Data Processing Addendum
Effective date: the date of execution below.
Version: 1.0 (2026-09-01)
Status
This is a working draft prepared for legal review by a UK data protection solicitor before publication. It is designed to satisfy the requirements of UK GDPR Article 28 (controller to processor), EU GDPR Article 28 (controller to processor), Article 26 (joint controllership) for AI-generated insights, EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor) and the UK International Data Transfer Addendum (IDTA) to the EU SCCs.
Sections 1 to 12 are the controller to processor DPA. Schedules A to D are the SCC and UK Addendum, the sub-processor list, the Technical and Organisational Measures and the data subject rights procedure. Section 13 sets out the joint controller allocation for AI insights.
This document is not legal advice. Final execution requires review by a qualified UK solicitor.
Parties
This Data Processing Addendum (DPA) forms part of the master services agreement, terms of service or order form (Agreement) between:
- Plughathon Limited (PlugZero, we, us), a company registered in England and Wales (Company No. 17033249), whose registered office is at Hull, East Riding of Yorkshire, England, acting as processor when processing Customer Personal Data on behalf of the Customer; and
- The Customer identified in the Agreement (Customer, you, Controller).
If the Customer is established in the European Economic Area (EEA) and the processing is governed by Regulation (EU) 2016/679 (EU GDPR), PlugZero additionally acts under the Standard Contractual Clauses at Schedule A. If the Customer is established in the United Kingdom, PlugZero additionally acts under the UK International Data Transfer Addendum at Schedule B. The Customer acts as controller for Customer Personal Data.
1. Definitions
1.1 Customer Personal Data means any personal data (as defined in UK GDPR and EU GDPR Article 4) that PlugZero processes on behalf of the Customer in performance of the Agreement, including any data the Customer, its team members or its data subjects upload to, generate in or send through the PlugZero service.
1.2 Data Subject means an identified or identifiable natural person to whom Customer Personal Data relates.
1.3 Instructions means the documented instructions of the Customer, including this DPA, the Agreement, the service configuration set by the Customer and any subsequent written instructions given by an authorised representative of the Customer.
1.4 Personal Data Breach has the meaning given in UK GDPR and EU GDPR Article 4(12).
1.5 Sub-processor means any third party engaged by PlugZero to process Customer Personal Data on PlugZero behalf, as listed in Schedule C.
1.6 UK GDPR means the UK General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), together with the EU GDPR as it forms part of UK law.
1.7 Other capitalised terms have the meanings given in UK GDPR and EU GDPR.
2. Roles and scope
2.1 The Customer is the controller. PlugZero is the processor. Each party shall comply with its respective obligations under UK GDPR and EU GDPR.
2.2 The Customer acknowledges that PlugZero may also be a joint controller with the Customer for the limited purpose of producing certain AI-generated outputs (sentiment, topic clusters, key drivers, SWOT, AI chat responses) where such outputs are subsequently used to make decisions about data subjects (Article 26 joint controllership). The allocation of obligations is set out in Section 13.
2.3 PlugZero shall process Customer Personal Data only on documented Instructions, including with regard to transfers, unless required to do otherwise by EU or UK law. If PlugZero is required by law to process Customer Personal Data otherwise, it shall inform the Customer of that legal requirement before processing (unless that law prohibits such information on important grounds of public interest).
3. Security of processing (Article 32)
3.1 PlugZero implements the Technical and Organisational Measures (TOMs) set out in Schedule D. PlugZero may update those measures from time to time, provided that the updated measures maintain a level of security appropriate to the risk.
3.2 PlugZero shall ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. Sub-processors
4.1 PlugZero engages the sub-processors listed in Schedule C to process Customer Personal Data. PlugZero shall: (a) impose on each sub-processor data protection terms substantially no less protective than those in this DPA; (b) remain fully liable to the Customer for the performance of each sub-processor obligations; (c) maintain an up to date public list of sub-processors at https://plugzero.app/legal/subprocessors (or any successor URL notified to the Customer).
4.2 Change notification. PlugZero shall give the Customer at least 30 days written notice (by email to the Customer designated notification address and via in-app notice) before adding a new sub-processor or replacing an existing sub-processor that processes Customer Personal Data. The Customer may object on reasonable data protection grounds by written notice within the notice period. The parties shall work in good faith to resolve the objection. If the objection cannot be resolved, the Customer may terminate the affected services without liability and shall be entitled to a pro rata refund of any prepaid fees.
4.3 The Customer consents generally to the engagement of sub-processors listed in Schedule C as at the effective date.
5. Data subject rights
5.1 PlugZero shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures (including the self-service tools in the PlugZero product) to fulfil the Customer obligation to respond to requests for exercising data subject rights under Articles 15 to 22 of UK GDPR and EU GDPR (access, rectification, erasure, restriction, portability, objection, automated decision making).
5.2 PlugZero self-service tools include: per-record right to access export (Article 15); per-record and per-project right to erasure (Article 17); per-record right to rectification (Article 16); structured, machine-readable export (Article 20).
5.3 If PlugZero receives a request directly from a data subject relating to Customer Personal Data, PlugZero shall forward the request to the Customer without undue delay and shall not respond to the data subject except to acknowledge receipt and direct them to the Customer, unless instructed otherwise in writing.
6. Personal data breaches
6.1 PlugZero shall notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 hours of becoming aware of it. The notification shall include: (a) the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; (b) the name and contact details of PlugZero data protection contact (operations@plughathon.com); (c) the likely consequences of the breach; (d) the measures taken or proposed to address the breach and mitigate its possible adverse effects.
6.2 PlugZero shall provide reasonable assistance to enable the Customer to comply with its obligations under Articles 33 (notification to the supervisory authority) and 34 (communication to data subjects) of UK GDPR and EU GDPR. The statutory 72-hour notification period to the ICO or supervisory authority runs from the moment the controller becomes aware. The 24-hour processor to controller notification above is intended to leave sufficient time for the Customer to triage and notify within 72 hours.
7. Data Protection Impact Assessments and prior consultation
PlugZero shall, on request, provide reasonable assistance to the Customer in connection with any data protection impact assessment required by Article 35 of UK GDPR and EU GDPR and any prior consultation with the ICO or other supervisory authority required by Article 36, taking into account the nature of the processing and the information available to PlugZero.
8. Return or deletion at end of services
8.1 On termination or expiry of the Agreement, PlugZero shall, at the Customer written election, delete or return all Customer Personal Data to the Customer, and delete any existing copies, unless EU or UK law requires storage.
8.2 PlugZero standard retention period following termination is 30 days to allow the Customer to export data. Thereafter PlugZero shall delete or anonymise the data and certify deletion on request.
9. Audit rights
9.1 PlugZero shall make available to the Customer all information necessary to demonstrate compliance with Article 28 and this DPA, and shall allow and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
9.2 Audits shall be conducted: (a) on at least 30 days written notice; (b) no more than once per calendar year, except where mandated by a supervisory authority or following a Personal Data Breach; (c) during normal business hours and in a manner that does not unreasonably interfere with PlugZero operations; (d) at the Customer cost, unless the audit reveals material non-compliance, in which case PlugZero shall bear its own reasonable costs.
9.3 PlugZero may satisfy an audit request by providing a current SOC 2 Type II report, ISO 27001 certificate, ISO 42001 certificate (for AI management) or equivalent independent assurance, where applicable.
10. International data transfers
10.1 PlugZero may transfer Customer Personal Data outside the UK or EEA only in accordance with Chapter V of UK GDPR and EU GDPR and as set out in this Section.
10.2 For transfers from the EEA to the United States or other third countries, PlugZero and the Customer agree to the EU Standard Contractual Clauses (Module 2, controller to processor) set out in Schedule A. The SCCs are incorporated into and form part of this DPA.
10.3 For transfers from the UK to third countries, PlugZero and the Customer agree to the UK International Data Transfer Addendum set out in Schedule B, which applies the EU SCCs (as varied by the Addendum) to UK-restricted transfers.
10.4 Where a recipient sub-processor is certified under the EU-US Data Privacy Framework (DPF) and has opted in to the UK Extension to the DPF, transfers to that sub-processor may rely on adequacy regulations in lieu of SCCs or UK Addendum.
10.5 PlugZero shall conduct and maintain a Transfer Risk Assessment for each non-adequacy-country recipient and shall make it available to the Customer on request.
11. Data minimisation, purpose limitation, accuracy
11.1 PlugZero shall not process Customer Personal Data for any purpose other than as necessary to provide the service and comply with Instructions.
11.2 PlugZero shall not train, fine-tune or otherwise use Customer Personal Data to improve any general purpose AI model. PlugZero shall not aggregate Customer Personal Data across customers for benchmarking or any other cross-customer purpose.
11.3 PlugZero shall take reasonable steps to ensure Customer Personal Data is accurate and up to date, having regard to the nature and purposes of processing.
12. Customer obligations
12.1 The Customer shall ensure it has a lawful basis under Article 6 (and Article 9 for special category data, where applicable) for processing the Customer Personal Data it uploads or generates via the service.
12.2 The Customer shall not upload to the service any personal data that the Customer is not lawfully entitled to process.
12.3 The Customer shall be responsible for honouring data subjects rights and for notifying PlugZero of any restriction on processing that the Customer wishes to impose.
12.4 The Customer shall be the single point of contact for data subjects and supervisory authorities in respect of Customer Personal Data.
13. Joint controllership for AI-generated outputs (Article 26)
13.1 The parties acknowledge that, where Customer Personal Data is processed by an AI engine to produce outputs that the Customer subsequently uses to make decisions producing legal or similarly significant effects on data subjects (for example, credit, employment or insurance decisions), both the Customer and PlugZero may be joint controllers for that output.
13.2 Allocation of joint controller responsibilities:
- Customer determines the ultimate purpose and the decision taken on the basis of the output, communicates the decision to the data subject, conducts any required DPIA, responds to data subject rights requests and bears primary responsibility for the lawfulness of the decision.
- PlugZero determines the means of generating the output (model selection, prompt engineering, system instructions), ensures Article 50 transparency (labelling AI-generated outputs), maintains the model registry and version pinning, logs every AI call in the audit log and assists the Customer with data subject rights requests and DPIAs on request.
- The Customer shall not represent the AI-generated output as having been produced solely by a human, or as the work of a named individual.
13.3 The Customer may switch off AI features entirely in account settings. Where the Customer switches off AI features, PlugZero ceases to be a joint controller for that processing.
14. Limitation of liability
14.1 The limitations and exclusions of liability in the Agreement apply to this DPA, except that nothing in this DPA shall limit either party liability for damages incurred by a data subject under Article 82 of UK GDPR and EU GDPR.
15. Order of precedence
In the event of any conflict between this DPA and the Agreement in respect of data protection matters, this DPA shall prevail.
16. Governing law
This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising out of or in connection with it, without prejudice to the Customer rights as a data subject under Article 79 of UK GDPR and EU GDPR.
Schedules
- Schedule A: EU Standard Contractual Clauses (Module 2)
- Schedule B: UK International Data Transfer Addendum
- Schedule C: Sub-processor list
- Schedule D: Technical and Organisational Measures (TOMs)
- Schedule E: Lawful bases most commonly relied on by Customers (informative)
End of DPA body.
