1. Parties, scope and priority
This Data Processing Agreement (“DPA”) forms part of the service agreement between the business customer identified in the account or signed order (“Customer”) and Global Data Intelligence Limited, company number 09410808 (“CompanyProof”). It applies to personal data processed on the Customer’s behalf in the service (“Customer Personal Data”).
The Customer acts as controller or, where it processes on behalf of another controller, as processor with authority to appoint CompanyProof as a subprocessor. Each party must comply with data-protection law applicable to its processing, including the UK GDPR and Data Protection Act 2018, EU GDPR and applicable US state privacy law where relevant.
This DPA controls on processing matters unless a signed DPA expressly replaces it. Mandatory law and applicable international-transfer clauses take priority. It does not govern CompanyProof’s separate controller processing of account, billing, security and independently sourced company-intelligence information, which is explained in the Privacy Notice.
2. Documented instructions
CompanyProof will process Customer Personal Data only on the Customer’s documented instructions to provide, support and secure the contracted service, including the settings, queries, authorised integrations and return/deletion requests the Customer submits. These instructions include transfers only where lawful safeguards are in place.
If law requires other processing, CompanyProof will inform the Customer of that requirement before processing unless legally prohibited. CompanyProof will promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law, and may pause the affected instruction while the parties resolve it.
The Customer must determine a lawful basis, provide required notices, respond to individual rights and ensure that its instructions and submissions are lawful. Do not submit special-category data, criminal-offence data, payment credentials, government identity-document images or children’s data unless a signed schedule specifically permits the categories and safeguards.
CompanyProof has no general-purpose model-training licence to Customer Personal Data and will not process it for unrelated advertising, data resale or an independent training purpose under this DPA.
3. Processing schedule
The table records the standard processing. A signed order may narrow it or specify additional authorised fields, jurisdictions, locations, retention, safeguards and service requirements. The Customer’s chosen data and active modules determine the actual scope.
| Item | Standard scope |
|---|---|
| Subject matter | Company verification, supported company-profile and text analysis requests, evidence storage, authorised monitoring and delivery of results. |
| Duration | For the contracted service and any instructed return/deletion period, with limited retention only where law requires it. |
| Nature of processing | Receipt, validation, matching, extraction, comparison with company evidence, organisation, storage, retrieval, authorised disclosure, monitoring, export and deletion. |
| Purpose | Produce and retain the company information and evidence requested by the Customer and operate that workflow securely. |
| People whose data may be processed | Customer users and authorised representatives; directors, officers, shareholders and professional business contacts identified in relevant submissions or records. |
| Personal data categories | Professional names, roles, business contact details where submitted or returned, relevant corporate affiliations, identifiers associated with individuals, submitted factual statements and source/evidence metadata. |
| Frequency | On customer request, during authorised service operation and at configured monitoring intervals. |
| Customer instructions and contact | Account settings, submitted requests and agreed written instructions from an authorised contact. The order/account identifies the Customer and its privacy contact. |
| Provider and location schedule | The provider register and applicable signed schedule. Exact customer-specific storage, backup, log, support and downstream AI-provider locations must be established for a location-restricted workflow. |
4. Confidentiality and personnel
CompanyProof will restrict access to people who require it for the contracted processing and ensure they are bound by appropriate confidentiality duties. Access must be removed when no longer required. Personnel must be instructed on applicable data-protection and security responsibilities.
Customer Personal Data remains subject to these duties during support, maintenance and any permitted retention after service termination.
5. Technical and organisational measures
Taking account of the state of the art, implementation cost, nature and context of processing and risk to individuals, CompanyProof will implement appropriate technical and organisational measures under applicable data-protection law. Measures must support confidentiality, integrity, availability, resilience, restoration and periodic assessment of effectiveness.
The standard application measures below describe the implemented controls relevant to this service. A contractual requirement for a particular recovery objective, residency restriction, independent assessment or certification must be supported by the applicable evidence and schedule; a provider’s certification does not certify CompanyProof.
| Control area | Application measure |
|---|---|
| Access separation | Authenticated account/organisation checks and applicable roles for evidence, billing, keys and configuration. |
| Credentials | CompanyProof keys stored as one-way hashes, revocation support and upstream credentials kept in server-side secret configuration. |
| Webhook protection | Encryption of endpoint secrets, signed outbound payloads, replay identifiers and controlled retry/delivery handling. |
| Request protection | HTTPS transport, request validation, size limits, rate limiting and browser security headers. |
| Operational records | Account-related audit events, security and delivery records, with access restrictions. |
| Minimisation and retention | Limited analytic event fields, optional tracking gated by consent, short-lived recovery references and applicable cleanup processes. |
6. Subprocessors and changes
The Customer grants general written authorisation for the providers identified for the relevant Customer Personal Data processing in the provider register and any agreed schedule. Services used only for CompanyProof’s independent controller purposes are not thereby Customer subprocessors.
Before appointing a subprocessor, CompanyProof will put written obligations in place that provide materially equivalent protection for the relevant processing, including confidentiality, security, assistance and deletion. CompanyProof remains responsible to the Customer for that subprocessor’s performance of its applicable data-protection obligations.
CompanyProof will give the Customer’s account or nominated privacy contact at least 30 days’ prior notice of an intended new or replacement subprocessor processing Customer Personal Data. The Customer may object within that period on reasonable, documented data-protection grounds. The parties will work in good faith on an alternative or mitigation.
If an objection cannot be resolved before the change, the Customer may stop and terminate the affected service without a termination penalty, receiving the unused prepaid portion for that service. The parties must not continue processing through a provider where doing so would breach applicable law.
7. Rights requests and compliance assistance
CompanyProof will promptly notify the Customer of a request relating to Customer Personal Data and, unless authorised or required by law, refer the requester to the Customer rather than determine the response independently.
Taking account of the nature of processing, CompanyProof will provide appropriate technical and organisational assistance with individual access, correction, deletion, restriction, objection and portability requests.
Taking account of available information, CompanyProof will assist with security obligations, breach notifications, data-protection impact assessments and prior consultation with a supervisory authority where required. Any charge for exceptional additional assistance must be reasonable and agreed, and must not prevent mandatory cooperation.
8. Personal data breaches
CompanyProof will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, categories and approximate numbers of affected people and records where known, likely consequences, measures taken or proposed, and a contact for further information.
Information may be supplied in phases as it becomes available, without delaying the initial notification. CompanyProof will take reasonable steps to contain, investigate and remediate the breach and preserve information needed to assess it.
The Customer is responsible for assessing notifications to its regulator and affected individuals. CompanyProof will assist and will not make a notification on the Customer’s behalf without instructions unless legally required.
9. International transfers
CompanyProof will not make a restricted international transfer of Customer Personal Data unless the relevant legal mechanism is established beforehand. This may involve a valid adequacy decision, the applicable EU Standard Contractual Clauses and UK Addendum, or a UK International Data Transfer Agreement, together with required assessments and supplementary safeguards.
Any required transfer terms must identify the parties, roles, data, purposes, destinations and safeguards. This DPA does not assert that a particular set of transfer clauses has been executed merely by naming it. Applicable transfer instruments cannot be contradicted by this DPA.
CompanyProof will make relevant safeguards available on request, subject to proportionate redaction of unrelated confidential information, and notify the Customer if a legal restriction prevents compliance with an agreed transfer arrangement.
10. Return and deletion
At the end of the relevant processing service, CompanyProof will, at the Customer’s choice, return or securely delete Customer Personal Data and delete existing copies without undue delay, unless applicable law requires retention. The parties will coordinate the export format and authenticated instructions so information is not returned to an unauthorised person.
If law requires retention, CompanyProof will explain the requirement where permitted, isolate the retained data and limit further processing to that purpose. Data in a backup must remain protected, must not be used for ordinary operations, and must be deleted through the applicable lifecycle. If restored for recovery, applicable deletion instructions must be reapplied.
CompanyProof will provide information about completion on reasonable request. The agreed processing schedule must specify any required fixed deletion or backup-erasure deadline; neither a subscription cancellation nor expiry of a link should be treated as proof of completed deletion.
11. Demonstrating compliance
CompanyProof will make available information necessary to demonstrate compliance with this DPA and allow and contribute to audits and inspections by the Customer or an independent auditor it appoints.
The parties will normally start with relevant documents or a questionnaire and coordinate any further inspection with reasonable notice, confidentiality and safeguards for other customers’ data. These arrangements must not prevent a legally required audit, a competent authority’s access or an appropriately urgent investigation following a breach or credible non-compliance concern.
CompanyProof will promptly inform the Customer if it can no longer comply with its applicable processing obligations and cooperate on appropriate remediation or cessation of the affected processing.
12. US service-provider terms where applicable
Where applicable US state privacy law treats CompanyProof as a service provider, contractor or processor for Customer Personal Data, it will process that data only for the limited and specified business purposes in this DPA, provide the legally required level of protection, and comply with applicable restrictions on retaining, using, disclosing and combining the data.
CompanyProof will not sell or share Customer Personal Data, use it outside the direct business relationship for an unrelated commercial purpose, or combine it with other-source personal information except where the law permits it. These restrictions apply to processor data, not an assertion about all independently sourced company intelligence.
The Customer may take reasonable and appropriate steps to confirm compliant use and, on notice, stop and remediate unauthorised processing. CompanyProof will notify the Customer if it determines that it can no longer meet these obligations.
Artisans’ House, 7 Queensbridge, Northampton, Northamptonshire, United Kingdom, NN4 7BF
Privacy: privacy@globaldatabase.com
Contracts and support: office@globaldatabase.com
