Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and The SaaSy People Ltd, company number 12341379, of 47 Cannon Street, Birmingham, B2 5EF ("Processor", "we", "us"), for the provision of the OmniSaaSy service ("Agreement"). It sets out the terms on which we process personal data on the Controller's behalf. Where there is any conflict between this DPA and the rest of the Agreement in relation to the processing of personal data, this DPA prevails.
Last updated: 16 July 2026
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in UK Data Protection Law. "UK Data Protection Law" means the UK GDPR and the Data Protection Act 2018, together with any applicable EU GDPR where it applies to the processing. "Sub-processor" means any third party engaged by us to process personal data under this DPA.
2. Scope and roles
The Controller is the controller of the personal data processed through OmniSaaSy that relates to the Controller's own customers, prospects and administrative users. We act as processor in respect of that personal data. The details of the processing are set out in Annex 1. We process personal data only on the Controller's documented instructions, including those set out in this DPA and the Agreement, unless required to do otherwise by law, in which case we will inform the Controller of that legal requirement before processing unless the law prohibits it.
3. Processor obligations
- Instructions. We process personal data only on the Controller's documented instructions and will promptly inform the Controller if, in our opinion, an instruction infringes UK Data Protection Law.
- Confidentiality. We ensure that personnel authorised to process the personal data are bound by appropriate obligations of confidentiality.
- Security. We implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk under Article 32 UK GDPR.
- Assistance. Taking into account the nature of the processing, we assist the Controller by appropriate technical and organisational measures in responding to data subject rights requests, and in meeting the Controller's obligations relating to security, breach notification, data protection impact assessments and prior consultation.
- Records. We maintain records of the categories of processing carried out on behalf of the Controller.
4. Sub-processors
The Controller provides general authorisation for us to engage the sub-processors listed in Annex 3. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable to the Controller for the performance of each sub-processor's obligations. We will give the Controller at least 30 days' notice of any intended addition or replacement of a sub-processor, during which the Controller may object on reasonable data protection grounds. If the parties cannot resolve the objection, the Controller may terminate the affected part of the service.
5. Data subject requests
Where we receive a request from a data subject in relation to personal data we process for the Controller, we will not respond directly (except to confirm that the request relates to the Controller) and will forward the request to the Controller without undue delay, and in any event within 72 hours of receipt. We will assist the Controller in fulfilling access, rectification, erasure, restriction, portability and objection requests through the functionality of the service and, where necessary, a documented manual workflow.
6. Personal data breaches
We will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it, to the extent known.
7. International transfers
We process the Controller's personal data within the UK and EEA. Any transfer of personal data outside the UK or EEA arises only where the Controller elects to connect third-party platforms. Where such a transfer takes place, it is carried out under the UK/EU-US Data Privacy Framework where the recipient is certified, or under the Standard Contractual Clauses together with the UK International Data Transfer Addendum, supplemented by additional safeguards where appropriate.
8. Audit and information
We make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, including our ISO/IEC 27001 certification and, on request and under confidentiality, relevant summaries of our controls. The Controller may audit our compliance no more than once in any 12-month period, on reasonable prior written notice, at the Controller's cost, and in a manner that does not unreasonably disrupt our operations; an independent third-party assurance report may be provided in satisfaction of an audit request.
9. Return and deletion
On termination or expiry of the Agreement, or on the Controller's earlier written request, we will return or delete the Controller's personal data. Personal data in the live environment is deleted within 30 days of the request or termination, and residual copies held in backups are deleted within the backup rotation cycle, which is up to 90 days. We will confirm completion in writing on request. We may retain personal data where required by law, in which case we continue to protect it under this DPA.
10. Liability and term
This DPA takes effect on the effective date of the Agreement and continues for as long as we process personal data on the Controller's behalf. The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
Annex 1: Details of processing
- Subject matter. Provision of the OmniSaaSy service, relaying customer messages, reviews and comments between connected platforms and the Controller's Intercom workspace.
- Duration. The term of the Agreement, plus the return and deletion periods in section 9.
- Nature and purpose. Collection, relay, short-term storage (retained for the period set out in section 9 and the Agreement), logging and retry, for the purpose of customer support and community management.
- Categories of data subjects. The Controller's customers and prospects who contact the Controller through connected channels; and the Controller's employees and contractors who use OmniSaaSy as administrative users.
- Types of personal data. Identifiers and contact details, platform handles and profile information, and the content of messages, reviews, comments and direct messages together with associated metadata. OmniSaaSy does not solicit, target or enrich special category personal data; such data may arise only where a data subject voluntarily includes it in a message, review or comment.
Annex 2: Technical and organisational measures
- Encryption of personal data in transit using TLS 1.2 or higher, with HTTP redirected to HTTPS and HSTS applied.
- Encryption of personal data at rest, including AES-256 encryption of sensitive database fields and AES-256 encryption of backups.
- Role-based access control on a least-privilege basis, with multi-factor authentication enforced on production and administrative accounts and access reviewed regularly.
- Audit logging of privileged actions and logging of employee access to the Controller's personal data.
- Automated uptime and error monitoring at the application and hosting layers, with regular reviews of server health, patching status and access logs.
- Daily backups with monitored integrity and periodic restoration testing, a documented business continuity and disaster recovery plan tested at least annually, a Recovery Time Objective of 72 hours and a Recovery Point Objective of 24 hours.
- Pre-employment checks, contractual confidentiality obligations, and security awareness training with phishing simulations on onboarding and annually.
- An information security management system certified to ISO/IEC 27001, including supplier risk management and incident management procedures.
Annex 3: Approved sub-processors
- Hetzner Online GmbH (Germany, EEA): application hosting and compute.
- Amazon Web Services EMEA SARL (Luxembourg): encrypted backup storage in the AWS London (eu-west-2) region, UK.
- Intercom R&D Unlimited Company (Ireland, EEA): ticketing platform.
Platforms elected by the Controller (for example Trustpilot, Meta (Facebook and Instagram), Google (Google Play and Google Business Profile), and X) process personal data under their own terms as part of the integrations the Controller chooses to enable.