This Data Processing Addendum (“Addendum”) forms part of the agreement between Varsuite Media Group Ltd, trading as Varsuite (“Varsuite”), and the Client identified on the applicable account, Quote or Statement of Work (“this Agreement”), and applies whenever Varsuite processes personal data on the Client's behalf in the course of providing a Service. It supplements, and forms part of, the Varsuite Service Contract, and takes priority over the Service Contract and Terms of Service in relation to the processing of personal data, in accordance with clause 2 of the Service Contract.
1. Definitions
1.1 “UK GDPR”, “Data Protection Act 2018”, “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “special category data” have the meanings given in the UK GDPR.
1.2 “Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations, and any successor or related UK legislation.
1.3 “AI Tools” means artificial intelligence, machine learning, large language model, and related automation technologies (whether developed by Varsuite or a third party) used to assist in delivering the Services.
1.4 “Sub-processor” means any third party engaged by Varsuite to process personal data on the Client's behalf in connection with the Services, including hosting, infrastructure, communications and AI Tool providers.
1.5 “Transfer Mechanism” means a lawful safeguard for the transfer of personal data outside the United Kingdom, or outside the European Economic Area where the EU GDPR applies, recognised under the UK GDPR or the EU GDPR as applicable, including UK adequacy regulations, European Commission adequacy decisions, the UK International Data Transfer Agreement, the UK Addendum to the European Commission's standard contractual clauses, and the European Commission's standard contractual clauses.
2. Roles of the parties
2.1 For the purposes of the processing described in this Addendum, the Client is the controller and Varsuite is the processor, unless the applicable Quote or Statement of Work states otherwise.
2.2 Each party will comply with the obligations that apply to it under the Data Protection Legislation in respect of that processing.
3. Varsuite's obligations
3.1 Varsuite will process personal data only on the Client's documented instructions, including the instructions inherent in the Service Contract and the applicable Quote or Statement of Work (which include the use of AI Tools and automation to deliver the Services, as described in clause 4 of the Service Contract), unless required to do otherwise by UK law, in which case Varsuite will inform the Client before processing, unless the law prohibits this.
3.2 Varsuite will ensure that personnel authorised to process personal data are subject to an appropriate duty of confidentiality.
3.3 Varsuite will implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, having regard to the nature of the data and the risks involved, as further described in Schedule 2 to the applicable Statement of Work.
3.4 Varsuite will engage Sub-processors only in accordance with clause 5 of this Addendum.
3.5 Varsuite will, taking into account the nature of the processing, provide reasonable assistance to the Client to enable the Client to respond to requests from data subjects exercising their rights, and to meet the Client's obligations relating to security, breach notification, data protection impact assessments and consultation with supervisory authorities, taking into account the information available to Varsuite.
3.6 Varsuite will notify the Client without undue delay after becoming aware of a personal data breach affecting personal data processed under this Agreement, and will provide the Client with the information reasonably available to it to allow the Client to meet its own notification obligations.
3.7 At the Client's election, and on expiry or termination of the applicable Service, Varsuite will delete or return all personal data processed under this Agreement in accordance with clauses 15 and 37 of the Service Contract, except to the extent Varsuite is required by law to retain it.
3.8 Varsuite will make available to the Client information reasonably necessary to demonstrate compliance with this Addendum, and will allow for and contribute to reasonable audits, including inspections, conducted by the Client or an auditor mandated by the Client, on reasonable prior written notice, no more than once in any 12-
month period save where a personal data breach has occurred, during normal business hours, and subject to reasonable confidentiality restrictions. The Client will bear its own costs of an audit, and Varsuite's reasonable costs, unless the audit identifies material non-compliance by Varsuite, in which case Varsuite will bear its own reasonable costs.
4. Sub-processors
4.1 The Client provides Varsuite with a general written authorisation to engage Sub-processors to help deliver the Services, including hosting and infrastructure providers, communications and payment providers, and providers of AI Tools, without the need to name each Sub-processor in this Addendum.
4.2 Varsuite will impose data protection terms on each Sub-processor that are no less protective of personal data than this Addendum, and remains responsible to the Client for the acts and omissions of its Sub-processors as if they were Varsuite's own.
4.3 Varsuite maintains a current list of its Sub-processors, available to the Client on request. Varsuite will give the Client reasonable advance notice, of at least 14 days where reasonably practicable, before engaging a new Sub- processor that will materially process the Client's personal data, during which the Client may object in writing on reasonable grounds relating to data protection. If the parties cannot resolve the objection within a reasonable period, either party may treat this as grounds to terminate the affected Service on notice, without further liability, save for fees already accrued.
4.4 This clause 4 applies generally to all Sub-processors engaged by Varsuite from time to time; Varsuite is not required to itemise or separately list every underlying AI model, tool or technology used by a Sub-processor to deliver the Services.
5. Use of AI Tools in processing
5.1 The Services may involve the use of AI Tools to assist in processing personal data as part of delivering the Services - for example, to help categorise records, draft communications, generate reports, or support customer interactions. The Client authorises this use as part of its documented instructions under clause 3.1, provided it is carried out in accordance with this Addendum.
5.2 Varsuite will not use personal data processed on the Client's behalf to train or improve the general, underlying capabilities of any third-party AI Tool, beyond what is reasonably necessary to deliver the specific processing instructed by the Client, and will seek to use AI Tools operating on terms that exclude the use of submitted data for general model training, where such terms are reasonably available from the provider concerned.
5.3 Varsuite will not permit an AI Tool to make a decision producing legal effects concerning a data subject, or which similarly significantly affects them, based solely on automated processing without appropriate human involvement, unless the Client has specifically instructed and authorised such use in writing and appropriate safeguards agreed between the parties are in place.
5.4 Nothing in this clause 5 requires Varsuite to disclose the identity of every individual AI Tool, model or provider used to deliver the Services; the obligations in this clause and in clause 4 apply generally and are intended to protect the Client's personal data regardless of which specific AI Tools are in use from time to time.
6. International transfers
6.1 The Client acknowledges that personal data processed under this DPA may be transferred to, stored in, or accessed from countries outside the United Kingdom, including within the European Economic Area and in countries outside both the United Kingdom and the EEA, by Varsuite, its Sub-processors, and the hosting, infrastructure, communications and AI providers used to deliver the Service. The Client provides its general authorisation for such transfers.
6.2 Where a transfer described in clause 6.1 takes place, Varsuite will ensure an appropriate Transfer Mechanism is in place in respect of that transfer, or that the transfer is otherwise permitted under the UK GDPR and, where the EU GDPR applies to the processing, under the EU GDPR.
6.3 Where the EU GDPR applies to the processing, this Addendum applies to that processing as if references to the UK GDPR were references to the EU GDPR, references to the Information Commissioner's Office were references to the competent supervisory authority, and references to a Transfer Mechanism included the European Commission's standard contractual clauses and any other safeguard recognised under the EU GDPR.
6.4 Where a Transfer Mechanism requires additional terms to be entered into between the parties or with a Sub- processor, Varsuite will put those terms in place and, on request, provide the Client with reasonable evidence that an appropriate Transfer Mechanism applies.
7. Client's obligations
7.1 The Client is responsible for the lawfulness of the personal data it provides to Varsuite and the instructions it gives, including having an appropriate lawful basis for the processing and providing any privacy information required to data subjects.
7.2 The Client will not instruct Varsuite to process special category data or data relating to criminal convictions or offences unless it has notified Varsuite in advance in writing and the parties have agreed any additional safeguards necessary.
7.3 The Client is responsible for ensuring that any personal data it provides is accurate, adequate and lawfully obtained.
8. Personal data breach
8.1 Following a personal data breach affecting personal data processed under this Agreement, Varsuite will, without undue delay, take reasonable steps to contain and remediate the breach, and will cooperate with the Client's reasonable requests for information to assist the Client in meeting its own notification obligations to a supervisory authority or affected data subjects.
9. Records and demonstrating compliance
9.1 Varsuite will maintain records of its processing activities carried out on the Client's behalf as required by Article 30(2) of the UK GDPR, and will make relevant extracts available to the Client on reasonable request.
10. Liability
10.1 Liability arising under or in connection with this Addendum is subject to the limitations and exclusions set out in clause 39 of the Service Contract, save to the extent such limitations or exclusions cannot lawfully apply to a party's data protection liability.
11. Term and general
11.1 This Addendum takes effect on the date personal data is first processed under this Agreement and continues for as long as Varsuite processes personal data on the Client's behalf, notwithstanding the expiry or termination of the Service Contract or an applicable Statement of Work.
11.2 This Addendum is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
ANNEX 1: DETAILS OF PROCESSING
Subject matter The processing of personal data reasonably necessary for Varsuite to provide the
Services described in the applicable Quote or Statement of Work.
Duration For the term of the applicable Service Contract, Quote or Statement of Work, plus any
period required for deletion or return of data under clause 3.7.
Nature and purpose Hosting, development, maintenance, support and AI-assisted automation of the Client's
business systems, communications and related workflows, as described in the
applicable Statement of Work.
Types of personal data May include names, contact details, addresses, order and transaction history, account
and billing information, communications, and other categories of personal data
described in the applicable Statement of Work. Special category data is processed only
where expressly agreed under clause 7.2.
Categories of data The Client's customers, prospects, employees, contractors, suppliers and other
subjects individuals whose personal data the Client provides to Varsuite, or authorises Varsuite to
collect, in connection with the Services.
Sub-processors As maintained in Varsuite's current Sub-processor list (available on request),
encompassing hosting, infrastructure, communications, payment and AI/automation
providers engaged from time to time to deliver the Services, in accordance with clause 4
of this Addendum.
This Annex is a summary for convenience; the specific detail of processing for a given Service is as described in the applicable Statement of Work.
ANNEX 2: INFRASTRUCTURE, STORAGE AND ACCESS This Annex describes, in categories rather than by named vendor, the infrastructure Varsuite uses to process personal data on the Client's behalf, where that data is held, and the basis on which Varsuite accesses it. The current named list of Sub-processors is available to the Client on request under clause 4.3, and is maintained separately so that a change of provider does not require an amendment to this Addendum.
A2.1 Categories of infrastructure
Personal data processed under this Addendum may be held and processed using the following categories of infrastructure and service:
- Managed application hosting and compute, running the platform itself.
- Managed relational database services, holding the platform's structured records, together with the tooling used to administer, migrate, monitor and back them up.
- Object and file storage services, holding uploaded files, documents, images, exports and generated assets.
- Backup and snapshot storage, holding point-in-time copies of the above.
- Content delivery, DNS, edge and security services, which handle traffic to and from the platform.
- Transactional email delivery services, which process the email the platform sends on the Client's behalf. Administrators of those services may be able to view message metadata and content for delivery, deliverability and abuse-investigation purposes.
- Messaging and notification services, where the Service sends SMS or similar messages.
- Recording, transcription and meeting-capture tools, where these are used in the delivery of the Service.
- AI Tools and AI provider APIs, as described in clause 5 of this Addendum.
- Analytics and product-usage services. Where Varsuite uses an analytics provider on its own behalf, it is configured so that no personally identifiable information is passed to that provider.
- Error tracking, logging, monitoring and alerting services.
- Source control, deployment and development tooling, which may hold personal data only incidentally, for example within a support attachment or a test dataset.
A2.2 Storage location
A2.2.1 As a default, Varsuite stores personal data processed under this Addendum in the United Kingdom or the European Economic Area, typically a London or other European region, so that the data remains within the scope of UK and EU adequacy. A2.2.2 Data may be stored or processed in another region, including the United States, where the Client requests it, where the location of the Client's users or website makes it appropriate, or where a Sub-processor's architecture requires it. Any such transfer is subject to clause 6 of this Addendum.
A2.2.3 Where the Client requires a specific storage location, data residency guarantee or restriction on the regions used, it must tell Varsuite before the Service begins so that it can be agreed and, where necessary, priced. In the absence of such a requirement, Varsuite selects the region.
A2.3 Varsuite access to Client data
A2.3.1 Varsuite personnel and its Sub-processors require access to the systems, databases, storage and data described in this Annex in order to deliver, support, secure and maintain the Services. A2.3.2 Varsuite will access personal data processed on the Client's behalf only where reasonably necessary to deliver or support the Service, to investigate a fault, security incident or suspected breach of the Acceptable Use Policy, to perform a migration, backup or restore, to fulfil the Client's own instruction, or where required by law. A2.3.3 Access is granted on a least-privilege basis to personnel who require it, is subject to authentication controls, and is logged. Varsuite may inspect, query and export data within the systems it hosts or manages for the purposes set out above, including where necessary to verify the integrity or correctness of data held in them. A2.3.4 Varsuite does not use personal data processed on the Client's behalf for its own purposes, and does not sell it or disclose it to a third party other than a Sub-processor engaged in accordance with clause 4, or as required by law.
A2.4 Children’s personal data
A2.4.1 Where the Client instructs Varsuite to process personal data of children, including photographs and images - for example within a nursery, school, childcare or activity provider platform - the Client is the controller for that data and Varsuite acts solely as its processor on the Client's documented instructions. A2.4.2 The Client is responsible for establishing the lawful basis for that processing, for obtaining parental or guardian consent where required, for providing the required privacy information, and for setting the retention period. The Client will inform Varsuite before any such processing begins so that appropriate technical and organisational measures, access restrictions and retention rules can be agreed.
A2.5 Data subject requests and self-service erasure
A2.5.1 Where the platform provides administrative functions allowing the Client to search, export, correct, restrict, anonymise or delete the records of an individual, the Client may use those functions to respond to a data subject request itself, without needing to raise a request with Varsuite. Where a Service includes those functions, they are described in the applicable Statement of Work. A2.5.2 Deletion carried out by the Client through the platform removes the record from the live system. A deleted record may persist in routine backups until those backups expire under the applicable retention schedule, and in audit logs where a record of the deletion itself must be retained. Varsuite will assist with the permanent removal of data from backups where the Client reasonably requires it and it is technically feasible to do so. A2.5.3 Clause 8 of this Addendum continues to apply to any data subject request the Client cannot fulfil through the platform.
Varsuite Media Group Ltd. Company number 14243978. Registered office: Mentor House, Ainsworth Street, Blackburn, England, BB1 6AY. ICO registration: ZB434970.