Data Processing Agreement

Annex to the Rigular Terms and Conditions

Version: 1.0 | Last updated: June 12, 2026

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions ("Agreement") between Rigular Ltd ("Processor", "Company", "We") and the Customer ("Controller", "You") and governs the processing of Personal Data by the Processor on behalf of the Controller in connection with the Service. Where the Processor processes Personal Data subject to the EU GDPR, the Processor's representative in the Union under Article 27 of the EU GDPR is Rigular SARL (60 rue François 1er, 75008 Paris, France).


1. Definitions

1.1 In this DPA, capitalised terms not otherwise defined herein have the meanings given to them in the Agreement. In addition:

  • "Applicable Data Protection Laws" means all laws and regulations relating to the processing of Personal Data that apply to the performance of this DPA, including (a) the UK GDPR and the Data Protection Act 2018; (b) the EU GDPR (Regulation 2016/679); (c) the ePrivacy Directive 2002/58/EC (as amended); and (d) any national implementing legislation, in each case as amended, replaced, or superseded from time to time.
  • "Controller" means the Customer, as the entity that determines the purposes and means of the processing of Personal Data.
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
  • "EEA" means the European Economic Area.
  • "International Data Transfer" means a transfer of Personal Data from the UK or EEA to a country outside the UK or EEA that has not been recognised as providing an adequate level of data protection.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller in connection with the Service.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
  • "Processing" (and its cognates "Process", "Processed") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
  • "Processor" means the Company, as the entity that Processes Personal Data on behalf of the Controller.
  • "Standard Contractual Clauses" or "SCCs" means (a) for transfers subject to the EU GDPR, the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914; and (b) for transfers subject to the UK GDPR, the International Data Transfer Agreement or the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office.
  • "Sub-processor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller in connection with the Service.
  • "Supervisory Authority" means the UK Information Commissioner's Office ("ICO") or any competent EU data protection authority, as applicable.
  • "Technical and Organisational Measures" or "TOMs" means the security measures described in Annex 2 of this DPA.

2. Scope and Roles

2.1 This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Service under the Agreement.

2.2 The parties acknowledge and agree that:

  • (a) the Controller is the controller of Personal Data within the meaning of Applicable Data Protection Laws;
  • (b) the Processor is the processor of Personal Data within the meaning of Applicable Data Protection Laws;
  • (c) the subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are as described in Annex 1 to this DPA.

2.3 Nothing in this DPA relieves the Controller of its own obligations under Applicable Data Protection Laws, including with respect to the lawfulness of its instructions to the Processor.


3. Controller Obligations

3.1 The Controller shall:

  • (a) ensure that its instructions to the Processor for the Processing of Personal Data comply with Applicable Data Protection Laws;
  • (b) ensure that it has established a valid legal basis for the Processing of Personal Data (e.g., consent, contractual necessity, legitimate interest);
  • (c) ensure that it has provided all required notices to, and obtained all required consents or authorisations from, Data Subjects as necessary for the Processor to Process Personal Data in accordance with this DPA and the Agreement;
  • (d) be responsible for the accuracy, quality, and legality of the Personal Data provided to the Processor.

4. Processor Obligations

4.1 Processing Instructions. The Processor shall Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before Processing, unless the law prohibits such notification on important grounds of public interest.

4.2 Purpose Limitation. The Processor shall Process Personal Data solely for the purpose of providing and maintaining the Service as described in the Agreement and this DPA, and shall not Process Personal Data for any other purpose unless expressly instructed in writing by the Controller.

4.3 Confidentiality. The Processor shall ensure that all persons authorised to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.4 Security. The Processor shall implement and maintain the Technical and Organisational Measures described in Annex 2 to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, theft, alteration, or disclosure. The Processor shall take reasonable steps to ensure compliance with these measures and shall regularly test, assess, and evaluate the effectiveness of such measures.

4.5 Assistance. Taking into account the nature of the Processing, the Processor shall assist the Controller, by appropriate technical and organisational measures insofar as this is possible, in fulfilling the Controller's obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws (see Section 8).

4.6 Deletion and Return. Upon termination or expiry of the Agreement, the Processor shall, at the Controller's election:

  • (a) return all Personal Data to the Controller in a standard, machine-readable format (e.g., CSV, JSON, or database export); or
  • (b) delete all Personal Data in its possession and in the possession of its Sub-processors, except to the extent that retention is required by applicable law.

The Controller shall make its election within ninety (90) days of termination. If no instruction is received within that period, the Processor shall delete the Personal Data. The Processor shall certify the deletion in writing upon the Controller's request.

4.7 Records of Processing. The Processor shall maintain a record of all categories of Processing activities carried out on behalf of the Controller, in accordance with Article 30(2) of the UK GDPR / EU GDPR, and shall make such records available to the Controller upon request.


5. Sub-processing

5.1 General Authorisation. The Controller provides a general written authorisation to the Processor to engage Sub-processors to Process Personal Data on behalf of the Controller, subject to the conditions set out in this Section 5.

5.2 Current Sub-processors. A list of the Processor's current Sub-processors is set out in Annex 3. The Processor shall keep this list up to date.

5.3 Notification of Changes. The Processor shall inform the Controller of any intended addition or replacement of a Sub-processor, providing details of the Sub-processor's identity, location, and the Processing it will perform, thereby giving the Controller the opportunity to object.

5.4 Objection Right. If the Controller has a reasonable, objectively justified ground related to data protection for objecting to a new or replacement Sub-processor, the Controller shall notify the Processor in writing within fifteen (15) days of receiving the notification under Section 5.3. The parties shall discuss the objection in good faith with a view to achieving a commercially reasonable resolution. If no resolution is reached within thirty (30) days of the Controller's objection, the Controller may terminate the affected part of the Service without penalty by providing written notice, and the Processor shall refund any prepaid Fees for the unused portion of the Subscription Term relating to the terminated Service.

5.5 Sub-processor Obligations. The Processor shall:

  • (a) impose data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, by way of a written contract;
  • (b) remain fully liable to the Controller for the performance of each Sub-processor's obligations;
  • (c) conduct appropriate due diligence on each Sub-processor's ability to meet its obligations before engagement.

6. International Data Transfers

6.1 The Processor shall not transfer Personal Data to a country outside the UK or EEA unless one of the following safeguards is in place:

  • (a) the destination country has been recognised by the UK Secretary of State or the European Commission (as applicable) as providing an adequate level of data protection;
  • (b) appropriate safeguards have been implemented, including the Standard Contractual Clauses, a binding corporate rules scheme, or an approved code of conduct or certification mechanism;
  • (c) a derogation under Article 49 of the UK GDPR / EU GDPR applies.

6.2 Standard Contractual Clauses. Where the Processor relies on the SCCs for International Data Transfers:

  • (a) for transfers subject to the EU GDPR : the SCCs (Commission Implementing Decision 2021/914) are incorporated by reference into this DPA, with: Module Two (Controller to Processor) applying; the Controller as "data exporter" and the Processor as "data importer"; the optional Clause 7 (Docking Clause) included; Clause 9 Option 2 (general written authorisation) applying with a 30-day notice period; Clause 11 (optional redress) not included; Clause 17 Option 1 applying with the governing law being that of the EU Member State in which the Controller is established; and the competent supervisory authority under Clause 13 being the supervisory authority of the EU Member State in which the Controller is established;
  • (b) for transfers subject to the UK GDPR : the UK International Data Transfer Addendum to the EU SCCs ("UK Addendum"), as issued by the ICO under Section 119A of the Data Protection Act 2018, is incorporated by reference, with Part 1 of the Addendum completed using the information set out in Annexes 1 and 2 of this DPA.

6.3 Transfer Impact Assessment. The Processor shall, upon the Controller's reasonable request, provide information necessary for the Controller to carry out a transfer impact assessment in relation to any International Data Transfer.

6.4 Annex 1 and Annex 2 of this DPA serve as the appendices to the SCCs and UK Addendum (as applicable).


7. Personal Data Breach

7.1 Notification. The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data. Notification shall be made to the Controller's designated contact (as specified in the Order Form or Account settings) via email, followed by written confirmation.

7.2 Content of Notification. The Processor's notification shall include, to the extent reasonably available:

  • (a) a description of the nature of the Personal Data Breach, including (where possible) the categories and approximate number of Data Subjects and Personal Data records affected;
  • (b) the name and contact details of the Processor's data protection point of contact;
  • (c) a description of the likely consequences of the Personal Data Breach;
  • (d) a description of the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

7.3 Cooperation. The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Personal Data Breach. The Processor shall preserve all relevant evidence and logs relating to the Personal Data Breach.

7.4 No Notification to Data Subjects by Processor. The Processor shall not notify any Data Subject or Supervisory Authority of a Personal Data Breach without the Controller's prior written approval, unless required to do so by applicable law.

7.5 Root Cause Analysis. Following a Personal Data Breach, the Processor shall, within thirty (30) days of becoming aware of the breach, provide the Controller with a written root cause analysis, including the steps taken to prevent recurrence.


8. Data Subject Rights

8.1 The Processor shall, taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, including rights of:

  • (a) access (Article 15 UK/EU GDPR);
  • (b) rectification (Article 16);
  • (c) erasure / right to be forgotten (Article 17);
  • (d) restriction of Processing (Article 18);
  • (e) data portability (Article 20);
  • (f) objection (Article 21);
  • (g) rights related to automated decision-making and profiling (Article 22).

8.2 If the Processor receives a request directly from a Data Subject, the Processor shall promptly redirect the Data Subject to the Controller and notify the Controller of the request within five (5) business days, unless prohibited by applicable law.

8.3 The Processor shall not respond to a Data Subject request except on the Controller's documented instructions or as required by applicable law.


9. Data Protection Impact Assessments

9.1 The Processor shall provide reasonable assistance to the Controller with data protection impact assessments ("DPIAs") and prior consultations with Supervisory Authorities, to the extent required under Articles 35 and 36 of the UK GDPR / EU GDPR, taking into account the nature of Processing and the information available to the Processor.


10. Audit and Compliance

10.1 Information and Audit. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and under Applicable Data Protection Laws, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

10.2 Audit Process. Audits shall be subject to the following conditions:

  • (a) the Controller shall provide at least thirty (30) days' prior written notice of an audit request;
  • (b) audits shall be conducted during normal business hours, no more than once per twelve (12) month period (unless a Personal Data Breach has occurred or a Supervisory Authority requires an additional audit);
  • (c) the Controller shall bear its own costs in connection with any audit;
  • (d) the auditor shall be bound by confidentiality obligations and shall not be a competitor of the Processor;
  • (e) the scope of the audit shall be limited to the Processor's compliance with this DPA and shall not extend to proprietary source code, algorithms, or other trade secrets of the Processor.

10.3 Third-Party Certifications. To satisfy its obligations under this Section 10, the Processor may, in lieu of permitting an on-site audit, make available:

  • (a) a current SOC 2 Type II report or ISO 27001 certificate covering the systems used to Process Personal Data; and/or
  • (b) a summary of the results of the most recent penetration test conducted by a qualified independent third party;

provided that such certifications or reports are less than twelve (12) months old and address the Controller's concerns. The Controller shall review such certifications before requesting an on-site audit.


11. Data Protection Officer

11.1 The Processor's point of contact for data protection matters is:

  • Role: Data Protection Lead (or Data Protection Officer, if appointed)
  • Email: dpo@rigular.com
  • Address: Rigular Ltd, 128 City Road, London, EC1V 2NX, United Kingdom

11.2 The Controller shall notify the Processor of its own data protection contact upon execution of this DPA.


12. Liability

12.1 Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement, except that the liability caps under the Agreement shall not apply to:

  • (a) either party's obligations under Applicable Data Protection Laws that cannot be limited by contract;
  • (b) any fines or penalties imposed by a Supervisory Authority directly on a party for that party's own breach of Applicable Data Protection Laws.

12.2 Nothing in this DPA limits the rights of any Data Subject under Applicable Data Protection Laws.


13. Term and Termination

13.1 This DPA shall become effective on the Effective Date of the Agreement and shall continue in force for as long as the Processor Processes Personal Data on behalf of the Controller.

13.2 Upon termination or expiry of the Agreement, the provisions of Section 4.6 (Deletion and Return) shall apply.

13.3 The obligations of the Processor regarding confidentiality and data protection shall survive termination of this DPA for as long as the Processor retains any Personal Data.


14. Conflict

14.1 In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the Processing of Personal Data.

14.2 In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.


15. Governing Law

15.1 This DPA shall be governed by the laws of England and Wales, without regard to its conflict-of-law provisions, except where the Standard Contractual Clauses require a different governing law for their purposes.


ANNEX 1 — Details of Processing

A. List of Parties

Data Exporter (Controller) Data Importer (Processor)
Name: [Customer legal name as per Order Form]
Address: [Customer address]
Contact person: [Name, title, email]
Role: Controller
Name: Rigular Ltd
Address: 128 City Road, London, EC1V 2NX, UK
Contact person: Data Protection Lead, dpo@rigular.com
Role: Processor

B. Description of Processing

Element Description
Subject matter The Processor provides a cloud-based software-as-a-service platform to the Controller. In the course of providing the Service, the Processor Processes Personal Data on behalf of the Controller as described below.
Duration of Processing For the duration of the Agreement, plus the data retention period described in Section 4.6 of this DPA.
Nature and purpose of Processing The Processing is carried out for the purpose of providing the Service, including: hosting and storage of Customer Data; computation and processing of data as configured by the Controller through the Service; transmission and display of data to Authorised Users; generation of reports and analytics as configured by the Controller; technical support and maintenance of the Service; backup and disaster recovery.
Categories of Data Subjects As determined by the Controller, which may include: the Controller's employees and contractors; the Controller's customers and end users; the Controller's business contacts and suppliers; individuals whose data is contained in datasets uploaded or processed through the Service.
Types of Personal Data As determined by the Controller and the nature of the Service used, which may include: name and contact details (email, phone, address); professional/employment information (title, department, employer); account credentials and authentication data; IP addresses and device identifiers; usage and activity logs within the Service; financial or transactional data (where applicable to the Service); logistics and transport data (where applicable); energy consumption or infrastructure data (where applicable).

Note: The Controller shall not submit Special Categories of Personal Data (Article 9 UK/EU GDPR) or criminal conviction data (Article 10) to the Service unless expressly agreed in writing with the Processor and subject to additional safeguards.
Frequency of transfer Continuous, for the duration of the Agreement.
Retention period Personal Data is retained for the duration of the Agreement plus ninety (90) days (the data export window), after which it is deleted in accordance with Section 4.6.

C. Competent Supervisory Authority

For transfers subject to the UK GDPR: the UK Information Commissioner's Office (ICO).
For transfers subject to the EU GDPR: the supervisory authority of the EU Member State in which the Controller is established.


ANNEX 2 — Technical and Organisational Measures (TOMs)

1. Encryption

Measure Implementation
Encryption in transit All data transmitted between the Controller and the Service is encrypted using TLS 1.2 or higher. HSTS is enforced on all web endpoints.
Encryption at rest All Personal Data stored in production databases and backup storage is encrypted using AES-256 (or equivalent) with keys held in a managed key management service (KMS).
Key management Encryption keys are rotated at least annually. Access to key management systems is restricted to authorised security personnel with multi-factor authentication.

2. Access Control

Measure Implementation
Authentication All Authorised Users authenticate via secure credentials. Multi-factor authentication (MFA) is available and recommended.
Role-based access Access to Personal Data within the Service is governed by role-based access controls (RBAC) configured by the Controller.
Administrative access Processor personnel access production systems only on a need-to-know basis, with individual accounts, MFA, and audit logging. Privileged access is reviewed quarterly.
Least privilege The principle of least privilege is applied to all system and database access.

3. Network Security

Measure Implementation
Firewalls and segmentation Production environments are isolated using network firewalls and segmentation. Direct access to databases from public networks is prohibited.
Intrusion detection Network intrusion detection/prevention systems (IDS/IPS) monitor for suspicious activity.
DDoS protection The Service infrastructure includes network-level DDoS mitigation provided by the hosting infrastructure provider.

4. Vulnerability and Patch Management

Measure Implementation
Vulnerability scanning Automated vulnerability scans of production systems are conducted at least quarterly.
Penetration testing Independent penetration tests are conducted at least annually, and before major releases, by a qualified third party.
Patch management Critical security patches are applied within 30 days of release. All other patches are applied within 60 days.

5. Physical Security

Measure Implementation
Data centre security The Service is hosted on OVHcloud infrastructure, with data centres located in France (EEA), which maintains ISO 27001 certification. Physical access to data centres is managed by the infrastructure provider.
Office security Access to Rigular offices where Personal Data may be accessed is restricted to authorised personnel.

6. Business Continuity and Disaster Recovery

Measure Implementation
Backups Automated backups of Customer Data (including Personal Data) are performed daily and stored in encrypted form in a geographically separate location within the EEA.
Recovery testing Disaster recovery procedures are tested at least semi-annually.
Redundancy The Service is deployed across geographically separate data centres (multi-region) to ensure resilience.

7. Personnel

Measure Implementation
Training All Processor personnel with access to Personal Data receive data protection and security awareness training upon onboarding and at least annually thereafter.
Confidentiality All personnel are bound by written confidentiality obligations.
Background checks Background checks are performed on personnel with access to production systems, to the extent permitted by applicable law.

8. Incident Response

Measure Implementation
Incident response plan The Processor maintains a documented incident response plan that is reviewed and updated at least annually.
Logging and monitoring Security events are logged centrally and monitored. Logs are retained for at least 12 months.
Notification Personal Data Breaches are escalated and reported in accordance with Section 7 of this DPA.

9. Data Minimisation and Pseudonymisation

Measure Implementation
Data minimisation The Processor only Processes the Personal Data necessary to provide the Service. Non-production environments use anonymised or pseudonymised data wherever practicable.
Pseudonymisation Where applicable and technically feasible, pseudonymisation techniques (e.g., tokenisation) are applied to reduce the identifiability of Personal Data.

ANNEX 3 — Approved Sub-processors

Sub-processor Purpose Location of Processing Safeguard for International Transfer
OVHcloud (OVH SAS) Cloud infrastructure hosting France (EEA) N/A (within EEA)
SMTP2GO Transactional email delivery USA EU SCCs + UK Addendum
Revolut Subscription payment processing United Kingdom / EEA UK adequacy / N/A (within EEA)

Changes to this list are communicated in accordance with Section 5.3 of this DPA.