Data Processing Addendum
Last updated · 2026-04-22The DPA supplements our Terms of Service and governs how we process personal data on your behalf as a data processor. A signable PDF is available on request.
How to get the full DPA
Email [email protected] with your company details. We'll send the signable PDF (pre-signed by Promptable) within two business days. No NDA required for the standard DPA; enterprise-specific addenda go through a short review.
What it covers
Subject matter and duration of processing, types of personal data, categories of data subjects, sub-processors (full list at /security), security measures, sub-processor change notifications, data subject rights assistance, breach notification, return and deletion, audit rights. Based on the EU GDPR Article 28 template with UK-specific adjustments.
Standard Contractual Clauses
Where personal data moves outside the UK — primarily inference calls to Anthropic and OpenAI in the US — we rely on the UK's International Data Transfer Addendum (IDTA) to the EU SCCs. Full copies of the SCCs and IDTA are appended to the DPA.
Security review pack
If your procurement process needs more than the DPA, we have a standard security review pack (architecture diagram, sub-processor list, data flow documentation, pen test summary, SOC 2 roadmap) available under NDA. Email [email protected].