S4W — DATA PROCESSING ADDENDUM
Version 1.0 · Effective from 3 September 2026. Superseded versions are available on request from hello@s4w.com.
S4W — DATA PROCESSING ADDENDUM
Version 1.0 Published at: https://s4w.com/dpa
Parties
This DPA is entered into between:
(1) S4W L.L.C-FZ, a company registered in the United Arab Emirates with licence number 2529741, whose registered address is Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. (S4W); and
(2) the Client that enters into an Agreement with S4W (the Client),
each a party and together the parties.
Data protection contact for S4W: hello@s4w.com (marked for the attention of the Data Protection Contact), or by post to the registered address above.
Data protection contact for the Client: the contact nominated by the Client under clause 4.1(b) of the Agreement, or such other contact as the Client notifies to S4W in writing.
UK Article 27 representative: S4W has appointed Dial Square Consultancy Ltd, 131 Finsbury Pavement, London, England, EC2A 1NT, as its representative in the United Kingdom for the purposes of Article 27 of the UK GDPR. The representative may be contacted at hello@s4w.com.
Payment collection agent. Dial Square Consultancy Ltd, a company registered in England and Wales with company number 17317079, whose registered address is 131 Finsbury Pavement, London, England, EC2A 1NT, acts as S4W's payment collection agent in respect of Fees, as the Payment Agent under clause 1.5 of the Agreement. Dial Square Consultancy Ltd is not a party to this DPA, does not contract with the Client, and does not resell the Services. Personal Data Processed in connection with the collection of Fees falls within clause 2.4 (S4W as independent Controller) and is described in the Privacy Notice at https://s4w.com/privacy.
Status of this DPA
This DPA forms part of the Agreement and is incorporated into it. It takes effect on the Commencement Date. No signature is required: this DPA forms part of every Agreement by operation of the definition of "Agreement" in clause 2.1 of the Agreement, and applies from the Commencement Date for so long as S4W Processes Personal Data on the Client's behalf. Where more than one Agreement is in force between the parties, this DPA applies to each of them separately.
1. Definitions
1.1 Capitalised terms not otherwise defined in this DPA have the meaning given to them in the Agreement, and all rules of interpretation set out in the Agreement apply to this DPA, unless the context otherwise requires. References in the Agreement to the Data Protection Laws and references in this DPA to the Data Protection Law are to the same body of law; to the extent the two definitions differ, the definition in this DPA prevails in respect of the Processing of Personal Data.
1.2 In this DPA:
Affiliate: in relation to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with, that party, where "control" means the ownership of more than 50% of the voting share capital or the ability to direct the management of that entity.
Agreement: the agreement formed by a SOW and the S4W General Terms of Business published at https://s4w.com/terms, together with the documents incorporated into them (including this DPA), as described in clause 1.2 and in the definition of "Agreement" in clause 2.1 of those Terms.
Anonymised and Aggregated Data or AAD: data derived from Client Data which has been irreversibly anonymised and aggregated in accordance with clause 2.5.
Appropriate Safeguards: such legally enforceable mechanism(s) for transfers of Personal Data as may be permitted under the Data Protection Law from time to time, including the EU SCC and the UK Addendum (as applicable), or any other mechanisms as set out in Article 46 of the EU GDPR and the UK GDPR (as applicable).
Business Purposes: the Services and the Deliverables to be provided by S4W to the Client as described in the Agreement, and any other purpose specifically identified in Annex A.
Client Data: the Client Materials, together with all Personal Data which a Deliverable reads, creates, updates, generates or moves between systems in the course of the Services, the information collected through any web page S4W operates for the Client, and the record of what a Deliverable did (including the events it processed, the actions it took and the event payloads involved).
Commencement Date: has the meaning given to it in clause 3.3 of the Agreement.
Data Processing Particulars: the particulars set out in Annex A, which describe the Processing of Personal Data carried out in connection with the Agreement.
Data Protection Law: (i) to the extent the UK GDPR applies, the law of the United Kingdom or of a part of the United Kingdom which relates to the protection of Personal Data; (ii) to the extent the EU GDPR applies, the law of the European Union or any member state of the European Union to which S4W or the Client is subject, which relates to the protection of Personal Data; and (iii) any other applicable national, provincial, federal, state and local legislation, and any associated regulations and secondary legislation, as amended or updated from time to time.
Data Subject Rights Requests or DSRR: a request, complaint or other communication from a Data Subject (or their authorised representative) to exercise any of their rights under Data Protection Law in relation to Personal Data processed under this DPA, including rights of access, rectification, erasure, restriction, data portability, objection and rights relating to automated decision-making.
EU GDPR: the General Data Protection Regulation 2016/679.
EU Standard Contractual Clauses or EU SCC: the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of Personal Data to third countries not otherwise recognised as offering an adequate level of protection for Personal Data by the European Commission (as amended and updated from time to time).
Personnel: in relation to a party, its Affiliates, stakeholders, directors, employees, agents, consultants, subcontractors, third-party vendors, or other persons authorised by (i) that party; (ii) its Affiliates; and/or (iii) its subcontractors, in each case engaged in the provision or receipt of the Services. Sub-processors are governed by clause 5.5 in addition to clause 5.1(d).
Privacy Notice: the S4W privacy notice published at https://s4w.com/privacy, as amended from time to time.
Sub-processor: any S4W Affiliate or third-party vendor Processing Personal Data on S4W's behalf in connection with the Agreement, as set out in clause 5.5 and Annex D.
Supervisory Authority: a governmental or government-chartered regulatory body having binding legal authority over a party for matters relating to the Processing of Personal Data.
Third Country: a country or territory that is not part of the United Kingdom or the EEA.
UK Addendum: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) UK DPA 2018, Version B1.0, in force as of 21 March 2022. References in this DPA to the UK Addendum are references to that instrument and not to the ICO's separate standalone International Data Transfer Agreement.
UK DPA 2018: the UK Data Protection Act 2018.
UK GDPR: the EU GDPR as transposed into United Kingdom national law by operation of section 3 of the European Union (Withdrawal) Act 2018, together with the UK DPA 2018.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing: have the meanings given to them in the Data Protection Law.
2. Personal data types and processing purposes
2.1 The parties agree that, in respect of the Services provided pursuant to the Agreement, S4W is the Processor of the Personal Data comprised in or derived from the Client Data, and the Client is the Controller. S4W acts as Processor, on the Client's documented instructions, for: all Personal Data comprised in the Client Materials; all Personal Data which a Deliverable reads, creates, updates, generates or moves between systems in the course of the Services; the information collected through any web page S4W operates for the Client; and the record of what a Deliverable did.
2.2 The Client retains control of the Personal Data and remains responsible for its compliance obligations under the Data Protection Law, including but not limited to providing any required notices and obtaining any required consents from the individuals concerned (including its own customers, prospects and enquirers, the individuals who use a web page S4W operates for it, and the recipients of messages sent in the course of the Services), and for the written processing instructions it gives to S4W, as applicable. S4W shall immediately notify the Client if, in S4W's reasonable opinion, the Client's instructions in respect of any Processing of Personal Data by S4W are unlawful.
2.3 The Data Processing Particulars in Annex A describe the subject matter, duration, nature and purpose of the Processing, and the Personal Data categories and Data Subject types in respect of which S4W may Process the Personal Data to fulfil the Business Purposes. The Data Processing Particulars take effect on the Commencement Date.
2.4 S4W acts as an independent Controller for: Client contact and relationship data, billing and payment data (including Fees invoiced and collected by the Payment Agent), support communications, website analytics and service administration data, and marketing data. S4W also acts as an independent Controller where it reviews records for the purpose of investigating suspected fraud, abuse or breach of the Agreement by the Client. Processing of that Personal Data is governed by the Privacy Notice and not by this DPA. The Processor-role Processing is described in clause 2.1. Data that has been irreversibly anonymised in accordance with clause 2.5 is not Personal Data and falls outside this allocation of roles.
2.5 The Client instructs S4W to transform Client Data into Anonymised and Aggregated Data. Anonymisation under this clause 2.5 must be irreversible: direct and indirect identifiers must be removed or masked, and the resulting data must be aggregated with data derived from the Services performed for other clients of S4W such that neither any individual, nor the Client, nor any Client Material can be identified from that data, taking account of all means reasonably likely to be used by S4W or any other person. S4W shall not attempt, and shall not permit any Sub-processor to attempt, to re-identify any individual from AAD. Once Client Data has been irreversibly converted into AAD in accordance with this clause 2.5, that AAD is no longer Personal Data and S4W may use it for its own legitimate business purposes, including developing, testing, securing, benchmarking and improving its methods, models, tooling and services in accordance with clause 8 of the Agreement. This clause 2.5 operates as a documented instruction from the Client for the purposes of clause 5.1(a).
2.6 Where the Client nominates or configures an endpoint, integration or third-party system to which a Deliverable transmits data (including webhooks, workflow steps, customer relationship management systems, spreadsheets, advertising platforms and other business applications), those transmissions are made on the Client's instruction. The recipients of those transmissions are not S4W Sub-processors, and the Client is solely responsible (as between the parties) for the lawfulness of those transfers, for any onward transfer safeguards required under the Data Protection Law, and for the acts and omissions of those recipients. S4W does not verify the identity, security or compliance posture of a recipient nominated by the Client. The systems and destinations commonly nominated are listed in Annex D, Part 2.
2.7 Nothing in this DPA relieves S4W of the obligations that apply to it directly as a Processor under the Data Protection Law.
2.8 Where the Client is itself a processor Processing Personal Data on behalf of a third party as controller, and receives the Services in that capacity, the Client enters into this DPA both on its own behalf and as agent for and on behalf of that third party as Controller. The Client warrants that it has that third party's authority to do so, and that its own contract with that third party permits the appointment of S4W to Process that Personal Data on the terms of this DPA. The obligations owed by S4W to the Client under this DPA are owed to that third party mutatis mutandis, and the rights exercisable by the Client under this DPA (including under clauses 5.2, 5.4 and 5.6) are exercisable in respect of that third party's Personal Data by the Client alone. Nothing in this clause 2.8 increases S4W's obligations or liability under this DPA, and S4W is entitled to deal exclusively with the Client in respect of all matters arising under it.
3. Client obligations
3.1 The Client warrants and represents that it has all necessary and appropriate consents and notices, in any form required by the Data Protection Law, and that the Personal Data has been collected or otherwise obtained in compliance with the Data Protection Law, and may be lawfully Processed, disclosed and transferred as described in or in connection with this DPA.
3.2 The Client will ensure and warrants that, where the Client instructs or configures any transfer of Personal Data outside the EEA or the UK, including to a recipient it nominates under clause 2.6, adequate measures will be taken by the Client so that the Personal Data is protected to an adequate level and the Data Subjects' rights under the Data Protection Law will not be prejudiced by such a transfer. This is without prejudice to S4W's obligations in respect of Restricted Transfers of Personal Data carried out by S4W (including via its Sub-processors) in connection with this DPA.
3.3 The Client will ensure and warrants that it utilises appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from its receipt of the Services and its own use and deployment of the Deliverables, including, as appropriate, the measures referred to in the Data Protection Law.
3.4 The Client confirms that it has assessed the security measures in place at the time of this DPA, and that it will continue to do so on an ongoing basis to ensure compliance with its obligations under this DPA. Nothing in this clause 3.4 or clause 3.3 relieves S4W of, or transfers to the Client, S4W's own obligations under clause 5.1(c), Annex B and Article 32 of the UK GDPR (and, where applicable, Article 32 of the EU GDPR).
3.5 The Client undertakes and confirms that any information required to be provided to a Data Subject has been so provided, or that an applicable exemption is available and is being relied upon by the Client.
3.6 The Client will immediately notify S4W if any necessary appropriate consents and notices required to enable lawful transfer of Personal Data to S4W for the duration and purposes of this DPA have been breached, terminated, withdrawn, or are otherwise no longer valid.
3.7 The Services are not designed for, and the Client shall not supply to S4W, or give a Deliverable access to, special category Personal Data (within the meaning of Article 9 UK GDPR) or Personal Data relating to criminal convictions and offences (within the meaning of Article 10 UK GDPR), unless expressly agreed in writing between the parties and recorded in the SOW. S4W does not inspect, validate or control the categories of data comprised in the Client Materials, or held in the systems a Deliverable operates on, and the Client warrants that they do not include special category or criminal offence data save as so agreed. The Client acknowledges that the data it supplies, and the data a Deliverable reads, may be transmitted to the artificial intelligence model providers listed in Annex D and to any recipient the Client nominates under clause 2.6.
3.8 Where an engagement includes a client-facing or consumer-facing web page which S4W operates in the Client's name (for example an online quotation page), the Client is the Controller for the information collected through that page and warrants that it will: (a) obtain any consent required under the Data Protection Law (including the Privacy and Electronic Communications (EC Directive) Regulations 2003) for the storage of, and access to, information on visitors' terminal equipment; and (b) provide visitors with the information required by Articles 13 and 14 UK GDPR at the point of collection, including its own privacy and cookie information.
3.9 Where an engagement provides for messages to be sent, or for conversations to be conducted, by a Deliverable, the Client is responsible for configuring and making any disclosure required as to the automated nature of the message or conversation, for sender identification, for honouring opt-out requests, and for obtaining any consent required for any recording or transcription the SOW provides for. S4W sends messages, conducts conversations and records or transcribes them only where the SOW provides for it and to the configuration the Client approves, and does so on the Client's documented instruction for the purposes of clause 5.1(a).
3.10 The Client shall indemnify S4W against all liabilities, costs, expenses, damages and losses (including reasonable legal fees) suffered or incurred by S4W arising out of or in connection with any third-party claim, or any investigation, enforcement action or penalty imposed by a Supervisory Authority or other regulator, arising from: (a) breach of any warranty given by the Client in this clause 3; (b) the provenance and lawfulness of the Client Materials and of any other contact, lead or record data supplied to S4W or held in the systems a Deliverable operates on; or (c) the Client's failure to give any notice, or obtain any consent, required under the Data Protection Law, including in respect of automated or AI-generated calling and messaging, recording, and direct marketing communications.
4. Data protection: general obligations
4.1 Each party shall comply with all applicable requirements of the Data Protection Law. This DPA is in addition to, and does not relieve, remove or replace, a party's obligations under the Data Protection Law.
4.2 The Client and S4W agree that, to the extent each party processes any Personal Data of the other party's Personnel in connection with entry into the Agreement or the management of their business relationship, that party processes such data as an independent Controller.
5. S4W's obligations
5.1 In addition to the obligations above, to the extent that the UK GDPR and/or the EU GDPR applies, and S4W Processes Personal Data in the course of providing the Services as a Processor, S4W shall:
(a) process that Personal Data only on the written instructions of the Client and as set forth in this DPA and the Agreement, except to the extent S4W is required to process data by applicable law. Where S4W is relying on applicable law as the basis for Processing Personal Data, S4W shall without undue delay notify the Client unless applicable law prohibits S4W from so notifying the Client;
(b) not access or use, or disclose to any third party, any Personal Data, except, in each case, as necessary to perform the Services and to deliver and support the Deliverables, or as necessary to comply with applicable law or a valid and binding order of a governmental body (such as a subpoena or court order);
(c) implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing and accidental loss, destruction, damage, theft or disclosure, having regard to the harm which might result from any unauthorised or unlawful Processing, accidental loss, destruction, damage or theft of the Personal Data and having regard to the nature of the Personal Data which is to be protected. Such measures are further set out in Annex B;
(d) ensure that all Personnel authorised to Process the Personal Data under the Agreement have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and take reasonable steps to ensure that they understand their obligations when handling Personal Data in accordance with this DPA; and
(e) provide reasonable assistance to the Client to meet its obligations to:
(i) respond to DSRR;
(ii) meet its legal obligations in relation to the security of Processing of Personal Data;
(iii) notify Personal Data Breaches to Supervisory Authorities and Data Subjects upon the specific written request of the Client in its role as a Controller or otherwise as required under applicable law; and
(iv) undertake data protection impact assessments and prior consultation with applicable Supervisory Authorities in relation to high-risk Processing, as applicable.
5.2 Assistance with Data Subject Rights Requests
5.2.1 The assistance described in clause 5.1(e)(i) is provided by a documented operational process and not by self-service tooling. S4W does not operate tooling which locates, exports or erases all Personal Data relating to a particular individual across the systems on which the Services run, and the Client should not rely on the deletion of a record in one system as achieving erasure of the copies of it which a Deliverable has written to another.
5.2.2 Where the Client requires assistance with a DSRR, it shall send a written request to hello@s4w.com identifying the individual and the identifiers by which that individual can be located (such as telephone number or email address), and the systems the request covers. S4W shall acknowledge the request within 2 Working Days and shall provide the requested assistance, or a written explanation of why it cannot do so, within 10 Working Days of the request, unless the request is of such volume or complexity that a longer period is reasonably required, in which case S4W shall notify the Client of the expected timescale.
5.2.3 Where S4W receives a DSRR directly from a Data Subject in relation to Personal Data Processed on the Client's behalf, S4W shall not respond to that request other than to acknowledge it and direct the Data Subject to the Client, and shall notify the Client of the request without undue delay.
5.3 Personal Data Breach management and notification
5.3.1 S4W shall notify the Client of a Personal Data Breach affecting Personal Data Processed under this DPA without undue delay after becoming aware of it, and in any event in sufficient time to allow the Client to meet its own obligations under Article 33 UK GDPR (and, where applicable, Article 33 EU GDPR). The notification shall include such information as is then available to S4W as to the source and nature of the breach, the type of data affected and the identity or categories of the affected Data Subjects, and S4W shall supplement that notification in phases as further information becomes known.
5.3.2 S4W is not obligated to report unsuccessful incidents or incidents that result in no unlawful or accidental destruction, loss, alteration, disclosure of, or unauthorised access to Personal Data or any of S4W's equipment or facilities storing Personal Data. Such non-reportable incidents may include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorised access to traffic data that does not result in access beyond headers), or similar incidents, provided in each case that the incident does not result in the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data, including any loss of availability of Personal Data.
5.3.3 S4W's obligation to report or respond to a security incident under this clause 5.3 is not and will not be construed as an acknowledgement by S4W of any fault or liability of S4W with respect to the incident.
5.4 Security programme and audit
5.4.1 S4W maintains an information security programme comprising the technical and organisational measures set out in Annex B, which S4W reviews periodically. S4W does not currently hold ISO 27001 certification, a SOC 2 report or any equivalent third-party attestation, and makes no representation that it does.
5.4.2 S4W shall maintain adequate records of its Processing activities under this DPA and, on the Client's written request (no more than once in any 12-month period, unless required more frequently by the Data Protection Law or following a Personal Data Breach affecting the Client), S4W shall provide the Client with a written description of its technical and organisational measures and shall respond to a reasonable security questionnaire.
5.4.3 Where the Client cannot reasonably satisfy itself as to S4W's compliance with this DPA through the materials provided under clause 5.4.2, or where required by the Data Protection Law, the Client may, on not less than 30 days' written notice, conduct an audit of S4W's applicable controls, either itself or through an appropriately qualified independent third-party representative bound by obligations of confidentiality. The parties shall mutually agree the details of the audit, including its reasonable start date, scope and duration, and the security and confidentiality controls applicable to it. The audit shall be limited to information relevant to the Client and shall not include any data relating to S4W's other clients. Audits shall be conducted during Business Hours, shall not unreasonably interfere with S4W's operations, and shall be at the Client's cost save where the audit reveals a material breach by S4W of this DPA.
5.4.4 Any audit, and any information arising from it or from clause 5.4.2, is S4W's Confidential Information. The Client may disclose it to: (a) any Controller on whose behalf the Client Processes Personal Data received by S4W under this DPA; (b) the Client's professional advisers; and (c) any Supervisory Authority or other regulator, and otherwise where required by law, in each case (other than where required by law) under equivalent obligations of confidentiality and on a need-to-know basis. Any other disclosure to a third party requires S4W's prior written agreement.
5.5 Sub-processors
5.5.1 The Client agrees that S4W may use Sub-processors to fulfil its contractual obligations under this DPA or to perform certain of the Services on its behalf, and consents to the use of Sub-processors as described in this clause 5.5. The Client authorises the Sub-processors listed in Annex D (the Sub-processor List). Annex D constitutes Annex III / Appendix 3 to the Standard Contractual Clauses, if and as applicable.
5.5.2 At least 30 calendar days prior to the date on which any new Sub-processor commences Processing Personal Data in relation to this DPA, S4W shall update Annex D and shall notify the Client of that update. That notice is given to the contact nominated by the Client under clause 4.1(b) of the Agreement, or to the address stated for that purpose in the SOW, and is served in accordance with clause 16 of the Agreement. It is the Client's responsibility to keep that contact's details accurate and current.
5.5.3 If the Client objects to a new Sub-processor, the Client must notify S4W in writing within 15 days of S4W's notice of the change, setting out the reasons for its objection (without prejudice to any termination rights the Client has under the Agreement). In the absence of such a notice, the Client is deemed to have consented to the new Sub-processor's appointment.
5.5.4 Where the Client raises a reasonable, documented objection under clause 5.5.3, the parties shall discuss it in good faith for a period of 30 days. Within that period S4W may: (a) propose an alternative Sub-processor; or (b) refrain from using the objected-to Sub-processor in connection with the Client's Personal Data; or (c) propose a change to the affected part of the Services or of a Deliverable that resolves the objection. If the objection is not resolved within that period, the Client may terminate the affected SOW, or the affected part of it, on written notice, and where no SOW is in place may terminate the affected part of the Services on written notice, and S4W shall in either case refund a pro-rata portion of any Fees prepaid by the Client in respect of the terminated Services for the period after termination.
5.5.5 S4W shall not appoint any Sub-processor to Process the Personal Data on its behalf unless it enters into a written contract with the Sub-processor that contains terms substantially the same as those set out in this DPA, in particular in relation to requiring appropriate technical and organisational data security measures, and S4W shall remain liable to the Client for that Sub-processor's performance of its obligations.
5.6 Retention, deletion, return and destruction
5.6.1 S4W retains Personal Data Processed on the Client's behalf for the duration of the Agreement. S4W does not currently operate automated retention, expiry or purge processing. Where the Client instructs a shorter retention period for a particular Deliverable, and S4W confirms in writing that it can be applied, that period applies.
5.6.2 For a period of 30 days following expiry or termination of the Agreement (the return window), and in accordance with clause 13.5(d) of the Agreement, S4W shall, where technically practicable and provided no sum is overdue, give the Client read-only access to the project environments and records it holds so that the Client may extract the Client Materials. Within that window the Client may also request return of the Personal Data in a commonly used machine-readable format; return is performed by documented manual process on written request to hello@s4w.com.
5.6.3 At the choice of the Client, S4W shall delete the Personal Data Processed on behalf of the Client. Deletion is performed by documented manual process and shall be completed within 60 days of the Client's written request to hello@s4w.com and of S4W confirming the identity and authority of the person making it. Where the Client makes no request, S4W shall delete the Personal Data Processed on the Client's behalf 60 days after expiry or termination of the Agreement, in accordance with clause 13.5(e) of the Agreement. This clause 5.6.3 does not apply to the extent S4W is required to retain the Personal Data to comply with applicable law.
5.6.4 S4W may retain Personal Data in backup systems for a limited period, provided that such Personal Data is protected in accordance with this DPA and is not actively Processed. Personal Data may persist in encrypted backups for up to 7 days after its deletion from the live system, after which those backups are overwritten in the ordinary course. Backups are not used for any Processing purpose.
5.6.5 S4W's deletion obligations under this clause 5.6 extend to Personal Data held by S4W and, on the Client's written request, S4W shall use reasonable endeavours to procure the deletion of Personal Data held by the Sub-processors listed in Annex D in accordance with those Sub-processors' own retention practices. S4W does not control, and does not warrant, the retention periods applied by those Sub-processors or by any recipient nominated by the Client under clause 2.6. Deleting a record in one system does not by itself delete the copies of it which a Deliverable has written to another; a request under this clause 5.6 should identify the systems it covers. Credentials held under clause 8.3 are revoked and deleted in accordance with that clause.
5.7 Personnel and internal access
5.7.1 A limited group of authorised S4W Personnel may access the environments on which the Services run, the systems S4W operates for the Client, and the Personal Data Processed on the Client's behalf, where necessary to perform, support, administer and secure the Services, or where required by applicable law.
5.7.2 S4W does not currently maintain record-level access logging of reads of Personal Data by its Personnel, and makes no representation that it does. Access to production environments is limited to Personnel who need it for their role and is granted through named accounts.
5.7.3 All S4W Personnel with access to Personal Data are bound by contractual or statutory obligations of confidentiality that survive the end of their engagement.
6. Restricted transfers
6.1 Where any Processing of the Personal Data would involve a transfer of Personal Data to a recipient located in a Third Country, and would otherwise be in breach of the Data Protection Law (a Restricted Transfer), S4W shall only undertake such Processing if:
6.1.1 the transfer is to a country approved under the applicable Data Protection Law as providing adequate protection; or
6.1.2 there are Appropriate Safeguards in place pursuant to the applicable Data Protection Law, being the EU Standard Contractual Clauses and, where the UK GDPR applies, the UK Addendum (incorporating the EU Standard Contractual Clauses as base clauses), in each case as set out in Annex C; or
6.1.3 one of the derogations for specific situations in the applicable Data Protection Law applies to the transfer.
6.2 Where the Processing of Personal Data would involve a Restricted Transfer to a party to this DPA, the parties shall ensure that the Appropriate Safeguards are in place pursuant to the applicable Data Protection Law, as set out in Annex C to this DPA, the terms of which are incorporated into this DPA.
6.3 Pursuant to clauses 6.1 and 6.2 above: where the UK GDPR applies, and the transfer of Personal Data is from the United Kingdom, either directly or via onward transfer, to any country or recipient outside of the UK not based on adequacy regulations pursuant to section 17A of the UK DPA 2018, Annex C shall apply; and where the EU GDPR applies, and the transfer is from the EEA, either directly or via onward transfer, to a Third Country which is not the subject of an adequacy decision of the European Commission, Annex C shall likewise apply.
6.4 Any election of governing law or forum made in Annex C, or arising under the Mandatory Clauses of the UK Addendum, applies solely to the transfer mechanism to which it relates. It does not vary, displace or otherwise affect the governing law and jurisdiction of the Agreement or of this DPA, which remain the law of England and Wales and the exclusive jurisdiction of the English courts.
6.5 The primary data store in which S4W holds the Personal Data Processed on the Client's behalf is located in the European Economic Area, as set out in Annex B. S4W is itself established in the United Arab Emirates, and the Client acknowledges that access to Personal Data by S4W Personnel located in the United Arab Emirates constitutes a Restricted Transfer and is made subject to the safeguards set out in Annex C. The Client further acknowledges that Personal Data is transmitted to the Sub-processors listed in Annex D, a number of which are established in, and Process Personal Data in, Third Countries. The location of each Sub-processor is set out in Annex D. Transfers made to recipients nominated by the Client under clause 2.6 are the Client's responsibility.
7. Liability
7.1 Liability for breach of this DPA shall be subject to the relevant clauses of the Agreement. For the avoidance of doubt, the limitations and exclusions of liability in clause 11 of the Agreement, and the cap on liability in clause 11.5 of the Agreement, apply to all liability arising under or in connection with this DPA and to all claims in respect of the Processing of Personal Data, save to the extent that liability may not lawfully be limited. Clause 11.6 of the Agreement provides that no separate or higher sub-cap applies to liability arising under this DPA.
7.2 Each party shall indemnify the other against the losses, liabilities, damages, costs and expenses payable to or claimed by a third party (including the reasonable costs of responding to an investigation by a Supervisory Authority) suffered or incurred by that other party as a result of the indemnifying party's breach of the Agreement or of this DPA. That indemnity does not extend to the amount of any fine or penalty imposed on the indemnified party itself by a Supervisory Authority; recovery of such a fine or penalty is governed by clause 11.10 of the Agreement. This clause 7.2 applies equally to both parties and is subject to clause 7.1.
8. Delivery of the Services
8.1 S4W acts as Processor on the Client's instructions in respect of all Personal Data relating to the Client's own customers, prospects, leads, enquirers and other individuals that S4W Processes in the course of the Services. The Client is the Controller of that Personal Data.
8.2 The Services may involve: receiving Personal Data from sources nominated by the Client (including web forms, advertising lead platforms, file transfers, spreadsheets, inbound email and inbound messages, and the Client's existing systems); enriching, transforming, extracting, classifying, scoring and routing that Personal Data; generating documents, quotations, messages and replies from it; creating, updating, reading and deleting records in the Client's own business systems; sending messages and, where the SOW provides for it, conducting conversations with individuals; operating a client-facing or consumer-facing web page in the Client's name; generating reports and notifications to destinations the Client nominates; and, where the SOW provides for a consumer-facing payment or deposit flow, creating and operating payment sessions through which the Client's own customers pay the Client. The systems written to and read from, and the destinations to which reports and notifications are sent, typically include those identified in Annex D, Part 2, together with any further system or destination the Client nominates in writing.
8.3 In order to perform the Services, S4W holds credentials (including application programming interface keys, OAuth tokens and service-account credentials) issued by or on behalf of the Client for the Client's own systems and for third-party systems the Client uses. S4W shall: (a) use those credentials only to perform the Services; (b) store them encrypted in accordance with Annex B; (c) hold only the credentials and permissions a Deliverable needs in order to do what the Client has instructed; (d) restrict access to them to authorised Personnel; and (e) on the Client's written request, or on expiry or termination of the Agreement, revoke and delete them in accordance with clause 5.6.
8.4 Personal Data Processed in the course of the Services is stored in a data environment dedicated to S4W's automation work and separate from the environments used for S4W's other services, as described in Annex B. Access within that environment is scoped to the Client the data belongs to.
8.5 Where S4W operates a message flow, campaign, chase sequence or similar function on the Client's behalf, it does so on the Client's documented instructions and to the configuration the Client approves. The Client remains responsible for the matters set out in clause 3, including the lawfulness of the contact data used, the making of required disclosures, and compliance with the rules applicable to direct marketing and to automated calling and messaging.
9. Duration, changes and versioning
9.1 This DPA takes effect on the Commencement Date and continues for so long as S4W Processes Personal Data on behalf of the Client, and thereafter in respect of clauses 3.10, 5.2, 5.4.4, 5.6, 5.7.3, 6, 7, 9 and 10, which survive expiry or termination, for so long as S4W holds any Personal Data Processed on the Client's behalf.
9.2 This DPA is versioned. S4W assigns a version number and an effective date to each version of this DPA, publishes the current version at https://s4w.com/dpa, and states the version number at the head of this document. S4W may amend this DPA, and shall give the Client not less than 30 days' notice of any amendment that materially reduces the protections afforded to Personal Data, served in accordance with clause 10.1. Amendments to this DPA are governed by this clause 9 and not by clause 14 of the Agreement. Superseded versions are archived and available on request from hello@s4w.com.
9.3 If a change to this DPA is required in order to comply with a change in the Data Protection Law, or with a decision of a Supervisory Authority or court, S4W may make that change on such shorter notice as is required to achieve compliance.
9.4 In the event of a conflict between this DPA and the remainder of the Agreement in relation to the Processing of Personal Data, this DPA prevails, in accordance with clause 1.3 and clause 18.1 of the Agreement. In respect of every other matter this DPA ranks below the Agreement.
10. Notices
10.1 Notices under this DPA shall be given: to S4W, by email to hello@s4w.com marked for the attention of the Data Protection Contact, or by post to the registered address in the Parties section above; and to the Client, to the address or email address stated in the SOW or, where none is stated, to the contact nominated by the Client under clause 4.1(b) of the Agreement. Clause 16 of the Agreement governs the form of a notice and the time at which it is deemed served.
ANNEX A — DATA PROCESSING PARTICULARS
This Annex A describes the Processing that S4W performs on behalf of the Client in order to provide the Services and the Deliverables, as required by Article 28(3) UK GDPR and equivalent provisions in other Data Protection Law. In accordance with clause 2.1, S4W Processes Personal Data as follows. This Annex A constitutes Annex I.B of the EU Standard Contractual Clauses.
A.1 Subject matter of the Processing
The performance of the Services and the delivery, deployment, operation and support of the Deliverables, in each case as described in the SOW and in the Agreement.
A.2 Duration of the Processing
From the Commencement Date and for the duration of the Term, followed by the retention and deletion periods set out in clause 5.6.
A.3 Nature and purpose of the Processing
S4W Processes Personal Data in order to perform the Business Purposes. The Services comprise:
(a) Discovery, build and test — receiving, reviewing and working with the Client Materials in order to design, build, configure, test and deploy a Deliverable, including in development and staging environments;
(b) Receiving records — receiving records from the sources the Client nominates, including web forms, advertising lead platforms, file transfers, spreadsheets, inbound email, inbound messages and the Client's existing systems;
(c) Enrichment, extraction and classification — extracting, summarising, transforming, enriching, classifying, scoring and routing the records a Deliverable processes, including by transmitting their content to the artificial intelligence model providers listed in Annex D;
(d) Generation — generating documents, quotations, messages, replies, reports and notifications from those records, including by transmitting their content to those providers;
(e) Integration — creating, updating, reading and deleting records in the systems the Client nominates, and holding and using the credentials needed to do so;
(f) Messaging and conversations — sending and receiving messages on the Client's behalf and, where the SOW provides for it, conducting voice or chat conversations with individuals, together with any recording, transcription and analysis the SOW provides for;
(g) Client-facing and consumer-facing pages — operating a web page in the Client's name as part of an engagement (for example an online quotation page), and storing the information submitted through it, including records of acceptance;
(h) Payments collected for the Client — where the SOW provides for a consumer-facing payment or deposit flow, creating and operating payment sessions through which the Client's own customers pay the Client into a payment account held in the Client's name, and recording the resulting transaction and payment-status data;
(i) Notification and reporting — sending alerts, notifications and reports to the destinations the Client nominates, and producing measures of what a Deliverable did;
(j) Service administration and security — administering, supporting, monitoring and securing the environments on which the Services run and the systems S4W operates for the Client.
A.4 Processing activities
Collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, in each case in order to provide the Business Purposes.
A.5 Categories of Personal Data
Depending on the Services described in the SOW, the Personal Data Processed by S4W (and its Sub-processors) on behalf of the Client may include:
Client Materials and configuration data
(a) the data, records, documents, content, exports and free-text fields the Client supplies to S4W, or gives S4W access to, for the purposes of the Services, to the extent they contain Personal Data. S4W neither controls nor inspects what the Client chooses to supply, and the Client's own free-text fields may contain anything its people have written there;
(b) configuration supplied by the Client for a Deliverable, including routing rules, prompts, templates, sample data and reference material, to the extent it contains Personal Data;
(c) credentials and access identifiers issued by or on behalf of the Client for its own systems and for the third-party systems it nominates, including the identity of the individual to whom a credential is issued;
The Client's own customers, prospects, leads and enquirers
(d) identity and contact data, such as name, postal address and postcode, email address and telephone number;
(e) enquiry, quotation, order, appointment and transaction data relating to those individuals, including property, product and financial details;
(f) the content of messages and conversations exchanged with those individuals and, where the SOW provides for voice or chat conversations, the audio, the transcript made from it and the conversation metadata;
(g) records of enquiries and their outcomes, including the summaries, extracted fields, classifications and scores generated from them by an artificial intelligence model, and the follow-up actions taken;
(h) technical data collected through a web page S4W operates for the Client, including IP address and browser user-agent, together with records of acceptance (such as the typed name, the time and the wording the individual agreed to);
(i) where the SOW provides for a consumer-facing payment or deposit flow, the payer's name and email address, the amount paid or requested, payment references and payment-status records. Card and bank details are entered directly with the payment provider identified in Annex D and are not received or stored by S4W;
Records held in the systems a Deliverable operates on
(j) Personal Data which a Deliverable reads, creates, updates, generates or moves between the systems the Client nominates, including records held in the Client's own customer relationship management, field-service, spreadsheet and advertising systems, and any free-text fields within them;
(k) the Client's own personnel data comprised in those systems, such as the names, business contact details and assignment of the individuals to whom records belong;
Execution records
(l) the record of what a Deliverable did — the events it processed, the actions it took, the timestamps and the event payloads involved, which carry the categories described above,
and any other Personal Data comprised in the Client Materials, or which a Deliverable encounters in the systems the Client nominates.
For the avoidance of doubt, and in accordance with clause 2.4, S4W's Processing of Client contact and relationship data, billing and payment data, support communications, website analytics and service administration data (such as IP addresses, device and browser information, sign-in times and configuration actions), and marketing data is carried out by S4W as an independent Controller and is governed by the Privacy Notice rather than by this DPA.
A.6 Special category and criminal offence data
S4W does not require special category Personal Data or criminal offence data in order to provide the Business Purposes, and the Client is not required to provide it in order to receive the Services.
The Client shall not supply special category or criminal offence data to S4W, or give a Deliverable access to it, whether through the Client Materials, a file transfer, an application programming interface, an ingest endpoint or the systems a Deliverable operates on, unless expressly agreed in writing between the parties and recorded in the SOW (see clause 3.7).
The parties nevertheless record, for the purposes of Article 28(3) UK GDPR and Annex I.B of the EU Standard Contractual Clauses, that Personal Data within the special categories in Article 9 UK GDPR, and Personal Data relating to criminal convictions and offences within the meaning of Article 10 UK GDPR, may be captured incidentally — in a free-text field within the Client Materials, in the content of a message or conversation where an individual volunteers it, in a summary or classification derived from it, or in a free-text field held in a system a Deliverable reads — and may therefore be Processed within the categories described at paragraphs A.5(a), (f), (g) and (j). The technical and organisational measures set out in Annex B apply to that data as they apply to all other Personal Data Processed under this DPA. Before deploying a Deliverable in a use case in which such data is likely to be disclosed, the Client shall carry out any data protection impact assessment required of it and shall identify the condition under Article 9(2) or Article 10 UK GDPR on which it relies.
S4W does not inspect, validate, monitor or control the categories of data comprised in the Client Materials or held in the systems a Deliverable operates on. Where the Client commissions and deploys a Deliverable in a context in which special category or criminal offence data is nonetheless supplied, encountered or generated incidentally, the Client remains solely responsible for determining whether and how that data is Processed, including selecting an appropriate legal basis, carrying out any required data protection impact assessment and providing all necessary notices to Data Subjects. S4W accepts no responsibility for any such data, beyond performing the Processing activities set out in this DPA in accordance with the Client's documented instructions.
A.7 Categories of Data Subject
Personal Data Processed under this DPA relates to the following categories of Data Subject:
(a) the Client's own customers, prospects, leads and enquirers, including individuals whose details are supplied to S4W or ingested by a Deliverable whether or not they are ultimately contacted;
(b) individuals who use a web page S4W operates for the Client, for example an online quotation page;
(c) recipients and senders of messages sent or received in the course of the Services, and individuals who take part in a conversation conducted by a Deliverable;
(d) the Client's own personnel and Representatives, including those whose Personal Data is comprised in the Client Materials, those to whom credentials are issued, and those whose records are held in the systems a Deliverable operates on;
(e) the Client's own suppliers, contractors and their personnel, where their details are held in the systems a Deliverable operates on; and
(f) any other individuals whose Personal Data is comprised in the Client Materials or which a Deliverable encounters in the course of the Services.
A.8 Frequency of the transfer
Continuous, as necessary to provide the Business Purposes.
A.9 Retention
As set out in clause 5.6: Personal Data is retained for the duration of the Agreement; the Client may extract the Client Materials, and request return of the Personal Data, within 30 days of expiry or termination; it is deleted within 60 days of the Client's written deletion request and, where no such request is made, 60 days after expiry or termination of the Agreement, save where retention is required by applicable law and save for backup copies dealt with under clause 5.6.4. Where the Client instructs a shorter retention period for a particular Deliverable, and S4W confirms it can be applied, that period applies. Retention periods applied by Sub-processors are determined by those Sub-processors and are not controlled by S4W.
A.10 Competent Supervisory Authority
The Information Commissioner's Office (ICO), United Kingdom. Where the EU GDPR applies to a Restricted Transfer, the competent supervisory authority for the purposes of Annex I.C of the EU Standard Contractual Clauses is determined in accordance with paragraph C.3(c) of Annex C.
ANNEX B — TECHNICAL AND ORGANISATIONAL MEASURES
This Annex B describes the technical and organisational measures implemented by S4W under clause 5.1(c). It constitutes Annex II of the EU Standard Contractual Clauses. The measures described are those in place as at the effective date of this DPA. S4W's information security programme comprises the measures set out in this Annex B, which S4W reviews periodically; S4W does not hold ISO 27001 certification or any equivalent third-party attestation.
B.1 Hosting and data residency
- The primary data store for the Services — including the Client Materials held by S4W, the records a Deliverable processes and the record of what it did — is a managed PostgreSQL database and object storage service hosted in Amazon Web Services' eu-west-1 region (Dublin, Ireland).
- That environment is dedicated to S4W's automation work and is separate from the environments used for S4W's other services. Data within it is scoped to the client it belongs to.
- Documents and files a Deliverable receives or generates are held in a private object storage bucket controlled by S4W within that same environment.
- Application services — the application programming interface, the worker and workflow runtime, and any web page S4W operates for the Client — are hosted with the providers identified in Annex D.
- The content a Deliverable processes is transmitted to the artificial intelligence, messaging and workflow orchestration providers identified in Annex D, some of which are established outside the UK and the EEA. Those transfers are made subject to Annex C.
B.2 Access control and separation
- Inbound requests to S4W's application programming interface are authenticated by an API key carried in a request header and compared using a timing-safe comparison. Per-client inbound keys are issued in addition to the shared key where an engagement requires them.
- Callbacks and webhooks from third-party platforms are authenticated by verifying the signature the platform sends where it supports one, and otherwise by a shared secret held for that endpoint.
- A web page S4W operates which exposes a record to a named individual (for example an online quotation page) is reached through a signed, time-limited link rather than a general-purpose login.
- Data in the primary data store is scoped to the client it belongs to in application code within the service and repository layers.
- Browser access to the web applications S4W operates is restricted by an explicit origin allowlist.
- S4W does not operate an end-user login for the Services and does not store user passwords.
B.3 Encryption and secret protection
- Personal Data is encrypted in transit using TLS.
- Personal Data at rest is encrypted using the encryption-at-rest facilities of the underlying hosting and storage providers.
- Credentials held under clause 8.3 for the Client's own systems and for the third-party systems the Client nominates are held in a credential store and are encrypted using AES-256-GCM with a random 12-byte initialisation vector and a 16-byte authentication tag, bound to the client the credential belongs to, before storage.
- API keys used to authenticate inbound requests are held as secrets in the runtime environment and are not stored in the application database.
- Payment card and bank details are entered directly into the payment provider's hosted checkout and are not received or stored by S4W. S4W retains only the transaction record — the amount, the status, the time, the payer's name and email address, and the provider's reference.
- Secrets are injected at runtime through environment variables and secret managers in runtime and continuous-integration environments, and are not hard-coded in application source.
B.4 Secure application and interface controls
- Input validation is enforced using typed schema validation (Zod) for environment configuration and request payloads.
- Error responses returned to clients are sanitised: stack traces, internal identifiers and third-party provider names are not exposed, and that behaviour is asserted by automated tests.
- Logging is designed so that the content of the records a Deliverable processes is not written to the logs. Where a model's output fails schema validation, only the schema paths that failed are logged, and not the generated content.
- Error handling is centralised so that security responses are consistent across the application.
- S4W does not verify the identity, security or compliance posture of a recipient the Client nominates under clause 2.6.
B.5 Personnel and internal access
- A limited group of authorised S4W Personnel may access the environments on which the Services run, the systems S4W operates for the Client, and the Personal Data Processed within them, where necessary to perform, support, administer and secure the Services.
- Access to production environments is limited to Personnel who need it for their role and is granted through named accounts. Direct reads of individual records by authorised Personnel are not individually logged.
- All Personnel with access to Personal Data are bound by contractual or statutory obligations of confidentiality that survive the end of their engagement.
B.6 Traceability
- Structured application logging with request identifiers is used for traceability and incident investigation.
B.7 Operational and organisational controls
- Development and production environments are separated, with environment-scoped secrets.
- Application builds fail closed on compilation and type errors, and a continuous-integration pipeline running lint, type checks and an automated test suite is in place for the codebase on which the Services run.
- Database schema changes are version-controlled through migrations and deployment workflows.
- Backups of the primary data store are taken by the managed hosting provider in accordance with that provider's standard backup regime.
- Deletion, return of data and assistance with Data Subject Rights Requests are performed by documented operational process as described in clauses 5.2 and 5.6.
B.8 Measures not currently implemented
For the avoidance of doubt, and so that the Client can conduct its own assessment under clause 3.4, S4W confirms that as at the effective date of this DPA it does not operate:
- any third-party security certification or attestation programme (including ISO 27001 certification and SOC 2 reporting);
- a penetration testing or vulnerability scanning programme;
- multi-factor authentication;
- record-level access logging of reads of Personal Data, security anomaly detection or automated security alerting;
- automated retention, expiry or purge processing of Personal Data;
- self-service tooling for the location, export or erasure of an individual Data Subject's Personal Data across the systems on which the Services run;
- verification of, or technical controls over, a recipient the Client nominates under clause 2.6.
Where the Client's own risk assessment requires any of these measures, it should raise that with S4W before supplying Personal Data to S4W or commissioning a Deliverable which will Process it.
ANNEX C — TRANSFERS OF PERSONAL DATA
This Annex C sets out the Appropriate Safeguards which apply to a Restricted Transfer under clause 6.
Where the UK GDPR applies to the Restricted Transfer, the parties agree that the EU Standard Contractual Clauses (incorporating the selections set out in paragraph C.1 below) are incorporated into the Agreement by reference and are deemed amended by the provisions of Part 2 (Mandatory Clauses) of the UK Addendum. For that purpose the EU Standard Contractual Clauses are incorporated only as the base clauses that the UK Addendum amends, and do not apply as a standalone transfer mechanism.
Where the EU GDPR applies to the Restricted Transfer, the EU Standard Contractual Clauses apply as a standalone transfer mechanism and are incorporated into the Agreement by reference with the selections set out in paragraph C.1 below, as modified by paragraph C.3.
Where both the UK GDPR and the EU GDPR apply, both mechanisms apply, each to the transfer it governs.
C.1 Selections in the incorporated Standard Contractual Clauses
(i) Module Two (Controller to Processor) applies, where the Client is a Controller of Personal Data and data exporter and S4W is its Processor and data importer. Where the Client is itself a processor within clause 2.8, Module Three (Processor to Processor) applies in place of Module Two. No other Module applies.
(ii) In Clause 7, the optional docking clause does not apply.
(iii) In Clause 9, Option 2 (general written authorisation) applies, and the time period for giving notice of Sub-processor changes shall be as set out in clause 5.5.2 of this DPA.
(iv) In Clause 11, the optional independent dispute resolution language does not apply.
(v) In Clause 17 and Clause 18, and as required by the Mandatory Clauses of the UK Addendum, the Standard Contractual Clauses as incorporated and amended by the UK Addendum are governed by the laws of England and Wales, and any dispute arising from them shall be resolved by the courts of England and Wales. That election applies solely to the transfer mechanism described in this paragraph C.1 as amended by the UK Addendum, and does not vary or displace the governing law and jurisdiction of the Agreement, which are the same (see clause 6.4 of this DPA).
(vi) Annex I.A (List of Parties) is completed with the information set out in the Parties section of this DPA.
(vii) Annex I.B (Description of Transfer) is completed with the information set out in Annex A of this DPA. The frequency of the transfer is continuous, as necessary to perform the Services, and retention is as set out in clause 5.6 and paragraph A.9 of Annex A.
(viii) Annex I.C (Competent Supervisory Authority) is completed as set out in paragraph A.10 of Annex A.
(ix) Annex II (Technical and Organisational Measures) is completed with the information set out in Annex B of this DPA.
(x) Annex III (List of Sub-processors) is completed with the information set out in Annex D of this DPA.
C.2 Information required for Part 1 (Tables) of the UK Addendum
(a) Table 1 (Parties): the exporter is the Client and the importer is S4W. The parties' full legal names, registered addresses, roles and data protection contacts are as set out in the Parties section of this DPA and, in the case of the Client, as recorded in the SOW. The start date is the Commencement Date.
(b) Table 2 (Selected SCCs, Modules and Selected Clauses): the EU Standard Contractual Clauses as set out in paragraph C.1 above, Module Two (Controller to Processor) or, where paragraph C.1(i) so provides, Module Three (Processor to Processor), with the clause selections at paragraph C.1 items (ii) to (v).
(c) Table 3 (Appendix Information): Annex I.A of the EU Standard Contractual Clauses (as incorporated and amended by the UK Addendum) is completed with the Parties section of this DPA; Annex I.B is completed with Annex A of this DPA; Annex I.C is completed with paragraph A.10 of Annex A (the competent supervisory authority being the Information Commissioner's Office); Annex II is completed with Annex B of this DPA; and Annex III is completed with Annex D of this DPA.
(d) Table 4 (Ending this Addendum when the Approved Addendum changes): Importer and Exporter. Either party may accordingly end the UK Addendum in accordance with Section 19 of its Mandatory Clauses.
(e) The parties agree that the governing law and choice of forum and jurisdiction for the Agreement, this DPA and the transfer mechanism described in paragraph C.1 as amended by the UK Addendum are those of England and Wales.
C.3 The standalone EU Standard Contractual Clauses
Where the EU Standard Contractual Clauses apply as a standalone transfer mechanism under this Annex C, paragraph C.1 applies to them, save that:
(a) in Clause 17, Option 1 applies and the Standard Contractual Clauses are governed by the law of Ireland;
(b) in Clause 18(b), the parties elect the courts of Ireland; and
(c) the competent supervisory authority for the purposes of Annex I.C is the supervisory authority of the EEA member state in which the data exporter is established or, where the data exporter is not established in the EEA, the supervisory authority of the member state in which its representative under Article 27 of the EU GDPR is established.
The elections in this paragraph C.3 apply solely to the standalone EU Standard Contractual Clauses. They do not apply to the transfer mechanism described in paragraph C.1 as amended by the UK Addendum, and they do not vary, displace or otherwise affect the governing law and jurisdiction of the Agreement or of this DPA, which remain the law of England and Wales and the exclusive jurisdiction of the English courts (see clause 6.4 of this DPA).
ANNEX D — SUB-PROCESSORS
This Annex D is the Sub-processor List referred to in clause 5.5.1 and constitutes Annex III / Appendix 3 to the Standard Contractual Clauses. The Client authorises the Sub-processors listed below. This Annex D is current as at the effective date of the version of this DPA in which it appears.
The "Location" column states the region in which Personal Data is stored or primarily processed by the Sub-processor concerned. A number of the Sub-processors listed are incorporated in a country other than that region, and their authorised personnel may access Personal Data from a country other than that region.
S4W will give the Client not less than 30 days' notice, served in accordance with clause 5.5.2, before a new Sub-processor commences Processing Personal Data in connection with the Agreement. The Client may object in accordance with clause 5.5.3, and the consequences of an unresolved objection are set out in clause 5.5.4.
Where an engagement requires a Sub-processor which is not listed in Part 1 — for example a voice orchestration, speech-to-text or text-to-speech provider engaged for an engagement which includes voice conversations — that Sub-processor is appointed under the notice procedure in clause 5.5.2 and is recorded in Part 1 or in the SOW for that engagement.
Providers which S4W engages only for its own Processing as an independent Controller under clause 2.4 — including the providers of its website analytics, its appointment scheduling and its marketing communications — are described in the Privacy Notice and are not Sub-processors of Personal Data Processed on the Client's behalf under this DPA.
Dial Square Consultancy Ltd acts as S4W's payment collection agent and is not a Sub-processor of Personal Data Processed on the Client's behalf under this DPA.
Part 1 — Sub-processors engaged by S4W
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Supabase | Managed PostgreSQL database and object storage for the environment in which the Services run | The Client Materials held by S4W, the records a Deliverable processes (including the Client's own customers' identity, contact, enquiry, quotation, conversation and payment-status data) and the record of what it did | AWS eu-west-1 (Dublin, Ireland) |
| OpenAI | Large language model inference — extraction, summarisation, classification and scoring of the records a Deliverable processes, and generation of documents, quotations, messages and replies | The content of the records, messages and documents a Deliverable processes, together with the prompts and responses exchanged with the model | United States |
| Twilio | Carriage of SMS messages sent and received in the course of the Services | Telephone numbers, message bodies, message metadata and delivery status | United States |
| Inngest | Durable workflow and event orchestration — the runtime on which a Deliverable executes | Event payloads, which carry the records, contact details, message content and document references a Deliverable processes | United States |
| Stripe | Payment processing and billing of the Client's own Fees | Billing contact details, card brand, last four digits and expiry, payment-method references, transaction records | United States and Ireland |
| Stripe (Connect) | Payment facilitation, where a SOW provides for a consumer-facing payment or deposit flow: collection of payments from the Client's own customers into a connected account operated in the Client's name. Card and bank details are captured directly by Stripe and are not received by S4W | Payer name and email address, payment amount, payment references, transaction and payment-status records | United States and Ireland |
| Resend | Transactional email delivery, and receipt of delivery and engagement events for the messages it sends | Recipient name and email address, message content, delivery status | United States |
| Slack | Internal notifications and operational alerting to S4W's own workspace | Notification content, which may contain contact details, enquiry and quotation details and the outcome of an automation run | United States |
| Sentry (Functional Software, Inc.) | Application error monitoring for the systems on which the Services run. The content of the records a Deliverable processes is not intentionally sent to it, although error diagnostics may incidentally include fragments of request data | Error and diagnostic events, which may include an IP address, request headers and an identifier for the request | European Union (Germany) |
| Railway | Hosting of S4W's application programming interface, worker and workflow runtime services | All Personal Data Processed in transit by those services | United States |
| Vercel | Hosting of the web pages S4W operates for the Client (including any client-facing or consumer-facing page) and of S4W's own websites | Request data, IP addresses and application telemetry, and the information submitted through a page S4W operates for the Client | United States (with edge processing in multiple regions) |
| GitHub | Source control for the codebase on which the Services run, and content management for S4W's websites | Source code and website content, which are not intended to contain the Client's Personal Data | United States |
| Trello | Support ticket and engagement task management. S4W is migrating this function to Asana; at the effective date of this DPA this provider still receives support tickets, and this row will be removed once migration completes | Submitter name, email address, company, free-text support message and any attachments or screenshots supplied, which may contain Personal Data | United States |
| Asana | Support ticket and engagement task management, on and from completion of the migration described in the Trello row above | Submitter name, email address, company, free-text support message and any attachments or screenshots supplied, which may contain Personal Data | United States |
Part 2 — Systems nominated by the Client
The following third-party systems are commonly nominated by the Client in the delivery of the Services. The list is illustrative of the categories of system a Client may nominate, and is not exhaustive; the same list appears in the Privacy Notice. Where S4W reads from or writes to an instance of one of these systems that is operated by or on behalf of the Client, or receives data from it on the Client's instruction, that system is a recipient nominated by the Client under clause 2.6 and is not a Sub-processor of S4W. The Client is responsible for its own contractual and transfer arrangements with those providers.
| System | Typical use in the Services |
|---|---|
| Zoho | Customer relationship management — record creation, update and lookup |
| GoHighLevel | Customer relationship management and marketing automation |
| ServiceM8 | Field service job management |
| InsTool | Industry-specific job and quotation management |
| Google Sheets | Data exchange, reporting and reconciliation. S4W reads a spreadsheet held in the Client's own environment using a credential the Client authorises; the spreadsheet and its contents remain with the Client's own provider |
| Meta lead advertising | Source of inbound lead records |
In addition, the Client nominates the destinations to which alerts, notifications and reports are sent, including its own Slack workspace, email addresses and webhook endpoints. The payloads sent to those destinations may contain contact details, enquiry and quotation details and the outcome of an automation run. Those destinations are recipients nominated by the Client under clause 2.6 and are not Sub-processors of S4W.
Where S4W procures one of the above in its own name rather than the Client's, it will be listed in Part 1 and the notice provisions in clause 5.5.2 will apply.