Protection Research

Data Processing Agreement

Effective Date: 3 August 2026

Contents

  • Introduction
  • Definitions
  • Scope and Application
  • Roles of the Parties
  • Customer Instructions
  • Protection Research Obligations
  • Customer Obligations
  • Security Measures
  • Confidentiality
  • Sub-processors
  • International Transfers
  • Data Subject Rights
  • Personal Data Breaches
  • Audits
  • Return and Deletion of Personal Data
  • Liability
  • General
  • Governing Law
  • Contact

1. Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between Protection Research Ltd ("Protection Research", "Processor", "we", "our" or "us") and the Customer ("Controller", "you" or "your") governing the provision of the Services. This DPA applies where Protection Research processes Personal Data on behalf of the Customer in connection with the Services. The purpose of this DPA is to satisfy the requirements of Article 28 of the UK General Data Protection Regulation (UK GDPR) and any other applicable data protection legislation. Where there is any conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA shall prevail to the extent of that conflict.

2. Definitions

Unless otherwise defined in this DPA, capitalised terms have the meanings given in the Terms of Service. For the purposes of this DPA: Applicable Data Protection Law means all applicable legislation relating to the processing of Personal Data, including the UK GDPR and the Data Protection Act 2018. Controller means the entity which determines the purposes and means of the processing of Personal Data. Customer Personal Data means any Personal Data processed by Protection Research on behalf of the Customer. Data Subject means an identified or identifiable natural person to whom Personal Data relates. Personal Data has the meaning given in Applicable Data Protection Law. Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. Processing shall have the meaning given in Applicable Data Protection Law. Processor means an entity which processes Personal Data on behalf of a Controller. Sub-processor means any third party appointed by Protection Research to process Personal Data on behalf of the Customer.

3. Scope and Application

This DPA applies only where Protection Research acts as a Processor on behalf of the Customer. Where Protection Research acts as an independent Controller in relation to Personal Data—for example, when administering its own business, complying with legal obligations or managing customer relationships—this DPA does not apply, and the processing is governed by the Privacy Policy and Applicable Data Protection Law. The subject matter of the processing is the provision of the Services under the Terms of Service. The duration of the processing shall continue for as long as Protection Research processes Customer Personal Data on behalf of the Customer in connection with the Services. The nature and purpose of the processing may include: hosting Customer data; storing Personal Data; transmitting Personal Data; organising and retrieving Personal Data; maintaining the Services; securing the Services; providing technical support; and carrying out other processing activities necessary to perform the Services. The categories of Data Subjects and Personal Data processed will depend upon the Customer's use of the Services.

4. Roles of the Parties

The Customer acts as the Controller of Customer Personal Data. Protection Research acts as the Processor solely to the extent that it processes Customer Personal Data on behalf of the Customer. The Customer: determines the purposes and means of processing; is responsible for establishing a lawful basis for processing; remains responsible for compliance with Applicable Data Protection Law; and warrants that it has all necessary authority to provide Personal Data to Protection Research.

Protection Research shall process Customer Personal Data only in accordance with:

  • this DPA
  • the Terms of Service
  • the Customer's documented instructions; and

Applicable Data Protection Law.

5. Customer Instructions

Protection Research shall process Customer Personal Data only on the documented instructions of the Customer unless otherwise required by Applicable Data Protection Law. The Customer's instructions are incorporated into this DPA through: the Terms of Service; the configuration and use of the Services; written instructions provided by authorised representatives of the Customer; and any mutually agreed written amendments. Where Protection Research believes that an instruction infringes Applicable Data Protection Law, it will notify the Customer without undue delay unless prohibited from doing so by law. Protection Research is not obliged to comply with instructions that are unlawful, technically impossible or outside the scope of the Services.

6. Protection Research Obligations

Protection Research shall, where acting as a Processor: process Customer Personal Data only in accordance with documented instructions from the Customer, unless otherwise required by Applicable Data Protection Law; ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations; implement and maintain appropriate technical and organisational measures to protect Customer Personal Data; assist the Customer in complying with its obligations under Applicable Data Protection Law where reasonably requested and taking into account the nature of the processing; notify the Customer of any Personal Data Breach in accordance with Section 13 of this DPA; make available information reasonably necessary to demonstrate compliance with this DPA; and comply with Article 28 UK GDPR and other applicable legal requirements relating to processors. Protection Research will not sell, disclose or use Customer Personal Data for its own marketing purposes or for any purpose inconsistent with this DPA.

7. Customer Obligations

The Customer remains responsible for ensuring that its processing of Personal Data complies with Applicable Data Protection Law. The Customer shall: ensure that it has a lawful basis for processing Personal Data; provide all necessary privacy information to Data Subjects; obtain any required consents; ensure the accuracy of Customer Personal Data; use the Services in accordance with Applicable Law; provide only Personal Data necessary for the intended purposes; ensure that its instructions are lawful; and promptly notify Protection Research of any changes affecting the processing of Personal Data. The Customer acknowledges that Protection Research is entitled to rely upon the accuracy and completeness of the Customer's documented instructions.

8. Security Measures

Protection Research shall implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk presented by the processing. Such measures may include, where appropriate: encryption of data in transit; encrypted password storage; role-based access controls; authentication mechanisms; least-privilege access principles; network security controls; vulnerability management processes; malware protection; security monitoring and logging; secure software development practices; backup and recovery procedures; change management controls; and staff security awareness and confidentiality training. Protection Research regularly reviews its security measures and may update or improve them to reflect technological developments, evolving threats and changes to the Services. Nothing in this DPA requires Protection Research to implement measures that would materially reduce the security of the Services.

9. Confidentiality

Protection Research shall ensure that any employee, contractor or other person authorised to process Customer Personal Data: is subject to appropriate contractual or statutory confidentiality obligations; receives access only where necessary to perform their duties; and processes Customer Personal Data only as required to provide the Services. These confidentiality obligations shall continue after the individual ceases to have access to Customer Personal Data. Protection Research shall maintain internal procedures designed to ensure that Customer Personal Data is accessed only by authorised personnel with a legitimate business need.

10. Sub-processors

The Customer authorises Protection Research to engage Sub-processors where reasonably necessary for the provision of the Services. Protection Research shall exercise appropriate care when selecting Sub-processors and shall ensure that each Sub-processor is subject to written contractual obligations providing a level of protection for Customer Personal Data substantially equivalent to those contained in this DPA. Protection Research remains responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Law. Protection Research may replace or appoint additional Sub-processors from time to time to support: cloud infrastructure; hosting; authentication; payment processing; customer communications; technical support; security monitoring; analytics; and other operational services necessary to deliver the Services. Where required by Applicable Data Protection Law, Protection Research will make information regarding Sub-processors available upon reasonable request.

11. International Transfers

Protection Research primarily stores and processes Customer Personal Data within the United Kingdom. Where it is necessary to transfer Customer Personal Data outside the United Kingdom, Protection Research shall ensure that appropriate safeguards are implemented in accordance with Applicable Data Protection Law.

Such safeguards may include:

  • the UK International Data Transfer Agreement (IDTA)
  • the UK Addendum to the European Commission's Standard Contractual Clauses
  • transfers to countries benefiting from UK adequacy regulations; or

any other lawful transfer mechanism recognised under Applicable Data Protection Law. Protection Research shall take reasonable steps to ensure that recipients provide an appropriate level of protection for Customer Personal Data.

12. Data Subject Rights

Taking into account the nature of the processing, Protection Research shall provide reasonable assistance to the Customer to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

These rights may include requests to:

  • access Personal Data
  • rectify inaccurate Personal Data
  • erase Personal Data
  • restrict processing
  • object to processing
  • obtain Personal Data in a portable format; and

exercise other rights provided by Applicable Data Protection Law. Where Protection Research receives a request directly from a Data Subject relating to Customer Personal Data, Protection Research shall: promptly notify the Customer unless prohibited by law; not respond directly except where authorised or legally required to do so; and provide reasonable assistance where appropriate.

13. Personal Data Breaches

Protection Research shall maintain procedures designed to detect, investigate and respond to Personal Data Breaches. Where Protection Research becomes aware of a Personal Data Breach affecting Customer Personal Data, Protection Research shall notify the Customer without undue delay after becoming aware of the breach. To the extent reasonably available, the notification shall include: the nature of the Personal Data Breach; the categories of Personal Data affected; the likely consequences of the breach; the measures taken or proposed to address the breach; and contact details for obtaining further information.

Protection Research shall:

  • investigate the breach
  • take reasonable steps to mitigate its effects
  • cooperate with the Customer where reasonably required; and

maintain records of Personal Data Breaches as required by Applicable Data Protection Law. Nothing in this DPA requires Protection Research to notify the Customer of unsuccessful or blocked attempts to compromise systems where no Personal Data Breach has occurred.

14. Audits

Protection Research shall make available information reasonably necessary to demonstrate compliance with this DPA. Where required by Applicable Data Protection Law, the Customer may request an audit of Protection Research's compliance with this DPA.

Any audit shall:

  • be conducted upon reasonable prior written notice
  • occur during normal business hours
  • minimise disruption to Protection Research's operations
  • be limited to matters directly relevant to this DPA
  • be subject to appropriate confidentiality obligations; and

not occur more than once in any twelve-month period unless required by law or following a confirmed Personal Data Breach. Protection Research may satisfy audit requests by providing independent audit reports, certifications or equivalent compliance documentation where appropriate. The Customer shall bear its own audit costs unless otherwise required by Applicable Law.

15. Return and Deletion of Personal Data

Upon termination or expiry of the Services, Protection Research shall, at the Customer's choice where technically feasible: return Customer Personal Data; or securely delete Customer Personal Data, unless Applicable Law requires continued retention.

Protection Research may retain:

  • backup copies retained in accordance with normal disaster recovery procedures
  • information required for legal, regulatory or accounting purposes; and

information necessary to establish, exercise or defend legal claims. Any retained Personal Data shall remain protected in accordance with this DPA until securely deleted.

16. Liability

Each party's liability under this DPA shall be subject to the liability provisions contained within the Terms of Service unless Applicable Data Protection Law requires otherwise. Nothing in this DPA excludes or limits liability where such exclusion or limitation would be prohibited by Applicable Data Protection Law.

17. General

This DPA forms part of the Terms of Service and shall remain in force for so long as Protection Research processes Customer Personal Data on behalf of the Customer. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. No amendment to this DPA shall be effective unless made in writing or incorporated into updated contractual documentation published by Protection Research where permitted by Applicable Law. This DPA constitutes the entire agreement between the parties relating to its subject matter and supersedes any previous agreements concerning the processing of Customer Personal Data, except where expressly agreed otherwise in writing.

18. Governing Law

This DPA and any dispute or claim arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction over any dispute arising under or in connection with this DPA, except where Applicable Law provides otherwise.

19. Contact

Questions regarding this Data Processing Agreement should be directed to:

Protection Research Ltd

Company Number: 17366537

  • Registered Office: 41 Colwyn Road, Stockport, Cheshire, England, SK7 2JG
  • Email: support@protectionresearch.com

End of Data Processing Agreement

Effective Date: 3 August 2026

© Protection Research Ltd. All rights reserved.