Home Pricing Product
verified_user Compliance & UK GDPR

Data Processing Agreement (DPA)

UK GDPR & Data Protection Act 2018 Compliance DECIBELS AI LTD

This Data Processing Agreement (“DPA”) forms part of the Terms of Service or Master Services Agreement (the “Principal Agreement”) between the Client (“Controller”) and DECIBELS AI LTD (“Processor”), a company registered in England and Wales.

1. Definitions

“Data Protection Legislation” means all applicable data protection and privacy legislation in force from time to time in the UK including the UK General Data Protection Regulation (UK GDPR); the Data Protection Act 2018 (DPA 2018); and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, and “Processing” shall have the meanings given to them in the Data Protection Legislation.
“Sub-processor” means any third party appointed by the Processor to process Personal Data on behalf of the Controller.

2. Roles and Scope

2.1 The parties acknowledge that for the purposes of the Data Protection Legislation, the Client is the Controller and Decibels AI Ltd is the Processor of the Personal Data described in Annex 1.

2.2 The Processor shall only process the Personal Data on the documented written instructions of the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by UK law to which the Processor is subject.

3. Processor Obligations

3.1 Confidentiality: The Processor shall ensure that personnel authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.2 Security: Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as outlined in Annex 2.

3.3 Compliance Assistance: The Processor shall assist the Controller in ensuring compliance with its obligations pursuant to Articles 32 to 36 of the UK GDPR (security, breach notifications, and data protection impact assessments), taking into account the nature of processing and the information available to the Processor.

4. Sub-processing

4.1 General Authorization: The Controller provides a general authorization for the Processor to engage Sub-processors to fulfill its obligations under the Principal Agreement.

4.2 Notification of Changes: The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller the opportunity to object to such changes.

4.3 Flow-down Obligations: The Processor shall ensure that any Sub-processor is bound by data protection obligations that are no less onerous than those set out in this DPA.

5. Data Subject Rights

The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the UK GDPR.

6. Personal Data Breach

The Processor shall notify the Controller without undue delay (and in any event within 48 hours) upon becoming aware of a Personal Data Breach affecting the Controller’s Personal Data. The Processor will provide sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects of the breach under Data Protection Legislation.

7. International Transfers

The Processor shall not transfer Personal Data outside the UK or European Economic Area (EEA) unless the prior written consent of the Controller has been obtained and the transfer relies on a legally valid mechanism (such as the UK International Data Transfer Agreement or an adequacy decision).

8. Deletion or Return of Data

At the choice of the Controller, the Processor shall delete or return all the Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless UK law requires storage of the Personal Data.

9. Audits and Inspections

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the UK GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (subject to reasonable advance notice and confidentiality restrictions).

A1

Annex 1: Details of Processing

Subject Matter The processing of Personal Data in connection with the provision of the Decibels AI SaaS platform (Marketing Mix Modeling and analytics).
Duration The duration of the Principal Agreement until the data is deleted or returned.
Nature and Purpose To ingest marketing, sales, and CRM data to provide statistical modeling, analytics, and business insights.
Categories of Data Subjects Employees of the Client; end-customers of the Client.
Types of Personal Data User login credentials (names, business email addresses); optionally, pseudonymized customer identifiers or CRM records uploaded by the Client.
A2

Annex 2: Technical and Organizational Security Measures

lock Encryption of Personal Data in transit and at rest.
key Implementation of Role-Based Access Controls (RBAC) and Multi-Factor Authentication (MFA) for all administrative access.
verified Regular vulnerability scanning and penetration testing.
domain Strict physical access controls to data centers provided by our sub-processing hosting partners (e.g., AWS/GCP).