Data processing addendum
Last updated: 15 July 2026
This addendum ("DPA") forms part of our terms of service and applies where plaingraph processes personal data on your behalf. It reflects Article 28 of the UK and EU GDPR. For the personal data plaingraph handles as a controller in its own right, see the privacy policy.
1. When this applies
This DPA applies when you use the service and, in doing so, submit personal data that we process on your behalf — for example the queries you send us (what you look up), which can contain personal data you control. By its nature the product is built from public company records and is designed to avoid holding person-level data (see privacy), so the personal data processed under this DPA is limited. Where we determine the purposes and means of processing ourselves — such as your account and billing data — we act as controller under the privacy policy, and this DPA does not apply to that processing.
2. Roles
For personal data you submit through the service, you act as the controller (or as a processor for your own customer) and plaingraph acts as your processor (or sub-processor). Each of us will comply with the data-protection law that applies to it. You are responsible for having a lawful basis for the data you submit and for issuing lawful instructions.
3. Our instructions and scope
We process personal data you submit only on your documented instructions — which your configured and ordinary use of the service constitutes — and only to provide, secure, and support the service, and to comply with the law. The subject matter, duration, nature, and purpose of the processing, and the types of personal data and categories of data subjects, are set out in the Annex below. We will tell you if we believe an instruction breaks data-protection law.
4. Confidentiality
We ensure that the people we authorise to process your personal data are bound by an appropriate duty of confidentiality.
5. Security
We put in place appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs, and the risk to individuals (Article 32). This includes encryption in transit, access controls and least-privilege, separation of query data from billing and audit records, and stripping request bodies, query strings, headers, and cookies from error data before it is sent to our monitoring tools.
6. Sub-processors
You give us general authorisation to engage the sub-processors listed in section 8 of the privacy policy. We impose data-protection terms on each of them that are no less protective than this DPA, and we remain responsible to you for what they do. We give notice before a new or replacement sub-processor starts handling personal data, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may stop using the affected part of the service.
7. International transfers
Most data stays in the UK or EEA. Where a sub-processor is outside the UK/EEA (currently as noted in the privacy policy), we rely on an appropriate transfer safeguard, such as the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. We can provide a copy on request.
8. Helping you meet your obligations
Taking into account the nature of the processing and the information available to us, we will give you reasonable help to respond to requests from individuals exercising their rights, and to meet your obligations on security, breach notification, and data-protection impact assessments (Articles 32 to 36). Because the service holds only limited personal data and does not profile the companies you look up, the assistance we can give reflects that.
9. No independent use, no training
We do not use the personal data you submit for our own purposes. We do not mine your query data to build the product, we do not use it to train or improve models, and we do not sell it — we use it only to provide and secure the service, as set out in the privacy policy.
10. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting the data we process for you, with the information you reasonably need to meet your own notification duties.
11. Return and deletion
When your access ends, or on your written request, we will delete or return the personal data we process on your behalf, and delete existing copies, unless the law requires us to keep it. Query data is kept only for a short period to run and secure the service and is then deleted or aggregated, as described in the privacy policy.
12. Audit
We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. Audits are subject to reasonable notice, confidentiality, and frequency, and must not compromise the security of other customers.
13. Annex — details of the processing
| Subject matter | Provision of the plaingraph service to you |
| Duration | For as long as you use the service, plus the short retention set out in the privacy policy |
| Nature and purpose | Receiving and answering your queries, and securing and supporting the service |
| Types of personal data | Any personal data contained in the queries you submit; incidental personal data present in public filings surfaced in a response (for example a name in a filed accounts document or charge record) |
| Categories of data subjects | Individuals whose data you choose to include in a query, and individuals incidentally named in public company filings |
| Sub-processors | As listed in section 8 of the privacy policy |
14. Putting this in place
This online DPA applies automatically whenever the service processes personal data on your behalf; you do not need to sign anything. If your organisation needs a countersigned copy, email [email protected] and we will arrange one. If there is any conflict between this DPA and the rest of the terms on the processing of personal data, this DPA prevails.
← Back to plaingraph