Legal

Data Processing Agreement

Last updated: 27 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Tamam Technologies Ltd (trading as React-IMS), a company registered in England and Wales under company number 16897253 with registered office at 2 Claremont Crescent, Morecambe, LA4 4HH, United Kingdom ("Processor"), for the use of the React-IMS platform and reflects the parties' obligations under Article 28 UK GDPR and EU GDPR.

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller for the purpose of providing the React-IMS platform, for the duration of the underlying subscription.

2. Nature and purpose of processing

Hosting, storage, retrieval, analysis, transmission and deletion of personal data submitted to the platform in connection with the Controller's integrated management system.

3. Types of personal data and categories of data subjects

  • Data subjects: the Controller's employees, contractors, suppliers and any other individuals whose information the Controller chooses to upload.
  • Data types: identification data, contact data, role and organisational data, training records, audit findings, risk and incident records.

4. Processor obligations

  • Process personal data only on documented instructions from the Controller.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (see Annex 1).
  • Assist the Controller with data subject requests, DPIAs and breach notification.
  • Notify the Controller without undue delay (and within 72 hours of becoming aware) of any personal data breach affecting Customer Data.
  • On termination, delete or return personal data unless retention is required by law.

5. Sub-processors

The Controller authorises the Processor to engage the sub-processors listed at /subprocessors. The Processor will give at least 30 days' notice of any intended additions or replacements; the Controller may object on reasonable data-protection grounds.

6. International transfers

Customer data is hosted in European Union (Frankfurt / Dublin). Where a transfer outside the UK / EEA is necessary, the parties will rely on the UK IDTA, the UK Addendum to the EU SCCs, or an adequacy decision, with supplementary measures as appropriate.

7. Audit

The Processor will make available all information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, on reasonable prior notice and subject to confidentiality.

8. Liability

Liability under this DPA is governed by the limitation of liability provisions of the main agreement.

Annex 1 — Security measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Tenant isolation enforced at the database layer via row-level security.
  • Role-based access control with least privilege.
  • Immutable audit logging of administrative actions.
  • Vulnerability monitoring and dependency scanning.
  • Background checks and security training for personnel with data access.
  • Documented incident response and breach notification procedures.
  • Backups with tested restore procedures and defined RPO / RTO targets.

Signing

Customers requiring a signed counterpart should contact privacy@react-ims.com.