Data Processing & Sub-Processors
This Data Processing & Subprocessor Framework (“Framework”) sets out the minimum requirements applicable where CariBound Ltd, a company incorporated and existing under the laws of Barbados, company number 36108, with its registered office at Cobbler’s Rock, The Crane, St Philip, Barbados (“CariBound”) engages a third party to process personal data on CariBound’s behalf in connection with Future Caribbean.
It is intended to operate as a framework for vendors, contractors, technology providers, partners and other service providers that process personal data for CariBound.
Where applicable law or the nature of the services requires a more detailed data processing agreement, the Parties shall enter into additional terms.
1. Definitions
For this Framework:
“Personal Data” means information relating to an identified or identifiable individual.
“Processing” means any operation performed on Personal Data, including collection, access, storage, use, disclosure, transfer or deletion.
“Processor” means the service provider processing Personal Data on behalf of CariBound.
“Subprocessor” means another organisation engaged by the Processor to process Personal Data in connection with the services.
Terms such as “Controller” and “Processor” shall have the meaning given to them under applicable data protection law.
2. Processing Instructions
The Processor shall:
process Personal Data only to provide the services agreed with CariBound;
follow CariBound’s documented instructions concerning the Processing of Personal Data;
not sell, rent or use Personal Data for its own unrelated purposes; and
promptly notify CariBound if it believes an instruction conflicts with applicable law.
The categories of individuals, types of Personal Data and purposes of Processing should be documented in the applicable service agreement, statement of work or processing schedule.
3. Confidentiality
The Processor shall ensure that persons authorised to access Personal Data are subject to appropriate confidentiality obligations.
Access shall be limited to persons who reasonably require it to perform the relevant services.
4. Security
The Processor shall maintain appropriate technical and organisational measures designed to protect Personal Data against unauthorised access, loss, destruction, alteration or disclosure.
Depending on the nature of the Processing, appropriate measures may include:
access controls and authentication;
encryption where appropriate;
secure transmission and storage;
logging and monitoring;
vulnerability management;
backup and recovery procedures;
employee security training; and
incident response procedures.
Security measures shall be proportionate to the nature and risks of the Personal Data being processed.
5. Security Incidents
The Processor shall notify CariBound without undue delay after becoming aware of a security incident involving Personal Data processed for CariBound.
The notification should, to the extent known, include:
the nature of the incident;
the categories of Personal Data affected;
the affected individuals or approximate number of individuals;
the likely consequences; and
measures taken or proposed to address the incident.
The Processor shall reasonably cooperate with CariBound in investigating, containing and responding to the incident.
The Processor shall not make a public statement specifically concerning a CariBound Personal Data incident without consulting CariBound, unless legally required to do so.
6. Subprocessors
The Processor may use Subprocessors only where:
they are necessary to provide the agreed services;
CariBound has been given appropriate information about their role where required by applicable law; and
the Subprocessor is subject to written data protection obligations providing an appropriate level of protection.
The Processor remains responsible for its Subprocessors’ compliance with the obligations applicable to them.
CariBound may object to a proposed Subprocessor where it has reasonable data protection grounds for doing so.
7. International Transfers
The Processor shall not transfer Personal Data internationally except in accordance with applicable data protection law.
Where a transfer requires a recognised safeguard, the Parties shall implement the appropriate mechanism, which may include contractual safeguards, adequacy arrangements or another lawful transfer mechanism.
The Processor shall provide reasonable information needed by CariBound to assess the location and legal basis of international Processing.
8. Data Subject Requests
Where the Processor receives a request from an individual concerning Personal Data processed on CariBound’s behalf, it shall promptly notify CariBound unless prohibited by law.
The Processor shall reasonably assist CariBound with requests relating to:
access;
correction;
deletion;
restriction;
portability;
objection; and
other rights applicable under relevant data protection law.
The Processor shall not respond substantively to a request on CariBound’s behalf unless authorised to do so.
9. Data Protection Impact Assessments
Where reasonably requested, the Processor shall provide information and reasonable assistance needed for CariBound to assess privacy risks associated with the services, including where a Data Protection Impact Assessment or similar assessment is required.
10. Retention and Deletion
The Processor shall retain Personal Data only for as long as reasonably necessary to provide the services or as otherwise instructed or required by law.
At the end of the relevant services, the Processor shall, at CariBound’s direction, return or securely delete Personal Data unless retention is required by law.
Where Personal Data is retained for legal or backup purposes, it shall remain protected and shall not be used for unrelated purposes.
11. AI and Machine Learning
The Processor shall not use Personal Data provided by or on behalf of CariBound to train, fine-tune or improve a general-purpose AI model unless:
CariBound has expressly authorised the use;
the purpose and nature of the use have been disclosed;
an appropriate legal basis exists; and
the use is consistent with applicable privacy commitments and law.
The Processor shall disclose material use of AI systems that involves Personal Data where reasonably relevant to the services.
12. Audit and Information
The Processor shall provide information reasonably necessary for CariBound to demonstrate compliance with this Framework.
Where reasonably necessary and proportionate, CariBound may request relevant security or privacy documentation, such as independent audit reports, certifications, policies or security questionnaires.
Any audit shall be conducted in a manner that minimises disruption to the Processor’s business and protects the confidentiality of its systems and information.
13. Government and Law Enforcement Requests
If the Processor receives a legally binding request from a government authority or law enforcement body for Personal Data processed on CariBound’s behalf, it shall, where legally permitted:
notify CariBound promptly;
provide reasonable information about the request; and
disclose only the Personal Data legally required.
Nothing in this Framework requires the Processor to breach applicable law.
14. Data Location and Processing Register
CariBound should maintain an internal record of material processors and Subprocessors, including where reasonably practicable:
provider name;
service provided;
categories of Personal Data processed;
categories of individuals;
processing location;
Subprocessors;
international transfer mechanism;
retention period; and
security assessment status.
The register should be reviewed periodically and when material services or processing arrangements change.
15. Conflicts with Other Agreements
This Framework supplements the relevant commercial, services or partner agreement between the Parties.
Where a separate data processing agreement has been signed for particular services, that agreement will govern the relevant Processing to the extent of any inconsistency.
Mandatory provisions of applicable data protection law prevail over this Framework.
16. General
Nothing in this Framework requires either Party to process Personal Data where doing so is not necessary for the agreed services.
The Parties shall cooperate in good faith to maintain appropriate privacy and security protections as the Future Caribbean platform and its services develop.
This Framework may be incorporated into a services agreement, Partner Agreement, sponsorship agreement or other written engagement by reference.
← Back to Future Caribbean