Data Processing Agreement
Preamble
This Data Processing Agreement (this "DPA") forms part of, and is incorporated by reference into, the agreement between Evryone Ltd and the Customer for the provision of the Frame.plus service (the "Principal Agreement", comprising the Frame.plus Terms of Service and any associated order form, subscription or commercial terms). This DPA governs the Processing of Customer Personal Data by Evryone Ltd as a Processor on behalf of the Customer as Controller.
This DPA is entered into between:
-
Evryone Ltd, a company registered in England and Wales whose registered office is at [Registered office address], trading as Frame.plus (the "Processor", "Frame", "we", "us", "our"); and
-
the Customer, being the legal person identified in the Principal Agreement who has accepted the Frame.plus Terms of Service and/or executed an order form for the Service (the "Controller", "you", "your"),
each a "Party" and together the "Parties".
Background
(A) The Processor provides Frame.plus, an AI marketing operating system that plans, generates, schedules, publishes and reports on marketing across social media, advertising, newsletters, blog and video, including lead generation and email outreach (the "Service"), more fully described in the Principal Agreement.
(B) In providing the Service, the Processor will Process Personal Data on behalf of, and on the documented instructions of, the Controller.
(C) The Parties wish to ensure that such Processing is carried out in compliance with the Data Protection Laws and, in particular, that the requirements of Article 28 of the UK GDPR are satisfied. This DPA records the terms on which the Processor will Process Customer Personal Data.
(D) Where the Processor processes Personal Data in respect of which it determines the purposes and means of Processing (for example, account registration, authentication, billing, support, product analytics and the Processor's own marketing), the Processor acts as a Controller in its own right; such Processing is governed by the Frame.plus Privacy Notice and not by this DPA. This DPA applies only to Customer Personal Data Processed by the Processor acting as a Processor.
1. Definitions and interpretation
1.1 In this DPA, the following definitions apply. Capitalised terms used but not defined in this DPA have the meaning given to them in the Principal Agreement.
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where "control" means ownership of more than 50% of the voting securities or equivalent interests.
"Approved Sub-processor" means a Sub-processor listed in Annex 3 (or otherwise notified to and not objected to by the Controller under Clause 7).
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" (and "Process", "Processed"), "Special Category Data" and "Supervisory Authority" each have the meaning given to them in the UK GDPR.
"Customer Personal Data" means any Personal Data that is uploaded to, submitted to, generated by, or otherwise Processed through the Service by or on behalf of the Controller, and that the Controller Processes for its own purposes as Controller, in respect of which the Processor acts as a Processor. Customer Personal Data includes, without limitation: audience and mailing-list contacts; contact and lead data generated, enriched or managed through the Outreach feature (the "Lead Data"); email message content and email engagement/event data (sends, opens, clicks, replies, bounces, complaints, unsubscribes); and Personal Data incidentally contained in brand assets and creative materials uploaded by the Controller (for example, images depicting identifiable individuals). The categories of Customer Personal Data are further described in Annex 1.
"Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Principal Agreement, including, as applicable: (a) the UK GDPR; (b) the Data Protection Act 2018 ("DPA 2018"); (c) the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"); and (d) to the extent applicable to Processing of the Personal Data of Data Subjects in the European Economic Area ("EEA"), the EU GDPR (Regulation (EU) 2016/679) and applicable EU member-state implementing legislation; in each case as amended, replaced or superseded from time to time.
"EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Decision 2021/914 of 4 June 2021.
"IDTA" means the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the DPA 2018, and/or the International Data Transfer Addendum to the EU SCCs (the "UK Addendum"), as applicable.
"Restricted Transfer" means: (a) a transfer of Personal Data from the United Kingdom to a country outside the United Kingdom that is not the subject of UK adequacy regulations; and/or (b) where the EU GDPR applies, a transfer of Personal Data from the EEA to a country outside the EEA that is not the subject of an EU adequacy decision.
"Standard Contractual Clauses" or "SCCs" means, as the context requires, the EU SCCs and/or the IDTA / UK Addendum.
"Sub-processor" means any third party (including any Affiliate of the Processor) engaged by the Processor to Process Customer Personal Data on behalf of the Controller.
"Supervisory Authority" means the UK Information Commissioner's Office (the "ICO") and, where the EU GDPR applies, any competent EU supervisory authority.
"Technical and Organisational Measures" or "TOMs" means the technical and organisational security measures set out in Annex 2 and in the Processor's Information Security Policy.
"Transfer Risk Assessment" or "TRA" means a documented risk assessment carried out in respect of a Restricted Transfer to determine whether the transfer tools relied upon provide a level of protection essentially equivalent to that guaranteed within the United Kingdom.
"UK GDPR" has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the DPA 2018.
1.2 Interpretation.
(a) References to a statute or statutory provision are references to it as amended, extended, re-enacted or replaced from time to time, and include any subordinate legislation made under it.
(b) The words "include", "including" and "in particular" are illustrative and do not limit the generality of the words that precede them.
(c) Clause, Annex and paragraph headings do not affect interpretation.
(d) References to "writing" or "written" include email.
(e) In the event of any ambiguity between a defined term in this DPA and an equivalent term in the Data Protection Laws, the meaning under the Data Protection Laws prevails for the purpose of construing the Parties' obligations.
2. Status of the Parties and scope
2.1 The Parties acknowledge and agree that, in respect of Customer Personal Data:
(a) the Controller is the Controller; and
(b) the Processor is a Processor acting on the Controller's behalf.
2.2 The Controller is responsible for, and warrants that it has and will maintain, a valid lawful basis under Article 6 of the UK GDPR (and, where applicable, a condition under Articles 9 or 10) for the Processing of Customer Personal Data, including for any direct marketing carried out through the Service. The Controller is responsible for the accuracy, quality, content and legality of Customer Personal Data and the means by which it acquired such data, and for providing any privacy information and obtaining any consents required from Data Subjects.
2.3 The subject-matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1 (Details of Processing).
2.4 This DPA applies for as long as the Processor Processes Customer Personal Data on behalf of the Controller. The Processor's obligations under Clauses 5 (confidentiality), 6 (security), 8 (assistance), 9 (breach notification), 11 (deletion or return), 12 (audit) and 13 (international transfers) survive termination of the Principal Agreement to the extent the Processor continues to hold Customer Personal Data.
2.5 Each Party will comply with its respective obligations under the Data Protection Laws. Nothing in this DPA relieves either Party of its own direct obligations or liabilities under the Data Protection Laws.
3. No Special Category Data
3.1 The Service is not designed or intended to Process Special Category Data or Personal Data relating to criminal convictions and offences. The Controller agrees not to upload, submit or otherwise Process through the Service any Special Category Data or criminal-offence data, and acknowledges that the TOMs in Annex 2 are calibrated for the categories of data described in Annex 1.
3.2 If the Controller nonetheless wishes to Process Special Category Data through the Service, it must first obtain the Processor's written agreement and the Parties must agree any additional safeguards required by Article 9 of the UK GDPR. In the absence of such agreement, the Controller is solely responsible for any Special Category Data it elects to Process through the Service and indemnifies the Processor in respect of any resulting liability, subject to Clause 14.
4. Processing on documented instructions
4.1 The Processor will Process Customer Personal Data only on the documented instructions of the Controller, including with regard to transfers of Customer Personal Data to a third country, unless required to do so by United Kingdom or EU member-state law to which the Processor is subject. In such a case, the Processor will inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
4.2 The Controller's documented instructions are constituted by:
(a) the Principal Agreement (including the configuration and use of the Service and its features by the Controller and its authorised users);
(b) this DPA, including its Annexes;
(c) the Controller's use of the functionality, settings and controls made available within the Service; and
(d) any further written instructions agreed by the Parties from time to time.
4.3 Taken together, the Principal Agreement and this DPA constitute the Controller's complete and final documented instructions to the Processor at the date of this DPA. Any additional or alternative instructions must be agreed in writing and may, if they require a change to the Service or to the Processor's systems or fees, be subject to the Processor's reasonable agreement and the change-control provisions of the Principal Agreement.
4.4 The Processor will immediately inform the Controller if, in its opinion, an instruction infringes the Data Protection Laws. In such circumstances the Processor is entitled to suspend performance of the affected instruction (without liability) until the Controller has confirmed, amended or withdrawn it. This Clause 4.4 does not oblige the Processor to carry out any legal assessment of the lawfulness of the Controller's instructions.
4.5 The Processor will not "sell" Customer Personal Data and will not Process Customer Personal Data for its own purposes, except: (a) to provide and support the Service in accordance with the Controller's instructions; (b) where it acts as a Controller for the purposes described in the Privacy Notice (which fall outside this DPA); and (c) where required by law.
5. Confidentiality of personnel
5.1 The Processor will ensure that any person it authorises to Process Customer Personal Data (including its employees, agents and contractors):
(a) is subject to a binding contractual or statutory duty of confidentiality in respect of the Customer Personal Data;
(b) Processes the Customer Personal Data only on the instructions of the Processor and as necessary to perform the Service, unless required to access the data by law;
(c) is granted access to Customer Personal Data on a strict need-to-know and least-privilege basis; and
(d) has received appropriate training in respect of their data-protection and information-security responsibilities.
6. Security of Processing (Article 32)
6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects, the Processor will implement and maintain appropriate Technical and Organisational Measures to ensure a level of security appropriate to the risk, as set out in Annex 2 (Technical & Organisational Measures) and the Processor's Information Security Policy.
6.2 The measures in Annex 2 include, as appropriate: the pseudonymisation and encryption of Personal Data; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems and services; the ability to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing and evaluating the effectiveness of the measures.
6.3 The Processor may update or modify the TOMs from time to time, provided that such updates do not materially reduce the overall level of security of the Customer Personal Data. Annex 2 is aligned with, and supplemented by, the Processor's Information Security Policy; in the event of a conflict between the summary in Annex 2 and the more detailed Information Security Policy, the document providing the higher standard of protection prevails.
6.4 In assessing the appropriate level of security, the Parties will in particular take account of the risks presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data transmitted, stored or otherwise Processed.
7. Sub-processing
7.1 General written authorisation. The Controller grants the Processor general written authorisation to engage Sub-processors to Process Customer Personal Data, subject to this Clause 7. The Sub-processors engaged by the Processor as at the date of this DPA are listed in Annex 3 (Approved Sub-processors), and the Controller authorises their engagement.
7.2 Notice of changes and right to object. The Processor will maintain an up-to-date list of Sub-processors and will give the Controller prior notice (which may be given by email and/or by updating Annex 3 or a published sub-processor list and notifying registered Controllers) of the intended addition or replacement of any Sub-processor, giving the Controller the opportunity to object. The Processor will give such notice not less than 14 days before the new Sub-processor begins Processing Customer Personal Data, save where a shorter period is necessary to address an urgent security or service-continuity need.
7.3 The Controller may object to the appointment of a new Sub-processor on reasonable data-protection grounds by notifying the Processor in writing within 14 days of the notice given under Clause 7.2. The Parties will work together in good faith to resolve the objection. If the Parties cannot reach a resolution, the Processor may, at its option, either: (a) not appoint the relevant Sub-processor in respect of the Controller's Customer Personal Data; or (b) where this is not reasonably possible without materially affecting the Service, permit the Controller to suspend or terminate the affected part of the Service (or, if the Sub-processor is integral to the Service, the Principal Agreement) without penalty, with a pro-rata refund of any pre-paid fees for the unused portion of the affected Service. Termination under this Clause 7.3 is the Controller's sole and exclusive remedy in respect of an objection to a Sub-processor.
7.4 Flow-down terms. Where the Processor engages a Sub-processor, it will do so by way of a written contract that imposes on the Sub-processor data-protection obligations that are no less protective than those imposed on the Processor under this DPA, in particular providing sufficient guarantees to implement appropriate Technical and Organisational Measures such that the Processing meets the requirements of the UK GDPR. The Processor will ensure that each Sub-processor is bound by obligations equivalent to those in Article 28(3) of the UK GDPR.
7.5 Processor liability for Sub-processors. The Processor remains fully liable to the Controller for the performance of each Sub-processor's data-protection obligations to the same extent as the Processor would be liable if performing those obligations itself, subject always to the limitations and exclusions of liability in Clause 14 and the Principal Agreement. Where a Sub-processor fails to fulfil its data-protection obligations, the Processor remains liable to the Controller for the performance of that Sub-processor's obligations.
7.6 Due diligence. The Processor will carry out appropriate due diligence on each Sub-processor prior to engagement and on an ongoing basis, including in respect of the Sub-processor's security measures and, where relevant, the location of Processing and applicable transfer safeguards.
8. Assistance to the Controller
8.1 Data Subject rights
8.1.1 Taking into account the nature of the Processing, the Processor will assist the Controller, by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests by Data Subjects to exercise their rights under Chapter III of the UK GDPR, including the rights of access, rectification, erasure ("right to be forgotten"), restriction of Processing, data portability, objection (including the absolute right to object to direct marketing), withdrawal of consent, and rights in relation to solely-automated decision-making and profiling (Article 22).
8.1.2 The Processor will, to the extent legally permitted, promptly notify the Controller if the Processor (or any Sub-processor) receives a request from a Data Subject in respect of Customer Personal Data, and will not respond to that request other than on the documented instructions of the Controller or as required by law. Where the Service provides self-service functionality enabling the Controller to access, correct, export, delete or restrict Customer Personal Data, the Controller will, in the first instance, use that functionality to give effect to a Data Subject request.
8.1.3 Automated decision-making and profiling. The Service uses artificial intelligence to generate marketing content and to assist with lead targeting and audience segmentation, which may involve profiling within the meaning of Article 4(4) of the UK GDPR. The Processor does not make, and the Service is not designed to make, any decision based solely on automated Processing (including profiling) that produces legal effects concerning a Data Subject or similarly significantly affects them. The Controller is responsible for ensuring that any profiling or automated decision-making it directs through the Service has a lawful basis and is accompanied by appropriate safeguards in accordance with Article 22. The Processor will assist the Controller, insofar as possible, in responding to any Data Subject request concerning automated decision-making or profiling.
8.2 Assistance with Articles 32 to 36
Taking into account the nature of the Processing and the information available to the Processor, the Processor will provide reasonable assistance to the Controller in ensuring compliance with the Controller's obligations under Articles 32 to 36 of the UK GDPR, namely:
(a) security of Processing (Article 32) — by maintaining the TOMs and, on reasonable request, providing information about them in accordance with Clause 12;
(b) personal-data-breach notification (Articles 33 and 34) — in accordance with Clause 9;
(c) data protection impact assessments (Article 35) — by providing, on reasonable request, information reasonably necessary to enable the Controller to carry out a DPIA in respect of the Processing performed by the Processor under this DPA; and
(d) prior consultation (Article 36) — by providing reasonable assistance in connection with any prior consultation with a Supervisory Authority.
8.3 Cost of assistance
The Processor will provide the assistance described in Clauses 8.1 and 8.2 without additional charge where it is readily achievable using the standard functionality of the Service. Where assistance requires material additional effort or resources beyond such standard functionality, the Processor may charge its reasonable costs, notified to the Controller in advance, save that the Processor will not charge for assistance in connection with a Personal Data Breach caused by the Processor's breach of this DPA.
9. Personal Data Breach notification
9.1 The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
9.2 Such notification will, to the extent known and as it becomes available, describe:
(a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned;
(b) the name and contact details of the Processor's data-protection contact (privacy@frame.plus) or other relevant point of contact from whom more information can be obtained;
(c) the likely consequences of the Personal Data Breach; and
(d) the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
9.3 Where, and insofar as, it is not possible to provide all of the above information at the same time, the information may be provided in phases without undue further delay.
9.4 The Processor will take reasonable steps to investigate, contain and remediate the Personal Data Breach and will reasonably cooperate with the Controller and provide such information as the Controller reasonably requires to enable the Controller to meet any obligations it may have to notify the ICO (within 72 hours where required) and/or affected Data Subjects under Articles 33 and 34 of the UK GDPR.
9.5 The obligation to notify the Controller under this Clause 9 is not an acknowledgement by the Processor of any fault or liability in respect of the Personal Data Breach. As between the Parties, the Controller is responsible for determining whether and how to notify the ICO and affected Data Subjects in respect of Customer Personal Data, unless otherwise required by law.
10. Records and compliance
10.1 The Processor will maintain a record of all categories of Processing activities carried out on behalf of the Controller, as required by Article 30(2) of the UK GDPR.
10.2 The Processor will designate, and the Controller may contact, the following points of contact in relation to this DPA:
- Privacy and data protection: privacy@frame.plus
- Data subject requests and DPO / data-protection matters: dpo@frame.plus (or the Data Protection Lead)
- General and legal: legal@frame.plus
- Post: [Registered office address]
11. Deletion or return of Customer Personal Data
11.1 On termination or expiry of the Principal Agreement, or on the Controller's earlier written instruction, the Processor will, at the choice of the Controller, delete or return all Customer Personal Data to the Controller and delete existing copies, unless United Kingdom or EU law requires storage of the Personal Data.
11.2 Unless the Controller notifies the Processor of its choice within 30 days of termination or expiry, the Processor may delete the Customer Personal Data in accordance with its standard retention and deletion processes. Customer Personal Data will be returned or deleted within 30 days of the Controller's instruction or of termination/expiry (as applicable), and copies of Customer Personal Data held in routine backups will be purged or rendered inaccessible in accordance with the Processor's backup-rotation cycle, within 90 days.
11.3 The detailed approach to retention periods, deletion methods and backup purging is set out in the Processor's Retention & Deletion Policy, which is incorporated by reference. Secure deletion methods are used in accordance with Annex 2.
11.4 PECR suppression-data exception. Notwithstanding Clauses 11.1 and 11.2, the Processor may retain, and is entitled to require the Controller to permit it to retain, the minimum data necessary to operate and honour unsubscribe and suppression mechanisms (for example, hashed email addresses or suppression-list identifiers) for as long as necessary to ensure that recipients who have objected to or unsubscribed from marketing continue to be suppressed, as required by PECR and Article 21 of the UK GDPR. Such suppression data will be Processed only for the purpose of honouring those objections and unsubscribes and will be subject to appropriate security measures. This Clause 11.4 survives termination of the Principal Agreement.
11.5 Where the Processor is required by law to retain some or all of the Customer Personal Data beyond the periods described above, it will: (a) inform the Controller (unless prohibited by law); (b) retain only the minimum data necessary for the period required; (c) protect the confidentiality of such data; and (d) Process it only as necessary for the purpose(s) of retention required by that law.
11.6 At the Controller's written request, the Processor will provide written confirmation of the deletion of Customer Personal Data carried out in accordance with this Clause 11.
12. Audit and information
12.1 The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the UK GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to this Clause 12.
12.2 The Processor may satisfy its obligations under Clause 12.1, in the first instance, by providing the Controller with: (a) a copy of, or summary of, the TOMs and the Information Security Policy; (b) responses to a reasonable written security questionnaire; and/or (c) copies of any then-current third-party certifications, attestations or audit reports (for example, ISO/IEC 27001 certification or SOC 2 reports of the Processor or its Sub-processors), to the extent available.
12.3 Where the information made available under Clause 12.2 is not sufficient for the Controller to demonstrate compliance, the Controller (or its mandated auditor, who must not be a competitor of the Processor and must be bound by appropriate confidentiality obligations) may, on giving not less than 30 days' prior written notice, conduct an audit or inspection. Any such audit will:
(a) be conducted no more than once in any 12-month period, save where required by a Supervisory Authority or following a Personal Data Breach affecting the Controller's Customer Personal Data;
(b) be conducted during the Processor's normal business hours;
(c) be of a reasonable duration and scope;
(d) be subject to the Processor's reasonable security, confidentiality and access policies; and
(e) not unreasonably disrupt the Processor's business, compromise the security of the data of the Processor's other customers, or require the Processor to disclose information that is commercially sensitive or subject to legal privilege.
12.4 The Parties will bear their own costs in connection with an audit, save that the Controller will reimburse the Processor's reasonable costs (at the Processor's then-current professional-services rates) for assistance provided in excess of that required by applicable law, where the audit reveals no material breach by the Processor.
12.5 The Processor will immediately inform the Controller if, in its opinion, an instruction given under this Clause 12 infringes the Data Protection Laws.
13. International transfers
13.1 The Processor will not transfer Customer Personal Data to a country outside the United Kingdom (or, where the EU GDPR applies, outside the EEA) except in accordance with this Clause 13 and on the Controller's documented instructions (which include the authorisation given by the Controller in respect of the Sub-processor locations set out in Annex 3).
13.2 Primary hosting region. The primary hosting region for Customer Personal Data is AWS Europe (London), region eu-west-2, in the United Kingdom. The Processor configures its core infrastructure to host and Process Customer Personal Data within the United Kingdom (and/or the EEA) wherever reasonably practicable.
13.3 Restricted Transfers. Where the provision of the Service requires a Restricted Transfer (including transfers to certain Sub-processors located in, or whose parent undertakings are located in, the United States, or transfers to providers located in China as flagged in Annex 3), the Processor will ensure that an appropriate transfer mechanism is in place before the transfer takes place. Such mechanisms may include:
(a) the IDTA and/or the EU SCCs together with the UK Addendum;
(b) reliance on the UK Extension to the EU–US Data Privacy Framework, where the relevant importer is certified under that framework; and/or
(c) any other transfer tool or derogation permitted under Article 46 or Article 49 of the UK GDPR (and, where applicable, the EU GDPR).
13.4 By entering into this DPA and authorising the Sub-processors listed in Annex 3, the Controller: (a) instructs and authorises the Processor (and its Sub-processors) to make Restricted Transfers as necessary to provide the Service; and (b) where required, authorises the Processor to enter into the SCCs (including the IDTA / UK Addendum) with the relevant Sub-processors on the Controller's behalf, or to rely on transfer mechanisms entered into directly between the Processor and the Sub-processor. Where the Processor is required to enter into SCCs directly with the Controller in respect of any transfer, the SCCs are incorporated into this DPA by reference and will be completed using the information in Annexes 1 to 3, with this DPA's governing-law, jurisdiction and liability provisions applying to the extent permitted by the SCCs.
13.5 Higher-risk transfers (China). The Controller acknowledges and specifically authorises that, where it elects to use the relevant features, certain content may be sent to Sub-processors located in China (the People's Republic of China) — namely DeepSeek (long-form blog/article generation) and, potentially, Seedance (premium UGC video generation). China is not the subject of UK adequacy regulations. Accordingly, the Processor will:
(a) put in place an IDTA (or EU SCCs + UK Addendum) with the relevant provider, or otherwise ensure an appropriate Article 46 transfer mechanism;
(b) carry out and maintain a documented Transfer Risk Assessment in respect of each such transfer;
(c) apply data minimisation so that only the data necessary for the relevant feature (for example, the marketing brief or prompt) is transferred, and instruct Customers not to include Special Category Data or unnecessary personal identifiers in such prompts/briefs; and
(d) keep these transfers under review and suspend or replace the relevant Sub-processor if the safeguards cease to provide an adequate level of protection.
The Controller is responsible for assessing the suitability of these higher-risk features for its own data and for instructing its authorised users accordingly. The Controller may avoid these transfers by not using the relevant features.
13.6 The Processor will, on reasonable request, provide the Controller with a copy of the relevant transfer mechanism (redacted as necessary for commercial confidentiality) and a summary of the applicable Transfer Risk Assessment.
14. Liability and indemnity
14.1 Each Party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to the exclusions and limitations of liability set out in the Principal Agreement, which apply to this DPA as if set out in full here. The Parties intend that the limitations and exclusions of liability in the Principal Agreement apply to the Parties' aggregate liability under both the Principal Agreement and this DPA taken together, and not separately.
14.2 Liability. Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement (the Frame.plus Terms of Service), which apply to this DPA as if set out in full here. Without limiting that allocation, the Controller shall indemnify and hold the Processor harmless against losses, claims, damages and regulatory fines arising from: (a) the Controller's processing instructions; (b) the Controller's lack of, or reliance on an invalid, lawful basis; (c) the Controller's breach of Clause 2.2, Clause 3 or the PECR warranties; or (d) the Controller's upload of unlawful Customer Personal Data. The allocation of any administrative fine, compensation award or Data Subject claim shall follow the parties' respective responsibilities under the Data Protection Laws and the Agreement.
14.3 Where the Parties are found jointly and severally liable in respect of damage caused by Processing, each Party is entitled to claim back from the other that part of the compensation corresponding to the other Party's responsibility for the damage, in accordance with Article 82 of the UK GDPR.
14.4 Nothing in this DPA limits or excludes either Party's liability to the extent such liability cannot be limited or excluded by law.
15. General
15.1 Order of precedence. This DPA forms part of and is subject to the Principal Agreement. In the event of any conflict or inconsistency between the documents, the order of precedence is:
(a) first, the Standard Contractual Clauses (including the IDTA / UK Addendum), to the extent applicable to a Restricted Transfer and to the extent of the conflict;
(b) second, this DPA (including its Annexes);
(c) third, the remainder of the Principal Agreement,
in each case solely to the extent of the conflict and solely in relation to the Processing of Customer Personal Data. Within this DPA, the body of the DPA prevails over the Annexes except where an Annex expressly states otherwise.
15.2 Changes in law. If a change in the Data Protection Laws (or guidance issued by a Supervisory Authority) requires amendment to this DPA, the Parties will negotiate in good faith to make the necessary amendments so as to maintain compliance.
15.3 Severance. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions continue in full force and effect.
15.4 Variation. Save as otherwise expressly provided in this DPA (including the Sub-processor and TOMs update mechanisms), no variation of this DPA is effective unless made in writing.
15.5 Governing law and jurisdiction. This DPA and any dispute or claim arising out of or in connection with it are governed by and construed in accordance with the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the courts of England and Wales, save that this Clause 15.5 does not override any mandatory governing-law or jurisdiction provisions of any applicable Standard Contractual Clauses.
15.6 Third-party rights. Save as expressly provided, a person who is not a Party to this DPA has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.
Annex 1 — Details of Processing
This Annex forms part of the DPA and constitutes the description required by Article 28(3) of the UK GDPR.
1. Parties
- Controller (data exporter): the Customer, as identified in the Principal Agreement.
- Processor (data importer): Evryone Ltd (t/a Frame.plus), [Registered office address], registered with the ICO as a data protection fee payer (ICO registration reference ZC182890).
2. Subject-matter of the Processing
The provision of the Frame.plus AI marketing operating system to the Controller, comprising the planning, generation, scheduling, publication, distribution and reporting of marketing content and communications, and the operation of lead generation and email outreach, in each case using Customer Personal Data submitted to or generated through the Service.
3. Duration of the Processing
For the term of the Principal Agreement, plus any period thereafter during which the Processor retains Customer Personal Data in accordance with Clause 11 of this DPA and the Retention & Deletion Policy (including PECR suppression data retained under Clause 11.4).
4. Nature and purpose of the Processing
Collection, recording, organisation, structuring, storage, hosting, retrieval, consultation, use, analysis, generation, enrichment, segmentation, transmission, distribution, disclosure to Sub-processors, and erasure of Customer Personal Data, for the purposes of:
(a) hosting and storing audience lists, contact lists, Lead Data and uploaded brand assets; (b) generating, scheduling, publishing and distributing marketing content across social, advertising, newsletter, blog and video channels; (c) operating the Outreach feature, including AI-assisted lead generation, sending and receiving email, drafting replies, and recording email engagement/event data; (d) producing analytics and reporting on marketing performance; (e) operating the Frame AI chat assistant and Creative Studio in respect of Customer Personal Data; and (f) providing related support and security functions.
5. Types of Personal Data
- Audience and contact data: names, business names, email addresses, and other contact details contained in audience lists and mailing lists uploaded or managed by the Controller.
- Lead Data (Outreach): names, business names, work email addresses, job roles/titles, company details and public profile data sourced via lead generation.
- Email content and engagement data: the content of marketing, outreach and reply emails, and engagement/event data (sends, opens, clicks, replies, bounces, complaints, unsubscribes, and inbound messages received).
- Brand assets / creative materials: Personal Data incidentally contained in uploaded or generated images, video and other creative (for example, identifiable individuals appearing in images).
The Parties confirm that Special Category Data and criminal-offence data are not within scope and must not be uploaded (Clause 3).
6. Categories of Data Subjects
- The Controller's leads and prospective business contacts (typically business contacts at "corporate subscribers" and other organisations).
- The Controller's existing contacts, subscribers and audience members.
- Recipients of, and senders to, email sent or received through the Outreach and email features.
- Individuals depicted in or identifiable from brand assets and creative materials uploaded by the Controller.
7. Frequency of the Processing
Continuous and on an ongoing basis for the duration of the Principal Agreement (including automated background generation and scheduled processing).
Annex 2 — Technical & Organisational Measures (TOMs)
This Annex summarises the security measures implemented by the Processor pursuant to Article 32 of the UK GDPR and Clause 6 of this DPA. It is aligned with, and supplemented by, the Processor's Information Security Policy.
| # | Measure | Description |
|---|---|---|
| 1 | Encryption in transit | All data transmitted to and from the Service is encrypted using TLS 1.2 or higher. Internal service-to-service and Redis (Upstash) connections use TLS. |
| 2 | Encryption at rest | Customer Personal Data is encrypted at rest using AES-256, via AWS KMS-managed keys and/or database-level encryption (Amazon S3, MongoDB Atlas). |
| 3 | Authentication | Passwordless authentication using email one-time codes; no passwords are stored. Authenticated sessions use signed session tokens. |
| 4 | Access control | Role-based access control (RBAC) and least-privilege principles for both Customer-facing roles and internal administrative access. Access to production data is restricted to authorised personnel on a need-to-know basis. |
| 5 | Secrets and key management | Centralised, access-controlled management of secrets, credentials and encryption keys (e.g. AWS KMS / secrets management). |
| 6 | Network security | Network segmentation, firewalls and security groups; restriction of inbound/outbound traffic; isolation of production environments. |
| 7 | Logging, monitoring and alerting | Centralised logging, monitoring and alerting, including event handling via SNS/SQS for delivery, bounce, complaint, open, click, unsubscribe and inbound events; security event monitoring and alerting. |
| 8 | Backups and resilience | Automated backups with tested restore procedures to ensure availability and resilience and timely restoration following an incident. |
| 9 | Vulnerability and patch management | Ongoing vulnerability management and timely patching of systems and dependencies. |
| 10 | Secure development | Secure software development lifecycle (SDLC), including code review and security testing prior to release. |
| 11 | Sub-processor due diligence | Due diligence on Sub-processors and the imposition of written data-processing terms (DPAs) with flow-down obligations. |
| 12 | Data minimisation and pseudonymisation | Data minimisation and pseudonymisation applied where feasible, including in respect of prompts/briefs sent to AI Sub-processors. |
| 13 | Personnel | Staff bound by confidentiality obligations and provided with data-protection and security training. |
| 14 | Incident response | Documented incident-response process, including assessment, containment, remediation, and Personal Data Breach notification to the ICO within 72 hours where applicable and to affected Controllers/individuals without undue delay. |
| 15 | Secure deletion | Secure deletion methods applied to Customer Personal Data on expiry of retention periods and on return/deletion under Clause 11, including purging of backups. |
The Processor may update these measures from time to time in accordance with Clause 6.3, provided the overall level of security is not materially reduced.
Annex 3 — Approved Sub-processors
This Annex lists the Sub-processors authorised under Clause 7 as at the date of this DPA. The Processor maintains an up-to-date list and will notify the Controller of changes in accordance with Clause 7.2. Region placeholders marked [ ] are to be completed/confirmed by the Processor.
| Sub-processor | Purpose | Location / hosting region | Transfer safeguard (if a Restricted Transfer) |
|---|---|---|---|
| Amazon Web Services (AWS) — Amazon SES v2, Amazon S3, Amazon SNS/SQS | Transactional, marketing, outreach and system email send and inbound receiving (SES); storage of uploaded and generated assets, email attachments and raw inbound email (S3); delivery, bounce, complaint, open, click, unsubscribe and inbound event handling (SNS/SQS) | Primary data hosting: AWS Europe (London), eu-west-2 (United Kingdom). AWS is a US-headquartered provider. | AWS DPA with UK IDTA / EU SCCs + UK Addendum for any transfers outside the UK. |
| MongoDB Atlas | Primary application database | AWS Europe (London), eu-west-2. Provider US-headquartered. | SCCs / UK IDTA. |
| Upstash (Redis) | Queues and cache for background jobs | European Union. TLS enabled. | SCCs / UK IDTA where applicable. |
| Stripe | Payment processing and subscription billing. Stripe acts as an independent controller in respect of payment data. | UK / EU / US. | Stripe DPA + SCCs / IDTA. |
| OpenAI | Frame AI chat and still-image generation (ChatGPT Image) | United States. API data not used to train models. | OpenAI API DPA; UK Extension to the EU–US Data Privacy Framework / IDTA. |
| Anthropic (Claude) | Creative orchestration, planning, copy/strategy drafting and review | United States. API data not used to train models. | Anthropic Commercial Terms + DPA; IDTA. |
| DeepSeek | Long-form blog/article generation | China (People's Republic of China). Prompts/briefs may contain personal data. HIGHER-RISK TRANSFER — no UK adequacy decision. | IDTA required + documented Transfer Risk Assessment (TRA); data minimisation; no Special Category Data. See Clause 13.5. |
| Seedance | Premium UGC video generation | outside the UK and EEA (a restricted transfer safeguarded by the UK IDTA / SCCs and a Transfer Risk Assessment). FLAGGED as higher-risk transfer. | IDTA / SCCs + TRA. See Clause 13.5. |
| Pexels | Stock imagery | AWS Europe (London), eu-west-2. No Customer Personal Data expected to be sent. | SCCs / IDTA if any transfer of personal data occurs. |
| Zernio | Social account connection, social publishing/scheduling, ads connection | European Union. | DPA + transfer safeguards as applicable. |
| Amazon Web Services (AWS) | Hosting and content delivery for the web application | Amazon Web Services (AWS) — AWS Europe (London), eu-west-2. | SCCs / IDTA where applicable. |
Notes.
- The transfers to DeepSeek and Seedance (China / outside the UK/EEA) are higher-risk and are subject to the specific safeguards and Controller authorisation in Clause 13.5, including data minimisation, an IDTA/SCCs, and a documented Transfer Risk Assessment. The Controller may avoid these transfers by not using the relevant blog/article-generation and premium UGC video features.
- Where a Sub-processor acts as an independent controller (e.g. Stripe for payment data), that Processing is governed by the relevant Sub-processor's own terms and privacy notice and not by this DPA.
End of Data Processing Agreement (v1.0). Cross-references: Frame.plus Privacy Notice; Information Security Policy / TOMs; Retention & Deletion Policy; Frame.plus Terms of Service.