← Home
Legal

Data Processing Agreement

Template · Last updated: 28 July 2026

1.Who this is between

This agreement is between the client (the "Controller", who decides why and how personal data is processed) and Creative Sauce Ltd, registered in England and Wales (Company No. 12582512, VAT No. GB365544675) (the "Processor", "we", "us"). It applies whenever we process personal data on the Controller's behalf, for example when building or running integrations, dashboards or AI systems that touch the Controller's own customer or business data.

2.What we process, and why

The specifics of each engagement are set out in the main agreement or statement of work. In summary:

Subject matterProcessing needed to provide the agreed services (e.g. building and running the systems described in the SOW).
DurationFor the term of the engagement, plus any short wind-down period agreed for data export.
Nature & purposeStoring, organising, analysing and displaying data; running automated and AI-assisted tasks the Controller requests.
Types of personal dataAs defined per engagement, e.g. customer names, contact details, enquiry content, usage and business metrics. No special category data unless expressly agreed in writing.
Categories of data subjectsAs defined per engagement, e.g. the Controller's customers, enquirers, staff or users.

3.Our obligations as processor

4.Sub-processors

The Controller gives general authorisation for us to engage sub-processors to help deliver the services. We impose data protection terms on each sub-processor that are no less protective than this agreement, and we remain responsible for their performance. Our current sub-processors typically include:

ProviderRole
VercelWebsite / application hosting and serverless functions
SupabaseDatabase hosting and authentication
AI providers (e.g. OpenAI, Anthropic, Google, OpenRouter)AI model APIs used to run the tasks the Controller requests, via API services on terms intended to keep inputs out of model training
Email / scheduling providersTransactional email and, where relevant, social scheduling

We keep an up-to-date list and will give the Controller reasonable notice of any intended change (adding or replacing a sub-processor), so the Controller can object on reasonable data protection grounds.

5.Security

6.International transfers

Where a sub-processor processes personal data outside the UK, we rely on an appropriate transfer mechanism, such as UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.

7.Personal data breaches

If we become aware of a personal data breach affecting the Controller's data, we will notify the Controller without undue delay and provide the information reasonably available to help them meet their own obligations.

8.Audit and information

On reasonable written request, and no more than once a year unless a regulator requires otherwise or following a breach, we will provide the information reasonably needed to demonstrate compliance with this agreement, and allow reasonable audits during business hours, subject to confidentiality.

9.Return or deletion

At the end of the engagement, at the Controller's choice, we will return or delete the personal data and delete existing copies, unless the law requires us to retain it. Aggregated or anonymised data that is no longer personal data may be retained.

10.General

This DPA forms part of, and is governed by the same terms as, our main agreement with the Controller, including its provisions on liability and on governing law (the laws of England and Wales). If there is a conflict on data protection matters, this DPA prevails.