Get a free audit

Data Processing Agreement

Version 0.4 (draft). Last updated [DATE].

This Data Processing Agreement (DPA) forms part of the agreement between [Max Okunev], a sole trader trading as Padon, address for service [VIRTUAL OFFICE ADDRESS] (we, us, the Processor), and the business named in the Order (you, the Controller), made under our Terms of Service at https://padon.ai/terms (the Terms). It sets out the terms required by Article 28(3) of the UK GDPR.

1. Definitions

1.1 Words defined in the Terms have the same meaning here. In addition:

2. Roles and scope

2.1 For Client Personal Data, you are the Controller and we are the Processor.

2.2 This DPA does not apply to Personal Data we process as a Controller for our own purposes, such as the contact details of your staff that we use to manage our relationship with you, our marketing records, or our accounts. Our privacy notice at https://padon.ai/privacy covers that data.

2.3 Payment data you give to GoCardless or Stripe is processed by those providers as independent controllers under their own terms and privacy notices. They are not our Sub-processors for Client Personal Data.

2.4 The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.

3. Your obligations

3.1 You are responsible for:

(a) having a lawful basis for the processing you ask us to carry out, and for the instructions you give us;

(b) giving Data Subjects the information required by Articles 13 and 14 of the UK GDPR, including a privacy notice on your Site that explains how enquiries sent through your forms are used;

(c) the accuracy and lawfulness of the Client Personal Data you give us, including personal data in Client Content such as staff names, photos and customer reviews;

(d) where your forms may receive special category data, for example health information sent to a health or care business, having a condition for that processing under Article 9 of the UK GDPR (and, where needed, Schedule 1 to the Data Protection Act 2018); and

(e) not asking visitors to send criminal offence data or payment card details through your Site’s forms unless we have agreed in writing that the form is suitable for it.

3.2 Visitors may include health or other sensitive details in free-text fields even when not asked. For health and care businesses, we will add a short note to your forms asking visitors not to include medical details, unless you tell us not to. We recommend you keep it.

4. Our obligations

4.1 We will:

(a) process Client Personal Data only on your documented instructions, including with regard to Restricted Transfers, unless we are required to do otherwise by UK law. In that case we will tell you of that legal requirement before processing, unless the law prohibits us from telling you on important grounds of public interest. The Agreement and your use of the Services are your documented instructions. Further instructions must be consistent with the Agreement;

(b) tell you immediately if, in our opinion, an instruction infringes Data Protection Law;

(c) make sure that anyone we authorise to process Client Personal Data is bound by a duty of confidentiality. Our backup contact named in clause 7.1 has access only to what is needed to notify you of a Personal Data Breach, and has given us a written confidentiality undertaking;

(d) take the security measures required by Article 32 of the UK GDPR, including those in Annex 3;

(e) comply with clause 5 when engaging Sub-processors;

(f) taking into account the nature of the processing, assist you by appropriate technical and organisational measures, so far as possible, to respond to requests from Data Subjects exercising their rights under Chapter 3 of the UK GDPR;

(g) assist you, taking into account the nature of the processing and the information available to us, in meeting your obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation with the ICO);

(h) at the end of the Services, delete or return Client Personal Data under clause 9; and

(i) make available to you all information necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits, including inspections, under clause 8.

4.2 We will not sell Client Personal Data, use it for our own purposes, or use it to contact your customers. We will not use Client Personal Data to train AI models. We do not send form enquiries to our AI provider, and our AI provider’s commercial terms do not allow it to train its models on content we send it. All Sub-processors process Client Personal Data only on our instructions, under their data processing terms.

4.3 If we receive a request directly from a Data Subject about Client Personal Data, we will pass it to you within 5 Business Days and will not respond to it ourselves except to tell the Data Subject that we have passed it on, unless you ask us to.

5. Sub-processors

5.1 You give us general written authorisation to engage Sub-processors. The Sub-processors we use at the date of this DPA are listed in Annex 2.

5.2 We will tell you by email at least 30 days before we add or replace a Sub-processor, and update Annex 2 at https://padon.ai/dpa. You may object on reasonable data protection grounds within that 30-day period. If you object, we will discuss your concerns in good faith. If we cannot resolve them, you may end the Agreement by written notice before the change takes effect, without paying the Early Exit Amount under the Terms.

5.3 We will impose on each Sub-processor, by written contract, data protection obligations that give the same protection as this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Where a Sub-processor offers only its standard terms, we will review those terms to check that they meet Article 28 of the UK GDPR before we use it.

5.4 We remain fully liable to you for the performance of each Sub-processor’s data protection obligations.

6. International transfers

6.1 We will only make, or allow a Sub-processor to make, a Restricted Transfer if it is covered by one of the following:

(a) UK adequacy regulations, including the Data Protection (Adequacy) (United States of America) Regulations 2023 (the UK-US data bridge) where the recipient is certified under the UK Extension to the EU-US Data Privacy Framework;

(b) appropriate safeguards under Article 46 of the UK GDPR, such as the International Data Transfer Agreement issued under section 119A of the Data Protection Act 2018 or the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with any transfer risk assessment required by Data Protection Law; or

(c) another mechanism permitted by Chapter 5 of the UK GDPR.

6.2 The transfer mechanism for each Sub-processor at the date of this DPA is set out in Annex 2. If a mechanism stops being available, we will rely on another permitted mechanism or stop the transfer.

7. Personal Data Breaches

7.1 We will tell you without undue delay, and in any case within 24 hours, after becoming aware of a Personal Data Breach affecting Client Personal Data. If [Max Okunev] is unavailable, our named backup contact, [BACKUP CONTACT NAME], will do this.

7.2 Our notice will, so far as we know at the time, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to deal with it. If we do not have all of that information at first, we will give it to you in stages as soon as we have it.

7.3 We will take reasonable steps to contain and investigate the breach and to reduce its effects, and will give you the help you reasonably need to notify the ICO and Data Subjects where required. Unless the law requires us to, we will not notify the ICO or Data Subjects about a breach affecting Client Personal Data without first consulting you.

8. Information and audits

8.1 We will answer your reasonable written questions about our processing of Client Personal Data, and give you copies of the relevant parts of our Sub-processors’ security documentation where we are allowed to share them.

8.2 If our written answers do not reasonably satisfy you, or the ICO requires it, you (or an independent auditor bound by confidentiality whom we do not reasonably object to) may audit our compliance with this DPA. You must give us at least 30 days’ written notice, carry out the audit during business hours without unreasonable disruption, and pay your own costs. Except where the audit follows a Personal Data Breach or is required by the ICO, you may audit no more than once in any 12-month period. Audits of Sub-processors are limited to the audit rights we have under our contracts with them.

9. Deletion and return

9.1 When the Services end, we will, at your choice, delete Client Personal Data or return it to you, and then delete existing copies, within 30 days, unless UK law requires us to keep it. If you do not tell us your choice within 30 days of the end of the Services, we will delete it.

9.2 Copies in backups will be deleted in the normal backup cycle, which is no more than [BACKUP RETENTION PERIOD, e.g. 30] days. Until then, we will keep them secure and not use them for any other purpose.

9.3 While the Services continue, we keep records of enquiries sent through your Site’s forms for [FORM RECORD RETENTION PERIOD, e.g. 12 months] and then delete them, so that we can send your monthly enquiry report and deal with delivery problems. Copies of enquiries emailed to you are in your own email account and are your responsibility.

10. Liability and general

10.1 Each party’s liability under or in connection with this DPA is subject to the limits and exclusions in clause 15 of the Terms. Nothing in this DPA limits either party’s liability to Data Subjects or the ICO under Data Protection Law.

10.2 If there is a conflict between this DPA and the Terms about the processing of Client Personal Data, this DPA wins.

10.3 This DPA lasts for as long as we process Client Personal Data for you, even if that continues after the Agreement ends.

10.4 We may update this DPA under clause 20 of the Terms, and to reflect changes in Data Protection Law or ICO guidance.

10.5 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex 1: Details of the processing

Item Details
Subject matter Hosting your Site and its content, and running the enquiry forms on your Site.
Duration The term of the Agreement and the period after it ends until the data is deleted or returned under clause 9.
Nature of processing Receiving, storing, hosting, transmitting, displaying, counting and deleting data. Generating and editing Site content with AI tools.
Purpose Providing the Services under the Terms: delivering enquiries from your Site’s visitors to you, producing your monthly enquiry report, publishing your Site and making changes you ask for.
Data Subjects (a) People who send enquiries through your Site’s forms (your customers and prospective customers). (b) People whose personal data appears in Client Content, such as your staff, owners and customers who left reviews.
Types of Personal Data (a) Whatever a visitor enters in a form, typically name, email address, phone number, postcode and the message, together with the date and time of submission, the page it was sent from [and technical data such as IP address used to deliver the form and block spam]. (b) Names, job titles, photos, quotes and reviews included in Client Content.
Special category data Not asked for by default. Health information may be volunteered by enquirers in free-text fields, particularly for health and care clients (see clauses 3.1(d) and 3.2). Some health and care clients may choose forms that ask for it, in which case clause 3.1(d) applies.

Annex 2: Sub-processors

Status at [DATE].

Sub-processor Purpose Location of processing Transfer mechanism
Cloudflare, Inc. Hosting the Site, receiving and storing form submissions, content delivery and security Global network; company based in the USA. Storage region: [CLOUDFLARE STORAGE REGION] UK-US data bridge (Cloudflare relies on the UK Extension to the EU-US Data Privacy Framework), with the UK Addendum to the EU Standard Contractual Clauses in Cloudflare’s DPA as a fallback
Resend ([RESEND CONTRACTING ENTITY, see Resend DPA]) Sending enquiry emails and monthly reports to you USA UK-US data bridge (UK Extension to the EU-US Data Privacy Framework) [VERIFY ON THE DPF LIST BEFORE PUBLISHING]; Standard Contractual Clauses with UK Addendum in Resend’s DPA
Anthropic, PBC AI processing of Site content and change requests (Client Content). Not form enquiries USA UK Addendum to the EU Standard Contractual Clauses in Anthropic’s DPA, which is incorporated into its Commercial Terms. Anthropic is not relied on as certified under the Data Privacy Framework. We have carried out a transfer risk assessment for this transfer
Google LLC (Google Workspace) [DELETE IF NOT USED] Our business email, where enquiries, Client Content or support requests pass through our inbox USA and other countries where Google operates UK-US data bridge (UK Extension to the EU-US Data Privacy Framework) [VERIFY ON THE DPF LIST BEFORE PUBLISHING]; Google’s Cloud Data Processing Addendum

GoCardless Ltd and Stripe are not Sub-processors. They process payment data as independent controllers (see clause 2.3).

Annex 3: Security measures

We maintain at least the following measures, proportionate to a small business processing low-risk enquiry data:

  1. Access control. Only [Max Okunev] has access to production systems and Client Personal Data. Our backup contact, [BACKUP CONTACT NAME], has access only to what is needed to notify clients of a Personal Data Breach (the client contact list and the breach log), not to form enquiries or Site content, and has signed a written confidentiality undertaking. Any future staff or contractors will be given only the access they need and will be bound by confidentiality.
  2. Authentication. Unique accounts, strong passwords held in a password manager, and multi-factor authentication on every service that holds Client Personal Data (hosting, email, AI provider, code repository, payment providers).
  3. Encryption. All Sites and form submissions are served over HTTPS (TLS). Data stored with our providers is encrypted at rest by those providers. Our laptop and phone use full-disk encryption and a screen lock.
  4. Devices and software. Operating systems, browsers and tools are kept up to date with security patches. We do not process Client Personal Data on shared or public computers.
  5. Data minimisation. Forms collect only the fields you ask for. Form records are kept only for the period in clause 9.3. We do not send form enquiries to our AI provider.
  6. Separation. Each client’s Site and form records are kept logically separate from other clients’.
  7. Spam and abuse protection. Forms use measures to block automated abuse.
  8. Supplier review. We review each Sub-processor’s security and data protection terms before use and when they change.
  9. Backups and recovery. Site files are kept in version control so a working version can be restored.
  10. Incident response. We have a written procedure for detecting, recording, containing and reporting Personal Data Breaches, and we keep a breach log. A named backup contact, [BACKUP CONTACT NAME], can act on a breach if [Max Okunev] is unavailable.
  11. Deletion. Data is deleted at the end of its retention period and at the end of the Services under clause 9.