Scope and roles
Identify when the customer is controller and FetchSet is processor, when FetchSet acts independently, the services covered, and the relationship to the main agreement.
Processing details
- Subject matter
- Identity resolution, validation, enrichment, account administration, and service security.
- Duration
- For the service term plus the approved deletion, backup, audit, and suppression periods.
- Data subjects
- Customer users, business contacts, prospects, customers, and other individuals specified in lawful customer instructions.
- Data types
- Identifiers, professional details, contact fields, company attributes, request metadata, and support records.
Documented instructions
Define permissible instructions, the process for unlawful-instruction notice, confidentiality duties, and customer responsibility for lawful basis and required notices.
Security measures
Attach approved technical and organizational measures covering access control, encryption, key handling, logging, availability, incident response, vendor risk, testing, and recovery.
Subprocessors
Define general authorization, notice periods, objection rights, equivalent obligations, and responsibility for subprocessors. Link to the live subprocessor list.
Assistance and incidents
Cover data-subject requests, security incidents, DPIAs, regulator consultation, government requests, audit evidence, deletion, return, and reasonable cooperation.
International transfers
Identify transfer mechanisms, SCC modules, UK addendum, supplementary measures, data residency, and the hierarchy of transfer terms.
Annexes and signatures
Reserve annexes for processing details, security measures, approved subprocessors, transfer terms, and signature blocks. Final content must match the production vendor inventory and architecture.