Data Processing Agreement

Last updated: March 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Controller”) and The Only Suite (“Processor”) and governs the processing of personal data on your behalf. This DPA is incorporated by reference into the Terms of Service.

1. Definitions

For the purposes of this DPA: “Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, and “Supervisory Authority” have the meanings given in the UK GDPR / EU GDPR. “Services Data” means personal data submitted to or processed through the Service by or on behalf of the Controller. “Sub-processor” means any third party engaged by the Processor to process Services Data.

2. Scope and Purpose

The Processor will process Services Data solely to provide the Service as described in the Terms of Service and only on documented instructions from the Controller, including those set out in this DPA. The subject matter, nature, and purpose of processing is the provision of AI-powered support, moderation, communications, and operations automation services. Categories of data subjects include the Controller’s end customers and users. Categories of personal data include names, email addresses, IP addresses, and the content of support communications.

3. Controller Obligations

The Controller warrants and represents that:

  • It has a lawful basis for processing each category of personal data submitted to the Service
  • It has provided adequate privacy notices to data subjects and obtained any necessary consents
  • It will comply with all applicable data protection laws in its use of the Service and this DPA
  • Instructions given to the Processor regarding processing of personal data comply with applicable law

4. Processor Obligations

The Processor agrees to:

  • Process Services Data only on documented instructions from the Controller, except where required by law
  • Ensure that persons authorised to process Services Data are bound by appropriate confidentiality obligations
  • Implement technical and organisational measures as set out in Article 32 of the GDPR
  • Assist the Controller with data subject rights requests, DPIAs, and breach notifications as required
  • Delete or return all Services Data upon termination of the Service, at the Controller’s choice
  • Make available all information necessary to demonstrate compliance with this DPA

5. Sub-processors

The Controller grants general authorisation to the Processor to engage sub-processors. Current sub-processors include: Amazon Web Services (SES, Rekognition, Comprehend — email delivery, image and text moderation); Cloudflare (email routing, object storage); Stripe (payment processing); Sentry (error monitoring); and PostHog (product analytics). The Processor will provide at least 14 days’ notice before adding or replacing a sub-processor, giving the Controller the opportunity to object. The Processor will impose data protection terms on sub-processors that are no less protective than this DPA and remains liable for sub-processor acts and omissions.

6. International Transfers

Where Services Data is transferred outside the UK or European Economic Area, the Processor will ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) where required, or will rely on an adequacy decision. AWS and Cloudflare data is processed within EU/UK regions by default where available. The Processor will maintain a record of transfer mechanisms and make these available to the Controller on request.

7. Security Measures

In accordance with Article 28 and Article 32 of the GDPR, the Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit using TLS 1.3 and at rest using AES-256
  • Pseudonymisation of cross-project reputation signals via SHA-256 hashing
  • Ongoing confidentiality, integrity, availability, and resilience of processing systems
  • Ability to restore availability and access to personal data in a timely manner following an incident (DR activation within 15 minutes via standby infrastructure)
  • Regular testing and evaluation of technical and organisational measures
  • Role-based access controls and principle of least privilege for all staff

8. Data Breach Notification

The Processor will notify the Controller without undue delay, and in any event within 48 hours, upon becoming aware of a personal data breach affecting Services Data. Notification will include, to the extent known: the nature of the breach, categories and approximate number of data subjects affected, categories and approximate number of records concerned, likely consequences, and measures taken or proposed to address the breach. The Controller remains responsible for notifying the relevant Supervisory Authority and affected data subjects as required by applicable law.