Version 1.0 · October 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between oboloo Limited (“oboloo”, “we”, “us”) and the Customer under the oboloo Terms of Service at oboloo.com/terms-of-service (the “Terms”). It sets out how we process personal data on the Customer's behalf when providing the Services. It applies automatically to every Customer from the date the Customer accepts the Terms. No signature is required, and a signed copy is available on request from support@oboloo.app. Capitalised terms not defined here have the meaning given in the Terms.
2.1For Customer Personal Data, the Customer is the Controller and we are the Processor. Where the Customer itself acts as a Processor for a third party, we act as its Sub-processor and the Customer warrants that it has the authority and instructions needed to appoint us.
2.2This DPA does not apply to personal data we process as a Controller for our own purposes, such as account, billing, support and marketing data about the Customer's users and Supplier Users. That processing is governed by our Privacy and Cookies Policy at oboloo.com/privacy-cookies-policy.
2.3Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data and the categories of Data Subjects.
Back to top3.1The Customer instructs us to process Customer Personal Data as necessary to provide, support and secure the Services in accordance with the Terms, this DPA, the Customer's use and configuration of the Services, and any further documented instructions the Customer gives that are consistent with the Terms. We may charge a reasonable fee for carrying out instructions that go beyond the normal operation of the Services.
3.2The Customer is responsible for: (a) the accuracy, quality and lawfulness of Customer Personal Data and the means by which it was obtained; (b) providing all notices to, and obtaining all consents and authorisations from, Data Subjects that Data Protection Laws require; (c) configuring the Services, user roles, permissions and record-level access appropriately; (d) its own compliance with Data Protection Laws as a Controller; and (e) not uploading special category data, criminal offence data or data about children to the Services unless we have agreed to it in writing.
3.3The Customer confirms that its instructions comply with Data Protection Laws. We will tell the Customer if, in our opinion, an instruction infringes Data Protection Laws, but we are not obliged to carry out a legal review of the Customer's instructions.
Back to topWe will:
5.1The Customer gives us general authorisation to engage Sub-processors. Our current Sub-processors are listed in Annex 3.
5.2We will give the Customer at least 30 days' notice before adding or replacing a Sub-processor, by email to the Account administrator or by notice in the Services. The Customer may object in writing within that period on reasonable grounds relating to data protection. We will then work with the Customer in good faith to resolve the objection, for example by offering an alternative. If we cannot resolve it within 30 days of the objection, the Customer may terminate the affected Licences by written notice and we will refund any Fees paid in advance for the period after termination. This is the Customer's only remedy for an objection to a Sub-processor.
5.3We will impose on each Sub-processor, by written contract, data protection obligations that are at least as protective as those in this DPA, and we remain fully liable to the Customer for the performance of each Sub-processor's obligations.
5.4Third-party services that the Customer chooses to connect to the Services are not our Sub-processors. This includes external AI assistants connected through our MCP server or API, Zapier and other integrations. The Customer is the Controller for any data it sends to them and is responsible for its own agreements with those providers.
Back to top6.1Our security measures are described in Annex 2 and at oboloo.com/data-and-security. We may update them from time to time, provided the overall level of security is not materially reduced during a Subscription Term.
6.2We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, so far as known at the time, the nature of the breach, the categories and approximate numbers of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. We will provide further information as it becomes available and will cooperate with the Customer's reasonable investigation.
6.3We will not notify Supervisory Authorities or Data Subjects of a Personal Data Breach on the Customer's behalf unless the Customer asks us to in writing or the law requires us to. The Customer is responsible for deciding whether and how to notify.
Back to top7.1The Services allow the Customer to access, correct, export and delete Customer Personal Data for itself. The Customer will use these functions to respond to Data Subject requests wherever possible.
7.2If we receive a request from a Data Subject relating to Customer Personal Data, we will not respond to it, other than to direct the Data Subject to the Customer, and will forward it to the Customer within five Business Days.
7.3Where a request cannot be handled using the Services, we will provide reasonable assistance on written request. We may charge a reasonable fee for assistance that is frequent or substantial.
Back to topWe will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities that relate to the Services, taking into account the nature of the processing and the information available to us. In the first instance we will do this by providing the documentation published at oboloo.com/data-and-security and by completing the Customer's reasonable security questionnaire. We may charge a reasonable fee for assistance beyond that.
Back to top9.1We will make available to the Customer, on written request, the information reasonably needed to demonstrate compliance with this DPA, including our current penetration test certificate, our published security policies and responses to the Customer's reasonable security questionnaire.
9.2Where that information is not sufficient to meet the Customer's obligations under Data Protection Laws, the Customer, or an independent auditor appointed by the Customer that is not our competitor and is bound by confidentiality, may audit our compliance with this DPA: no more than once in any 12-month period, unless required by a Supervisory Authority or following a Personal Data Breach; on at least 30 days' written notice; during Business Days and normal business hours; remotely unless an on-site visit is essential; without unreasonably disrupting our operations; and at the Customer's cost. We may charge a reasonable fee for our time.
9.3The Customer will give us a copy of any audit report, which is our Confidential Information. We will remedy any material non-compliance found within a reasonable time.
Back to top10.1During the Term the Customer can export Customer Personal Data at any time using the export functions in the Services.
10.2On termination or expiry of the Agreement or the relevant Subscription, we will, on written request made within 30 days, provide an export of Customer Personal Data in a standard machine-readable format at no charge. We will delete Customer Personal Data within six months of termination, except for copies held in routine backups, which are overwritten in the ordinary course, and data we are required by law to keep. We will confirm deletion in writing on request.
Back to top11.1Customer Personal Data is hosted in the United Kingdom, in ISO 27001 certified data centres in London operated by IONOS, with backups held in geographically separate locations. Customer documents are stored in Amazon Web Services S3 in the London region. The location of each Sub-processor is stated in Annex 3.
11.2Transfers of Customer Personal Data between the United Kingdom and the European Economic Area are covered by the European Commission's adequacy decision for the United Kingdom and the UK's adequacy regulations for the EEA, for as long as they remain in force.
11.3We will not make a Restricted Transfer of Customer Personal Data, and will not allow a Sub-processor to do so, unless a Transfer Mechanism is in place. Where a Sub-processor is located outside the United Kingdom and the EEA, the applicable Transfer Mechanism is shown in Annex 3. On request we will provide a copy of the relevant Transfer Mechanism, with commercial information redacted.
Back to topEach party's liability under or in connection with this DPA is subject to the exclusions and limits in clause 16 of the Terms, including the enhanced cap in clause 16.4. Nothing in this DPA limits either party's liability where Data Protection Laws do not allow it to be limited.
Back to top13.1This DPA applies for as long as we process Customer Personal Data on the Customer's behalf, including the retention period in clause 10.
13.2If this DPA conflicts with the Terms on a matter relating to the processing of personal data, this DPA prevails. If it conflicts with a Transfer Mechanism, the Transfer Mechanism prevails.
13.3We may update this DPA to reflect changes in Data Protection Laws, regulatory guidance, Sub-processors or the Services, by giving notice in accordance with clause 17 of the Terms. The current version, with its version number and date, is published at oboloo.com/dpa.
Back to top14.1Questions and requests under this DPA should be sent to support@oboloo.app with the subject line “Data protection”.
14.2This DPA is governed by the law of England and Wales, and clause 19.13 of the Terms applies to it.
Back to topOur current measures include the following. Up-to-date detail, policies and live certificates are published at oboloo.com/data-and-security.
We give at least 30 days' notice before adding or replacing a Sub-processor, as set out in clause 5.2. Where a Sub-processor is located in the United Kingdom or the European Economic Area, no Transfer Mechanism is required.
| Sub-processor | Service | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| IONOS | Hosting of the oboloo application and databases | All Customer Personal Data | United Kingdom (London) | None required |
| Amazon Web Services | Document storage (S3) and backup storage | Uploaded documents and backup copies | United Kingdom (London, eu-west-2) | None required |
| Cloudflare | Network security, DNS and TLS termination | Traffic metadata and IP addresses | United States and global edge network | EU-US Data Privacy Framework with UK extension |
| Stripe | Payment processing and billing portal | Billing contact details and payment history | United States and European Union | EU-US Data Privacy Framework with UK extension; Standard Contractual Clauses under Stripe's DPA |
| Twilio SendGrid | Transactional email (invitations, notifications, authentication codes) | Names, email addresses and message content | United States | EU-US Data Privacy Framework with UK extension |
| ThriveDesk | Help Centre and support ticketing | Support requester details and ticket content | Ireland | None required |
| Mixpanel | Product analytics and session replay | User identifiers, usage data and on-screen content in replays | European Union | None required |
| Candu | In-app onboarding guides | User identifiers and usage data | Ireland | None required |
| OpenAI | AI Features, primary model, via the OpenAI API | Content of records submitted to AI Features. Not used for training. Retained up to 30 days for abuse monitoring. | United States | Standard Contractual Clauses with UK Addendum under the OpenAI Data Processing Addendum |
| Anthropic | AI Features, fallback model, via the Anthropic API | Content of records submitted to AI Features. Not used for training. Retained up to 30 days for safety monitoring. | United States | Standard Contractual Clauses with UK Addendum under the Anthropic Data Processing Addendum |