Pour les clients

Security addendum

Version 1.0 · Dernière mise à jour le 2026-09-09

Ce document est disponible uniquement en anglais. Lire la version anglaise
This addendum describes how we protect our customer's data.

1. General

1.1. Non-exhaustive. This Addendum outlines the minimum requirements for UNLESS’s operations and protection of Customer’s data (personal and non-personal) and forms an integral part of the Agreement entered into between the Customer (you) and UNLESS (the “Main Agreement”).

For the avoidance of doubt, the measures outlined in this document are not intended to be an exhaustive list of measures required by UNLESS. Additional and/or more stringent measures may be required in line with the actual risks and the proportionality principle as outlined below. Furthermore, the requirements outlined in this document are supplementary to all other functional and non-functional security requirements outlined in the Main Agreement or as otherwise provided by UNLESS.

1.2. Proportionality. UNLESS’s security measures shall ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of data processing as well as the risk of varying likelihood and severity for any adverse consequences for the Customer or the natural persons involved.

2. Organisational measures

2.1. Information security management. UNLESS undertakes to have an information security management system modelled after the ISO 27001 and 27002:2022 (or subsequent versions) or an equivalent industry standard for information security management. It must encompass measures detailed herein, which UNLESS is required to implement following industry best practices and the principles of continuous improvement.

2.2. Training. UNLESS must provide regular and comprehensive training to its employees to raise awareness of data protection principles and security best practices.

2.3. System access and control. UNLESS must implement organisational measures to prevent unauthorised access to the data processing systems, including, but not limited to:

  • i. Secure user authentication processes;
  • ii. Role-based access control to limit access to personal data to authorised personnel;
  • iii. Password policies, e.g. requiring strong, unique passwords that are periodically updated;
  • iv. Multi-factor authentication for accessing sensitive and/or business critical systems or data;
  • v. Regular review and monitoring of access logs.

3. Privacy and security incident management

3.1. Incident response plan. UNLESS must have a documented incident response plan in place to detect, contain, and remediate data breaches or security incidents (together referred to as “incidents”). Regular testing and updates to the incident response plan must be conducted.

3.2. Notification and information obligations. In the event of any actual or suspected incidents concerning the services provided under the Main Agreement, UNLESS shall promptly notify the Customer in writing, providing all available relevant details regarding the incident, including its nature, scope, and potential impact on Customer’s data. Any privacy breach shall, in addition to the requirements set forth herein, be informed and handled in accordance with the requirements outlined in the data processing agreement entered into between the Parties.

3.3. Cooperation and mitigation. UNLESS shall cooperate fully with the Customer to mitigate any adverse effects resulting from the incident. This includes, but is not limited to, taking immediate corrective actions, providing necessary support, and collaborating to prevent further unauthorized access or data compromise.

3.4. Information sharing and documentation. UNLESS shall furnish the Customer with all information and documentation pertinent to investigations, analyses, or reviews related to the incident, upon the Customer’s reasonable request.

UNLESS shall assist the Customer in conducting an inquiry or audit regarding the incident, facilitating access to relevant records, systems, or personnel to support the investigation.

Throughout the incident resolution process, UNLESS shall provide regular updates to the Customer regarding the progress made in rectifying the breach and implementing security measures to prevent similar occurrences.

4. Physical measures

4.1. General. UNLESS must implement appropriate physical measures, such as entry controls, to ensure only authorised personnel can access facilities where data processing occurs.

5. Technical measures

5.1. Network security. UNLESS must implement appropriate network security measures, such as firewalls, intrusion detection/prevention systems, and network segmentation to safeguard internal data networks. UNLESS must regularly update anti-malware solutions and conduct periodic network scans to detect and mitigate threats.

5.2. Data encryption. UNLESS must utilise strong encryption protocols for data at rest and in transit to protect the confidentiality and integrity of Customer’s data. Management of encryption keys must be performed securely, with periodic changes and secure storage of keys.

5.3. Secure development. UNLESS must supply secure coding practices and conduct regular code reviews and/or scans to identify and remediate security vulnerabilities in applications.

5.4. Business continuity and disaster recovery. UNLESS shall maintain a documented Business Continuity Plan (BCP) outlining procedures, resources, and strategies to ensure the continuity of services in the event of disruptive incidents.

UNLESS shall establish comprehensive Disaster Recovery (DR) procedures to address scenarios where critical systems or services are unavailable due to unforeseen events.

UNLESS shall conduct periodic tests and reviews of the BCP and DR procedures to ensure their effectiveness and responsiveness in various disaster scenarios.

5.5. Backup routines. UNLESS shall implement robust and regular backup routines for all business critical and sensitive data involved in providing services under the Main Agreement. Backups shall be performed at defined intervals, ensuring data integrity, accessibility, and secure storage in compliance with industry standards and regulatory requirements.

Backup data shall be securely stored and readily accessible in case of data loss or system failure, enabling timely restoration of services.

6. Compliance and audits

6.1. Applicable laws and regulations. UNLESS shall ensure strict compliance with all applicable security and privacy laws, regulations, and standards pertinent to the services rendered under this Agreement.

6.2. Verifications. Customer reserves the right to periodically verify UNLESS’s compliance with the requirements outlined in this Addendum. UNLESS shall provide necessary documentation in this regard upon Customer’s reasonable request.

6.3. Audits. Customer may, upon reasonable notice, conduct audits or assessments to verify UNLESS’s adherence to these requirements. UNLESS agrees to cooperate fully with such audits.

6.4. Subcontractors and third-party security. UNLESS will ensure that any subcontractors or third parties it engages in the provision of services to Customer adhere to materially equivalent security standards and are contractually bound to do so.

6.5. Failure to implement security measures. In the event of any breach, unauthorized access, or compromise of data due to UNLESS’s failure to implement or maintain adequate security measures, the liability of UNLESS is regulated in the Main Agreement.

Sous-traitants