Legal

Data Processing Agreement

Version draft · September 13, 2026

This DPA is provided for review. To put a countersigned DPA in place for your organisation, email privacy@squidgy.ai and we will return an executed copy.

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer", the controller) and 4142 Ltd, trading as Squidgy (the "Processor"), for your use of the Squidgy platform (the "Services"). It applies where, and to the extent that, Squidgy processes personal data on your behalf as your processor in the course of providing the Services, and it governs that processing under the UK GDPR and, where applicable, the EU GDPR.

2. Subject-matter and details of processing

  • Subject-matter and nature: providing an AI agent platform — building, running, and operating agents you configure, and the storage and processing that requires.
  • Duration: for as long as Squidgy provides the Services to you, plus the retention periods in the Privacy Notice.
  • Purpose: to deliver the Services in accordance with your instructions and the main agreement.
  • Types of personal data: the content you and your users submit to agents (messages, uploads), account and contact details, and the contact details of leads or end-customers you process through the Services.
  • Categories of data subjects: your personnel and authorised users, and the individuals whose data you choose to process through the Services (such as your leads and customers).

3. Our obligations as processor

In processing personal data on your behalf, Squidgy will:

  • process it only on your documented instructions (including as set out in the main agreement and your configuration of the Services), unless required to do otherwise by law, in which case we will tell you unless the law prohibits it;
  • ensure that people authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures as required by Article 32 (see §4);
  • engage sub-processors only as permitted by §5;
  • taking into account the nature of the processing, assist you by appropriate measures to respond to data-subject requests (see §6);
  • assist you with your obligations on security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to us;
  • at your choice, delete or return the personal data at the end of the Services and delete existing copies unless the law requires storage (see §8); and
  • make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits as described in §9.

4. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access controls and row-level security, managed secrets, and least-data retention, as described on our Security page. We may update these measures provided the level of protection is not reduced.

5. Sub-processors

You give general authorisation for Squidgy to engage the sub-processors listed at squidgy.ai/legal/subprocessors. We impose data-protection terms on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you a way to be notified of intended changes to sub-processors and a reasonable opportunity to object.

6. Data-subject requests

If we receive a request from one of your data subjects, we will refer them to you and will not respond directly except on your instruction or as required by law. Taking into account the nature of the processing, we will help you respond to requests to exercise data-subject rights, including through the tools the Services provide.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and provide the information you reasonably need to meet your own notification obligations.

8. Return and deletion

On termination of the Services, and at your choice, we will delete or return the personal data we process for you and delete existing copies, save to the extent the law requires us to keep it. Our standard retention periods are in the Privacy Notice.

9. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, contribute to audits conducted by you or an auditor you appoint, no more than once a year unless required by a supervisory authority or following a breach.

10. International transfers

Where processing involves transferring personal data outside the UK or EEA, we rely on an adequacy decision where one applies, or otherwise on appropriate safeguards such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, as described in the Privacy Notice.

11. Precedence

This DPA forms part of and is subject to the main agreement between you and Squidgy. If there is a conflict on the subject of data protection, this DPA prevails over the main agreement and the Privacy Notice.

Chat with Squidgy