What's included
Roles (customer as controller, SimuPhish as processor), processing details, sub-processor list, technical and organisational measures, breach notification, audit rights, deletion and return of data, and international transfer clauses including SCCs and the UK IDTA where required.

