1.Who this is between
This agreement is between the client (the "Controller", who decides why and how personal data is processed) and Creative Sauce Ltd, registered in England and Wales (Company No. 12582512, VAT No. GB365544675) (the "Processor", "we", "us"). It applies whenever we process personal data on the Controller's behalf, for example when building or running integrations, dashboards or AI systems that touch the Controller's own customer or business data.
2.What we process, and why
The specifics of each engagement are set out in the main agreement or statement of work. In summary:
| Subject matter | Processing needed to provide the agreed services (e.g. building and running the systems described in the SOW). |
|---|---|
| Duration | For the term of the engagement, plus any short wind-down period agreed for data export. |
| Nature & purpose | Storing, organising, analysing and displaying data; running automated and AI-assisted tasks the Controller requests. |
| Types of personal data | As defined per engagement, e.g. customer names, contact details, enquiry content, usage and business metrics. No special category data unless expressly agreed in writing. |
| Categories of data subjects | As defined per engagement, e.g. the Controller's customers, enquirers, staff or users. |
3.Our obligations as processor
- We process personal data only on the Controller's documented instructions, including for international transfers, unless the law requires otherwise (in which case we will tell the Controller, unless the law prohibits it).
- We ensure people authorised to process the data are bound by confidentiality.
- We put in place appropriate technical and organisational security measures (see section 5), taking account of the risk (Article 32 UK GDPR).
- We assist the Controller, taking account of the nature of the processing, in responding to data subject rights requests.
- We assist the Controller with security, breach notification, data protection impact assessments and prior consultation, so far as this applies to our processing.
- At the end of the engagement we delete or return the personal data, and delete existing copies, unless the law requires us to keep it.
- We make available the information the Controller reasonably needs to show compliance with Article 28, and allow for and contribute to audits (see section 8).
4.Sub-processors
The Controller gives general authorisation for us to engage sub-processors to help deliver the services. We impose data protection terms on each sub-processor that are no less protective than this agreement, and we remain responsible for their performance. Our current sub-processors typically include:
| Provider | Role |
|---|---|
| Vercel | Website / application hosting and serverless functions |
| Supabase | Database hosting and authentication |
| AI providers (e.g. OpenAI, Anthropic, Google, OpenRouter) | AI model APIs used to run the tasks the Controller requests, via API services on terms intended to keep inputs out of model training |
| Email / scheduling providers | Transactional email and, where relevant, social scheduling |
We keep an up-to-date list and will give the Controller reasonable notice of any intended change (adding or replacing a sub-processor), so the Controller can object on reasonable data protection grounds.
5.Security
- Data in transit is encrypted using TLS.
- Access is restricted to authorised personnel and, where applicable, isolated per project.
- Credentials and secrets are stored securely, with access controls.
- We follow the principle of least privilege and review access periodically.
6.International transfers
Where a sub-processor processes personal data outside the UK, we rely on an appropriate transfer mechanism, such as UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
7.Personal data breaches
If we become aware of a personal data breach affecting the Controller's data, we will notify the Controller without undue delay and provide the information reasonably available to help them meet their own obligations.
8.Audit and information
On reasonable written request, and no more than once a year unless a regulator requires otherwise or following a breach, we will provide the information reasonably needed to demonstrate compliance with this agreement, and allow reasonable audits during business hours, subject to confidentiality.
9.Return or deletion
At the end of the engagement, at the Controller's choice, we will return or delete the personal data and delete existing copies, unless the law requires us to retain it. Aggregated or anonymised data that is no longer personal data may be retained.
10.General
This DPA forms part of, and is governed by the same terms as, our main agreement with the Controller, including its provisions on liability and on governing law (the laws of England and Wales). If there is a conflict on data protection matters, this DPA prevails.