Esc

Legal

Data Processing Agreement

Applies to Business Customers when an Order or signed agreement incorporates it. Ordinary Store purchases of local-first software involve no processing under it.

Last updated 3 October 2026

Document control

This document is version-controlled. The version accepted at checkout, incorporated into an Order, or signed with a Statement of Work governs the relevant transaction. Mandatory rights imposed by law remain unaffected.

Parties and effect

This Data Processing Agreement, DPA, forms part of the agreement between Oxford Private Studios Ltd, trading as Aevornix, and the Customer that incorporates it. It applies only to processing of Customer Personal Data by OPS as a processor on behalf of the Customer.

It does not make OPS a processor of information that remains solely on Customer devices or a Customer-controlled local network and is never transmitted to OPS. Local-first software, by itself, does not create a processor relationship for the local dataset.

1. Definitions

Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018 as amended, Data (Use and Access) Act 2025, PECR where relevant, the EU GDPR where it applies, and other binding data-protection law identified in an Order. Customer Personal Data means Personal Data processed by OPS on behalf of Customer under the Services. Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.

Controller, Processor, Data Subject, Personal Data, Processing and Supervisory Authority have the meanings given by Applicable Data Protection Law.

2. Roles and Customer instructions

Customer is the Controller or a Processor authorised by the relevant Controller. OPS is the Processor or subprocessor for Customer Personal Data. The agreement, Order, service configuration and documented support requests are Customer’s documented instructions.

OPS processes Customer Personal Data only on documented instructions unless law requires other processing. If law requires processing beyond instructions, OPS will inform Customer before processing unless the law prohibits notice.

If OPS reasonably believes an instruction infringes Applicable Data Protection Law, OPS will inform Customer and can suspend the affected instruction while the parties resolve the issue. OPS is not required to give legal advice about Customer’s compliance.

3. Customer responsibilities

Customer has authority to disclose Customer Personal Data to OPS and has a lawful basis for processing.

Customer provides required privacy notices and obtains required consents.

Customer gives only lawful instructions and limits data to what the Service needs.

Customer decides whether a Service is suitable for special-category, criminal-offence, children’s, financial, health, biometric, government or other high-risk data before uploading it.

Customer conducts any required DPIA, consultation, record of processing and sector-specific assessment.

Customer configures users, permissions, retention, connectors and authentication appropriately and promptly removes access that is no longer needed.

Customer does not instruct OPS to process data in a country, manner or service feature that the contract does not support.

4. Processing details

The subject matter, duration, nature, purpose, data types and Data Subject categories are set out in Schedule 1. An Order can add or narrow those details. Processing continues for the Service term and any limited deletion or backup period.

5. Confidentiality

OPS ensures that personnel authorised to process Customer Personal Data are bound by confidentiality duties and receive access only where needed for their work. Access is removed or adjusted when the role changes or ends.

6. Security measures

OPS implements appropriate technical and organisational measures proportionate to the risk, service and state of the art. Schedule 2 describes the baseline. A specific Service can use stronger or different measures documented in its security schedule. OPS does not represent that any security control makes a Service immune from attack.

7. Subprocessors

Customer gives general written authorisation for OPS to use subprocessors to provide the Services. OPS will maintain a current list for material hosted Services. Before adding or replacing a subprocessor that processes Customer Personal Data, OPS will provide reasonable notice through the published list, service notice or direct notice where the Service supports it.

Customer can object on reasonable data-protection grounds within 15 days after notice. The parties will seek a practical alternative. If none is reasonably available, OPS can terminate the affected feature or Service on reasonable notice and refund prepaid fees for the unused terminated period, if any. An objection does not require OPS to redesign the Service or stop using a subprocessor across all customers.

OPS imposes data-protection obligations on each subprocessor that are no less protective in substance for the relevant processing than the obligations required by Applicable Data Protection Law. OPS remains responsible for its subprocessor obligations to the extent required by law.

8. Data Subject requests

Taking account of the nature of processing, OPS will provide reasonable assistance through technical measures or support so Customer can respond to requests from Data Subjects. If OPS receives a request relating to Customer Personal Data, OPS will redirect it to Customer unless law requires OPS to respond directly.

Customer remains responsible for deciding whether a request is valid and for communicating the substantive response. Additional manual work outside standard Service functions can be charged at the agreed professional-services rate if the work was not caused by OPS breach.

9. Assistance with compliance

Taking account of the nature of processing and information available to OPS, OPS will reasonably assist Customer with security obligations, personal-data breach duties, DPIAs and prior consultation where required by Articles 32 to 36 UK GDPR or equivalent law. Customer pays reasonable costs for exceptional assistance unless the need arose from OPS breach of this DPA.

10. Security Incidents

OPS will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data. The notice will include information reasonably available about the nature of the incident, affected data or people, likely consequences, containment and mitigation. Information can be provided in phases as the investigation develops.

OPS notification is not an admission of fault or liability. Customer is responsible for regulator and Data Subject notifications unless law places the duty directly on OPS. OPS will preserve relevant evidence and cooperate reasonably with Customer.

11. International transfers

OPS will not make a restricted transfer of Customer Personal Data without a lawful transfer mechanism. For UK restricted transfers, the parties incorporate the UK International Data Transfer Agreement or UK Addendum where required. For EU restricted transfers, the parties incorporate the applicable EU Standard Contractual Clauses, normally Module 2 for controller-to-processor or Module 3 where Customer is itself a processor.

The transfer mechanism is completed by reference to the agreement, this DPA, the relevant Order, the subprocessor list and the Security Measures. If a regulator-approved mechanism is replaced or invalidated, the parties will use a lawful replacement mechanism.

12. Government and law-enforcement requests

If OPS receives a legally binding request for Customer Personal Data, OPS will, where law permits, notify Customer before disclosure, review the request for legal validity, disclose only what is legally required and seek proportionate protection for the information.

13. Return and deletion

At termination of the relevant Service, OPS will delete or return Customer Personal Data according to the Service function and Customer instruction, unless law requires retention. Data can remain in secure backups until the normal backup cycle expires, provided it remains protected and is not restored for ordinary business use except for disaster recovery or legal necessity.

14. Audit and information rights

OPS will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. Customer should first use current security documentation, independent assessment material and written responses supplied by OPS.

If additional audit is legally required or reasonably necessary after reviewing that material, Customer may conduct one audit in a 12-month period on at least 30 days written notice, during normal business hours, through an independent non-competitor auditor bound by confidentiality. The audit must not access data of other customers, source code unrelated to the audit, vulnerability details that create disproportionate risk, or privileged information.

Customer pays audit costs and OPS reasonable support time unless the audit identifies a material breach of this DPA by OPS. Urgent regulator-directed or post-incident audits are not subject to the annual frequency limit where law requires more.

15. Records and regulator cooperation

OPS maintains processor records required by Applicable Data Protection Law and cooperates with competent supervisory authorities as required. Customer is responsible for its Controller records and regulatory registrations.

16. Liability

The liability limits and exclusions in the governing MSA, Terms or Order apply to this DPA and are not increased by it, except to the extent Applicable Data Protection Law prohibits a limitation. Each party remains responsible for fines, damages and compensation allocated to it by law, subject to any lawful contractual allocation between the parties.

17. Order of precedence and changes in law

For processing of Customer Personal Data, this DPA prevails over conflicting general terms. A signed data-protection addendum can override this DPA. If Applicable Data Protection Law changes, the parties will interpret and, where needed, amend this DPA to preserve lawful processing without unnecessarily changing the commercial allocation of risk.

18. Governing law

The governing law and jurisdiction in the main agreement apply to this DPA. Mandatory rights of regulators and Data Subjects remain unaffected.

Schedule 1. Processing description

Schedule 1. Processing description
ItemDescription
Subject matterProvision, support, security and administration of the hosted, managed or connected Aevornix Service identified in the Order.
DurationService term plus documented deletion, return, backup and legal-retention periods.
Nature of processingCollection, receipt, hosting, storage, organisation, transmission, retrieval, support access, logging, backup, deletion and other operations needed to provide the Service.
PurposesProvide requested functions, authenticate users, secure the Service, maintain availability, troubleshoot, support Customer and comply with documented instructions.
Personal Data typesCustomer-configured account data, identifiers, business contact data, Customer Content, service metadata, device or log data and other Personal Data Customer chooses to submit within supported fields.
Data SubjectsCustomer users, workers, clients, suppliers, contacts, end users and other individuals whose data Customer lawfully places in the Service.
Special categoriesNot intended unless the Order expressly permits them and Customer has completed required legal and security assessment.

Schedule 2. Baseline technical and organisational measures

Schedule 2. Baseline technical and organisational measures
Control areaBaseline
GovernanceDefined security ownership, risk review, incident response, access review and secure development procedures proportionate to the Service.
Access controlLeast privilege, unique administrative identities, strong authentication for privileged access, role-based access where supported and prompt offboarding.
EncryptionIndustry-standard encryption in transit for hosted Service communications. Encryption at rest for hosted production data where technically appropriate to the Service and storage architecture.
DevelopmentSource control, dependency review, code review or automated checks, release controls, vulnerability handling and separation of development from production access where practicable.
InfrastructurePatch and vulnerability management, hardened configuration, secrets management, network restrictions, logging and monitoring proportionate to the Service.
ResilienceBackups and restoration procedures for hosted data where the Service promises retention, plus tested recovery appropriate to the Service tier.
Incident responseTriage, containment, investigation, evidence preservation, recovery and notification procedures.
PersonnelConfidentiality duties, role-appropriate security awareness and restricted access to Customer Personal Data.
SuppliersSecurity and privacy due diligence proportionate to subprocessor risk and written data-processing obligations.
Data minimisationCollect and retain only what the Service needs. Local-first designs keep Customer Content off OPS infrastructure where the connected function does not require it.

Schedule 3. Optional UK and EU transfer addendum

If a restricted transfer occurs and no adequacy decision applies, the relevant approved transfer terms are incorporated by reference. The parties will complete mandatory variables through the Order and DPA schedules. If the transfer terms conflict with the commercial agreement on a mandatory data-protection point, the transfer terms prevail only for that point.

Acceptance

The DPA is accepted when the main agreement is signed, an Order expressly incorporates it, or an authorised Business Customer accepts it through the contracting flow. A separate signature is optional unless the parties or applicable law require one.

Acceptance
Date:Date:

Cart