Data processing agreement
Berkeley Myles Solutions Ltd. Part of the customer agreement, read together with your Order Form.
Last updated · 25 September 2026Customer agreement · General terms and conditions · Service specific terms
1. Information about this DPA
This data processing agreement (“DPA”) forms part of the Agreement between the Supplier and the Customer and sets out the terms that apply to the processing of Personal Data in connection with the provision and receipt of the Services.
Capitalised terms used but not defined in this DPA shall have the meaning given to them in the Order Form, the General Terms and Conditions or the Service Specific Terms (as applicable).
2. Definitions and interpretation
The following terms shall have the following meanings unless the context requires otherwise:
- “Agreement”
- has the meaning given to it in the Order Form.
- “Controller”
- has the meaning given to it by GDPR.
- “Data Protection Laws”
- means, in relation to any Personal Data which is Processed in the performance of this Agreement: (i) in respect of the United Kingdom, the Data Protection Act 2018, the UK GDPR and the Data (Use and Access) Act 2025; and (ii) in respect of the European Economic Area, the EU GDPR, the Directive on Privacy and Electronic Communications 2002/58 and other data protection or privacy legislation in force from time to time in the European Economic Area, in each case together with any national implementing laws, regulations, secondary legislation and any other applicable or equivalent data protection or privacy laws, as amended or updated from time to time, and any successor legislation to such laws.
- “Data Subject”
- has the meaning given to it by GDPR.
- “GDPR”
- means the UK GDPR and/or the EU GDPR, in each case as applicable, where: (a) “UK GDPR” means Regulation (EU) 2016/679 General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of Section 3 of the European Union (Withdrawal) Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019; and (b) “EU GDPR” means Regulation (EU) 2016/679 General Data Protection Regulation as applicable in the European Economic Area, together with any applicable national data protection legislation of the relevant EEA member state.
- “Personal Data”
- has the meaning given to it by GDPR, and except for the caveat at Clause 4, relates only to personal data, or any part of such personal data, of which the Customer is the Controller and in relation to which the Supplier is the Processor in providing the Services under this Agreement.
- “Personal Data Breach”
- has the meaning given to it by GDPR.
- “Process” and “Processing”
- have the meaning given to them by GDPR.
- “Processor”
- has the meaning given to it by GDPR.
- “Special Categories of Personal Data”
- means those categories of data listed in Article 9(1) GDPR.
- “Supervisory Authority”
- means any regulatory authority responsible for the enforcement of Data Protection Laws, which shall at least include, in respect of the UK, the UK Information Commissioner’s Office and, in respect of the EEA, the relevant competent supervisory authority of the applicable member state.
In this DPA, references to “Clauses” are to clauses of this DPA. The rules of interpretation set out in the General Terms and Conditions apply to this DPA.
3. Roles of the parties
The Parties acknowledge that, to the extent the Supplier is acting as a Controller in relation to Personal Data as set out in Clause 4, the Supplier acts as a separate and independent Controller from the Customer.
Except as in the limited circumstances provided for in Clause 4, the Parties acknowledge that:
for the purposes of Data Protection Laws, the Customer is the Controller and the Supplier is the Processor of any Personal Data; and
the Personal Data shall be in respect of data shared by necessity by the Customer with the Supplier for the provision and receipt of the Services only.
4. Supplier acting as controller
To the extent the Supplier is acting as Controller, the Supplier shall:
comply with Data Protection Laws when Processing Personal Data;
only Process Personal Data:
in order to perform the Supplier’s obligations under this Agreement; and
solely to the extent permitted by Applicable Laws to the extent necessary for the following purposes as Controller:
maintaining and developing the Supplier’s relationship with the Customer;
billing and invoicing;
compliance with quality control and risk management procedures;
IT security-related processing (for example, automated scanning of incoming and outgoing emails for viruses);
complying with legal and regulatory obligations; and
establishing, exercising and defending legal claims;
notify the Customer as soon as reasonably practicable upon becoming aware of a Personal Data Breach affecting Personal Data, and, where reasonably practicable, provide a copy of any proposed notification and consider in good faith any comments made by the Customer before notifying the Personal Data Breach to any Supervisory Authority; and
comply with Data Protection Laws in relation to any transfers of Personal Data under GDPR that would otherwise be prohibited but for the implementation of appropriate safeguards in accordance with Article 46 GDPR.
5. Processing details and instructions
The scope, nature and purpose of the Processing, which constitutes the Customer’s Processing instruction as Controller to the Supplier as Processor, is set out in Annex A.
The Customer’s instructions for the Processing of Personal Data shall comply with Data Protection Laws. The Supplier shall inform the Customer immediately if, in the Supplier’s opinion, an instruction from the Customer violates Data Protection Laws.
Each Party confirms that, in the performance of this Agreement, it shall comply with Data Protection Laws.
6. Supplier obligations as processor
The Supplier shall:
Process Personal Data only on documented instructions from the Customer, unless required to do so by Data Protection Laws or any other Applicable Law to which the Supplier is subject; in such a case, the Supplier shall inform the Customer of that legal requirement before Processing, unless that Applicable Law prohibits the Supplier from informing the Customer;
take reasonable steps to ensure that persons authorised to Process the Personal Data have committed themselves to confidentiality undertakings;
ensure that the Supplier has in place appropriate technical and organisational measures to protect against unauthorised or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, appropriate to the harm that might result from the unauthorised or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures (those measures may include, where appropriate, pseudonymising and encrypting Personal Data, ensuring confidentiality, integrity, availability and resilience of the Supplier’s systems and services, ensuring that availability of and access to Personal Data can be restored in a timely manner after an incident, and regularly assessing and evaluating the effectiveness of the technical and organisational measures adopted by the Supplier);
be generally authorised to engage another Processor to Process Personal Data (“Subprocessor”), subject to the Supplier:
making available to the Customer a list of Subprocessors authorised to Process Personal Data (“Subprocessor List”), the initial Subprocessor List as at the date of this DPA being set out in Annex A;
notifying the Customer of any intended changes to its use of Subprocessors by providing the Customer with notice of any updates to the Subprocessor List, which the Supplier shall provide to the Customer at least 30 calendar days prior to authorising any new Subprocessor;
including terms in its contract with each Subprocessor which are no less protective than those set out in this Agreement;
remaining liable to the Customer for any failure by each Subprocessor to fulfil its obligations in relation to the Processing of the Customer’s Personal Data.
allow the Customer, in relation to any notice received under Clause 6.4.2, a period of 14 calendar days from the date of the notice to register any reasonable objection to the use of that Subprocessor. Where any objection is registered, the following shall apply:
the Parties shall meet as soon as possible to discuss the reasons for the objection, whereby the Customer shall provide the Supplier with all details of the concerns which led to the objection;
if the Customer does not withdraw the Customer’s objection within 1 month from the date on which the Customer made the Customer’s objection, the Supplier will use reasonable efforts to make available to the Customer a change in the Services or recommend a commercially reasonable change to the Customer’s configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Subprocessor without unreasonably burdening the Customer;
if the Supplier is unable to make available to the Customer a change in the Services or recommend a commercially reasonable change to the Customer’s configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Subprocessor as per Clause 6.5.2 above, or if the Customer does not accept the proposed changes or recommendations, the Supplier shall not proceed with appointing that Subprocessor;
if the Supplier’s provision of Services is not possible without engaging the proposed Subprocessor, the Supplier shall be entitled to proceed with appointing that Subprocessor. The Supplier shall notify the Customer that the appointment of that Subprocessor is required in order for the Supplier to provide the Services and the Customer may terminate the Agreement by providing written notice within 30 days from receipt of the Supplier’s notice under this Clause 6.5.4.
taking into account the nature of the Supplier’s Processing, assist the Customer by putting in place appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the Data Subject’s rights laid down in Data Protection Laws, to the extent that such requests relate to Personal Data Processed in connection with this Agreement;
notwithstanding Clause 6.6 above, the Supplier shall direct:
all individual Data Subject requests, complaints or other communications (whether from the Data Subject or on their behalf); and
any requests, correspondence or communications from a Supervisory Authority,
to the Customer within 2 Business Days of receipt and provide all reasonable co-operation to allow the Customer to investigate any such request and to fulfil the Customer’s obligations under applicable Data Protection Laws. The Supplier shall not engage with such Data Subject, requester or Supervisory Authority directly;
assist the Customer, at the Customer’s cost, in responding to any request from a Data Subject and in ensuring compliance with the Customer’s obligations under Data Protection Laws with respect to Personal Data Breach notifications, data protection impact assessments and consultations with Supervisory Authorities;
in relation to the Customer’s assessment of the Supplier’s compliance with this DPA:
at the Customer’s request, make available to the Customer all information necessary to demonstrate the Supplier’s compliance with this DPA (which obligation may be satisfied by providing relevant certifications (such as ISO/IEC 27001 or equivalent), third party audit reports or other appropriate documentation);
to the extent that information obtained pursuant to Clause 6.9.1 is insufficient for the Customer to verify the Supplier’s compliance with this DPA and Data Protection Laws, the Customer shall be entitled to carry out an inspection of the technical and organisational measures taken by the Supplier as relevant to the Supplier’s compliance with this DPA upon giving at least 30 calendar days prior notice, unless a shorter period is required (in particular in cases where a Supervisory Authority requires an inspection to be performed at shorter notice), provided that any inspection takes place during normal Business Hours and with no unreasonable disruption to the Supplier’s business, is proportionate to the Services the Supplier provided to the Customer and the criticality or importance of such Services, adheres to commonly accepted national and international audit standards, is conducted no more than once in any calendar year (unless a Supervisory Authority requires otherwise), does not include access to systems, data or information relating to any other customer of the Supplier, and employees or third party auditors being subject to appropriate confidentiality obligations in relation to any audit and / or inspection, and the costs of any such audit or inspection being borne by the Customer;
where the Customer requires additional assistance or information beyond what is reasonably necessary to demonstrate the Supplier’s compliance with this DPA, the Supplier may charge reasonable fees for providing such additional assistance or information on a time and materials basis;
notify the Customer promptly and without undue delay if the Supplier becomes aware of a Personal Data Breach relating to the Supplier’s obligations under this Agreement, which notification shall include, where available:
a description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned;
the likely consequences of the Personal Data Breach; and
the measures taken or proposed to be taken to address and mitigate the Personal Data Breach;
in relation to any such notification under Clause 6.10, take all reasonable measures to prevent any further negative impact of the Personal Data Breach. The Supplier shall provide assistance, and provide the Customer with sufficient information so that the Customer is able to meet any obligations to assess and report a Personal Data Breach under the Data Protection Laws, which may be provided in stages as it becomes available to the Supplier, including obtaining any information that needs to be included in a notification to the Supervisory Authority or impacted Data Subjects; and
not transfer any Personal Data outside of the United Kingdom and the European Economic Area unless the Customer’s prior written consent has been obtained (such consent not being required in respect of transfers of Personal Data to Subprocessors appointed in accordance with Clause 6.4) and appropriate safeguards have been implemented in accordance with Article 46 GDPR, which safeguards may include the Standard Contractual Clauses approved by the European Commission or any other lawful transfer mechanism recognised under Data Protection Laws (and the Customer authorises the Supplier to enter into such transfer mechanisms with Subprocessors on the Customer’s behalf where required).
7. Data return and destruction
Upon termination or expiry of the Agreement, the Customer may, within 30 days, request the return or export of Personal Data Processed by the Supplier on the Customer’s behalf. Following the expiry of that period, the Supplier shall delete or irreversibly anonymise all Personal Data, unless Applicable Law requires retention of such Personal Data.
Notwithstanding Clause 7.1, Personal Data may be retained in backups, archives or disaster recovery systems until such data is deleted in accordance with the Supplier’s standard retention cycles. During this period, such Personal Data shall remain protected in accordance with this DPA and shall not be actively Processed.
Upon written request, the Supplier shall confirm that deletion has been completed in accordance with this Clause 7, to the extent technically feasible.
The Customer is responsible for ensuring that it has securely exported or otherwise retained any Personal Data it requires prior to deletion. The Supplier shall not be liable for any loss of Personal Data following deletion carried out in accordance with this Clause 7.
8. Indemnity
The Customer agrees to indemnify the Supplier, and keep the Supplier indemnified, and defend the Supplier at the Customer’s own expense, against all costs, claims, damages or expenses incurred by the Supplier or for which the Supplier may become liable, due to any failure by the Customer or the Customer’s employees or agents to comply with this DPA.
9. Liability
Nothing in this DPA shall increase or extend either Party’s liability beyond that set out in the Agreement.
Annex A
Personal Data processing purposes and details
| Subject matter of Processing | Processing of Personal Data as necessary for the Supplier to provide the Services under the Agreement. |
| Duration of Processing | For the duration of the Agreement and any applicable retention period in accordance with Clause 7. |
| Nature of Processing | Processing activities may include collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, restriction, deletion or destruction of Personal Data. |
| Purpose of Processing | Provision and operation of the Services, including: (a) hosting and storage of Personal Data; (b) processing of Customer Data; (c) support, maintenance and troubleshooting; (d) security monitoring and fraud prevention; (e) analytics and performance monitoring (in aggregated and anonymised form where possible); and (f) creation of Aggregated Data (as defined in the General Terms and Conditions) as permitted by the Agreement. |
| Personal Data Categories | Depending on the Customer’s use of the Services, Personal Data may include: (a) name, email address and contact details; (b) professional information (e.g. job title, organisation); (c) Customer Data (including any Personal Data contained in files, communications or materials uploaded to the Services); and (d) technical data (e.g. IP address, device information, log data). |
| Data Subject Types | (a) the Customer’s employees; (b) the Customer’s suppliers, contractors or agents; (c) end users of the Customer’s services (if applicable); and (d) any individuals whose Personal Data is included in Customer Data. |
Approved Subprocessors (initial Subprocessor List)
| Name of Subprocessor | Processing activities | Location | Safeguard mechanism |
|---|---|---|---|
| GoCardless Ltd | Payment processing and direct debit administration | United Kingdom | N/A. |
| Microsoft Ireland Operations Limited | Cloud hosting and infrastructure services for the Software and customer data | United Kingdom United States and other countries where Microsoft or its subprocessors operate (where applicable) | UK – N/A. US and other countries - UK IDTA, SCCs and other GDPR Article 46 transfer safeguards implemented by Microsoft. |