Data Processing Terms

The Article 28 terms that apply when we process personal data on a customer’s behalf, and who we use to do it.

When these terms apply

These terms apply where an organisation (the “customer”) uses the service and we process personal data on its behalf. The customer is the controller; we are the processor. They form part of the End User Licence Agreement and satisfy Article 28 of the UK GDPR. Where a customer has signed a separate data processing agreement with us, that one applies instead.

What we process, and why

What we undertake

Sub-processors

The customer gives general authorisation for the sub-processors below. We remain responsible for their performance and impose equivalent obligations on them.

We will give at least 30 days’ notice before adding or replacing a sub-processor. If the customer reasonably objects on data protection grounds, it may terminate the affected part of the service without penalty.

A customer’s own sign-in provider is not our sub-processor: the customer chooses and controls it, and it acts for the customer, not for us.

Transfers

Personal data may be processed outside the United Kingdom. Where it is, we put in place the UK International Data Transfer Agreement or the Addendum to the European Commission’s standard contractual clauses, unless the destination is covered by adequacy regulations, and we assess whether the safeguards are effective in practice.

Last updated 29 July 2026.

All policies · Sign in