← All legal documents

DPA

Version 1 · GB · Effective

1. Scope & Roles

This Data Processing Agreement ("DPA") forms part of the Terms between the Company and the Customer. Where we process personal data on the Customer's behalf, the Customer is the controller and the Company is the processor under applicable data protection law.

2. Processing Instructions

We process personal data only on the Customer's documented instructions, including for transfers, unless required by law. We will inform the Customer if, in our opinion, an instruction infringes applicable data protection law.

3. Security Measures

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and regular review of our security practices.

4. Sub-processing

The Customer authorises our use of the sub-processors listed in our Sub-processors document. We remain responsible for their compliance and will give notice of intended changes, allowing the Customer to object on reasonable grounds.

5. Data Subject Requests & Breach Notification

We assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting breach-notification obligations. We notify the Customer without undue delay after becoming aware of a personal data breach.

6. Deletion & Audit

On termination we delete or return personal data at the Customer's choice, save where retention is required by law. We make available information necessary to demonstrate compliance and allow for audits on reasonable notice.