SERVE ITSM · LEGAL
Data processing terms
Last updated 27 September 2026
This page is an overview only. Where Serve ITSM processes personal data for a customer, the customer is generally the controller and the contracted service provider is the processor. A signed data processing agreement and service-specific schedules are required before production customer data is processed.
Customer responsibilities
The customer determines its purposes and lawful basis, provides required notices, configures access, minimises information, validates instructions and ensures it has authority to submit personal data to the service.
Processor responsibilities
The signed DPA should require processing only on documented instructions, confidentiality, appropriate security, assistance with data-subject requests and compliance duties, breach notification, controls on subprocessors and deletion or return at the end of service.
Security and hosting
The service description and order must identify the selected hosting region, backups, access controls, encryption, logging, recovery and support arrangements. Do not rely on this overview as a statement that a particular certification or control is already in place.
Subprocessors and transfers
A current subprocessor list, processing locations and transfer safeguards must be supplied in the signed DPA or a referenced schedule. Customers should review that schedule before enabling integrations or using production data.
Request the contract
Registered customers and prospective customers can request the current data-processing schedule from info@serveitsm.com.