Last updated: March 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Controller”) and The Only Suite (“Processor”) and governs the processing of personal data on your behalf. This DPA is incorporated by reference into the Terms of Service.
For the purposes of this DPA: “Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, and “Supervisory Authority” have the meanings given in the UK GDPR / EU GDPR. “Services Data” means personal data submitted to or processed through the Service by or on behalf of the Controller. “Sub-processor” means any third party engaged by the Processor to process Services Data.
The Processor will process Services Data solely to provide the Service as described in the Terms of Service and only on documented instructions from the Controller, including those set out in this DPA. The subject matter, nature, and purpose of processing is the provision of AI-powered support, moderation, communications, and operations automation services. Categories of data subjects include the Controller’s end customers and users. Categories of personal data include names, email addresses, IP addresses, and the content of support communications.
The Controller warrants and represents that:
The Processor agrees to:
The Controller grants general authorisation to the Processor to engage sub-processors. Current sub-processors include: Amazon Web Services (SES, Rekognition, Comprehend — email delivery, image and text moderation); Cloudflare (email routing, object storage); Stripe (payment processing); Sentry (error monitoring); and PostHog (product analytics). The Processor will provide at least 14 days’ notice before adding or replacing a sub-processor, giving the Controller the opportunity to object. The Processor will impose data protection terms on sub-processors that are no less protective than this DPA and remains liable for sub-processor acts and omissions.
Where Services Data is transferred outside the UK or European Economic Area, the Processor will ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) where required, or will rely on an adequacy decision. AWS and Cloudflare data is processed within EU/UK regions by default where available. The Processor will maintain a record of transfer mechanisms and make these available to the Controller on request.
In accordance with Article 28 and Article 32 of the GDPR, the Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
The Processor will notify the Controller without undue delay, and in any event within 48 hours, upon becoming aware of a personal data breach affecting Services Data. Notification will include, to the extent known: the nature of the breach, categories and approximate number of data subjects affected, categories and approximate number of records concerned, likely consequences, and measures taken or proposed to address the breach. The Controller remains responsible for notifying the relevant Supervisory Authority and affected data subjects as required by applicable law.