Introduction
This Data Processing Agreement ("DPA") governs how we process personal data about your clients, prospects, and other third parties when you enter or upload it into the Platform.
It applies between:
- Harry Needham Ltd ("we", "us", "our"), a company registered in England and Wales (company number 13366906), registered office Tyttenhanger House, Coursers Road, Colney Heath, St Albans, Hertfordshire, AL4 0PG, acting as processor; and
- you, the account holder ("you", "your"), acting as controller of the third-party personal data you provide.
This DPA forms part of, and is incorporated by reference into, our Terms of Service (the "Agreement"). It becomes binding when you accept the Agreement, and it governs all processing of Client Data (defined below) that you carry out through the Platform. You do not need to sign a separate copy for it to take effect. If you require a countersigned copy for your own records, email harry@harryneedham.com and we will provide one.
This DPA covers only personal data about third parties that you are responsible for (your "Client Data"). It does not cover the personal data we hold about you as our own customer — that is dealt with in our Privacy Policy, where we act as controller.
1. Definitions
- "Client Data" means personal data about your clients, prospects, or any other individual (who is not you) that you enter, upload, or generate through the Platform, and that we process on your behalf.
- "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended.
- "Controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in the UK GDPR.
- "Sub-processor" means any third party we engage to process Client Data on our behalf.
- "UK IDTA" means the International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
2. Roles and responsibilities
For Client Data, you are the controller and we are your processor. You decide what Client Data to provide and why; we process it only to provide the Platform to you.
You are responsible for:
- Having a lawful basis to provide the Client Data to us and to have it processed as described here.
- Meeting your own transparency obligations to your clients (for example, telling them their data may be processed using third-party tools).
- The accuracy, quality, and legality of the Client Data and the means by which you obtained it.
- Ensuring your instructions to us do not require us to breach Data Protection Law.
As set out in our Privacy Policy, wherever possible we ask you to anonymise Client Data. You rarely need a real name for the Platform to be useful, and doing so reduces risk for you and your clients.
3. Our obligations
We will:
(a) Process only on your instructions. We will process Client Data only on your documented instructions — which are the Agreement, this DPA, and your use of the Platform's features — unless required to do otherwise by law, in which case we will tell you first unless the law prohibits it.
(b) Keep it confidential. Anyone we authorise to process Client Data will be bound by an appropriate duty of confidentiality.
(c) Keep it secure. We will implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk, in line with Article 32 UK GDPR.
(d) Not train AI on it. We will not, and our AI sub-processors are contractually bound not to, use Client Data to train their models. Client Data is processed only to generate the outputs you request.
(e) Use sub-processors only under section 4.
(f) Assist you with data subject rights and your wider compliance obligations, as set out in sections 5 and 6.
(g) Delete or return it at the end of processing, as set out in section 7.
(h) Demonstrate compliance and allow for audits, as set out in section 8.
4. Sub-processors
You give us general authorisation to engage the sub-processors listed in Annex 3 to process Client Data. Only sub-processors that handle Client Data are listed there; other providers we use for our own operations (such as our transactional and marketing email providers) do not process your Client Data.
For every sub-processor we will:
- Put in place a written contract imposing data protection obligations no less protective than those in this DPA; and
- Remain fully liable to you for the sub-processor's performance.
If we intend to add or replace a sub-processor that will process Client Data, we will give you at least 14 days' notice. If you object on reasonable data protection grounds within that period, we will work with you in good faith to resolve it. If we cannot, you may terminate the part of the Agreement affected by the change.
5. Assisting you with data subject rights
If one of your clients exercises a right under Data Protection Law (for example, access, rectification, erasure, or objection), and it concerns Client Data we hold, we will provide reasonable assistance to help you respond. If a data subject contacts us directly about Client Data, we will refer them to you and will not respond substantively ourselves unless legally required to.
The Platform also gives you self-service controls to access, correct, export, and delete Client Data directly.
6. Assisting you with your wider obligations
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with:
- Your obligation to keep Client Data secure (Article 32);
- Personal data breach notification and communication (Articles 33 and 34); and
- Data protection impact assessments and prior consultation with the ICO (Articles 35 and 36).
Breach notification. If we become aware of a personal data breach affecting Client Data, we will notify you without undue delay, and in any event within 48 hours of becoming aware. Our notice will describe, as far as we can, the nature of the breach, the likely consequences, and the measures taken or proposed. You remain responsible for any notification to the ICO or to affected individuals.
7. Deletion and return
On termination or expiry of the Agreement, and in line with our Privacy Policy and Terms:
- We retain Client Data for 90 days, during which you may export or retrieve it.
- After 90 days, we permanently delete Client Data, except any part we are required to keep by law.
You may also delete specific Client Data at any time using the Platform's controls, or request earlier deletion by emailing harry@harryneedham.com.
8. Audits and information
On your reasonable written request (no more than once a year, unless required by Data Protection Law or following a breach), we will make available the information reasonably necessary to demonstrate our compliance with this DPA. Where available, we may satisfy this by providing our sub-processors' third-party audit reports or certifications, which give independent assurance without disrupting the service or exposing other customers' data. Any audit will be conducted on reasonable notice, during business hours, subject to confidentiality, and in a way that minimises disruption.
9. International transfers
Some of our sub-processors are based in the United States. Where Client Data is transferred outside the UK, we rely on appropriate safeguards — specifically the UK IDTA to the EU Standard Contractual Clauses — incorporated into our agreements with each relevant sub-processor. You may request a copy of the relevant safeguards by contacting us.
Where the Platform's storage region is configurable, Client Data is stored in the EU/UK region (see Annex 3).
10. Liability
As between you and us, liability arising out of or in connection with this DPA is subject to the same limitations and exclusions, including the aggregate cap, set out in the "Limitation of liability" section of the Terms of Service.
However, nothing in this DPA or the Agreement limits or excludes either party's liability to a data subject, or any liability that cannot be limited or excluded under Data Protection Law or under the UK IDTA. The UK IDTA and the Standard Contractual Clauses prevail over this DPA to the extent of any conflict.
11. General
- Precedence. If there is a conflict between this DPA and the rest of the Agreement in relation to the processing of Client Data, this DPA prevails. The UK IDTA and Standard Contractual Clauses prevail over both.
- Changes. We may update this DPA to reflect changes in law, our sub-processors, or the Platform. If a change is material, we will notify you by email or through the Platform before it takes effect.
- Duration. This DPA remains in force for as long as we process Client Data on your behalf.
- Governing law. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1 — Details of the processing
| Subject matter | Processing of Client Data to provide the Synthesise AI platform to you |
| Duration | For the term of the Agreement, plus the 90-day retention period in section 7 |
| Nature and purpose | Hosting, storage, and AI-assisted generation of business content (messaging, offers, campaigns, content, plans, and critiques) from information you provide |
| Types of personal data | Whatever you choose to enter about third parties — typically names, business details, testimonials, results, and the content of communications. You are asked to anonymise where possible and must not enter special category data about third parties. |
| Categories of data subjects | Your clients, prospects, and other individuals whose information you choose to enter |
| Your instructions | This DPA, the Agreement, and your use of the Platform's features |
Annex 2 — Technical and organisational measures
We maintain measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest.
- Row-level security enforced at the database level, so that no user can access another user's data.
- Passwords stored only as secure cryptographic hashes.
- Restricted and logged access to production data, on a least-privilege basis.
- Disabled public sign-up — accounts are created individually by us.
- Sub-processors selected for, and contractually bound to, appropriate security standards (including SOC 2 and/or ISO 27001 where applicable).
- Regular review of these measures.
Annex 3 — Authorised sub-processors
The following sub-processors may process Client Data on our behalf:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Supabase | Database, authentication, and file storage | Data hosted in the EU/UK region; company based in the USA |
| Vercel | Application hosting | USA |
| Anthropic | AI processing (Claude) | USA |
| OpenAI | AI processing and voice transcription | USA |
Providers we use for purposes that do not involve Client Data — including Resend (transactional email to you) and Kit (marketing email to you) — are not sub-processors under this DPA. They are listed in our Privacy Policy, which covers the data we hold about you as our customer.
Acceptance
By accepting the Terms of Service and by entering Client Data into the Platform, you agree to this DPA on behalf of yourself and, where applicable, the business you represent. A countersigned copy is available on request from harry@harryneedham.com.
Harry Needham Ltd Tyttenhanger House, Coursers Road, Colney Heath, St Albans, Hertfordshire, AL4 0PG harry@harryneedham.com