Data processing addendum

This addendum ("DPA") forms part of our terms of service and applies where plaingraph processes personal data on your behalf. It reflects Article 28 of the UK and EU GDPR. For the personal data plaingraph handles as a controller in its own right, see the privacy policy.

1. When this applies

This DPA applies when you use the service and, in doing so, submit personal data that we process on your behalf — for example the queries you send us (what you look up), which can contain personal data you control. By its nature the product is built from public company records and is designed to avoid holding person-level data (see privacy), so the personal data processed under this DPA is limited. Where we determine the purposes and means of processing ourselves — such as your account and billing data — we act as controller under the privacy policy, and this DPA does not apply to that processing.

2. Roles

For personal data you submit through the service, you act as the controller (or as a processor for your own customer) and plaingraph acts as your processor (or sub-processor). Each of us will comply with the data-protection law that applies to it. You are responsible for having a lawful basis for the data you submit and for issuing lawful instructions.

3. Our instructions and scope

We process personal data you submit only on your documented instructions — which your configured and ordinary use of the service constitutes — and only to provide, secure, and support the service, and to comply with the law. The subject matter, duration, nature, and purpose of the processing, and the types of personal data and categories of data subjects, are set out in the Annex below. We will tell you if we believe an instruction breaks data-protection law.

4. Confidentiality

We ensure that the people we authorise to process your personal data are bound by an appropriate duty of confidentiality.

5. Security

We put in place appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs, and the risk to individuals (Article 32). This includes encryption in transit, access controls and least-privilege, separation of query data from billing and audit records, and stripping request bodies, query strings, headers, and cookies from error data before it is sent to our monitoring tools.

6. Sub-processors

You give us general authorisation to engage the sub-processors listed in section 8 of the privacy policy. We impose data-protection terms on each of them that are no less protective than this DPA, and we remain responsible to you for what they do. We give notice before a new or replacement sub-processor starts handling personal data, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may stop using the affected part of the service.

7. International transfers

Most data stays in the UK or EEA. Where a sub-processor is outside the UK/EEA (currently as noted in the privacy policy), we rely on an appropriate transfer safeguard, such as the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. We can provide a copy on request.

8. Helping you meet your obligations

Taking into account the nature of the processing and the information available to us, we will give you reasonable help to respond to requests from individuals exercising their rights, and to meet your obligations on security, breach notification, and data-protection impact assessments (Articles 32 to 36). Because the service holds only limited personal data and does not profile the companies you look up, the assistance we can give reflects that.

9. No independent use, no training

We do not use the personal data you submit for our own purposes. We do not mine your query data to build the product, we do not use it to train or improve models, and we do not sell it — we use it only to provide and secure the service, as set out in the privacy policy.

10. Personal-data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting the data we process for you, with the information you reasonably need to meet your own notification duties.

11. Return and deletion

When your access ends, or on your written request, we will delete or return the personal data we process on your behalf, and delete existing copies, unless the law requires us to keep it. Query data is kept only for a short period to run and secure the service and is then deleted or aggregated, as described in the privacy policy.

12. Audit

We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. Audits are subject to reasonable notice, confidentiality, and frequency, and must not compromise the security of other customers.

13. Annex — details of the processing

14. Putting this in place

This online DPA applies automatically whenever the service processes personal data on your behalf; you do not need to sign anything. If your organisation needs a countersigned copy, email [email protected] and we will arrange one. If there is any conflict between this DPA and the rest of the terms on the processing of personal data, this DPA prevails.

← Back to plaingraph