1Definitions

Customer Personal Data
Personal data contained in Customer Data that we process on the Customer's behalf in providing the Services.
Data Protection Laws
The UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and, where applicable to the Customer, the EU GDPR (Regulation (EU) 2016/679), each as amended or replaced, together with any other data protection law that applies to a party.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Supervisory Authority
Have the meanings given in the UK GDPR.
Restricted Transfer
A transfer of Customer Personal Data to a country outside the United Kingdom or the European Economic Area that is not covered by an adequacy decision.
Sub-processor
Any third party we engage to process Customer Personal Data on our behalf.
Transfer Mechanism
The UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, the UK extension to the EU-US Data Privacy Framework, or any other mechanism recognised under Data Protection Laws for a Restricted Transfer.
Back to top

2Roles and scope

2.1For Customer Personal Data, the Customer is the Controller and we are the Processor. Where the Customer itself acts as a Processor for a third party, we act as its Sub-processor and the Customer warrants that it has the authority and instructions needed to appoint us.

2.2This DPA does not apply to personal data we process as a Controller for our own purposes, such as account, billing, support and marketing data about the Customer's users and Supplier Users. That processing is governed by our Privacy and Cookies Policy at oboloo.com/privacy-cookies-policy.

2.3Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data and the categories of Data Subjects.

Back to top

3Customer's instructions and responsibilities

3.1The Customer instructs us to process Customer Personal Data as necessary to provide, support and secure the Services in accordance with the Terms, this DPA, the Customer's use and configuration of the Services, and any further documented instructions the Customer gives that are consistent with the Terms. We may charge a reasonable fee for carrying out instructions that go beyond the normal operation of the Services.

3.2The Customer is responsible for: (a) the accuracy, quality and lawfulness of Customer Personal Data and the means by which it was obtained; (b) providing all notices to, and obtaining all consents and authorisations from, Data Subjects that Data Protection Laws require; (c) configuring the Services, user roles, permissions and record-level access appropriately; (d) its own compliance with Data Protection Laws as a Controller; and (e) not uploading special category data, criminal offence data or data about children to the Services unless we have agreed to it in writing.

3.3The Customer confirms that its instructions comply with Data Protection Laws. We will tell the Customer if, in our opinion, an instruction infringes Data Protection Laws, but we are not obliged to carry out a legal review of the Customer's instructions.

Back to top

4Our obligations as Processor

We will:

  • process Customer Personal Data only on the Customer's documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by a law that applies to us, in which case we will tell the Customer before processing unless the law prohibits it;
  • ensure that the people we authorise to process Customer Personal Data are bound by written confidentiality obligations and receive appropriate data protection training;
  • implement and maintain the technical and organisational measures in Annex 2, and such other measures as are appropriate to the risk, to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access;
  • engage Sub-processors only in accordance with clause 5;
  • assist the Customer, taking into account the nature of the processing, in responding to Data Subject requests in accordance with clause 7;
  • assist the Customer in meeting its obligations relating to security, Personal Data Breach notification, data protection impact assessments and prior consultation with Supervisory Authorities, taking into account the nature of the processing and the information available to us;
  • delete or return Customer Personal Data at the end of the Services in accordance with clause 10; and
  • make available the information needed to demonstrate compliance with this DPA and allow for audits in accordance with clause 9.
Back to top

5Sub-processors

5.1The Customer gives us general authorisation to engage Sub-processors. Our current Sub-processors are listed in Annex 3.

5.2We will give the Customer at least 30 days' notice before adding or replacing a Sub-processor, by email to the Account administrator or by notice in the Services. The Customer may object in writing within that period on reasonable grounds relating to data protection. We will then work with the Customer in good faith to resolve the objection, for example by offering an alternative. If we cannot resolve it within 30 days of the objection, the Customer may terminate the affected Licences by written notice and we will refund any Fees paid in advance for the period after termination. This is the Customer's only remedy for an objection to a Sub-processor.

5.3We will impose on each Sub-processor, by written contract, data protection obligations that are at least as protective as those in this DPA, and we remain fully liable to the Customer for the performance of each Sub-processor's obligations.

5.4Third-party services that the Customer chooses to connect to the Services are not our Sub-processors. This includes external AI assistants connected through our MCP server or API, Zapier and other integrations. The Customer is the Controller for any data it sends to them and is responsible for its own agreements with those providers.

Back to top

6Security and Personal Data Breaches

6.1Our security measures are described in Annex 2 and at oboloo.com/data-and-security. We may update them from time to time, provided the overall level of security is not materially reduced during a Subscription Term.

6.2We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, so far as known at the time, the nature of the breach, the categories and approximate numbers of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. We will provide further information as it becomes available and will cooperate with the Customer's reasonable investigation.

6.3We will not notify Supervisory Authorities or Data Subjects of a Personal Data Breach on the Customer's behalf unless the Customer asks us to in writing or the law requires us to. The Customer is responsible for deciding whether and how to notify.

Back to top

7Data Subject requests

7.1The Services allow the Customer to access, correct, export and delete Customer Personal Data for itself. The Customer will use these functions to respond to Data Subject requests wherever possible.

7.2If we receive a request from a Data Subject relating to Customer Personal Data, we will not respond to it, other than to direct the Data Subject to the Customer, and will forward it to the Customer within five Business Days.

7.3Where a request cannot be handled using the Services, we will provide reasonable assistance on written request. We may charge a reasonable fee for assistance that is frequent or substantial.

Back to top

8Data protection impact assessments

We will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities that relate to the Services, taking into account the nature of the processing and the information available to us. In the first instance we will do this by providing the documentation published at oboloo.com/data-and-security and by completing the Customer's reasonable security questionnaire. We may charge a reasonable fee for assistance beyond that.

Back to top

9Audits

9.1We will make available to the Customer, on written request, the information reasonably needed to demonstrate compliance with this DPA, including our current penetration test certificate, our published security policies and responses to the Customer's reasonable security questionnaire.

9.2Where that information is not sufficient to meet the Customer's obligations under Data Protection Laws, the Customer, or an independent auditor appointed by the Customer that is not our competitor and is bound by confidentiality, may audit our compliance with this DPA: no more than once in any 12-month period, unless required by a Supervisory Authority or following a Personal Data Breach; on at least 30 days' written notice; during Business Days and normal business hours; remotely unless an on-site visit is essential; without unreasonably disrupting our operations; and at the Customer's cost. We may charge a reasonable fee for our time.

9.3The Customer will give us a copy of any audit report, which is our Confidential Information. We will remedy any material non-compliance found within a reasonable time.

Back to top

10Return and deletion

10.1During the Term the Customer can export Customer Personal Data at any time using the export functions in the Services.

10.2On termination or expiry of the Agreement or the relevant Subscription, we will, on written request made within 30 days, provide an export of Customer Personal Data in a standard machine-readable format at no charge. We will delete Customer Personal Data within six months of termination, except for copies held in routine backups, which are overwritten in the ordinary course, and data we are required by law to keep. We will confirm deletion in writing on request.

Back to top

11International transfers

11.1Customer Personal Data is hosted in the United Kingdom, in ISO 27001 certified data centres in London operated by IONOS, with backups held in geographically separate locations. Customer documents are stored in Amazon Web Services S3 in the London region. The location of each Sub-processor is stated in Annex 3.

11.2Transfers of Customer Personal Data between the United Kingdom and the European Economic Area are covered by the European Commission's adequacy decision for the United Kingdom and the UK's adequacy regulations for the EEA, for as long as they remain in force.

11.3We will not make a Restricted Transfer of Customer Personal Data, and will not allow a Sub-processor to do so, unless a Transfer Mechanism is in place. Where a Sub-processor is located outside the United Kingdom and the EEA, the applicable Transfer Mechanism is shown in Annex 3. On request we will provide a copy of the relevant Transfer Mechanism, with commercial information redacted.

Back to top

12Liability

Each party's liability under or in connection with this DPA is subject to the exclusions and limits in clause 16 of the Terms, including the enhanced cap in clause 16.4. Nothing in this DPA limits either party's liability where Data Protection Laws do not allow it to be limited.

Back to top

13Term, precedence and changes

13.1This DPA applies for as long as we process Customer Personal Data on the Customer's behalf, including the retention period in clause 10.

13.2If this DPA conflicts with the Terms on a matter relating to the processing of personal data, this DPA prevails. If it conflicts with a Transfer Mechanism, the Transfer Mechanism prevails.

13.3We may update this DPA to reflect changes in Data Protection Laws, regulatory guidance, Sub-processors or the Services, by giving notice in accordance with clause 17 of the Terms. The current version, with its version number and date, is published at oboloo.com/dpa.

Back to top

14Contact and governing law

14.1Questions and requests under this DPA should be sent to support@oboloo.app with the subject line “Data protection”.

14.2This DPA is governed by the law of England and Wales, and clause 19.13 of the Terms applies to it.

Back to top

Annex 1: Details of processing

Subject matter
Provision of the oboloo procurement platform (supplier, sourcing, contract and savings management) and related support to the Customer.
Duration
The Term of the Agreement plus the retention period in clause 10.
Nature and purpose
Hosting, storage, backup, display, transmission, analysis within the Services, export, support and troubleshooting, in each case to provide the Services as the Customer configures and uses them.
Categories of Data Subjects
The Customer's employees, contractors and other Authorised Users. Employees and representatives of the Customer's suppliers and prospective suppliers, including Supplier Users. Other individuals whose details appear in documents or records the Customer uploads.
Types of personal data
Names, job titles, work email addresses, work telephone numbers and employer details. User account details, roles and activity logs. Messages exchanged through the Services. Personal data contained in supplier records, questionnaires, certificates, contracts, sourcing responses and savings records. IP addresses and technical data.
Special category data
Not intended to be processed. The Customer must not upload special category or criminal offence data without our written agreement.
Frequency
Continuous, for the duration of the Services.
Retention
As set out in clause 10.
Back to top

Annex 2: Technical and organisational security measures

Our current measures include the following. Up-to-date detail, policies and live certificates are published at oboloo.com/data-and-security.

Hosting and isolation
Application and database hosting in ISO 27001 certified data centres, in a high-availability environment with load balancing and failover. Each Customer has its own subdomain and its own isolated database.
Document storage
Customer documents stored in Amazon Web Services S3.
Encryption
All data encrypted at rest. All data in transit encrypted using TLS 1.2 or higher. Cloudflare in front of the Services for DDoS mitigation and web application firewall.
Access control
Role-based access control, record-level access restrictions, two-factor authentication, Microsoft single sign-on, active session management and new-device sign-in notifications.
Staff access
Access to Customer Tenants restricted to authorised staff for support and maintenance, on a least-privilege basis, through individual credentials with multi-factor authentication, and subject to confidentiality obligations. Access rights are removed immediately when staff leave or change role.
Testing
Continuous automated penetration testing with a published certificate (Beagle Security). Vulnerability scans at least monthly.
Backups and recovery
Daily incremental and weekly full database backups, nightly document backups, encrypted in transit and at rest and stored in geographically separate locations. Backups retained for at least 30 days. Restore tests at least twice a year. Recovery point objective 6 hours; recovery time objective 2.5 hours.
Logging and monitoring
Centralised logging of critical systems with logs retained for at least 12 months. Continuous monitoring and alerting. Change logs on supplier, contract, sourcing and savings records.
Governance
Information Security Policy, Backup Policy, Risk Treatment Plan and internal audit programme aligned to ISO/IEC 27001:2022, published in summary at oboloo.com/data-and-security. Security awareness training for all staff. Incident response and breach notification procedure as set out in clause 6.
Deletion
Deletion of Customer Personal Data within six months of termination as set out in clause 10.
Back to top

Annex 3: Sub-processors

We give at least 30 days' notice before adding or replacing a Sub-processor, as set out in clause 5.2. Where a Sub-processor is located in the United Kingdom or the European Economic Area, no Transfer Mechanism is required.

Sub-processorServiceData processedLocationTransfer mechanism
IONOSHosting of the oboloo application and databasesAll Customer Personal DataUnited Kingdom (London)None required
Amazon Web ServicesDocument storage (S3) and backup storageUploaded documents and backup copiesUnited Kingdom (London, eu-west-2)None required
CloudflareNetwork security, DNS and TLS terminationTraffic metadata and IP addressesUnited States and global edge networkEU-US Data Privacy Framework with UK extension
StripePayment processing and billing portalBilling contact details and payment historyUnited States and European UnionEU-US Data Privacy Framework with UK extension; Standard Contractual Clauses under Stripe's DPA
Twilio SendGridTransactional email (invitations, notifications, authentication codes)Names, email addresses and message contentUnited StatesEU-US Data Privacy Framework with UK extension
ThriveDeskHelp Centre and support ticketingSupport requester details and ticket contentIrelandNone required
MixpanelProduct analytics and session replayUser identifiers, usage data and on-screen content in replaysEuropean UnionNone required
CanduIn-app onboarding guidesUser identifiers and usage dataIrelandNone required
OpenAIAI Features, primary model, via the OpenAI APIContent of records submitted to AI Features. Not used for training. Retained up to 30 days for abuse monitoring.United StatesStandard Contractual Clauses with UK Addendum under the OpenAI Data Processing Addendum
AnthropicAI Features, fallback model, via the Anthropic APIContent of records submitted to AI Features. Not used for training. Retained up to 30 days for safety monitoring.United StatesStandard Contractual Clauses with UK Addendum under the Anthropic Data Processing Addendum
Back to top