Roles and instructions
This Addendum applies where Glemad Inc. processes personal data on behalf of a business customer under a qualifying written agreement. The customer acts as controller and Glemad Inc. as processor, except where law assigns a different role.
Processing commitments
- Process covered data only on documented lawful instructions.
- Ensure personnel are bound by confidentiality.
- Maintain proportionate security measures and incident procedures.
- Assist with rights requests, impact assessments and regulator consultations as reasonably required.
Subprocessing and transfers
The customer authorizes the subprocessors listed on this site subject to contractual protections. International transfers use an applicable legal mechanism, which may include approved standard contractual clauses.
Deletion, return and audits
At the end of services, covered data is returned or deleted unless law requires retention. We provide information reasonably necessary to demonstrate compliance and support proportionate audits under agreed confidentiality, scope and timing conditions.
Security schedule
- Access controls and least privilege.
- Encryption in transit and appropriate encryption at rest.
- Logging, vulnerability management, backups and recovery testing.
- Incident response, supplier review and personnel security.
Changes to this document
We may update this document to reflect changes to Nabtap, the law or the way we protect the community. When a change is material, we will provide notice appropriate to its significance and request fresh acceptance where required.
Contact
Questions about this document can be sent through the Nabtap Contact Centre. Choose the topic that best matches your request so it reaches the appropriate team at Glemad Inc.
Open Nabtap