This Data Processing Agreement ("DPA") forms part of, and is governed by, the Master Subscription Agreement. Capitalised terms not defined here have the meanings given there.
1. Roles
In respect of Inputted Personal Data (personal data the Customer or an End Customer submits to, or the Fig Software ingests from, the Fig Services): the Customer (or, for an MSP's End Customer, the End Customer) is the Controller; where the Customer is an MSP acting as Processor of its End Customer, the MSP is a Processor; and Fig is a Processor, or Sub-processor where the architecture requires it. Fig processes Inputted Personal Data only on the Controller's documented instructions (which include this DPA, the Order Form, and any feature the Customer configures within the platform).
In respect of User Personal Data (names, business contact details, role and authentication data of Authorised Users, processed for account administration, billing, support and security), Fig is the Controller - see our Privacy Policy.
The parties are not joint Controllers of any personal data unless expressly agreed in writing.
2. Processing details
| Item | Detail |
|---|---|
| Subject matter | Provision of the Fig Services, including hosting the Fig Platform, operating the Fig Software, and generating Output. |
| Duration | The subscription term, plus any retention period set out in section 8 below or required by law. |
| Nature of processing | Storage, hosting, analysis, classification, alerting, reporting, transmission, deletion and (where enabled) remediation of Inputted Personal Data. |
| Purpose | Providing the Fig Services and Output; legal compliance; security and integrity of the Fig Services; generating System Data in aggregated, de-identified form. |
| Categories of data | Identification and contact data of personnel; account, role and authorisation data; device, asset and configuration data; IP addresses and similar identifiers; employment data from HR integrations; data identified by the Data Scanner's classifiers (which may include any category of personal data depending on the Customer's own data sources); special category or criminal-conviction data only where present in the Customer's own data sources and the Customer has a lawful basis to process it. |
| Categories of data subject | The Customer's (and, for MSPs, End Customers') employees, contractors and other personnel; their customers and counterparties where present in scanned data; third parties referenced in Customer Data. |
3. Fig's obligations as Processor
Fig will: process Inputted Personal Data only on documented instructions, and flag if an instruction appears to breach data protection law; ensure personnel handling personal data are bound by confidentiality; implement the security measures summarised in section 5; engage Sub-processors only as permitted below; assist the Customer, where reasonably possible, in responding to data-subject rights requests and in meeting its security, breach-notification and DPIA obligations; delete or return Inputted Personal Data at the end of the Fig Services in accordance with our data-retention practice (section 8), unless retention is legally required; make available information to demonstrate compliance and support audits (section 9); and maintain a record of processing activities.
4. Personal data breaches
Fig will notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting Inputted Personal Data, with the information available at the time. Fig will provide reasonable co-operation with investigation, containment and any onward regulatory or data-subject notifications the Customer needs to make.
5. Security measures
Fig maintains a comprehensive information security programme, including: single sign-on with mandatory multi-factor authentication for all internal access to production systems; role-based, least-privilege access with regular reviews; encryption of Customer Data at rest (AES-256 or equivalent) and in transit (TLS 1.2+); network segmentation, firewalls, intrusion detection and DDoS mitigation; a secure development lifecycle aligned with OWASP ASVS, with code, dependency and secret scanning; logical tenant isolation with automated isolation testing on every release; centralised, tamper-evident security logging and 24/7 monitoring; encrypted backups with tested recovery objectives; risk-based due diligence and contractual flow-down of obligations to Sub-processors; and hosting in third-party data centres holding SOC 2 Type II or ISO 27001 attestation. Full technical detail, our current security certifications and independent audit reports are available in our Trust Centre at www.docs.figgroup.co.uk.
6. Sub-processors
The Customer authorises Fig to engage the Sub-processors listed in our live Sub-processor List, maintained at www.figgroup.co.uk/subprocessors. We'll give at least 30 days' notice of any new or replacement Sub-processor by updating that list and emailing subscribed administrators; the Customer may object on reasonable data-protection grounds within that window, and if we can't resolve the objection within 15 days, the Customer may terminate the affected element of the Fig Services with a pro-rata refund. Fig imposes data-protection obligations on its Sub-processors no less protective than this DPA, and remains liable for their acts.
7. International transfers
Where Fig or a Sub-processor transfers Inputted Personal Data outside the UK or EEA, we rely on an adequacy decision, the UK International Data Transfer Agreement, the EU Standard Contractual Clauses (Module 2 or, between processors, Module 3), or another lawful transfer mechanism. The Customer is the data exporter and Fig is the data importer; governing law for the EU SCCs is Irish law, and for the UK IDTA, the law of England and Wales.
8. Data retention
- During the subscription: Customer Data and Inputted Personal Data are retained for the subscription term, subject to any earlier deletion the Customer requests and any retention rules the Customer configures. Deleted items are held in a 30-day recoverable state before permanent deletion. Audit logs are retained for 90 days to 12 months depending on plan. Encrypted backups roll over on a 7-day (continuous), 30-day (daily) and 12-month (monthly) cycle.
- On termination: the Customer has 30 days to request an export, which Fig provides within a further 30 days (subject to outstanding Fees) in a common machine-readable format. Active-system data is then deleted within 30 days; backups age out within 12 months; records Fig needs for legal, tax or security purposes are retained for up to 6 years with restricted access; aggregated/de-identified data and System Data may be retained indefinitely.
- Fig will provide written certification of deletion on request once complete, and may retain otherwise-deletable data under a legal hold where required by law, a court, or a regulator.
9. Audits
Fig maintains a partner-accessible Trust Centre (www.docs.figgroup.co.uk) with our current security audit reports, security whitepaper, vendor-questionnaire responses, penetration-test summaries and Sub-processor list, available throughout the subscription term. Where a formal audit is needed beyond this, the Customer (or an independent auditor it mandates, who isn't a Fig competitor) may audit Fig's compliance with this DPA once per year, on 30 days' notice, during business hours, at the Customer's cost (save where the audit finds a material breach, in which case Fig reimburses reasonable costs). Fig will co-operate with any audit a regulator requires by law.
10. Liability
Liability under this DPA is subject to the limitation of liability provisions of the Master Subscription Agreement, including the enhanced cap that applies to data-protection and security breaches.
This document is part of Fig's public legal documentation. It works alongside our Terms of Service, Master Subscription Agreement, Product-Specific Terms, MSP Partner Agreement, Service Level Agreement and Support Policy.