annoying.legal

DATA PROCESSING TERMS · VERSION 2026-08-31

Data Processing Terms

These terms apply where Brandon Rofe - Entrepreneur individuel processes personal data on behalf of a business customer through Annoying. They form part of the Terms of Service.

Roles and instructions

The customer is the controller (or a processor acting for another controller) for customer-controlled project data and Brandon Rofe - Entrepreneur individuel acts as processor for that data. We process it only on the customer's documented instructions, including the instructions inherent in using Annoying, unless law requires otherwise.

Processing details

Confidentiality and security

People authorised to process customer personal data are subject to appropriate confidentiality obligations. We maintain technical and organisational measures appropriate to the service risk, including access controls, transport security, secure password hashing, request forgery protection, rate limiting and controlled upload handling.

Sub-processors

The customer authorises use of sub-processors reasonably necessary to operate Annoying, subject to data-protection obligations appropriate to their role. Production providers and material changes will be identified in service documentation or privacy information. We remain responsible for our obligations regarding our processors as required by applicable law.

Rights and assistance

Taking into account the nature of processing, we will provide reasonable assistance for customer obligations concerning data-subject requests, security, breach response, data-protection impact assessments and regulator consultation where applicable. Customers remain responsible for determining whether and how to respond to requests concerning data they control.

Security incidents

We will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled personal data where notification is required, and provide information reasonably available to support the customer's response.

Deletion or return

At the end of processing, we will delete or return customer-controlled personal data as provided by the service or on reasonable request, unless applicable law requires retention. Backup copies may persist for a limited protected cycle before deletion.

Audits

We will make information reasonably necessary to demonstrate compliance with these processor obligations available to the customer and permit proportionate audits where legally required, subject to reasonable notice, confidentiality, security and measures to avoid unnecessary disruption.

International transfers

We will use a lawful transfer mechanism where one is required for restricted transfers of customer personal data.