How we handle and protect your data when providing our services.
This Data Processing Agreement ("DPA") is entered into between Factor Technologies Ltd, a company incorporated in England and Wales under No. 16929514 whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, England ("Supplier") and the customer identified in the applicable service agreement ("Customer").
Each a "party" and together the "parties".
In this DPA, the following words are defined:
Terms such as Data Subject, Processing, Personal Data, Controller, Processor, "Supervisory Authority" and "Personal Data Breach" shall have the same meaning as ascribed to them in the Data Protection Law.
In this DPA unless the context requires a different interpretation:
For the purpose of Data Protection Law, the Customer shall be the Controller and the Supplier shall be the Processor.
The Supplier and each Supplier Affiliate shall:
The Supplier and each Supplier Affiliate shall take reasonable steps to ensure the reliability of Personnel who have access to the Personal Data, ensuring in each case that such Personnel is subject to a strict duty of confidentiality (whether a contractual or statutory duty) and that they Process the Personal Data in compliance with all applicable law and only for the purpose of delivering the Services under the Agreement.
The Supplier will establish data security in relation to the Processing of Personal Data under this DPA. The measures to be taken must guarantee a protection level appropriate to the risk concerning confidentiality, integrity, availability and resilience of the systems. Such measures may include, as appropriate:
In assessing the appropriate level of security, the Supplier shall take into account any risks that are presented by the Processing, in particular, from a Personal Data Breach.
The Supplier has laid down the technical and organisational measures in Schedule 2 of this DPA. Technical and organisational measures are subject to technical progress and further development. In this respect, the Supplier may implement adequate alternative measures, provided the security level of the defined measures is not reduced.
Taking into account the nature of the Processing, the Supplier and each Supplier Affiliate shall assist the Customer in implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising Data Subjects' rights under the Data Protection Law.
The Supplier shall:
The Supplier shall:
The Supplier and each Supplier Affiliate shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities or other competent authorities which the Customer considers necessary pursuant to Articles 35 and 36 of the UK GDPR.
Such assistance from the Supplier shall be limited, in each case, to the Processing of Personal Data under this DPA.
This DPA will be governed by and interpreted according to the law of England and Wales and all disputes arising under the DPA (including non-contractual disputes or claims) shall be subject to the exclusive jurisdiction of the English and Welsh courts.
This Schedule includes certain details of the Processing of Personal Data as required by Article 28(3) UK GDPR. The subject matter and duration of the Processing of the Personal Data are set out in the Agreement and this DPA.
The Supplier will Process Personal Data as necessary to provide the Services pursuant to the Agreement, and as further instructed by the Customer in its use of the Services.
The Customer may submit Personal Data to the Services, the extent of which is determined and controlled by the Customer in its sole discretion, and which may include, but is not limited to:
The Customer may submit Personal Data relating to the following categories of Data Subjects:
The obligations and rights of the Customer (and any Customer Affiliates) are set out in the Agreement and this DPA.
The Supplier will conduct the activities covered by this DPA in compliance with its Information Security Policy and relevant data protection policies and guidance.
The Supplier also has the following technical and organisational measures in place:
The Customer agrees that the Supplier may sub-contract certain obligations under this DPA to the following Sub-processors:
| Sub-Processor | Location | Sub-contracted Activities |
|---|---|---|
| Amazon Web Services | EU and/or UK | Cloud infrastructure hosting, data storage, backup, and security services. |
| Vercel | EU, UK, and/or US | Frontend hosting, content delivery (CDN), and serverless or edge function execution. |
| Supabase | EU, UK, and/or US | Managed database services, authentication, and file storage. |
| Langfuse | EU | Logging, monitoring, and observability of AI/LLM interactions. |
| OpenAI | US | AI model inference via API. |
| OpenRouter | US | API gateway providing access to third-party AI models. |
| Google Gemini | EU, UK, and/or US | AI model inference via API. |
| Google Workspace | EU, UK, and/or US | Internal communications, document storage, and collaboration containing Customer Personal Data. |
The Supplier shall ensure that all Sub-Processors are subject to written data protection obligations no less protective than those set out in this DPA, in accordance with Article 28(4) GDPR.