This Addendum forms part of the PB Online service agreement where PB Online processes personal data on a customer’s behalf. PB Online is operated by Padraic O'Toole, trading as PB Online in Ireland. Contact: hello@pbonline.ie.
1. Scope and roles
The customer controls the purposes of processing; PB Online acts as processor for website setup, hosting, maintenance, support and handover. Processing may involve receiving, storing, organising, accessing, transmitting and deleting enquiry and website data during the service and agreed handover period. It may concern visitors, enquirers, customers and staff, and include names, contact details, enquiry messages, business information and technical logs. Sensitive information is outside the standard service unless separately agreed in writing with appropriate safeguards. The order and documented instructions identify the customer, website and any additional processing details.
2. Instructions and confidentiality
PB Online will use customer data only to deliver the agreed service under documented lawful instructions, including instructions about international transfers. If law requires other processing, we will inform the customer before processing unless prohibited. We will flag instructions we believe infringe data-protection law. Access is limited to authorised people bound by confidentiality. The customer is responsible for lawful collection, notices and instructions.
3. Protection and assistance
We will maintain measures appropriate to the data and risks, including access restrictions, secure transfer, account protection, updates, recovery arrangements and checks of safeguards. We will help the customer handle individual rights requests, security obligations, impact assessments and regulatory consultation, taking account of the processing and information available to us. We will notify the customer without undue delay after becoming aware of a personal-data breach and provide available information and updates to support their response.
4. Other providers and transfers
Before a provider processes customer data as our subprocessor, we will identify its legal entity, service, processing location and relevant transfer safeguard in the customer’s written service record and obtain the customer’s written authorisation. No unspecified provider is authorised by this page alone. We will seek authorisation for replacements or additions, impose equivalent data-protection obligations and remain responsible for their performance. Transfers outside the EEA require a valid GDPR transfer mechanism and any necessary supplementary safeguards.
5. Service ending and accountability
At the customer’s choice, we will return or delete personal data when processing ends, and delete copies unless law requires retention. We will agree the return format and timing with the customer, restrict access to any retained backups until their documented deletion cycle, and explain any legally required retention. We will provide information needed to demonstrate compliance and allow and assist proportionate audits and inspections by the customer or its appointed auditor. This Addendum takes priority over conflicting service terms for processing on the customer’s behalf.
6. Processing for our own business
PB Online acts as a separate controller for its own enquiries, billing and business records, as explained in our Privacy Policy. This Addendum does not change those roles.