Version draft · September 13, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer", the controller) and 4142 Ltd, trading as Squidgy (the "Processor"), for your use of the Squidgy platform (the "Services"). It applies where, and to the extent that, Squidgy processes personal data on your behalf as your processor in the course of providing the Services, and it governs that processing under the UK GDPR and, where applicable, the EU GDPR.
In processing personal data on your behalf, Squidgy will:
We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access controls and row-level security, managed secrets, and least-data retention, as described on our Security page. We may update these measures provided the level of protection is not reduced.
You give general authorisation for Squidgy to engage the sub-processors listed at squidgy.ai/legal/subprocessors. We impose data-protection terms on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you a way to be notified of intended changes to sub-processors and a reasonable opportunity to object.
If we receive a request from one of your data subjects, we will refer them to you and will not respond directly except on your instruction or as required by law. Taking into account the nature of the processing, we will help you respond to requests to exercise data-subject rights, including through the tools the Services provide.
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and provide the information you reasonably need to meet your own notification obligations.
On termination of the Services, and at your choice, we will delete or return the personal data we process for you and delete existing copies, save to the extent the law requires us to keep it. Our standard retention periods are in the Privacy Notice.
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, contribute to audits conducted by you or an auditor you appoint, no more than once a year unless required by a supervisory authority or following a breach.
Where processing involves transferring personal data outside the UK or EEA, we rely on an adequacy decision where one applies, or otherwise on appropriate safeguards such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, as described in the Privacy Notice.
This DPA forms part of and is subject to the main agreement between you and Squidgy. If there is a conflict on the subject of data protection, this DPA prevails over the main agreement and the Privacy Notice.