Last updated: 14 August 2026
This Schedule sets out the terms on which the Supplier processes personal data on behalf of the Customer and forms part of the agreement. It is intended to satisfy the requirements of Article 28 of the UK GDPR.
Last updated: 14 August 2026
In this Schedule, the terms controller, processor, data subject, personal data, personal data breach, processing and appropriate technical and organisational measures have the meanings given to them in the Data Protection Laws.
Processing Instructions: the documented instructions of the Customer set out in this Schedule and as otherwise notified by the Customer to the Supplier in writing from time to time; and Sub-processor: any third party engaged by the Supplier to process personal data in connection with the Services.
The Parties acknowledge that, for the purposes of the Data Protection Laws, the Customer is the controller and the Supplier is the processor in respect of the personal data processed under this agreement. The nature and details of the processing are set out in Annex 1 (Details of Processing).
Each Party shall comply with its respective obligations under the Data Protection Laws. Nothing in this Schedule relieves either Party of its own direct responsibilities and liabilities under the Data Protection Laws.
The Supplier shall process the personal data only on and in accordance with the Customer's documented Processing Instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by applicable law; in which case, the Supplier shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Supplier shall immediately inform the Customer if, in its opinion, a Processing Instruction infringes the Data Protection Laws.
The Supplier shall ensure that any person authorised to process the personal data (including its staff and Sub-processors) is subject to a binding duty of confidentiality in respect of that personal data and processes it only on the Customer's instructions.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, the Supplier shall implement and maintain the appropriate technical and organisational measures set out in Annex 2 (Technical and Organisational Measures) to ensure a level of security appropriate to the risk, including as appropriate the measures referred to in Article 32 of the UK GDPR.
The Supplier shall not engage any Sub-processor without the prior specific or general written authorisation of the Customer. The Customer provides its general authorisation to the engagement of the Sub-processors listed in Annex 1. Where the Supplier intends to appoint a new Sub-processor or replace an existing one, it shall give the Customer prior written notice and a reasonable opportunity to object, and shall not appoint that Sub-processor if the Customer reasonably objects.
The Supplier shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those set out in this Schedule, and shall remain fully liable to the Customer for the performance of each Sub-processor's obligations.
The Processor may transfer or permit access to Personal Data outside the United Kingdom where necessary to provide the Services or otherwise fulfil its obligations under this DPA.
Where Personal Data is transferred to a country or territory that is not the subject of UK adequacy regulations under the UK GDPR, the Processor shall ensure that the transfer is subject to an appropriate safeguard in accordance with applicable Data Protection Laws, including, where applicable:
(a) the UK International Data Transfer Agreement (IDTA);
(b) the UK Addendum to the European Commission's Standard Contractual Clauses;
(c) regulations recognising the destination country or territory as providing an adequate level of protection; or
(d) any other lawful transfer mechanism recognised under applicable Data Protection Laws.
The Processor shall ensure that any recipient of the Personal Data is subject to contractual or other legally binding obligations that provide a level of protection for the Personal Data that is substantially equivalent to that required under this DPA and applicable Data Protection Laws.
Taking into account the nature of the processing, the Supplier shall assist the Customer by appropriate technical and organisational measures, insofar as is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising the data subject's rights under the Data Protection Laws.
The Supplier shall assist the Customer in ensuring compliance with its obligations relating to security of processing, notification of personal data breaches, data protection impact assessments and prior consultation with the Information Commissioner, taking into account the nature of the processing and the information available to the Supplier.
The Supplier shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the personal data, and shall provide the Customer with sufficient information to allow the Customer to meet its obligations to report or inform data subjects and the Information Commissioner. The Supplier shall co-operate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation and remediation of the breach.
On termination or expiry of the agreement, and at the choice of the Customer, the Supplier shall return to the Customer or securely delete all the personal data and delete existing copies, save to the extent that applicable law requires the Supplier to retain that personal data. This paragraph operates in addition to, and is consistent with, clause 7.7 (Data on exit).
The Supplier shall make available to the Customer all information necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and this Schedule, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. This paragraph operates in addition to the audit and information rights set out in clause 7.
The Customer provides its general authorisation to the engagement of the Sub-processors set out in the table below, in accordance with paragraph 6 (Sub-processing).
| Sub-processor | Country of registration | Data processed |
|---|---|---|
Amazon Web Services | Luxembourg | Identity data, contact information, identification documents, verification results, technical data |
Anthropic | United States | Technical data; limited personal data contained in content submitted to AI features |
Cloudflare | United Kingdom | Technical data (IP addresses and traffic metadata) |
Datadog | United States | Technical data; limited identity and contact data in logs |
Expel | United States | Technical data; limited identity and contact data in security logs and alerts |
GitHub | United States | Technical data; source code and limited identity and contact data of authorised users |
Google Cloud | Ireland | Identity data, contact information, technical data |
Google Workspace | Ireland | Contact information, identity data, correspondence content |
Notion | United States | Identity data, contact information, content within internal documents |
Okta | United States | Identity data, contact information, authentication and access data |
PagerDuty | United States | Contact information of on-call personnel; technical incident data |
Slack | United States | Identity data, contact information, message content |
Smartdev | United Kingdom | Technical data; limited personal data accessed during software development and support |
Vanta | United States | Technical data; limited identity and contact data for security and compliance monitoring |