub-processors reasonably necessary to operate Annoying, subject to data-protection obligations appropriate to their role. Production providers and material changes will be identified in service documentation or privacy information. We remain responsible for our obligations regarding our processors as required by applicable law.
Rights and assistance
Taking into account the nature of processing, we will provide reasonable assistance for customer obligations concerning data-subject requests, security, breach response, data-protection impact assessments and regulator consultation where applicable. Customers remain responsible for determining whether and how to respond to requests concerning data they control.
Security incidents
We will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled personal data where notification is required, and provide information reasonably available to support the customer's response.
Deletion or return
At the end of processing, we will delete or return customer-controlled personal data as provided by the service or on reasonable request, unless applicable law requires retention. Backup copies may persist for a limited protected cycle before deletion.
Audits
We will make information reasonably necessary to demonstrate compliance with these processor obligations available to the customer and permit proportionate audits where legally required, subject to reasonable notice, confidentiality, security and measures to avoid unnecessary disruption.
International transfers
We will use a lawful transfer mechanism where one is required for restricted transfers of customer personal data.