Legal
Data Processing Addendum
Template — executed version provided on request. This addendum describes how ISHI KOI FARM COMPANY LIMITED processes personal data on behalf of a customer that uses AAMDM. Write to contact@aamdm.com to receive a version for signature.
Last updated:
1. Parties and roles
The customer is the controller of the personal data processed through its AAMDM workspace, including data about its employees and their devices. ISHI KOI FARM COMPANY LIMITED, Tax ID 0601224050, 185 Loc Vuong, Nam Dinh 10000, Vietnam (“AAMDM”) is the processor and processes that data on the customer’s behalf.
For website information and administrator account information, AAMDM acts as a controller, as described in the Privacy Policy. This addendum does not cover that processing.
2. Scope and purpose of processing
AAMDM processes personal data only to provide the service the customer has asked for: enrolling and managing devices, keeping an inventory, delivering commands and keeping an audit log.
- Categories of data subjects: the customer’s administrators and the employees or other users of devices the customer manages.
- Types of personal data: administrator names, work email addresses and roles; device identifiers and hardware details such as serial number and model; operating system and enrollment status; assigned policies and apps; compliance status; administrator audit records.
- Duration: for the term of the agreement, then as set out under deletion and return below.
3. Customer instructions
AAMDM processes personal data only on the customer’s documented instructions, which are the agreement, this addendum and the customer’s use and configuration of the service. If AAMDM believes an instruction breaks applicable data protection law, it will tell the customer.
4. Confidentiality
People at AAMDM who can access customer personal data are bound by confidentiality obligations and have access only as far as their work requires.
5. Subprocessors
The customer agrees that AAMDM may use the subprocessors listed on the Subprocessors & Data Retention page. AAMDM will tell customers about changes to providers that process their device data before the change takes effect, so the customer can object. AAMDM stays responsible for its subprocessors’ work and requires them to protect data to a comparable standard.
6. Security measures
AAMDM applies technical and organizational measures suited to the risk. They include:
- Separation of each customer’s data into its own tenant
- Encryption of stored service credentials such as certificates and tokens, and encryption of data in transit
- Two-factor authentication for administrator sign-in
- An audit log of administrative actions
- Access to customer data limited to people who need it
AAMDM does not currently hold third-party security certifications. The Security page describes our approach in more detail.
7. Personal data breach notification
If AAMDM becomes aware of a personal data breach affecting customer personal data, it will notify the customer without undue delay and aim to do so within 72 hours of becoming aware. The notice will describe what is known about the nature of the breach, the data affected, and the steps taken or proposed, and AAMDM will give further detail as it learns it.
8. Assistance with data subject requests
Taking into account the nature of the processing, AAMDM will help the customer respond to requests from individuals to exercise their rights, for example access, correction or deletion. If AAMDM receives such a request directly, it will refer the person to the customer and will not respond on the customer’s behalf unless instructed.
AAMDM will also give reasonable help with data protection impact assessments and consultations with regulators where they relate to the service.
9. Deletion and return of data
Before the agreement ends, the customer can export its organization’s data, including the audit log. After the agreement ends, AAMDM deletes customer personal data within the periods in the retention table, unless the law requires it to keep some data.
10. Audits
On reasonable written request, and not more than once a year unless a breach has occurred, AAMDM will give the customer the information needed to show it follows this addendum. Where that is not enough, the parties will agree in good faith a reasonable audit, with notice, during business hours, subject to confidentiality and without harming other customers’ data.
11. International transfers
AAMDM is based in Vietnam, and data may be processed in Vietnam and in the countries where its subprocessors operate. Where applicable data protection law requires a transfer mechanism, the parties will put one in place and AAMDM will cooperate to do so.
12. Governing law and contact
This addendum is governed by the laws of Vietnam. Questions, or a request for an executed copy: contact@aamdm.com.
This page is a template to help customers review our terms. It does not bind either party until it is signed.
Operated by ISHI KOI FARM COMPANY LIMITED, Tax ID 0601224050, 185 Loc Vuong, Nam Dinh 10000, Vietnam.