GDPR Policy
Last updated: 1 April 2026
Formation, duration and termination
This Data Processing Agreement (DPA) activates on the service agreement's effective date and remains active throughout the contract period. Upon termination of the service agreement, this DPA automatically terminates.
Scope of processing
Processing occurs only on documented instructions from the Controller, including transfers to third countries, unless required by law. Activities support platform services, application upkeep, and analytics per the underlying agreement.
Processor obligations
Compliance & Security: The Processor must adhere to GDPR with measures aligned to ISO 27001, NCSC, and/or NIST standards, including encryption and access control.
Sub-Processors: The Processor cannot engage third parties without prior written consent of the Controller.
Data Subject Requests & Breaches: The Processor must assist with GDPR Articles 15–22 requests and notify the Controller of any Personal Data breach within 48 hours.
Upon termination, the Processor must return or permanently delete Personal Data unless otherwise required by law.
International transfers
Transfers outside the EEA require Standard Contractual Clauses (SCCs) or equivalent safeguards, plus explicit written Controller consent.
Audits
Controllers may audit annually or as needed for compliance verification. The Controller bears audit costs unless non-compliance is discovered, which shifts expenses to the Processor.
Confidentiality
The Processor shall maintain strict confidentiality of all Personal Data, with obligations extending to all personnel and sub-processors.
Breach notification
Notifications are required within 48 hours, detailing the breach's nature, scope, and potential impact on Data Subjects. The Processor reimburses the Controller for breach management costs resulting from Processor non-compliance.
Sub-processors
Current sub-processors are documented in service agreements, with Controller objection rights for new additions.
Liability
The Processor remains liable for non-compliance breaches and indemnifies the Controller for fines or claims arising directly from its failures.
Governing law
This DPA is governed by the laws of England and Wales. Written amendments require both parties' signatures.
Annex A: details of processing
- Data Subjects: Employees, clients, and platform users
- Data Categories: Names, contact information, IP addresses, compliance records, and client-uploaded sensitive information
- Activities: Storage, retrieval, transmission, and deletion per Controller direction
Annex B: technical and organisational measures
- Ensure lawful processing
- Provide processing instructions
- Conduct periodic compliance audits
- Encryption of data at rest and in transit
- Multi-factor authentication
- Real-time monitoring
- Incident response procedures per NCSC guidance
- Periodic penetration testing and vulnerability assessments