Skip to content
OpticCount
All documents

Data processing terms for business customers

When a business customer uses the system, the data inside it is theirs. This document defines the division of roles between us, as the Protection of Privacy (Data Security) Regulations, 5777-2017 require, and forms an annex to the customer contract.

Updated:

Who owns the database and who holds it

The customer is the database owner in respect of the data they enter: the catalogue, the counts, the stores and their users.

The Company acts as a holder on the customer's behalf for that data, and processes it solely on their instructions and for the purpose of providing the service.

In respect of the customer's own contact details and account administration, the Company is the database owner.

What we may do with the data

  • Process it only to provide and operate the service, and on the customer's instructions.
  • Not use it for our own purposes, not sell it and not pass it to a third party, other than suppliers required to deliver the service and subject to the same obligations.
  • Not access it except by permission, on a need-to-know basis, and with logging.

Any use of aggregate, anonymised data to improve the product will only be made where no individual or business can be identified from it.

Security

We apply the security obligations that fall on us under the Data Security Regulations, including database classification, a definitions document, a security procedure, access control, activity logging and encrypted transport.

Our employees and service providers are bound by confidentiality undertakings.

Security incidents

In a severe security incident affecting customer data we will notify the customer without undue delay, with the information we hold on the nature and scope of the incident and the steps taken.

We will assist the customer with their own reporting obligations to the Privacy Protection Authority and to data subjects, to the extent those apply to them.

The customer's responsibilities

  • Enter only data they are entitled to process, and ensure they have a lawful basis for doing so.
  • Not enter personal data that the process does not require, and in particular no data of special sensitivity.
  • Inform their employees that their actions in the system are recorded under their name, for control and counting accuracy.
  • Manage permissions in the system, and remove users who have left the role.

End of the contract

At the end of the contract the customer may export their data. It will then be deleted or anonymised within a reasonable period, except what we are required to retain by law.

Data subject requests

A request reaching us from a customer's employee about data in the customer's database will be passed to the customer, who owns it, and we will help them handle it.