Legal

Data Processing Agreement

Last updated: 8 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Data Professionals Ltd, trading as Pressifo (Company No. 12030418, VAT No. GB 411 3471 40), the "Processor", and the customer identified in the applicable order or account record, the "Controller". It applies whenever Pressifo processes personal data on the Controller's behalf under UK GDPR Art. 28.

By using Pressifo the Controller enters into this DPA. A countersigned version is available on request to privacy@pressifo.com.

1. Definitions

"UK GDPR", "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" bear the meanings given in the UK GDPR and the Data Protection Act 2018.

2. Subject-matter and duration

The Processor processes personal data to provide the Pressifo platform (story generation, journalist discovery, outreach delivery, analytics) for the duration of the Controller's subscription and any wind-down period defined in Section 9.

3. Nature and purpose of processing

Storage, hosting, retrieval, transmission, computation via large language models, sending outreach emails, delivering the user interface, generating aggregate analytics.

4. Categories of data and data subjects

  • Controller's personnel: name, business email, role, workspace activity.
  • Journalists and media contacts: name, outlet, business email, beats, published articles, public social profiles.
  • Engagement events: opens, clicks, bounces, unsubscribes on Controller-approved outreach.

5. Controller's obligations

The Controller warrants it has a lawful basis to instruct the processing described above, including in respect of any personal data it uploads or targets, and that its own privacy notices reflect the use of Pressifo.

6. Processor's obligations

  • Process personal data only on the Controller's documented instructions, which include use of the platform in accordance with the Terms.
  • Ensure staff authorised to process personal data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Annex A).
  • Assist the Controller with data-subject requests, DPIAs and consultations with the ICO, taking into account the nature of the processing and the information available to us.
  • Notify the Controller of any personal data breach without undue delay and in any event within 72 hours of becoming aware.
  • Make available all information necessary to demonstrate compliance and allow for audits, subject to reasonable notice and confidentiality; a recent SOC 2 / ISO report from the Processor or a sub-processor may satisfy this requirement.

7. Sub-processors

The Controller provides general written authorisation for the Processor to engage the sub-processors listed at /subprocessors. The Processor gives at least 30 days' notice by email and via that page before adding or replacing a sub-processor. The Controller may object on reasonable, documented data-protection grounds; if the objection cannot be resolved, either party may terminate the affected service with pro-rata refund of prepaid fees.

8. International transfers

Where personal data is transferred outside the UK, transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations.

9. Return and deletion

On termination the Processor will, at the Controller's choice, delete or return all personal data within 30 days, save where retention is required by law (e.g. UK tax records) or on the suppression list to honour opt-outs.

10. Liability

Each party's liability under this DPA is subject to the limitations in the Terms of Service.

Annex A — Technical and organisational measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access control, principle of least privilege, audit logging.
  • Secrets stored in provider-managed vaults; no plaintext in code.
  • Automated backups with point-in-time recovery on the primary database.
  • Vulnerability scanning, dependency monitoring, prompt patching.
  • Documented incident-response process with 72-hour breach notification.
  • Sub-processor due diligence and contractual DPAs before onboarding.
  • Staff confidentiality obligations and periodic security training.

Annex B — Sub-processors

The current sub-processor list is maintained at /subprocessors.