Data Processing Agreement
Public edition: 1.9
Public edition date: 6 Sep 2026
Authoritative terms: Approved Word v1.8, effective 28 Aug 2026
Master next review: 30 Jun 2027, or sooner after material change
Owner: Chief Executive / Privacy Lead
This page presents SpotDev's standard data-processing terms. They apply where incorporated into the relevant agreement. Publishing this edition does not automatically amend an existing agreement. Engagement-specific schedules and execution details are supplied privately. Data-protection enquiries may be sent to hello@spotdev.co.uk for the Privacy Lead.
1. Parties and effect
This Data Processing Agreement (DPA) forms part of the agreement under which SpotDev Services Ltd, a company registered in England and Wales under company number 14296175 (SpotDev), supplies services to the client identified in that agreement (Client). It applies where SpotDev processes Client Personal Data as a processor or sub-processor.
Version control. This version strengthens the operational controls authorised on 28 August 2026. The preceding approved version remains the historical record for 1 July to 27 August 2026; this version applies from 28 August 2026.
If there is a conflict about the protection or processing of Client Personal Data, this DPA takes precedence over the main agreement unless the parties expressly agree a stricter requirement in writing. Commercial liability, payment, intellectual-property and termination terms in the main agreement continue to apply unless this DPA expressly states otherwise.
2. Definitions and interpretation
| Term | Meaning |
| Applicable Data Protection Law | The UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and any other data protection or privacy law applicable to the processing, each as amended or replaced. |
| Client Personal Data | Personal data processed by SpotDev on behalf of the Client under the agreement. |
| Data Protection Regulator | The Information Commissioner's Office and any other competent supervisory authority. |
| Personal Data Breach | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Personal Data. |
| Restricted Transfer | A transfer of personal data for which Applicable Data Protection Law requires an adequacy decision, appropriate safeguard or valid exception. |
| Sub-processor | A third party engaged by SpotDev to process Client Personal Data on the Client's behalf. |
The terms controller, processor, personal data, processing, data subject and special categories of personal data have the meanings given by Applicable Data Protection Law. References to written instructions include the main agreement, a statement of work, this DPA and other documented directions agreed by authorised representatives.
3. Roles and processing details
The Client is a controller or a processor acting for another controller. SpotDev is the Client's processor or sub-processor, as applicable. Each party remains responsible for its own compliance with Applicable Data Protection Law.
The subject matter, duration, nature and purpose of processing, categories of data subjects and types of personal data are set out in Schedule 1 and the relevant statement of work. The Client warrants that its instructions are lawful and that it has the rights, notices, permissions and legal bases needed for the processing.
SpotDev may also process business contact, account, billing, security and service-usage information as an independent controller for legitimate administration, legal compliance, fraud prevention, security and relationship management. That controller processing is governed by SpotDev's privacy information and is outside the processor obligations in this DPA.
4. Documented instructions
SpotDev shall process Client Personal Data only on the Client's documented instructions, including transfers, unless required by applicable law. If law requires other processing, SpotDev shall notify the Client before processing unless the law prohibits notice on important grounds of public interest.
SpotDev shall inform the Client without undue delay if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. SpotDev may suspend the affected processing while the parties resolve the concern. The Client remains responsible for the legality, accuracy and quality of its instructions and source data.
SpotDev may process, access, transmit and store Client Personal Data in approved client systems, SpotDev systems or Sub-processor services only to the extent required for the agreed services, security, support and lawful record keeping. Where AI or automated processing is used, the documented instruction and Schedule 1 record the purpose, provider categories, data categories, training position, maximum retention, deletion route, human oversight and any client choice or restriction. This DPA does not assume that processing occurs only inside Client-controlled systems.
5. Confidentiality and personnel
SpotDev shall ensure that persons authorised to process Client Personal Data are bound by contractual or statutory confidentiality duties, receive appropriate data-protection and security instruction, and access data only to the extent required for their responsibilities. Those obligations survive the end of their access or engagement.
6. Security of processing
Taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risk to individuals, SpotDev shall implement and maintain appropriate technical and organisational measures. The current minimum control framework is described in Schedule 2 and includes risk-based AI governance, secure development, testing, monitoring, supplier assurance and recoverability where AI is used.
SpotDev may update security measures where this does not materially reduce the overall protection of Client Personal Data. No description of a measure is a guarantee that a security incident cannot occur. Controls are applied proportionately to the actual service, data and risk.
7. Sub-processors
The Client gives SpotDev general written authorisation to use Sub-processors. SpotDev shall maintain a controlled list of Sub-processors that process Client Personal Data and make a current client-relevant version available on request or through a notified publication location.
SpotDev shall give reasonable advance notice of an intended addition or replacement that materially affects Client Personal Data, normally at least 15 business days before the change takes effect where practicable. The Client may object during the notice period on reasonable, documented data-protection grounds. The parties shall work in good faith on a reasonable solution; if none is available, either party may terminate only the affected processing or service in accordance with the main agreement.
SpotDev shall impose written data-protection obligations on each Sub-processor that provide substantially the same level of protection required by this DPA for the relevant processing. SpotDev remains responsible to the Client for the Sub-processor's performance of those obligations, subject to the liability terms of the main agreement.
8. International transfers
SpotDev shall not make a Restricted Transfer unless it is permitted by the Client's instructions and a valid transfer mechanism or exception is in place. Where required, the parties shall complete a transfer risk assessment and apply supplementary contractual, organisational or technical measures proportionate to the risk.
The applicable mechanism may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or another lawful safeguard. Schedule 4 records the mechanism for the relevant service. Remote access from another country is treated as a transfer where Applicable Data Protection Law requires it.
If a transfer mechanism is replaced, invalidated or no longer adequate, the parties shall cooperate promptly to implement a valid alternative. SpotDev may suspend the affected transfer where continued processing would breach Applicable Data Protection Law.
9. Data-subject requests
Taking account of the nature of the processing, SpotDev shall provide reasonable assistance through appropriate technical and organisational measures so that the Client can respond to requests to exercise data-protection rights. SpotDev shall refer a request relating to Client Personal Data to the Client without undue delay and shall not respond substantively unless instructed by the Client or required by law.
The Client is responsible for deciding whether and how to respond. Additional assistance outside the agreed services may be chargeable at the rates in the main agreement, except to the extent the request arose from SpotDev's breach of this DPA.
10. Compliance assistance
Taking account of the nature of processing and information available to it, SpotDev shall provide reasonable assistance with the Client's obligations relating to security, breach notification, communications to individuals, data protection impact assessments and prior consultation with a regulator.
The Client shall give sufficient context, scope and time for the requested assistance and remains responsible for its decisions and submissions as controller. SpotDev shall not contact a regulator or affected individual on the Client's behalf unless authorised or legally required.
11. Personal Data Breaches and security incidents
SpotDev shall notify the Client without undue delay after becoming aware of a confirmed Personal Data Breach affecting Client Personal Data and, where reasonably practicable, within 24 hours of awareness. An initial notice may be incomplete and may be provided in phases as facts become available. A precautionary security alert does not by itself amount to confirmation of a Personal Data Breach.
The notification and subsequent updates shall include the following information, to the extent available:
- the nature of the breach, including affected systems, data and approximate scale where known;
- the likely consequences and the measures taken or proposed to contain, investigate and remediate it;
- the incident contact and available information relevant to regulatory or individual notification; and
- material updates until containment and an appropriate closure or lessons-learned summary.
SpotDev shall take reasonable steps to contain and mitigate the breach, preserve relevant evidence and cooperate with the Client. Notice is not an admission of fault or liability. The Client remains responsible for its own regulator and data-subject notifications unless the parties agree otherwise in writing.
12. Records, information and audits
SpotDev shall maintain records required by Applicable Data Protection Law and make available information reasonably necessary to demonstrate compliance with this DPA. SpotDev may satisfy routine assurance requests using current policies, certificates, independent reports, questionnaires or other appropriate evidence.
If that evidence is insufficient for a specific material concern, the Client may conduct or commission an audit no more than once in any 12-month period, except following a material incident or regulator request. Audits require reasonable written notice, must occur during normal business hours, minimise disruption, protect other customers and confidential information, and use an independent auditor bound by confidentiality. The Client bears reasonable audit costs unless the audit identifies a material breach by SpotDev.
SpotDev is not required to disclose information that would compromise another customer's confidentiality, security secrets, privileged material or personal data, but shall provide a reasonable alternative form of assurance where possible.
13. Return, deletion and retention
At the Client's written choice, during or on termination of the affected service, SpotDev shall return or securely delete Client Personal Data, and delete existing copies, unless applicable law requires retention. This includes stored prompts, outputs, uploads and evaluation records held by SpotDev or an authorised Sub-processor, subject to verified technical limitations and protected-backup cycles. The parties may agree a reasonable export format and transition period.
Deletion from resilient backups may occur through the normal protected backup lifecycle where immediate selective deletion is not technically feasible, provided the data remains secured, is not restored except for continuity or recovery, and is deleted or overwritten in the ordinary cycle. SpotDev may retain minimum records necessary to establish, exercise or defend legal rights, comply with law, evidence security activity or maintain financial records, subject to continuing protection.
14. Notifications, change and cooperation
Each party shall maintain an authorised privacy and security contact under the main agreement and notify the other of material contact changes. Formal notices follow the notice clause in the main agreement. Incident notifications may use the agreed operational route where speed is required.
The parties shall cooperate in good faith to update this DPA where Applicable Data Protection Law or a binding regulator decision requires change. Any other amendment must be in writing and authorised by both parties.
15. Term, survival and governing law
This DPA begins when incorporated into the main agreement and continues while SpotDev processes Client Personal Data. Confidentiality, security, audit cooperation, deletion, liability and other provisions intended by their nature to survive remain effective after termination.
Unless the main agreement states otherwise, this DPA is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction. If the Client is a processor, the rights and instructions of its relevant controller are accommodated to the extent required by Applicable Data Protection Law and the agreement.
Schedule 1 - Details of processing
| Item | Standard position; refine in the statement of work where needed |
| Subject matter | Access to, configuration of, migration of, integration with, support for, analysis of, development around, or other agreed operation of systems and data used in the Client's business. |
| Duration | For the term of the affected service, plus a reasonable transition, deletion and protected-backup lifecycle and any legally required retention. |
| Nature and purpose | Consultancy, implementation, development, integration, testing, support, training, troubleshooting, security, service administration and other purposes documented in the agreement. |
| Data subjects | The Client's prospects, customers, users, employees, contractors, suppliers, partners and other individuals represented in the systems or data made available for the service. |
| Personal data | Names, business and personal contact details, identifiers, account and CRM records, communications, activity and preference data, support information, technical logs and other data documented in the service scope. |
| Sensitive data | Not assumed. Special-category, criminal-offence, children's, precise-location, financial-account, authentication or similarly sensitive data must be identified before processing and may require additional controls or a separate instruction. |
| Frequency and scale | As required by the service and documented in the statement of work, taking account of users, records, systems, locations and access pattern. |
| Controller rights | The Client retains the rights and obligations of controller, including lawful instructions, decisions about requests, DPIAs, regulator notices, retention and the accuracy and lawfulness of source data. |
| AI and automated processing | Where used: approved purpose, provider or model category, data categories, system role, human oversight, material decisions, fallback and client restrictions are recorded in the statement of work or controlled service record. |
| Training and model improvement | Client Personal Data is not used by SpotDev to train or fine-tune a shared or general-purpose model. Client-specific training requires an explicit written instruction and separate risk, lawful-basis, security and retention assessment. |
| Maximum retention | The service record states maximum periods for prompts, outputs, uploads, evaluation data, logs and provider copies. Unless a documented service requirement states otherwise, Client-data prompts and outputs held for an immediate AI task are deleted within 30 days after the task is complete. |
| Client choice and removal | The Client may object to an AI processing method or request removal from stored training, evaluation and inference records. SpotDev implements the request without a punitive fee and agrees any necessary change where an alternative service method materially affects scope, timing or cost. |
Schedule 2 - Technical and organisational measures
| Control area | Minimum framework applied proportionately to the service |
| Governance and risk | Named accountability; documented policies; risk-based service, change, supplier and AI review; controlled exceptions and evidence. |
| Identity and access | Authorised accounts; least privilege; multi-factor authentication where supported; joiner, mover and leaver controls; periodic review of privileged and relevant third-party access. |
| Devices and endpoints | Managed security configuration, encryption where appropriate, malware protection, supported software, security updates, screen locking and remote-work controls. |
| Encryption and secrets | Encryption in transit using current secure protocols; encryption at rest where supported and proportionate; controlled storage and rotation of credentials, tokens and secrets. |
| Data handling | Purpose limitation, minimisation, classification, approved storage and transfer, controlled sharing, retention and secure deletion or disposal. |
| Secure delivery | Separation of duties and environments where warranted; peer or independent review; testing; change records; dependency and vulnerability management; rollback or recovery planning. |
| Logging and monitoring | Security-relevant logs and alerts appropriate to the service, protected from unauthorised access and retained for an assessed period. |
| Incident management | Documented reporting, triage, containment, evidence preservation, notification, recovery and lessons learned, exercised on a risk-based schedule. |
| Continuity and recovery | Resilience, backup or recoverability requirements defined for relevant systems; restoration and continuity arrangements reviewed and tested proportionately. |
| Suppliers | Risk classification, due diligence, contractual controls, subprocessor governance, material-change monitoring and secure exit. |
| People | Confidentiality obligations, role-based access, security and privacy awareness, reporting duties and disciplinary or contractual consequences for misuse. |
| Assurance | Risk-based testing and evidence review; current certifications or independent reports shared only within their verified scope. |
| AI data lifecycle | Approved data sources and purposes; data minimisation; malicious-file and unauthorised-data checks where relevant; per-system maximum retention; secure deletion; training restrictions; and controlled removal requests. |
| AI security testing | Threat modelling; peer review; dependency, secret and vulnerability checks; adversarial tests for prompt injection, data leakage, malicious content, excessive agency and provider failure; recorded remediation and release approval. |
| AI recoverability | Version-controlled or reproducible SpotDev-controlled code, prompts and configurations; defined recovery objectives and fallback for critical dependencies; proportionate restore and continuity testing. |
Schedule 3 - Sub-processors
SpotDev maintains a controlled Sub-processor Register because providers, locations and service configurations may change. The client-relevant register or service schedule supplied with the agreement identifies, as applicable:
- the Sub-processor's legal name and service;
- the purpose and categories of Client Personal Data processed;
- the principal processing locations and transfer mechanism where relevant;
- the date approved, material restrictions and status; and
- the notice route for additions or replacements.
A provider used only for SpotDev's independent controller activities is not a Sub-processor under this DPA. A tool does not become authorised for Client Personal Data merely because it appears in an internal supplier inventory.
Schedule 4 - Restricted Transfer record
| Field | Information recorded privately for the applicable Restricted Transfer |
| Exporter and role | Client legal entity and contact; controller or processor. |
| Importer and role | SpotDev Services Ltd or relevant authorised Sub-processor; processor or sub-processor. |
| Mechanism | Applicable adequacy regulation, UK IDTA, UK Addendum to EU SCCs, EU SCC module, or other lawful safeguard. |
| Transfer details | Data, data subjects, purpose, frequency, locations, onward transfers and retention, by reference to Schedule 1 and the service scope. |
| Technical and organisational measures | Schedule 2 plus service-specific supplementary controls. |
| Assessment and approvals | Transfer risk assessment reference, residual risk, owner, approval date and review trigger. |
Schedule 5 - Execution
This DPA may be incorporated by signature of the main agreement, an order, statement of work, electronic acceptance or a separate signature block. Where signed separately, the execution details are completed in the controlled Word agreement supplied privately to the parties. They identify the parties, authorised representatives, titles, signatures, dates and agreement reference.