Data Processing Agreement
- Last updated 4 July 2026
- About 6 minutes to read
- Applies worldwide
When this applies
This agreement forms part of our contract whenever we handle personal data belonging to your users, customers, or staff — building or maintaining a system that stores it, migrating a database, running support on a live product, or being given access to your production environment. It does not apply to your own contact details as our client; those we hold as a controller, and the Privacy Policy covers them.
Roles
You are the controller: you decide why and how the personal data is processed. We are the processor: we act only on your documented instructions. If any local law forces us to process data beyond your instructions, we tell you before doing so unless that law forbids the warning.
Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Design, development, maintenance, and support of the software described in the statement of work |
| Duration | For the length of the project plus the agreed retention window, then deletion |
| Nature and purpose | Storage, retrieval, testing, migration, debugging, and support — nothing else |
| Types of data | Whatever your system holds. Typically names, email addresses, account identifiers, and usage records. Special category data only where the statement of work names it |
| Categories of person | Your customers, users, employees, or other people your system serves |
Our obligations
- Process personal data only on your documented instructions, including for transfers to other countries.
- Ensure that everyone authorised to process the data is bound by confidentiality that survives the engagement.
- Apply the technical and organisational measures required by Article 32 — see Security measures below.
- Not engage a subprocessor without your general written authorisation and the notice period set out below.
- Help you meet your own obligations for security, breach notification, impact assessments, and prior consultation.
- Delete or return the data at the end of the engagement, at your choice.
- Make available the information you need to demonstrate compliance, and allow audits as described below.
Subprocessors
You give general authorisation for the subprocessors listed on our Subprocessors page. We publish any addition there at least 30 days before it starts processing, and you may object on reasonable data protection grounds within that window. Every subprocessor is bound by terms no less protective than these, and we remain fully liable to you for their performance.
International transfers
Where personal data leaves the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Module 3, processor to processor, or Module 2 where we act for you directly), completed with the UK International Data Transfer Addendum and the Swiss amendments. We carry out a transfer impact assessment for each destination and apply extra safeguards — encryption, pseudonymisation, minimisation — where the assessment calls for them. On request we set your data's primary region to the EU.
Security measures
The measures in our Security Overview form Annex II of this agreement: encryption in transit and at rest, mandatory multi-factor authentication, least-privilege access reviewed quarterly, secrets held outside version control, weekly dependency patching, tested backups, and logging of administrative actions. We may improve these measures over time but will not weaken them during the engagement.
Assisting you
If one of your users exercises a right — access, deletion, correction, portability, objection — send it to us and we will help you answer within your deadline, at no extra cost for a reasonable volume. We do not respond to your users directly unless you ask us to in writing. We also help with data protection impact assessments and with any prior consultation with a supervisory authority.
Breach notification
We notify you without undue delay and in any case within 24 hours of becoming aware of a personal data breach affecting your data — well inside the 72 hours you have to notify your own authority. The notice describes what happened, the categories and approximate number of people and records involved, the likely consequences, and what we are doing about it. If the full picture is not available at once, we send what we have and follow up rather than waiting.
Deletion and return
At the end of the engagement you choose: we return the data in a structured, commonly used format, or we delete it. Either way, our own copies are removed from live systems within 30 days and age out of backups within 90, except where law requires us to keep something — in which case we tell you what, and why, and keep it protected.
Audits
You may audit our compliance with this agreement once a year, or after a breach affecting your data, on 30 days notice. In the first instance we answer questionnaires and provide documentation, because that satisfies most requests without disrupting either side. Where that is genuinely not enough, an on-site or remote audit is arranged at a mutually workable time, at your cost, with your auditor bound by confidentiality.
Term
This agreement runs for as long as we process personal data on your behalf. The confidentiality, deletion, and audit obligations survive its end.
Signing this
Most clients do not need a bespoke DPA — this one is pre-signed by us and incorporated by reference into every statement of work. If your legal team needs their own paper, send it and we will review it properly rather than refusing on principle.
Need our DPA on your paper?
Send your template. We review vendor DPAs and usually come back within five working days.