Last updated: 7 September 2026
This addendum applies where PluginZ Solutions processes personal data on behalf of a business customer while delivering managed IT, Microsoft 365 administration, cloud infrastructure, cybersecurity, backup, migration, software and ERP, support, integration or Ops360 services.
It is published so that customers and their procurement and legal teams can review the terms before signing. It becomes binding only when it is incorporated into a signed agreement between the parties, or signed separately. Customers are encouraged to review it with their own advisers, and PluginZ will consider a customer version on request.
Processing where PluginZ decides for itself why personal data is used, such as handling an enquiry or administering a customer account, is not covered here. That is described in the Privacy Policy at pluginz.co/privacy-policy/.
1. Definitions
In this addendum the following terms have the meanings given below. Where the applicable data protection law uses a different term for the same concept, that term applies.
- "Agreement" means the signed proposal, quotation, statement of work, master services agreement or subscription agreement between the Customer and PluginZ to which this addendum relates.
- "Applicable Data Protection Law" means the data protection and privacy legislation that applies to the processing under this addendum.
- "Customer Personal Data" means personal data contained in, or accessible through, the systems, services or data that PluginZ processes on the Customer's behalf under the Agreement.
- "Controller" means the party that determines the purposes and means of processing personal data.
- "Processor" means the party that processes personal data on behalf of, and under the instructions of, a controller.
- "Data Subject" means the individual to whom personal data relates.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- "Subprocessor" means a third party engaged by PluginZ to process Customer Personal Data in connection with the Services.
- "Services" means the services PluginZ provides under the Agreement.
2. Roles of the parties
For Customer Personal Data processed under the Agreement, the Customer is the Controller and PluginZ is the Processor, unless the Applicable Data Protection Law characterises the relationship differently on the facts.
Where PluginZ determines the purposes and means of processing for its own business, for example administering the customer relationship, billing, and its own security and legal obligations, PluginZ acts as a Controller for that processing. It is described in the PluginZ Privacy Policy at pluginz.co/privacy-policy/ and is outside the scope of this addendum.
Where the Customer is itself a processor for another controller, the Customer confirms it has the authority of that controller to enter into this addendum and to give the instructions it gives, and PluginZ acts as a subprocessor.
Neither party sells Customer Personal Data, and neither acts as a joint controller with the other in respect of the processing covered by this addendum unless expressly agreed in writing.
3. Scope and purpose of processing
PluginZ processes Customer Personal Data only to provide, support, secure and administer the Services, and for the purposes set out in the Agreement and Annex A.
PluginZ will not process Customer Personal Data for its own independent purposes, will not sell it, and will not use it to develop, improve or train products, models or services for other customers or for PluginZ, unless the Customer has agreed to that specific use in writing.
The subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects, are set out in Annex A and in the Agreement.
4. Categories of data subjects
Depending on the Services contracted, Customer Personal Data may relate to the following categories of individuals. The categories that actually apply to an engagement are recorded in Annex A.
- The Customer's employees, contractors, temporary staff and other personnel.
- The Customer's administrators and system users.
- The Customer's own customers, clients and their contacts.
- The Customer's suppliers, partners and their contacts.
- Job applicants and other individuals whose data the Customer holds in systems within scope.
- Any other individual whose personal data is present in the systems or data the Services cover.
5. Categories of personal data
Depending on the Services and on what the Customer places in the systems within scope, the following categories may be processed. Those that apply to an engagement are recorded in Annex A.
- Identity and contact data: names, usernames, sign-in identifiers, email addresses, phone numbers, job titles and department.
- Account and access data: roles, group and licence assignments, permissions, authentication metadata and access logs.
- Device and technical data: device identifiers, configuration, asset records, network and system logs, telemetry and security events.
- Communications and support data: support tickets, correspondence and the content of messages within the systems covered.
- Business content: documents, files, mailboxes, database records and application data held in the systems covered, which may contain personal data the Customer determines.
- Backup data: copies of the above held in backup and recovery systems within scope.
Special categories of personal data, and data relating to children, are not required for the Services. Where such data is nonetheless present in the systems within scope, the Customer remains responsible for identifying it and for any additional requirement the Applicable Data Protection Law imposes, and will tell PluginZ where additional measures are needed.
6. Processing instructions
PluginZ processes Customer Personal Data only on the Customer's documented instructions, including as to transfers, unless required to do otherwise by a law to which PluginZ is subject. Where such a legal requirement applies, PluginZ will inform the Customer before processing unless that law prohibits it.
The Agreement, this addendum, Annex A, and the configuration and requests the Customer makes through the agreed channels together constitute the Customer's documented instructions.
The Customer is responsible for the lawfulness of its instructions, for having a lawful basis for the processing, for the accuracy and quality of the data it provides, and for providing any notice or obtaining any consent that the Applicable Data Protection Law requires of it.
If PluginZ considers that an instruction infringes the Applicable Data Protection Law, it will inform the Customer without undue delay and may suspend the affected processing until the instruction is confirmed, withdrawn or amended.
Instructions outside the scope of the Agreement may be subject to a change request and additional charges.
7. Confidentiality
PluginZ treats Customer Personal Data as confidential information of the Customer and does not disclose it except as this addendum or the Agreement permits.
PluginZ ensures that personnel authorised to process Customer Personal Data are bound by an obligation of confidentiality, that the obligation survives the end of their engagement, and that access is limited to those who need it to perform the Services.
Where PluginZ is legally compelled to disclose Customer Personal Data, it will, to the extent lawful, notify the Customer in advance so the Customer can seek protective relief, and will limit the disclosure to what is legally required.
8. Security measures
PluginZ operates an information security management system certified to ISO/IEC 27001:2022 under certificate number UKS-ISMS-25-047, verifiable on IAF CertSearch.
PluginZ implements appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure. The measures that apply generally are described in Annex B, and any measure specific to an engagement is recorded in the Agreement or Annex A.
The measures take into account the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risk to individuals.
PluginZ may update its measures over time provided that the level of protection is not materially reduced.
The Customer is responsible for configuring the Services it controls appropriately, for its own security within its environment, and for assessing whether the measures meet its requirements before entrusting data to the Services.
9. Subprocessors
The Customer gives PluginZ general authorisation to engage Subprocessors to deliver the Services, subject to this section.
PluginZ imposes on each Subprocessor data protection obligations that are substantially equivalent to those in this addendum, to the extent applicable to the service the Subprocessor provides, and remains responsible to the Customer for the Subprocessor's performance of those obligations.
The Subprocessors engaged for an engagement are listed in Annex C to the signed addendum for that engagement. PluginZ will give the Customer reasonable prior notice before adding or replacing a Subprocessor that will process Customer Personal Data.
The Customer may object on reasonable data protection grounds within the notice period. The parties will discuss the objection in good faith and seek a workable alternative. If none is available and the change is necessary to deliver the Services, either party may terminate the affected Services in accordance with the Agreement.
Where a Subprocessor is the vendor whose platform the Customer has itself selected, for example the operator of a cloud service the Customer subscribes to, that vendor processes data under its own terms with the Customer as well as under the arrangements described here.
10. International transfers
Customer Personal Data may be processed or stored outside the country in which the Customer or the relevant data subjects are located. Whether that happens, and where the data goes, depends on the Services selected, the cloud region and configuration chosen, the platforms involved, and any data-location requirement recorded in the Agreement.
PluginZ does not represent that Customer Personal Data will be held only in a particular country unless the Agreement records that requirement for the engagement.
Where the Applicable Data Protection Law requires a legal ground, safeguard or authorisation before personal data is transferred to another country, the parties will put in place the mechanism that law prescribes for that transfer. The mechanism is identified in the Agreement or in the signed addendum for the engagement, because the correct mechanism depends on the jurisdictions involved.
The Customer will tell PluginZ of any data-location or transfer restriction that applies to it before entrusting data to the Services, so that the Services can be configured accordingly.
11. Assistance with data subject requests
PluginZ will not respond to a request from a data subject in respect of Customer Personal Data, except to confirm that the request should be directed to the Customer, unless the Customer instructs otherwise or the Applicable Data Protection Law requires PluginZ to respond.
If PluginZ receives such a request, it will inform the Customer without undue delay and forward the request.
Taking into account the nature of the processing, PluginZ will provide the Customer with reasonable assistance, by appropriate technical and organisational measures and so far as is possible, to enable the Customer to respond to requests to exercise rights of access, correction, deletion, restriction, objection and portability.
Where the Customer can perform the action itself using the administrative functions of the systems PluginZ manages for it, PluginZ will support the Customer in doing so. Assistance beyond what is reasonably required may be chargeable at the rates in the Agreement.
12. Personal data breaches
PluginZ will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, to the extent known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. PluginZ will provide further information in phases as the investigation progresses.
PluginZ will take reasonable steps to contain, investigate and mitigate the breach, and will cooperate with the Customer so the Customer can meet its own notification obligations.
Notification to a supervisory authority or to affected data subjects in respect of Customer Personal Data is the Customer's responsibility as Controller. PluginZ will not make such a notification on the Customer's behalf unless the Customer instructs it to or the law requires it.
A notification or assistance under this section is not an acknowledgement of fault or liability.
This addendum does not fix a notification deadline in hours. Deadlines differ between jurisdictions, and where the Applicable Data Protection Law or the Agreement sets a specific period, that period applies.
13. Impact assessments and regulatory cooperation
Taking into account the nature of the processing and the information available to it, PluginZ will provide the Customer with reasonable assistance with data protection impact assessments and with any prior consultation with a supervisory authority that the Applicable Data Protection Law requires the Customer to carry out.
PluginZ will cooperate, on request and at the Customer's cost where the assistance is substantial, with a competent supervisory authority in the performance of its tasks in relation to the processing under this addendum.
14. Return or deletion of customer data
On termination or expiry of the Agreement, or earlier on the Customer's written request, PluginZ will, at the Customer's choice, return Customer Personal Data or delete it, and delete existing copies, unless a law to which PluginZ is subject requires it to be retained.
The Customer should make its choice within the period stated in the Agreement. Where the Customer gives no instruction within that period, PluginZ may delete the data in accordance with its normal processes.
Deletion is not instantaneous. Data held in backups, archives and system logs is removed in accordance with the relevant retention cycle rather than immediately, and remains protected by this addendum and by PluginZ security measures until it is.
Where data sits in a platform the Customer owns, for example the Customer's own cloud tenant, deletion within that platform is under the Customer's control. PluginZ will remove its own access and any copies it holds.
On request, PluginZ will confirm in writing that it has complied with this section.
15. Audit and information rights
PluginZ will make available to the Customer the information reasonably necessary to demonstrate compliance with this addendum.
PluginZ may satisfy this obligation by providing its certification documentation, a description of its technical and organisational measures, and written responses to a reasonable security questionnaire.
Where the Applicable Data Protection Law requires an audit or inspection beyond that, the parties will agree its scope, timing, duration and cost in advance. An audit will take place during business hours, on reasonable written notice, subject to confidentiality obligations, and in a manner that does not disrupt PluginZ operations or the security or confidentiality of other customers.
Any inspection is limited to the systems, records and premises relevant to the processing of that Customer's data. PluginZ may charge for the reasonable costs of supporting an audit beyond the information described above.
16. Liability
The limitations and exclusions of liability in the Agreement apply to this addendum and to any claim arising from it, and the liability of each party under the Agreement and this addendum together is subject to the aggregate cap in the Agreement, except where the Applicable Data Protection Law does not permit that.
Nothing in this addendum limits a liability that cannot lawfully be limited, or affects a data subject's rights under the Applicable Data Protection Law.
17. Order of precedence
This addendum supplements the Agreement. In the event of a conflict between this addendum and the Agreement on a matter of data protection, this addendum prevails for that matter.
Where a data protection addendum has been separately negotiated and signed between the parties, that signed document prevails over the standard version published here.
Where a mandatory clause required by the Applicable Data Protection Law, or a transfer mechanism entered into between the parties, conflicts with this addendum, that clause or mechanism prevails.
Otherwise the order of precedence in the Agreement applies.
18. Jurisdiction-specific provisions
Where the processing under this addendum is subject to a law listed below, the parties will comply with the additional requirements that law imposes on their respective roles, and will enter into any additional terms, clauses or transfer mechanism that it prescribes.
- Egypt: Law No. 151 of 2020 on the Protection of Personal Data and its implementing regulations.
- Saudi Arabia: the Personal Data Protection Law issued by Royal Decree No. M/19, its Implementing Regulations, and the regulation governing transfers of personal data outside the Kingdom, as supervised by the Saudi Data and Artificial Intelligence Authority (SDAIA).
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and the requirements of the UAE Data Office, or, where the Customer is established in a free zone with its own regime such as the Dubai International Financial Centre, that regime instead.
- European Union, EEA and United Kingdom: the General Data Protection Regulation and its UK equivalent, where their territorial scope is met, including Article 28 requirements and, for transfers, the standard contractual clauses or other approved mechanism applicable to the transfer.
This section identifies the frameworks the parties may need to address. It does not state that any of them applies to a given engagement, and it is not legal advice. The frameworks that actually apply, and the specific terms needed, are confirmed for each engagement.
19. General
This addendum takes effect when it is incorporated into a signed Agreement between the parties, or when the parties sign it separately. Publishing it on this page does not by itself create obligations between PluginZ and any reader.
This addendum is governed by the law and jurisdiction that govern the Agreement.
If a provision of this addendum is held invalid or unenforceable, the remainder continues in effect.
To request a signed copy, to raise a question, or to send a customer version for review, contact info@pluginz.co.
Annex A: Processing details
Annex A records the processing for a specific engagement. It is completed and attached to the signed addendum, because the answers depend on which services the Customer has contracted for. It captures:
- Subject matter and duration of the processing, aligned to the term of the Agreement.
- Nature and purpose of the processing, described by reference to the contracted services, for example Microsoft 365 administration, cloud infrastructure management, cybersecurity monitoring, backup and recovery, migration, application support or Ops360.
- The systems, tenants, environments and data stores within scope.
- The categories of data subjects that apply, selected from section 4.
- The categories of personal data that apply, selected from section 5, and whether any special category data is expected.
- The frequency of the processing, whether continuous or occasional.
- Any data-location or transfer restriction agreed for the engagement.
- Retention and deletion arrangements at the end of the engagement, and the period within which the Customer must give its return-or-delete instruction.
- The named contacts on each side for data protection matters.
Annex A is engagement-specific and is completed when the addendum is signed. The version published on this page is the standard template and does not describe processing for any particular customer.
Annex B: Technical and organisational measures
PluginZ maintains the following categories of measure as part of its certified information security management system. Measures specific to an engagement, including any control the Customer requires, are recorded in the signed addendum for that engagement.
- Information security governance: a documented management system, defined security responsibilities, and management review, certified to ISO/IEC 27001:2022.
- Access control: access granted on a need-to-know basis, role-based permissions, authorisation before access to customer environments is granted, and removal of access when it is no longer required or when personnel leave.
- Personnel measures: confidentiality obligations on personnel, security awareness training, and defined responsibilities for handling customer data.
- Encryption in transit: encrypted transport for the PluginZ website and for the administrative connections used to deliver the Services.
- Logging and monitoring: logging of relevant activity within the systems PluginZ operates, with review as part of the management system.
- Incident management: documented processes for identifying, recording, escalating, investigating and responding to security incidents, and for notifying affected customers.
- Supplier management: assessment of the providers PluginZ relies on, and contractual data protection obligations on subprocessors.
- Change and configuration management for the systems PluginZ operates.
- Business continuity and backup arrangements for PluginZ own systems, and, where contracted, for customer systems as described in the Agreement.
- Physical and environmental security appropriate to the PluginZ premises and to the facilities of the infrastructure providers it uses.
This annex lists categories of measure, not the configuration of any particular system. It does not state that a specific technology, encryption standard, testing frequency or monitoring arrangement is in place beyond what is described above. Where a Customer requires a specific control, it is agreed in the Agreement or in the signed addendum, and PluginZ will confirm whether it can be provided.
Controls that are engagement-specific, such as encryption at rest for a particular data store, multi-factor authentication enforcement within a customer tenant, log retention periods and security testing arrangements, depend on the environment and the contracted scope. They are confirmed in writing for each engagement rather than stated here.
Annex C: Subprocessors
PluginZ engages subprocessors from the following categories, depending on the Services contracted:
- Cloud infrastructure and hosting providers, for the platforms on which services are operated.
- The platform vendor whose service is being administered or resold, where the Customer has selected that platform. For Microsoft 365 and Azure engagements this is Microsoft.
- Communications, ticketing and remote support tooling used to deliver and support the Services.
- Security and monitoring tooling used to protect the environments within scope.
- Backup and recovery providers, where backup is part of the contracted scope.
The named subprocessors for an engagement, with their role and processing location, are listed in the Annex C attached to the signed addendum for that engagement. The set depends on which services the Customer has contracted for, so this published template does not name them.
Customers and prospective customers can request the current named list for the services they are considering by emailing info@pluginz.co.
The subprocessors PluginZ uses for its own website and business operations, which is separate processing where PluginZ acts as a controller, are named in section 9 of the Privacy Policy at pluginz.co/privacy-policy/.
Questions about this document? Email info@pluginz.co.

