Data Processing Addendum
Last updated: 30 July 2026 · UK GDPR Article 28 terms + subprocessor register
1. Scope & roles
This Data Processing Addendum ("DPA") forms part of the agreement between the customer organisation ("Customer", the controller) and ProcessTwin AI Ltd ("ProcessTwin", the processor) and applies to personal data ProcessTwin processes on the Customer's behalf. It is drafted for UK GDPR and the Data Protection Act 2018; references to UK GDPR include EU GDPR where that regulation applies to the Customer.
2. Details of processing
Subject matter and nature: process discovery over connected work tools, opportunity scoring, operation of governed AI agents, analytics and support. Duration: the term of the agreement plus the deletion grace period. Purpose: providing the Service as configured by the Customer.
Categories of data subjects: the Customer’s personnel and the individuals appearing in connected content (for example email correspondents). Categories of data: workspace membership data; business communications metadata and content within the scopes the Customer connects (subject to scope controls and PII masking); agent inputs/outputs; usage records. The Service is not intended for special category data, and the Customer agrees not to direct such data into it.
3. Processor obligations (UK GDPR Article 28(3))
ProcessTwin will: (a) process personal data only on the Customer’s documented instructions — given through the Service’s configuration and the agreement — including for international transfers, unless required otherwise by law, in which case ProcessTwin informs the Customer unless prohibited; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures described at /security and in SECURITY.md — including per-tenant envelope encryption, enforced tenant isolation, tamper-evident audit chains, retention automation and executor-enforced AI guardrails; (d) respect the subprocessor conditions below; (e) assist the Customer, insofar as possible, in responding to data subject requests — the Service provides self-serve export and deletion; (f) assist with the Customer’s Articles 32–36 obligations, including breach information and DPIA input; (g) at the Customer’s choice, delete or return all personal data at the end of the Service (export is self-serve; deletion runs after a 30-day grace period and removes derived data and per-tenant keys); and (h) make available information necessary to demonstrate compliance and allow and contribute to audits, initially by written response and, where reasonably required, an audit under confidentiality on 30 days’ notice, at the Customer’s cost.
4. Subprocessors
The Customer gives general written authorisation for the subprocessors listed below. ProcessTwin imposes data protection obligations no less protective than this DPA on every subprocessor and remains fully liable for their performance. ProcessTwin will give at least 30 days’ notice of any intended addition or replacement (via the Service or email), during which the Customer may object on reasonable data-protection grounds; if no resolution is found the Customer may terminate the affected Service for a pro-rata refund.
AI subprocessors apply only where the Customer enables AI features, per workspace configuration. Under our agreements, customer content is not used to train providers’ models.
| Subprocessor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Netcup GmbH | Hosting — all workspace content and databases | Germany (EEA) | UK→EEA: UK adequacy regulations |
| Clerk, Inc. | Authentication & user identity | United States | UK-US Data Bridge / IDTA + UK Addendum |
| Stripe Payments Europe / Stripe, Inc. | Payments & invoicing | Ireland / United States | UK adequacy (IE); UK-US Data Bridge (US) |
| Anthropic, PBC | AI processing — only when enabled for the workspace | United States | IDTA + UK Addendum; no training on customer content |
| OpenAI, LLC | AI processing — only when enabled for the workspace | United States | IDTA + UK Addendum; no training on customer content |
5. International transfers
Workspace content is hosted in Germany; UK→EEA transfers rely on the UK adequacy regulations. Where a subprocessor processes personal data in the United States, transfers rely on the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the ICO’s International Data Transfer Agreement or the UK Addendum to the EU SCCs, with supplementary measures where appropriate.
6. Personal data breach
ProcessTwin notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s personal data, with the information reasonably required for the Customer’s own UK GDPR Article 33 notification (which, for controllers, is due to the ICO within 72 hours where the breach is likely to result in a risk). ProcessTwin documents all breaches and remediation.
7. Liability & order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service, except where UK GDPR provides otherwise. If this DPA conflicts with the Terms, this DPA prevails for data protection matters.
Enterprise customers can request a countersigned copy of this DPA including the IDTA / UK Addendum as executed documents: privacy@processtwin.ai. This document is maintained as part of the product and reviewed with counsel before material releases.