Last updated 1 August 2026

Data Processing Agreement

Article 28 processing terms for organisation-controlled information.

Operator
Naleia & co ltd
Audience
Organisations using the platform as a processor
Contact
support@theconsiliom.com

Roles of the parties

This agreement applies where the platform processes personal data on behalf of an organisation. It records when the organisation acts as controller, when the platform acts as processor, and any purposes for which either party acts independently as controller.

Processing details

The subject matter is provision of the enabled organisation workspace. Duration follows the service agreement and the controlled deletion period. Data may include identity, membership, appointment, consent and limited wellbeing information relating to members, staff and invited users. Processing is limited to documented instructions and enabled product functions.

Processor commitments

  • Process only on documented instructions unless the law requires otherwise.
  • Ensure authorised personnel are bound by confidentiality.
  • Maintain proportionate technical and organisational security measures.
  • Control subprocessors and flow down equivalent obligations.
  • Assist with data-subject rights, security incidents, breach assessment, DPIAs and regulator consultation as required.
  • At termination, return or delete data as instructed, subject to law and protected backup expiry.
  • Provide information reasonably needed for compliance evidence and agreed audits.

Transfers and subprocessors

Approved subprocessors, processing locations and transfer safeguards are listed in the Subprocessor Notice. International transfers are protected using an approved mechanism such as an adequacy decision, the UK International Data Transfer Addendum or Standard Contractual Clauses. Organisations receive notice of new subprocessors as set out in their service agreement.