Contractor Data Processing Terms
Contractor Data Processing Terms
These terms apply to Contractor Compliance Watch where a business customer provides personal data about contractors, contractor staff or business contacts and instructs Titan Commercial Lab to process that data on the customer's behalf.
1. Roles and instructions
The customer is the controller for customer-defined contractor monitoring data where it determines why the data is processed and what evidence or contacts are required. Titan Commercial Lab acts as processor for that processing and will process the data only on documented customer instructions, unless UK law requires otherwise. Written instructions may include the order, onboarding information, agreed evidence rules and saved email instructions.
2. Processing details
Subject matter: administrative contractor-document monitoring and agreed document chasing.
Duration: the purchased pilot/service period plus only the limited period reasonably required for support, return/deletion and dispute handling.
Purpose: maintain an evidence register, track customer-defined document status and expiry dates, identify exceptions, send authorised administrative chasers and produce exception summaries.
Data types: business contact details, contractor/company name, role, agreed evidence categories, document status, expiry/review dates, communication history and minimum supporting records required for the agreed purpose.
Data subjects: contractor proprietors, directors, employees or business contacts identified by the customer.
3. Customer responsibilities
The customer determines and documents the lawful basis for the processing, ensures its instructions are lawful, provides only data necessary for the agreed purpose, identifies any special handling restrictions, and remains responsible for contractor approval, competence, supervision, health and safety and statutory compliance. The customer must not instruct Titan to process special-category or criminal-offence data through the standard route unless a separate lawful and appropriate handling arrangement has been agreed.
4. Confidentiality and security
Titan will keep customer-controlled personal data confidential and apply appropriate technical and organisational measures proportionate to the processing. Access is limited to the service purpose. Customers should not send passwords, payment-card information or unrelated personal data.
5. Sub-processors
The customer gives general authorisation for Titan to use service providers necessary to operate the standard service, including Google/Gmail/Drive for communications and working records and Shopify for order/customer administration where relevant. Titan remains responsible for imposing applicable data-protection obligations on sub-processors used for processor activities and will provide reasonable information about the standard route on request.
OpenAI/ChatGPT is not part of the standard Contractor Compliance Watch route for contractor personal data or evidence files. Titan will not intentionally submit such customer-controlled data to OpenAI/ChatGPT unless the customer expressly agrees a different documented processing arrangement.
6. Individuals' rights and controller assistance
Titan will provide reasonable assistance, taking account of the nature of the processing, to help the customer respond to applicable data-subject rights requests. If Titan receives a request clearly relating to customer-controlled contractor data, Titan will notify or direct the requester to the customer where appropriate rather than deciding the request independently.
7. Security incidents, DPIAs and regulatory assistance
Titan will provide reasonable assistance to the customer with applicable security, personal-data-breach, data-protection-impact-assessment and regulator-consultation obligations where those obligations relate to Titan's processing, taking account of the nature of the processing and information available to Titan.
8. Return and deletion
At the end of the service, Titan will return or delete customer-controlled personal data in accordance with the customer's documented choice, except to the extent UK law requires retention. Titan may retain separate order, accounting, legal or suppression records where it acts as controller and has an applicable lawful basis.
9. Audit information
Titan will make available information reasonably necessary to demonstrate compliance with these processor obligations and will permit reasonable audits or inspections required by applicable data-protection law, subject to proportionate confidentiality, security and scheduling arrangements.
10. International transfers
Where a service provider processes personal data outside the UK, Titan will rely on the relevant lawful transfer mechanism and contractual safeguards applicable to that provider and processing route.
11. Scope boundary
These terms govern data processing only. They do not transfer the customer's contractor-management, health-and-safety, competence-assessment or other statutory duties to Titan Commercial Lab.