LEGAL
Data Processing Agreement
Last updated: 29 August 2026
Your customers' feedback is your data. This agreement sets out how Premoloop processes it on your behalf: who does what, where it lives, who else touches it, and what happens when you leave.
1. Roles and scope
For Customer Data, meaning the feedback, ratings, names and contact details your End Customers submit through the Services, you are the controller and Premoloop is your processor. You decide why that data is collected; we process it on your instructions under UK GDPR Article 28(3). This agreement forms part of the Terms of Service, and capitalised words carry the meaning given there.
For your own account data (your name, email, billing records and your use of the Services), Premoloop is a controller in its own right, as described in the Privacy Notice. This agreement does not cover that data.
2. What processing this covers
Collection, storage, retrieval, aggregation, display, AI-assisted analysis and drafting, export, pseudonymisation, anonymisation and deletion of Customer Data, for the purpose of operating a customer feedback and reputation platform for your business. It runs while you hold an account and until deletion or return under section 10.
The data subjects are your End Customers (name, optional consent-based email, free-text feedback, answers to custom questions, device and timestamp context, consent records, and a hashed IP used for rate limiting) and your staff (name, email, role, optional employee reference and audit records). No special category data is intentionally collected; anything a customer happens to type into free text is stored verbatim, escaped wherever it is shown, and never sent to analytics.
3. Your obligations as controller
You warrant that you have a lawful basis for the processing you instruct, that your privacy information to End Customers is accurate, and that you will not instruct processing that breaches UK data protection law. The platform records the consent wording actually shown (for example the follow-up email opt-in); contacting people outside the consent they gave is your responsibility.
4. Our obligations as processor
Instructions. We process Customer Data only on your documented instructions: the Terms, this agreement and your configuration of the Services. If UK law requires us to process beyond them, we tell you before doing so unless that law forbids it.
Confidentiality. Everyone authorised to process Customer Data is bound by contractual confidentiality. Access is role-scoped; any cross-tenant access runs through a single audited accessor, and support impersonation is time-limited, reasoned and visible.
Security. We implement the measures in section 8, including tenant isolation enforced at the database, encryption in transit and at rest, MFA on administrative access, a logging policy that keeps personal data out of logs and error tracking, and tested backups.
Data subject rights. We assist you with access, rectification, erasure, restriction, portability and objection requests through the platform's self-serve export and deletion workflows and, where those do not suffice, within 5 working days of a written request.
Audit. We make available the information necessary to demonstrate compliance and allow audits by you or your mandated auditor on 14 days' notice, at most once a year absent a breach or regulator requirement, during business hours, and never with access to other tenants' data.
5. Sub-processors
You give general written authorisation for the sub-processors below. We give at least 14 days' notice of any intended addition or replacement, by email to the account owner, during which you may object on reasonable data protection grounds; if we cannot resolve an objection, you may cancel under the Terms. We impose equivalent data protection obligations on every sub-processor and remain fully liable for their performance.
- Acumei Ltd (UK, company no. 17394071): platform development and operation. UK.
- Railway: application hosting. EU (Amsterdam).
- Neon: managed PostgreSQL. EU (Frankfurt).
- Cloudflare: object storage (R2, EU jurisdiction) and DNS.
- Clerk: staff sign-in. US; UK Addendum to the EU SCCs.
- Stripe: payments. US; UK Addendum to the EU SCCs.
- Sentry: error tracking on EU data residency, personal data scrubbed before send.
- Anthropic: AI analysis and drafting under a written no-training commitment. US; UK Addendum to the EU SCCs.
- Transactional email provider: alerts and digests. To be appointed; notice will be given as above.
6. Breach notification
We notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your Customer Data, with enough detail for you to meet your own 72-hour obligation to the ICO as controller. We assist with data protection impact assessments and prior consultation where required.
7. International transfers and AI processing
Customer Data is stored and processed in the UK or EEA. Where a sub-processor entails a restricted transfer, we rely on the UK Addendum to the EU SCCs or an ICO-approved IDTA, as noted against that sub-processor in section 5.
The Premo assistant analyses your feedback and drafts replies. Prompts and outputs are processed under a written commitment from the AI provider that your data is not used to train models, and nothing is sent to an End Customer without your approval.
8. Technical and organisational measures
Tenant isolation enforced by database row-level security, with an automated suite that fails the build on any cross-tenant read; TLS in transit and encryption at rest; role and scope access control with MFA for platform administrators; allowlist logging with a redaction layer; data minimisation (no customer phone numbers or addresses collected, email optional and consent-gated); separate development, staging and production environments with synthetic data outside production; encrypted in-region backups with tested restore; deletion completeness proven by direct query; protected branches with second review on security-critical changes; and a rehearsed incident response runbook.
9. Liability, records and cooperation
Liability under this agreement is subject to the limitations in the Terms of Service and does not create a separate or additional cap. We maintain Article 30(2) records of processing and cooperate with the ICO on request. If we believe an instruction infringes UK data protection law, we tell you immediately and may suspend that instruction until it is confirmed or withdrawn.
10. Deletion and return on termination
At your choice, we delete or return all Customer Data at the end of services and delete existing copies unless UK law requires storage. Deletion reaches every store where Customer Data lives, and absence is provable by query. Backups expire on their fixed cycle; data in expired backups is not restored except for disaster recovery, and any such restore re-applies deletions.
11. Versions and acceptance
This agreement is versioned like the privacy notice. Acceptance is captured when you create your account, with the version and timestamp recorded. If we change it, you stay on the version you accepted until you accept the new one, and we tell you what changed.