Draft — not legally reviewed.These documents are placeholder text pending solicitor review and completion of the company's trading details. They do not form a binding agreement in their current state, and must not be relied on in any commercial relationship until an executed, reviewed version is published.

Data Processing Addendum

Data Processing Addendum

⚠ DRAFT — NOT LEGALLY REVIEWED. Placeholder drafted to common UK-SaaS practice under Article 28 UK GDPR, with reference to the UK IDTA and the EU SCCs as amended. It has not been reviewed by a qualified solicitor. This document must be reviewed by legal counsel and the sub-processor list (Annex C) confirmed before it governs any commercial relationship. The UK GDPR / EU GDPR transfer tooling cited here moves periodically and should be rechecked at sign-off.

Effective date: [EFFECTIVE_DATE] Version: 0.1 — draft pending legal review.

This Data Processing Addendum ("DPA") forms part of the Tracker Terms of Service ("Principal Agreement") between the customer ("Controller") and [LEGAL_ENTITY_NAME] ("Processor", "we", "us"). Where there is a conflict between this DPA and the Principal Agreement, this DPA prevails for the subject of personal data processing.

In this DPA, the terms "Personal Data", "Processing", "Data Subject", and "Controller" have the meanings given in the UK GDPR; where applicable, references to UK GDPR include the EU GDPR as retained or applied by the parties.

1. Scope and roles

1.1 This DPA applies where the Processor processes Personal Data on behalf of the Controller in connection with the Service.

1.2 The Controller is the controller of such Personal Data. The Processor is the processor. The Processor will process Personal Data only on the Controller's documented instructions, set out in this DPA and reasonably inferred from the Controller's use of the Service.

2. Description of processing

Mandatory Article 28(3) detail is set out in Annex A. In summary:

  • Subject matter — operation of the Tracker compliance-tracking SaaS.
  • Duration — the term of the Principal Agreement plus any post-termination retention set out in clause 10.
  • Nature and purpose — hosting, storage, retrieval, structuring, analysis, AI-assisted content operations, and deletion of Controller data to enable the Service.
  • Types of Personal Data — authentication details, identifiers of the Controller's personnel and contacts, content the Controller uploads (which may incidentally contain Personal Data), technical logs.
  • Categories of Data Subjects — the Controller's personnel, contractors, and any other individuals referenced in content the Controller uploads.

3. Controller obligations

The Controller:

3.1 is solely responsible for having a lawful basis for instructing the Processor to process Personal Data, for the accuracy and lawfulness of the Personal Data, and for providing any notices and obtaining any consents required from Data Subjects;

3.2 must not submit to the Service any special-category Personal Data (Article 9) or Personal Data relating to criminal convictions and offences (Article 10) without the Processor's prior written consent; and

3.3 must configure the Service appropriately (including access controls, roles, and invitations) to enforce its own policies.

4. Processor obligations

The Processor will:

4.1 process Personal Data only on the Controller's documented instructions (which include the Principal Agreement, this DPA, and the Controller's use of the Service), unless required to process by UK or EU law, in which case we will inform the Controller unless that law prohibits it;

4.2 ensure that personnel authorised to process Personal Data are bound by an obligation of confidentiality;

4.3 implement appropriate technical and organisational security measures to protect Personal Data, as set out in Annex B, and review them periodically;

4.4 taking into account the nature of the processing, provide reasonable assistance to the Controller in responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection);

4.5 taking into account the nature of processing and the information available to the Processor, provide reasonable assistance to the Controller with: (a) security of processing (Article 32); (b) notification of personal-data breaches to the ICO (Article 33); (c) communication of breaches to Data Subjects (Article 34); (d) Data Protection Impact Assessments (Article 35); and (e) prior consultation (Article 36);

4.6 on termination of the Service, delete or return Personal Data as described in clause 10; and

4.7 make available to the Controller information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in clause 9.

5. Sub-processors

5.1 The Controller provides a general authorisation to the Processor to engage sub-processors to perform the Service. The Processor will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA.

5.2 A current list of sub-processors is set out in Annex C. The Processor will notify the Controller of any intended addition or replacement of sub-processors at least 30 days in advance, giving the Controller an opportunity to object on reasonable grounds relating to data protection. If the Controller objects and the parties cannot agree a resolution, the Controller may terminate the affected Service on 30 days' notice.

5.3 The Processor remains responsible for the acts and omissions of its sub-processors as if they were its own.

6. International transfers

6.1 The production Service is hosted in the United Kingdom. Where the Processor or an authorised sub-processor transfers Personal Data out of the UK or the EEA, the Processor relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (IDTA) or, where applicable, the EU Standard Contractual Clauses with the UK IDTA addendum. A copy of the relevant safeguards is available to the Controller on request.

6.2 The Controller hereby enters into those safeguards on behalf of itself and its authorised affiliates to the extent necessary.

7. Personal-data breaches

7.1 The Processor will notify the Controller of any Personal Data breach affecting Controller data without undue delay, and in any case within 72 hours of becoming aware of it. The notification will include, as available at the time: a description of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed.

7.2 The Processor will take reasonable steps to mitigate the effects of the breach and to prevent recurrence.

8. Security measures

The technical and organisational measures the Processor applies are described in Annex B. The Processor may update those measures from time to time, provided the overall level of protection is not reduced.

9. Audits

9.1 On the Controller's reasonable request and no more than once per year (except following a Personal Data breach or where required by a supervisory authority), the Processor will make available to the Controller information reasonably necessary to demonstrate compliance with Article 28 and this DPA.

9.2 The Processor's standard method of demonstrating compliance is to provide: this DPA, Annex B, the latest security review report we can share under NDA, and responses to reasonable written questions.

9.3 Where the Controller requires an on-site audit, the parties will agree reasonable scope, timing (at least 30 days' notice), duration, and cost-sharing in advance. On-site audits are carried out by the Controller or a mutually-agreed auditor under confidentiality, during business hours, without disrupting the Service or any other customer.

10. Termination, deletion, and return

10.1 On termination of the Service for any reason, the Processor will, at the Controller's choice, either return all Personal Data to the Controller or delete it from active systems within 30 days, unless UK or EU law requires continued storage.

10.2 Backup copies will rotate out of the retention window set out in the Privacy Notice; during that period, the Processor will not use the residual data for any purpose.

10.3 The audit log (see Privacy Notice, section 4) is retained for its stated period for accountability and integrity, even after termination. It contains descriptions of actions taken rather than the Controller's underlying content, and is protected by the security measures in Annex B.

11. Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Principal Agreement.

12. Miscellaneous

12.1 Term. This DPA applies for as long as the Processor processes Personal Data on behalf of the Controller.

12.2 Order of precedence. In the event of conflict: (i) this DPA; (ii) the Principal Agreement; (iii) the Privacy Notice.

12.3 Governing law. This DPA is governed by the laws of England and Wales.

12.4 Execution. This DPA is entered into by acceptance of the Principal Agreement and is effective without further signature.


Annex A — Details of processing (Article 28(3))

Item Detail
Subject matter Provision of the Tracker SaaS.
Duration Term of the Principal Agreement plus post-termination retention per clause 10.
Nature and purpose Hosting, storage, retrieval, structuring, analysis, AI-assisted tooling, and deletion of Controller data.
Types of Personal Data Authentication credentials; identifiers and contact details of the Controller's personnel; content the Controller uploads, which may incidentally contain Personal Data; technical metadata (IP, user-agent, timestamps); audit events.
Categories of Data Subjects The Controller's personnel, contractors, customers, and any other individuals referenced in uploaded content.
Obligations and rights of the Controller As set out in this DPA and the Principal Agreement.

Annex B — Technical and organisational security measures

The Processor applies the following measures (Article 32):

Transmission and storage

  • TLS for all traffic between clients and the Service.
  • Encryption-at-rest on the underlying storage tier.
  • Passwords stored only as bcrypt hashes; API tokens stored only as SHA-256 hashes.

Access control

  • Role-based access at the application layer (owner / admin / member for organisations; owner / editor / viewer for projects).
  • Row-level security in the database enforces tenant isolation at a layer below the application — even a compromised app request cannot read another tenant's data.
  • Per-user API tokens, revocable at any time from the Service.
  • Production access is restricted to a small number of named engineers with multi-factor authentication.

Integrity

  • Append-only audit log at the database grant and policy layer — no user or process (including the application role) can update or delete audit rows.
  • All container images digest-pinned; dependencies exact-pinned; CVE-scanned on every version bump, with baseline history retained.

Availability and resilience

  • Daily database backups with a documented, tested restore runbook.
  • Automated rate-limiting on authentication endpoints to deter credential-stuffing.
  • Monitoring of cluster-level health and error rates.

Personnel

  • Contractual confidentiality obligations for staff and contractors.
  • Principle of least privilege for administrative access.

The Processor may update these measures from time to time to address new risks or technology. Material reductions in the level of protection will be notified in advance.

Annex C — Sub-processors

Sub-processor Purpose Region
[SMTP_PROVIDER] Transactional email delivery [TBC]
[HOSTING_PROVIDER] Production compute, storage, networking UK
[PAYMENT_PROVIDER] Payment processing (when billing lands) [TBC]

The Processor will publish updates to this list at least 30 days before engaging a new sub-processor, per clause 5.2.