Who we are
This website and the OnyxOne service are operated by ONYXONE TECHNOLOGIES LTD, a private limited company registered in England and Wales under company number 17352132, whose registered office is at 3 Mantua Street, London, England, SW11 2NE. In this document, “OnyxOne”, “we”, “us” and “our” mean ONYXONE TECHNOLOGIES LTD.
- Legal name: ONYXONE TECHNOLOGIES LTD
- Company number: 17352132
- Registered in: England and Wales
- Registered office: 3 Mantua Street, London, England, SW11 2NE
- Governing law: the laws of England & Wales (United Kingdom)
- Contact: hello@onyxone.uk
1. Roles & scope
For personal data processed on the Controller's behalf, the Controller is the controller and OnyxOne is the processor. OnyxOne processes such personal data only on the Controller's documented instructions, including as set out in the Terms and this DPA, unless required otherwise by law.
2. Subject matter & duration
- Subject matter: provision of the OnyxOne Service.
- Duration: for the term of the Terms and until deletion or return of the personal data.
- Nature & purpose: hosting, authentication, screening, due-diligence, case-management and compliance operations necessary to deliver the Service.
- Data subjects: the Controller's customers, counterparties, third parties, and authorised personnel.
- Categories: identifiers, contact and organisation data, screening and due-diligence records and related risk data.
3. Processor obligations
- Process personal data only on documented instructions.
- Ensure personnel authorised to process are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Article 32).
- Assist the Controller with data-subject requests and with its security, breach-notification and impact-assessment obligations.
- Make available information necessary to demonstrate compliance.
4. Security measures
- Encryption in transit and at rest.
- Role-based access control, segregation of duties and server-side-only secret handling.
- Signed, hardened sessions and least-privilege service credentials.
- Logging, monitoring, an immutable audit trail and a documented incident-response process.
5. Sub-processors
The Controller authorises the use of the sub-processors listed in our Privacy Policy, together with screening and data providers configured for the Controller's deployment. We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give notice of intended changes and a chance to object.
6. Personal data breach
We notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, with the information needed for the Controller to meet its own notification duties.
7. Audits
We make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an appointed auditor, subject to reasonable confidentiality and security safeguards.
8. International transfers
Where processing involves transfers outside the UK/EEA, we rely on an appropriate transfer mechanism (adequacy, UK IDTA or Standard Contractual Clauses) with supplementary measures where required.
9. Deletion or return
On termination, we delete or return the Controller's personal data at the Controller's choice, save where retention is required by law.