Complete, but not yet reviewed by a solicitor.
This data processing addendum is finished — every term is settled and there are no gaps left to fill — but it has not been settled by a qualified legal adviser. Read it, rely on it for an evaluation, and tell us if something does not work for you. If you need a counter-signed copy for a procurement pack or a contract, ask us first and we will get it reviewed.
Queries: olly@dijitul.uk
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between dijitul Ltd (“Processor”) and the customer identified in the account (“Controller”). Capitalised terms not defined here have the meaning given in the Terms.
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018, and, where applicable to the Controller, Regulation (EU) 2016/679 and the national laws implementing it.
1. Scope and roles
The Controller determines the purposes and means of processing Customer Personal Data. The Processor processes it only on the Controller's documented instructions. Where the Processor determines purposes and means in respect of account administration data, it acts as a controller in its own right and its Privacy Notice applies to that processing instead.
2. Processing instructions
The Controller instructs the Processor to process Customer Personal Data as necessary to provide the Service, which comprises: receiving API requests; applying the configured privacy mode; forwarding requests to the sub-processor for inference within the permitted residency scope; returning the response; and recording usage metadata for metering and diagnostics. The configuration the Controller sets in the dashboard forms part of its instructions.
The Processor will inform the Controller if, in its opinion, an instruction infringes Data Protection Law. The Processor will not process Customer Personal Data for its own purposes, and will not use it to train, fine-tune or evaluate any machine learning model.
3. Confidentiality
The Processor ensures that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, and that access is limited to those who need it to perform their role.
4. Security measures
The Processor implements appropriate technical and organisational measures under Article 32, as described in Annex B. The Controller acknowledges that these measures are appropriate having regard to the state of the art, the costs of implementation and the risks presented by the processing, and that they may be updated provided the level of protection is not reduced.
5. Sub-processors
The Controller gives the Processor general authorisation to engage sub-processors. The current list is in Annex C. The Processor will give the Controller at least 3 days' notice by email of any intended addition or replacement, during which the Controller may object on reasonable data protection grounds. If the objection cannot be resolved, the Controller may terminate the affected part of the Service without penalty.
The Processor imposes on each sub-processor obligations no less protective than those in this DPA and remains fully liable for the sub-processor's performance.
6. International transfers
Customer Personal Data is processed within the residency scope of the API key that submitted it:
- United Kingdom only. Inference is invoked In-Region on AWS Europe (London),
eu-west-2, using a bare model identifier. Prompts are processed in the United Kingdom and do not leave it. - No other scope is offered. The Processor does not operate an EEA or global tier. A request that cannot be served in London is refused; it is not routed elsewhere.
Where a restricted transfer arises, appropriate safeguards apply. In respect of Amazon Web Services, the AWS Data Processing Addendum, the EU Standard Contractual Clauses and the Information Commissioner's Office International Data Transfer Addendum are incorporated automatically into the AWS Customer Agreement and therefore apply to the Processor's use of AWS without separate execution.
Between the Controller and the Processor, no restricted transfer arises where both parties are established in the United Kingdom and processing is performed in the United Kingdom, as described in clause 6. In that case no Article 46 safeguard is required between us, and none is attached: standard contractual clauses would be paperwork describing a transfer that does not happen.
If you are established outside the United Kingdom, tell us before you sign. The position changes, an appropriate mechanism has to be put in place between us, and we would rather agree that at the outset than have you rely on a clause that does not fit your circumstances.
7. Assistance to the controller
Taking into account the nature of the processing, the Processor will assist the Controller with:
- responding to data subject requests, insofar as the Processor holds relevant data — noting that prompt content is not retained in normal operation, so in most cases the Processor will hold nothing responsive;
- data protection impact assessments and prior consultation with a supervisory authority; and
- demonstrating compliance with Articles 32 to 36.
The Processor will notify the Controller without undue delay if it receives a request directly from a data subject relating to Customer Personal Data, and will not respond to it other than to redirect the data subject to the Controller.
8. Personal data breach
The Processor will notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed.
9. Audit
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice, no more than once in any twelve-month period except following a personal data breach, during business hours, and subject to confidentiality undertakings.
The Processor may satisfy an audit request in whole or in part by providing the relevant certifications and audit reports of its sub-processors — for Amazon Bedrock these include ISO/IEC 27001:2022, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, ISO/IEC 42001 and SOC 1, SOC 2 and SOC 3 reports.
10. Deletion and return
On termination, the Processor will delete Customer Personal Data within 30 days, save where retention is required by law. Because prompt and completion bodies are not retained in normal operation, in most cases there is nothing to delete beyond usage metadata and account records.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms.
Annex A — Details of the processing
| Subject matter | Provision of an API gateway that routes large language model requests to a UK or EEA inference platform. |
|---|---|
| Duration | For the term of the Terms, plus the retention periods in Annex B. |
| Nature and purpose | Receipt, optional redaction, transmission for inference, return of response, and metering. |
| Types of personal data | Any personal data the Controller chooses to include in a prompt. The Processor does not control this and applies no assumption about it. Detection and redaction of common identifier types is available but is a control, not a guarantee. |
| Special category data | Only if the Controller submits it. The Controller must satisfy itself that it has an Article 9 condition before doing so. |
| Categories of data subject | Determined by the Controller — typically its clients, patients, employees or correspondents. |
| Frequency | Continuous, on each API request. |
Annex B — Technical and organisational measures
- Encryption in transit. TLS 1.2 or above on all external interfaces; SigV4-authenticated TLS to the inference platform.
- Credential storage. API keys stored only as SHA-256 hashes; plaintext keys are displayed once and never persisted.
- Minimisation. Prompt and completion bodies are not written to disk. PII detections are recorded as type and count only, never as values.
- Bounded debug capture. Body capture is opt-in per key, audit-logged, and expires automatically after at most 24 hours.
- Access control. Multi-factor authentication for administrative access; per-key residency tier, privacy mode, model allow-list, IP allow-list and expiry.
- Residency enforcement. Fail-closed routing: a request that cannot be served within its residency scope is refused rather than routed outside it.
- Retention. Request metadata deleted after 90 days.
- Audit trail. Key lifecycle and configuration changes recorded with actor, source address and timestamp.
- Backups. The database and application configuration are backed up nightly at approximately 02:30 UK time. Backups are streamed directly to encrypted object storage without being staged on the server, and are never deleted by the backup process itself.
- Backup retention and integrity. Object versioning is enabled, so a superseded or corrupted backup does not overwrite its predecessor. Superseded versions are retained for 90 days by a storage lifecycle policy applied at the storage provider rather than by the backup agent, so a fault in the agent cannot destroy backup history.
- Restore testing. Restores are tested by importing a backup into an isolated database and verifying the application starts against it. An untested backup is an assumption, not a control.
- Secure development. Changes are version controlled and peer reviewed, and an automated test suite runs before release. Tests specifically assert the residency guarantees described in clause 6, so a change that would route data outside its permitted scope fails the build.
We do not currently commission independent penetration testing, and we do not hold ISO 27001, SOC 2 or Cyber Essentials certification. We would rather say so plainly than imply an assurance we have not obtained. Where a procurement process requires one of these, tell us and we will say whether we can meet it rather than leaving you to discover we cannot.
Annex C — Authorised sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services EMEA SARL, UK Branch | Model inference via Amazon Bedrock; hosting | United Kingdom — Europe (London), eu-west-2 |
| Stripe Payments Europe Ltd | Payment processing and invoicing | EEA and United Kingdom |
| Sand Dune Mail Ltd, trading as SMTP2GO | Transactional email delivery (account, billing and usage notifications) | European Economic Area — Amsterdam. Vendor incorporated in New Zealand, which is covered by UK adequacy regulations. |
This annex is published at a stable URL so that additions can be notified under clause 5. We do not currently use a third-party application monitoring or error-reporting service; if we adopt one, it will be added here and notified in advance under that clause.
Anthropic, PBC is not a sub-processor under this DPA. Models are accessed through Amazon Bedrock, which operates a zero-operator-access model: the model provider does not receive prompts or completions sent through it.
Questions about this document should go to olly@dijitul.uk. Nothing on this page is legal advice, and it does not create any obligation on dijitul Ltd until a settled version has been executed.