Loading...
Legal
This Data Processing Agreement ("DPA") forms part of the agreement between Pericls Ltd ("Processor", "Pericls", "we", "us") and the entity agreeing to the Pericls Terms of Service ("Controller", "Customer", "you", "your") for the provision of the Pericls regulatory compliance intelligence platform (the "Service"), as described in the Terms of Service (the "Principal Agreement").
This DPA applies to the extent that Pericls processes Personal Data on behalf of the Controller in connection with the Service. This DPA is incorporated into and subject to the Principal Agreement.
In the event of any conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to the processing of Personal Data.
In this DPA, the following terms have the meanings set out below. Terms not defined here have the meanings given in the GDPR or the Principal Agreement.
| Term | Definition |
|---|---|
| "Applicable Data Protection Law" | All laws and regulations relating to the processing of Personal Data applicable to the processing described in this DPA, including the UK GDPR, the Data Protection Act 2018, the EU GDPR, the ePrivacy Directive (2002/58/EC), the Privacy and Electronic Communications Regulations 2003 (PECR), and any national implementing legislation. |
| "Controller" | The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data. For this DPA, the Controller is the Customer. |
| "Data Subject" | An identified or identifiable natural person to whom Personal Data relates. |
| "EEA" | The European Economic Area (EU Member States plus Iceland, Liechtenstein, and Norway). |
| "EU GDPR" | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation). |
| "UK GDPR" | The EU GDPR as retained in UK law by the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019. |
| "GDPR" | References to the "GDPR" in this DPA refer to the UK GDPR and/or the EU GDPR as applicable to the Processing in question. |
| "IDTA" | The International Data Transfer Agreement issued by the UK Information Commissioner's Office under Section 119A of the Data Protection Act 2018, or the UK Addendum to the EU Standard Contractual Clauses issued under Section 119A of the Data Protection Act 2018, as applicable. |
| "Personal Data" | Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR, that is processed by the Processor on behalf of the Controller in connection with the Service. |
| "Personal Data Breach" | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed, as defined in Article 4(12) GDPR. |
| "Processing" | Any operation or set of operations performed on Personal Data, whether or not by automated means, as defined in Article 4(2) GDPR. This includes collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction. |
| "Processor" | A natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller. For this DPA, the Processor is Pericls. |
| "Standard Contractual Clauses" or "SCCs" | The standard contractual clauses approved by the European Commission for the transfer of Personal Data to third countries, as set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021. For transfers subject to UK GDPR, this includes the IDTA or the UK Addendum to the EU SCCs as approved by the ICO. |
| "Sub-processor" | Any third party engaged by the Processor to process Personal Data on behalf of the Controller. |
| "Supervisory Authority" | An independent public authority responsible for monitoring the application of data protection law. The lead Supervisory Authority for Pericls is the UK Information Commissioner's Office (ICO). For EU/EEA data subjects, the relevant Supervisory Authority is the competent authority in the applicable EU/EEA Member State pursuant to Article 51 EU GDPR. |
This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller as described in Annex I (Details of Processing).
This DPA shall remain in effect for the duration of the Principal Agreement and shall automatically terminate upon termination of the Principal Agreement, subject to Section 12 (Obligations upon Termination).
The Controller shall:
3.1 Ensure that it has a valid legal basis under Applicable Data Protection Law for the Processing of Personal Data and for instructing the Processor to process such data on its behalf.
3.2 Ensure that it has provided appropriate notice to Data Subjects regarding the Processing and, where required, obtained valid consent.
3.3 Ensure that its instructions to the Processor comply with Applicable Data Protection Law. The Controller acknowledges that by using the features of the Service (including AI/LLM analysis), it is instructing the Processor to process Personal Data in accordance with the service description and Documentation.
3.4 Be responsible for the accuracy, quality, and legality of the Personal Data it provides to the Processor.
3.5 Promptly inform the Processor if it becomes aware of any circumstances that could affect the Processor's ability to comply with Applicable Data Protection Law.
4.1.1 The Processor shall process Personal Data only on the documented instructions of the Controller, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
4.1.2 The Controller's instructions are documented in: (a) this DPA and its Annexes; (b) the Principal Agreement; (c) the Controller's use of the Service's features and configuration settings; and (d) any additional written instructions agreed between the parties.
4.1.3 If the Processor considers that an instruction from the Controller infringes Applicable Data Protection Law, the Processor shall promptly inform the Controller. The Processor shall not be required to carry out such instruction until the Controller has confirmed or modified it.
4.2.1 The Processor shall ensure that all persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2.2 The Processor shall ensure that access to Personal Data is limited to those personnel who require access to perform the services under the Principal Agreement.
4.3.1 The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons.
4.3.2 The specific technical and organisational measures implemented by the Processor are described in Annex II (Technical and Organisational Measures).
4.3.3 The Processor shall regularly test, assess, and evaluate the effectiveness of the technical and organisational measures for ensuring the security of Processing.
4.3.4 The Controller acknowledges that the security measures are subject to technical progress and development, and the Processor may update them from time to time, provided that such updates do not materially decrease the overall level of security.
4.4.1 The Controller provides general written authorisation for the Processor to engage Sub-processors, subject to the requirements of this Section 4.4.
4.4.2 The Processor's current list of authorised Sub-processors is set out in Annex III and published at Sub-Processor List.
4.4.3 The Processor shall:
(a) Notify the Controller of any intended addition or replacement of Sub-processors at least 30 days before the new Sub-processor begins Processing Personal Data, by email to the Organisation administrator address on file.
(b) Impose on each Sub-processor, by way of a written contract, data protection obligations that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.
(c) Remain fully liable to the Controller for the performance of each Sub-processor's obligations. If a Sub-processor fails to fulfil its data protection obligations, the Processor shall be liable to the Controller for the performance of the Sub-processor's obligations.
4.4.4 Objection Right: If the Controller objects to a new Sub-processor on reasonable data protection grounds, the Controller shall notify the Processor in writing within 14 days of receiving the notification. The parties shall negotiate in good faith to resolve the objection. If no resolution is reached within 30 days, the Controller may terminate the affected services without penalty.
4.5.1 Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests from Data Subjects to exercise their rights under Chapter III of the GDPR (Articles 15–22), including:
4.5.2 If a Data Subject contacts the Processor directly regarding the exercise of their rights, the Processor shall promptly redirect the request to the Controller and shall not respond to the Data Subject without the Controller's prior instruction, unless required by Applicable Data Protection Law.
4.5.3 The Processor shall provide the Controller with self-service tools within the Service to respond to Data Subject requests, including:
4.5.4 Where the Controller cannot fulfil a Data Subject request using the self-service tools, the Processor shall provide reasonable additional assistance upon request.
4.6.1 The Processor shall provide reasonable assistance to the Controller with data protection impact assessments under Article 35 GDPR and, where applicable, prior consultations with Supervisory Authorities under Article 36 GDPR, taking into account the nature of Processing and information available to the Processor.
4.7.1 The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.
4.7.2 The notification shall include, to the extent available at the time of notification:
(a) A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned.
(b) The name and contact details of the Processor's data protection officer or other contact point for further information.
(c) A description of the likely consequences of the Personal Data Breach.
(d) A description of the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects.
4.7.3 Where it is not possible to provide all information at the same time, the Processor shall provide the information in phases without further undue delay.
4.7.4 The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Personal Data Breach.
4.7.5 The Processor's notification of a Personal Data Breach shall not be construed as an acknowledgement of fault or liability by the Processor.
4.7.6 The Controller acknowledges that it is solely responsible for determining whether a Personal Data Breach is notifiable to Supervisory Authorities under Article 33 GDPR (within 72 hours) or to Data Subjects under Article 34 GDPR, and for making such notifications.
The Processor shall not transfer Personal Data to a country outside the United Kingdom or the EEA unless:
(a) An adequacy decision has been issued for the recipient country by the UK Secretary of State (under UK GDPR) or the European Commission (under EU GDPR, Article 45); or
(b) Appropriate safeguards have been provided in accordance with Article 46 GDPR (and the equivalent provisions of UK GDPR), including the execution of Standard Contractual Clauses (SCCs) and/or the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs as approved by the ICO.
5.2.1 To the extent that the Processing involves the transfer of Personal Data to Sub-processors outside the EEA, the parties agree that the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are hereby incorporated by reference. For transfers from Controller to Processor: Module Two (Controller to Processor) applies. For onward transfers from Processor to Sub-processor: Module Three (Processor to Processor) applies.
5.2.2 For the purposes of the EU SCCs:
5.3.1 To the extent that the Processing involves the transfer of Personal Data from the United Kingdom to Sub-processors outside the UK, the parties agree that the UK Addendum to the EU Standard Contractual Clauses (as approved by the ICO under Section 119A of the Data Protection Act 2018) is hereby incorporated by reference and shall apply in addition to the EU SCCs set out in Section 5.2.
5.3.2 In the event of any conflict between the UK Addendum and the EU SCCs, the UK Addendum shall prevail to the extent of such conflict for transfers subject to UK GDPR.
5.3.3 The ICO shall act as the competent supervisory authority for the purposes of the UK Addendum.
5.2.3 The details required under Annex I, II, and III of the SCCs are set out in Annexes I, II, and III of this DPA.
5.4.1 The Processor has conducted Transfer Impact Assessments for international transfers and, where necessary, implements supplementary measures to ensure an essentially equivalent level of protection, as recommended by the European Data Protection Board (EDPB Recommendations 01/2020) and in accordance with ICO guidance on international transfers.
5.4.2 Supplementary measures include, where applicable:
6.1.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
6.1.2 The Controller's right to audit is subject to the following conditions:
(a) The Controller shall provide at least 30 days' written notice of an audit request.
(b) Audits shall take place during normal business hours and shall not unreasonably disrupt the Processor's business operations.
(c) The Controller shall bear its own costs of the audit. If the audit requires more than 8 hours of the Processor's personnel time, the Controller shall reimburse the Processor's reasonable costs at the Processor's then-current professional services rates.
(d) The Controller shall ensure that any third-party auditor is bound by appropriate confidentiality obligations and is not a competitor of the Processor.
(e) Audits shall be limited to one per calendar year, unless a Personal Data Breach has occurred or is reasonably suspected, or a Supervisory Authority requires or requests an additional audit.
6.2.1 To the extent that the Processor holds relevant certifications or third-party audit reports (such as SOC 2 Type II, ISO 27001, or equivalent), the Processor shall make such reports available to the Controller upon request as an alternative to an on-site audit, where they provide sufficient assurance of the Processor's compliance with this DPA.
6.2.2 The Controller agrees that, where such reports are available and reasonably address the Controller's audit objectives, the Controller shall accept such reports in satisfaction of its audit rights under Section 6.1 for the period covered by the report.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement, except to the extent that Applicable Data Protection Law prohibits such limitations.
The Processor shall be liable for damage caused by Processing only where it has not complied with obligations of the GDPR specifically directed to Processors, or where it has acted outside of or contrary to the Controller's lawful instructions (Article 82(2) GDPR).
The Controller shall be liable for damage caused by Processing that infringes the GDPR, including where the Controller has given instructions that infringe Applicable Data Protection Law.
8.1.1 Upon termination of the Principal Agreement, the Processor shall, at the Controller's election:
(a) Return all Personal Data to the Controller in a structured, commonly used, and machine-readable format (JSON or CSV); and/or
(b) Delete all Personal Data, including all copies, from the Processor's systems and those of its Sub-processors.
8.1.2 The Controller shall communicate its election within the 30-day data export period following termination (as specified in the Principal Agreement). If the Controller does not communicate a preference within this period, the Processor shall securely delete all Personal Data.
8.1.3 The Processor shall complete the deletion within 90 days of the end of the data export period, except where Applicable Data Protection Law requires continued storage (e.g., billing records for tax compliance purposes).
8.1.4 Upon the Controller's written request, the Processor shall certify in writing that it has deleted all Personal Data, including specifying any data retained pursuant to legal obligations and the legal basis for such retention.
Sections 1, 4.2, 5, 6, 7, and this Section 8 shall survive termination of this DPA.
This DPA shall be governed by and construed in accordance with the laws of England and Wales, without regard to its conflict of laws provisions, except that the SCCs and UK Addendum shall be governed as specified in Sections 5.2.2 and 5.3.
This DPA may be amended only by written agreement of the parties. The Processor may update the Annexes to this DPA to reflect changes in Sub-processors (subject to Section 4.4), security measures, or processing activities, provided that such updates do not materially reduce the protections afforded to Personal Data.
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
In the event of a conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to the Processing of Personal Data. In the event of a conflict between this DPA and the SCCs, the SCCs shall prevail.
Notices under this DPA shall be sent to:
Data Exporter (Controller):
Data Importer (Processor):
| Element | Description |
|---|---|
| Subject matter of processing | Provision of the Pericls regulatory compliance intelligence platform, including document analysis, compliance gap identification, regulatory monitoring, and report generation |
| Duration of processing | For the duration of the Principal Agreement plus the data export and deletion periods described in Section 8 |
| Nature of processing | Collection, storage, organisation, structuring, retrieval, consultation, use (including AI/LLM analysis), disclosure by transmission (to Sub-processors), restriction, erasure, and destruction |
| Purpose of processing | To provide the Service as described in the Principal Agreement, including: account management, authentication, document storage and analysis, AI-powered regulatory analysis, compliance reporting, billing and subscription management, customer support, security monitoring, and analytics |
| Category | Description |
|---|---|
| Customer employees and representatives | Individuals with user accounts on the Service (Authorised Users) |
| Customer's customers and contacts | Individuals whose data may be contained in documents uploaded to the Service by the Customer |
| Billing contacts | Individuals responsible for payment and billing within the Customer's Organisation |
| Category | Data Elements | Sensitivity |
|---|---|---|
| Identity data | Full name, email address, avatar URL, display name | Standard |
| Authentication data | Password hash (bcrypt), OAuth tokens, SSO configuration, session tokens | High (credentials) |
| Organisation data | Organisation name, industry, size, membership roles | Standard |
| Contact data | Email address, billing address | Standard |
| Financial data | Stripe customer ID, payment method metadata, transaction history, subscription status | High (financial) |
| Technical data | IP address, user agent, browser type, device information, timezone | Standard |
| Usage data | Page views, feature interactions, session duration, clickstream data | Standard |
| Document data | Uploaded documents and extracted text content (may contain any categories of personal data as determined by the Controller) | Variable (determined by Controller) |
| Analysis data | AI/LLM analysis results, compliance reports, gap analysis outputs, assessment responses | Standard (derived data) |
| Communication data | Support correspondence, notification content | Standard |
| Error data | Error messages, component stack traces, request context | Standard |
The Processor does not require the Controller to provide special categories of data (Article 9 GDPR) or criminal conviction data (Article 10 GDPR). If such data is contained in documents uploaded by the Controller, the Controller is responsible for ensuring a lawful basis for processing under Article 9(2) GDPR.
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account + 30 days |
| Organisation data | Duration of organisation + 90 days |
| Uploaded documents | Duration of account; deleted within 30 days of deletion |
| Analysis results and reports | Duration of account; deleted within 30 days of deletion |
| Billing records | 7 years (UK tax and accounting requirements — HMRC) |
| Authentication logs | 12 months |
| Analytics data (PostHog) | 24 months, then anonymised |
| Error tracking data (Sentry) | 90 days |
| Server access logs | 12 months |
| Support correspondence | Duration of account + 12 months |
Personal Data is transferred to Sub-processors on a continuous, real-time basis as required by the normal operation of the Service.
The UK Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Website: https://ico.org.uk. For EU/EEA data subjects, the competent supervisory authority of the relevant EU/EEA Member State may also have jurisdiction.
The Processor implements the following technical and organisational measures pursuant to Article 32 GDPR:
| Measure | Implementation |
|---|---|
| Encryption in transit | All data transmitted between clients and servers is encrypted using TLS 1.2 or higher. HTTPS is enforced on all endpoints with HSTS headers. |
| Encryption at rest | Database storage is encrypted at rest using AES-256. Document storage (S3-compatible object storage) uses server-side encryption. Redis cache uses encrypted connections. |
| Password hashing | User passwords are hashed using bcrypt with a minimum work factor of 12. Plaintext passwords are never stored or logged. |
| Measure | Implementation |
|---|---|
| Authentication | JWT-based authentication with short-lived access tokens (15 minutes) and HTTP-only secure refresh tokens (7 days). Support for multi-factor authentication (MFA) and SSO (Google OAuth, SAML). |
| Authorisation | Role-based access control (RBAC) with organisation-scoped data isolation. Principle of least privilege applied to all internal and external access. |
| Administrative access | Production system access restricted to authorised personnel via SSH key-based authentication with MFA. Access logs maintained for all administrative actions. |
| API security | Rate limiting on all API endpoints. Input validation via Pydantic schemas. CORS restricted to authorised origins. |
| Measure | Implementation |
|---|---|
| Network isolation | Backend services deployed in isolated private networks. Database not publicly accessible. |
| Firewall rules | Restrictive ingress/egress rules. Only required ports and protocols allowed. |
| DDoS protection | Network-level DDoS mitigation provided by the hosting provider (Hetzner). Application-level rate limiting (Redis-backed). |
| DNS security | DNSSEC enabled where supported. CAA records configured. |
| Measure | Implementation |
|---|---|
| Data minimisation | Only Personal Data necessary for the specified processing purposes is collected. AI/LLM providers receive only the minimum content required for analysis. |
| Pseudonymisation | Analytics data uses pseudonymous user identifiers. Error tracking data is scrubbed of sensitive fields before transmission. |
| Purpose limitation | Technical controls enforce data access restrictions based on processing purpose. Organisation-level data isolation prevents cross-tenant access. |
| Measure | Implementation |
|---|---|
| Infrastructure redundancy | Managed hosting with high-availability configurations. Automated failover for database and application layers. |
| Backup and recovery | Automated daily database backups with point-in-time recovery. Backup encryption and off-site storage. Recovery procedures tested periodically. |
| Monitoring | 24/7 infrastructure and application monitoring. Automated alerting for anomalies, errors, and performance degradation. |
| Disaster recovery | Documented disaster recovery plan with defined RPO and RTO objectives. Regular DR testing. |
| Measure | Implementation |
|---|---|
| Incident response plan | Documented incident response procedures with defined severity levels, escalation paths, and communication templates. |
| Breach detection | Automated security monitoring, intrusion detection, and anomaly detection. |
| Forensic readiness | Comprehensive audit logging enabling post-incident investigation. Logs retained for a minimum of 12 months. |
| Measure | Implementation |
|---|---|
| Staff training | Regular data protection and security awareness training for all personnel with access to Personal Data. |
| Confidentiality agreements | All personnel sign confidentiality agreements. Contractors bound by equivalent obligations. |
| Vendor management | Due diligence conducted before engaging Sub-processors. Ongoing monitoring of Sub-processor compliance. |
| Privacy by design | Data protection considerations integrated into the software development lifecycle. Privacy impact assessments conducted for new features involving Personal Data. |
| Security development lifecycle | Secure coding practices, code review, dependency scanning, and regular security testing. |
| Measure | Implementation |
|---|---|
| Data centre security | The hosting provider's data centres (Hetzner — Nuremberg and Falkenstein, Germany) maintain physical security certifications (ISO 27001). Physical access is restricted to authorised personnel with multi-layer authentication. |
| Media disposal | Sub-processors follow certified media sanitisation and destruction procedures. |
The following Sub-processors are approved by the Controller as of the Effective Date of this DPA. The current version of this list is maintained at Sub-Processor List.
| Sub-Processor | Entity Country | Processing Location | Purpose | Transfer Mechanism |
|---|---|---|---|---|
| Hetzner Online GmbH | Germany | Germany (Nuremberg, Falkenstein) | Application hosting (frontend and backend), PostgreSQL, Redis, S3-compatible document and report storage | Not applicable — EU/EEA processing |
| OpenAI, L.L.C. | US | US | LLM regulatory analysis | SCCs |
| Anthropic PBC | US | US | LLM regulatory analysis | SCCs |
| Google LLC (Gemini) | US | US | LLM regulatory analysis | DPF + SCCs |
| Stripe, Inc. | US | US + EU | Payment processing, billing | DPF + SCCs |
| Resend, Inc. | US | US | Transactional email delivery | SCCs |
| PostHog, Inc. | US | US | Product analytics | SCCs |
| Functional Software, Inc. (Sentry) | US | US | Error monitoring | SCCs |
| Google LLC (OAuth) | US | US | Authentication (SSO) | DPF |
| GitHub, Inc. (Microsoft) | US | US | Source code hosting, CI/CD | DPF + SCCs |
For detailed information about each Sub-processor, including data categories processed and links to their privacy policies and DPAs, see the Sub-Processor List.
This DPA is entered into and becomes binding upon the Controller's acceptance of the Principal Agreement (Terms of Service). No separate signature is required.
Pericls Ltd
London, United Kingdom
Email: dpo@pericls.com
This Data Processing Agreement is provided in English. If there is any conflict between a translated version and the English version, the English version shall prevail.