Skip to content

Last Updated: 1 October 2026

Data Processing Agreement (DPA)

1 Application and interpretation

1.1 This Agreement is between DUCTIO LTD, incorporated in England and Wales under company number 17303286, with its registered office as recorded at Companies House (Ductio), and the customer identified in the accepted Order (Customer). It becomes binding when incorporated into an Order accepted by both parties, including recorded electronic acceptance, or when separately signed. It applies to trial and paid Services whenever Ductio acts as a processor or subprocessor.

1.2 Applicable Data Protection Law means the UK GDPR and Data Protection Act 2018, as amended including by the Data (Use and Access) Act 2025 to the extent in force; the EU GDPR where applicable; and other binding data protection and electronic communications laws applicable to the processing. Controller, processor, processing, personal data, special category data, supervisory authority and personal data breach have their statutory meanings.

1.3 Customer Personal Data means personal data processed by Ductio on the Customer's behalf in providing the Services, including uploads, connected content, project inputs, recordings, transcripts, prompts and customer-specific outputs. Services and Order have the meanings in the Customer Terms. Subprocessor means a third party engaged by Ductio to process Customer Personal Data on the Customer's behalf. A Restricted Transfer means a transfer, including relevant remote access, requiring safeguards under applicable international-transfer law.

1.4 The Customer is controller and Ductio processor, except where the Customer itself processes for another controller, in which case Ductio is subprocessor. The Customer must hold authority from that controller to give instructions, approve subprocessors and enter into this Agreement. Ductio will assist the Customer in meeting its obligations to that controller and, where law requires, cooperate with the controller through the Customer.

1.5 Roles follow the actual processing. The same person's information may be held separately in different roles. Customer uploads and customer-specific analysis are not converted into Ductio-controlled intelligence by matching, enrichment, scoring or incorporation into an output. Ductio may process account administration, billing, independently sourced professional intelligence and necessary security information as an independent controller only to the extent it actually determines the purposes and means lawfully, as described in its Privacy Policy. This Agreement does not provide a lawful basis for those activities or permit use of Customer Personal Data for them.

1.6 For conflicts concerning processing on the Customer's behalf, mandatory international-transfer clauses prevail, followed by this Agreement and its schedules. An express Order variation must identify the affected provision and remain lawful; it cannot reduce mandatory protection. For other subject matter the accepted Customer Terms govern precedence: the Product and Usage Schedule governs measurements and allowances, the Data and Intelligence Licence Schedule governs intelligence and report rights, the Acceptable Use Policy governs misuse and enforcement, and incorporated Product Specific Terms govern enabled service operation. Privacy notices and internal governance policies do not vary this Agreement or create processor instructions merely by being listed in Corporate Records. Commercial provisions apply only consistently with these rules.

2 Documented instructions and permitted processing

2.1 Ductio shall process Customer Personal Data only on documented Customer instructions, including for international transfers, unless processing is required by applicable law. The initial instructions comprise the accepted Order, this Agreement, Schedule 1 and authorised service configurations. Further instructions may be recorded through authenticated administrators, support requests or signed amendments. The Customer controls access and instructions issued by its authorised users.

2.2 Instructions authorise only the operations necessary to deliver the enabled Services, secure and maintain the Customer's environment, provide authorised support, and return or delete data. Ductio shall not sell or license Customer Personal Data, build a shared candidate database from it, disclose it to unrelated customers, use it for advertising, or train or fine-tune shared or general-purpose AI models with it. A different use requires a separately agreed lawful arrangement and any notices, permissions and safeguards required by law; a general product-improvement clause is insufficient.

2.3 Ductio shall immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. It may pause the affected processing while seeking a lawful instruction, protecting unaffected processing where practicable. If law requires processing beyond instructions, Ductio shall inform the Customer of the legal requirement before processing unless the law prohibits this on important public-interest grounds. Ductio shall limit such processing to what is required.

2.4 Material changes to purpose, data categories, sensitive data, recipients or processing locations require an updated documented instruction and any necessary risk assessment and safeguards before implementation. Ductio shall not make those changes through a unilateral website update. It may maintain genuinely anonymous service statistics only where their creation is within documented instructions and individuals cannot reasonably be identified; pseudonymised information remains personal data.

2.5 A mixed output can contain both licensed independently sourced intelligence and Customer Personal Data. Matching or enriching private content does not change Ductio's processor role for that content. Record provenance and authorised disclosure scope where needed. A controller-only intelligence supplier must not receive private customer content unless its actual processor role, instructions, authorisation and safeguards have been established. Neither the intelligence licence nor an export allowance authorises repurposing private content.

3 Customer responsibilities

3.1 The Customer shall determine lawful purposes and bases, supply required notices, obtain consent or permissions where required, ensure source and integration rights, and submit only necessary and lawfully collected data. Where special category or criminal-offence data is expressly agreed, the Customer shall establish the additional legal conditions and safeguards. Public availability does not remove these requirements.

3.2 The Customer shall maintain appropriate account security and access permissions, select proportionate retention settings, handle its controller obligations and notify Ductio of corrections, restrictions and deletions requiring action. Ductio remains responsible for its own processor obligations; these duties do not excuse a Ductio breach.

3.3 The Customer shall provide meaningful human review before hiring, rejection, promotion, dismissal, succession or any other decision with legal or similarly significant effects. A competent reviewer must have sufficient evidence, time and authority to question and change a result; automatic confirmation is insufficient. The standard Services must not be the sole basis for such a decision, even where local law might permit automated decision-making. Each party shall meet its own applicable employment, equality, AI and automated-decision obligations. This contractual restriction does not assert that all automated decisions are prohibited by UK or EU law.

3.4 Access is for named Authorised Users within accepted entitlements. Do not share passwords, pool seats, rotate accounts to simulate additional users, impersonate another user or retain access after reassignment. Authorised service accounts and integrations require controlled permissions and an expressly accepted scope; they do not permit credential sharing with a commissioning client.

3.5 Do not scrape, harvest or systematically extract intelligence, reconstruct a database, aggregate repeated small exports into a general profile warehouse, or resell or supply datasets to an unauthorised commercial service. This includes bots, browser automation, manual repetition, OCR and API use whose purpose or effect exceeds accepted assignment and licence rights. An expressly authorised API, scoped ATS/CRM export or separate written licence remains permitted within its scope. Restrictions do not obstruct statutory disclosure, rights assistance or return of the Customer's own data under this Agreement.

3.6 Do not instruct unlawful profiling, discrimination or harmful surveillance, including use of protected characteristics or proxies to exclude people unlawfully. Public professional information does not authorise coercion, targeting for harm or unsupported assertions about character, security clearance or guilt. Fairness analysis requiring sensitive data needs a separately agreed lawful purpose, applicable additional conditions, minimisation and safeguards; ordinary psychometric or career information is not automatically Article 9 data, but inferences revealing special categories require the corresponding legal protection.

3.7 Do not submit malware, malicious scripts or documents, prompt injections intended to defeat access restrictions, or material designed to extract secrets or another tenant's data. Do not manipulate tokens, metering, identities, projects or retries to evade agreed allowances. Good-faith reporting of suspected errors or vulnerabilities through the agreed channel is not, by itself, misconduct; testing requires an authorised scope.

3.8 Legitimate client report sharing remains permitted under the accepted Data and Intelligence Licence Schedule. For an identified commissioning client and assignment, the Customer may securely share proportionate reports, shortlists and permitted extracts with necessary personnel and advisers, including through the Customer's normal paid professional engagement. Use written purpose, confidentiality, privacy, onward-use, retention and correction restrictions; an appropriate engagement contract may supply them. A genuine longlist requires the recorded assignment scope. This does not grant shared platform credentials, unrelated reuse, a profile library, resale of standalone data, or guest, portal or white-label access beyond express entitlements. The Customer instructs authorised disclosure of its private content and is responsible for lawful onward use and recipient arrangements; Ductio remains responsible for its own processing and safeguards.

3.9 Reaching an allowance is not itself abuse. An allowance measures permitted service consumption and does not expand purpose, licensing, sensitive-data permission or retention. No automatic upgrade, top-up, penalty or unrelated processing is authorised by exhaustion. Restrictions on new activity must preserve access to saved results and required data return, subject to necessary security safeguards.

4 Confidentiality and personnel

4.1 Ductio shall ensure that every person authorised to process Customer Personal Data is bound by confidentiality obligations or an appropriate statutory duty, receives relevant privacy and security training, and processes only within assigned duties. Access shall be restricted to what is necessary and reviewed and withdrawn when no longer required.

4.2 Confidentiality survives employment, engagement and termination of the Services. Ductio shall apply equivalent requirements to subprocessors and shall not disclose data except on instructions, to authorised subprocessors, or as law requires subject to sections 2 and 11.

5 Security

5.1 Ductio shall implement and maintain appropriate technical and organisational measures under Article 32 and equivalent applicable requirements, considering the state of the art, implementation costs, processing context and risks to individuals. Schedule 2 sets the contractual minimum measures. Ductio shall assess risks, maintain evidence of implementation and regularly test the effectiveness of its measures.

5.2 Ductio may improve or replace controls provided overall protection is not materially reduced. Any material reduction requires prior written agreement and must remain lawful. Supplier certification alone does not establish that Ductio is certified. No ISO, SOC or other certification is promised unless explicitly stated in an accepted Order and supported by current evidence.

5.3 The Customer remains responsible for its own devices, administrator assignments and chosen integrations. Ductio shall provide appropriate configuration information and is responsible for the security of the Services and its processing chain, including tenant access enforcement.

5.4 Security and misuse checks shall use necessary technical metadata first and access content only where proportionate to a documented risk or authorised support need. Restrict and log such access, maintain confidentiality and apply Schedule 1 retention. Evidence retention requires a defined necessary period and lawful instruction or legal requirement; enforcement does not create unrestricted monitoring, training or controller reuse of private files. Ductio shall explain material monitoring practices and relevant role boundaries in the applicable notices and contract information.

6 Subprocessors

6.1 The Customer gives general written authorisation to the identified subprocessors in the version of Schedule 3 supplied and accepted at contract formation, solely for their listed services. No provider category, placeholder or unverified supplier name constitutes authorisation. Ductio shall provide the completed register before that provider receives Customer Personal Data.

6.2 Ductio shall notify the Customer's designated contact directly in writing at least 30 calendar days before adding or replacing a subprocessor or materially expanding its processing or locations. Notice shall identify the legal entity, service, data, locations, proposed start date, safeguards and means of objection. A website change alone is insufficient. The Customer may object on reasonable data protection grounds within the notice period.

6.3 Ductio shall not send affected Customer Personal Data to an objected-to provider until the objection is resolved. The parties shall seek a reasonable alternative. If none is available, either party may terminate the affected Service before the change, with a pro rata refund of prepaid unused fees for that Service and return or deletion under section 10. Urgency does not dispense with required authorisation; where continuity requires an immediate change, Ductio shall obtain specific written permission or suspend the affected processing.

6.4 Ductio shall conduct proportionate due diligence and enter into a binding written contract imposing substantially the same applicable data protection obligations, including confidentiality, instructions, security, assistance, breach notification, deletion, audit and transfer safeguards. Ductio remains fully liable to the Customer for the subprocessor's performance of those obligations. Ductio shall obtain rights necessary to demonstrate compliance and provide a relevant contract copy on request, with redactions limited to protecting unrelated confidential information.

6.5 A Customer-appointed integration provider is not automatically Ductio's subprocessor. The parties shall identify its actual role and who engages it. Where Ductio engages or instructs it to process on the Customer's behalf, this section applies. Authorising an integration does not authorise unrelated onward transfers or provider model training.

7 Personal data breaches

7.1 Ductio shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and, in any event, within 24 hours of awareness. Notice shall go to the Schedule 5 incident contact through a monitored channel; Ductio shall use an alternative confirmed contact if delivery fails. Notification shall not await a completed investigation or a finding that the incident is reportable by the Customer.

7.2 The initial notice shall include available information about the nature and timing of the breach, affected data and individuals, approximate numbers of records and people, likely consequences, containment and remedial measures, and an incident contact. Ductio shall identify unknown facts and provide phased updates without undue delay, including material changes and a written closure report when available.

7.3 Ductio shall promptly contain, investigate and remediate the breach, preserve relevant evidence and logs, document actions and cooperate with the Customer in assessing risk, meeting notification deadlines and responding to affected individuals and authorities. Ductio shall require subprocessors to report in time for it to meet these obligations.

7.4 The Customer determines controller notifications unless law requires otherwise. Ductio shall not notify individuals or authorities on the Customer's behalf without instruction, except where legally required; where permitted it shall notify the Customer first. Notice is not an admission of liability. Ductio shall bear its own investigation and remediation costs for incidents within its processing chain.

8 Individual rights and regulatory assistance

8.1 Taking account of the nature of processing, Ductio shall assist through appropriate technical and organisational measures with access, rectification, erasure, restriction, portability, objections and applicable automated-decision rights. Assistance shall include locating relevant uploads, prompts, outputs, recordings and records, supplying intelligible exports, executing authorised corrections or restrictions and explaining relevant processing.

8.2 Ductio shall forward a rights request concerning Customer Personal Data without undue delay and normally within two business days of receipt, without responding substantively unless instructed or legally required. It may acknowledge receipt and identify the responsible Customer where appropriate. It shall preserve confidentiality and avoid disclosure of another customer's data. The Customer determines identity verification, exemptions and the substantive response.

8.3 Ductio shall assist the Customer with security obligations, breach assessment and notifications, data protection impact assessments and prior consultation with supervisory authorities, taking account of processing and information available to Ductio. It shall supply relevant data-flow, recipient, retention, security and AI-processing information in time for applicable deadlines and alert the Customer promptly where an instruction may not be achievable in time.

8.4 Routine assistance and evidence under this Agreement are included in the fees. For exceptional Customer-requested work beyond ordinary service functionality, the parties may agree reasonable fees in advance. Fees, commercial disputes or contractual limits shall not delay mandatory assistance or restrict statutory rights. No additional fee is payable for remedying Ductio's non-compliance.

8.5 Intelligence licensing and exhausted allowances shall not block assistance required by law, disclosure of an individual's own personal data where legally required, or export of Customer Personal Data under section 10. The parties shall protect third-party rights through lawful, proportionate redaction or separation, rather than withholding the entire response. This does not create a right to demand Ductio's whole independently controlled database or unrelated customers' information.

9 Demonstrating compliance and audit

9.1 Ductio shall maintain appropriate processing records and make available all information necessary to demonstrate compliance with this Agreement and Article 28. It shall allow and contribute to audits, including inspections, by the Customer or its independent auditor. Evidence may include security summaries, risk assessments, relevant supplier assurances, test summaries, access controls, deletion records and incident reports, with proportionate redactions.

9.2 The parties shall normally begin with documentary evidence and remote review. If that does not reasonably establish compliance, or following a material breach, credible non-compliance concern or regulatory requirement, the Customer may inspect relevant systems, premises and processes. Independent reports do not replace the Customer's audit right.

9.3 Routine inspections shall normally be on 15 business days' notice, during business hours and no more than annually unless further review is justified. Those arrangements shall not delay urgent, incident-related or regulator-required audits. Auditors shall observe reasonable confidentiality and security requirements. Ductio may protect other customers' information and legitimate secrets through supervised access, redaction or equivalent evidence, without frustrating effective audit.

9.4 The Customer bears its auditor's ordinary costs. Ductio bears its own cooperation costs and reasonable additional verification costs arising from material non-compliance established by the audit. Ductio shall agree and implement a corrective-action plan without undue delay. Nothing restricts supervisory authority access or requires regulator approval through a commercial process.

10 Return retention and deletion

10.1 During the Services, Ductio shall apply Schedule 1 and the Customer's lawful retention and deletion instructions. Erasure shall cover copies, derived customer-specific records, search indexes and vector or embedding stores where they contain personal data. Deleting a source file alone is insufficient. Ductio shall propagate instructions to subprocessors.

10.2 At the end of processing, the Customer may choose return followed by deletion, or deletion alone. Ductio shall provide a secure, commonly used machine-readable export of Customer Personal Data on request made before termination or within 30 days afterwards, subject to identity and authority checks. This export window is not permission to retain data where earlier deletion is instructed. No continuing paid subscription is required merely to exercise this choice.

10.3 Unless an earlier lawful instruction applies, Ductio shall delete active copies no later than 90 days after termination and shall not use them during that period except to provide the requested return, complete deletion or meet a lawful retention requirement. Residual backup copies shall be isolated, protected and overwritten or securely erased within a further maximum 90 days. If restored for disaster recovery, prior deletion and restriction instructions shall be reapplied before ordinary use resumes.

10.4 Where law requires retention, Ductio shall identify the data, legal requirement and period to the Customer unless prohibited, minimise and isolate the retained data, restrict processing to that requirement and delete it when the requirement ends. A general interest in product improvement or possible future usefulness is not a retention exception. Ductio's separate controller records do not permit it to retain Customer Personal Data in another role.

10.5 Ductio shall provide written confirmation of completed deletion on request, identifying any legal-retention exception and any remaining isolated backups and their scheduled expiry. Ductio shall obtain equivalent confirmations from relevant subprocessors. Confidentiality, security, assistance and transfer obligations survive while any Customer Personal Data remains.

10.6 Survival of a lawfully exported assignment report under the intelligence licence does not extend Ductio's hosted retention or override an individual's rights. The licence's separate removal period for unused raw intelligence or API caches concerns the Customer's licensed independent copies; it does not replace this section's processor return and deletion duties. Storage capacity is not a retention entitlement. Trial-to-paid migration requires confirmed Customer instructions and must not silently create additional projects, duplicate retention or unrelated use.

11 International transfers and disclosure demands

11.1 Ductio shall process only in the locations recorded in the accepted Schedules 3 and 5. Customer instructions to use a Service do not waive transfer requirements. Ductio shall identify relevant storage, backup, support, model-processing and remote-access countries, assess each Restricted Transfer and establish an applicable mechanism before it occurs.

11.2 Schedule 4 applies to Restricted Transfers. Ductio shall maintain necessary transfer assessments and supplementary measures, monitor changes affecting safeguards and supply relevant information or copies of safeguards on request, subject to proportionate redaction. An adequacy decision or certified framework shall be relied on only while valid and covering the recipient and processing concerned.

11.3 Ductio shall scrutinise government and other compulsory disclosure demands, seek clarification or challenge where there are reasonable grounds, disclose only the minimum legally required and notify the Customer before disclosure where permitted. If prohibited, it shall seek permission to notify and document the prohibition. It shall not create voluntary unrestricted government access. Mandatory transfer-clause requirements, including assessment, challenge and transparency obligations, prevail.

11.4 If the required protection can no longer be provided, Ductio shall notify the Customer promptly, suspend the affected transfer and seek a lawful alternative. If none is available, affected processing shall end and data shall be returned or deleted as required. The Customer may terminate the affected Service with a pro rata refund of prepaid unused fees. Neither party may require continued unlawful processing.

12 AI voice integrations and trials

12.1 AI providers processing Customer Personal Data shall be authorised subprocessors under section 6 and bound to use prompts, outputs and related content only for the contracted processing. Ductio shall configure and contractually restrict provider training, retention and human access consistently with this Agreement. Customer-specific adaptation is permitted only where explicitly instructed, isolated to the Customer and covered by the agreed processing details.

12.2 Ductio shall minimise content sent to models, restrict access to customer-specific outputs and record sufficient processing information to support correction, deletion and meaningful human review. It shall not intentionally infer special category characteristics for candidate ranking or use voice to infer emotions, health or biometric identity under this Agreement.

12.3 Voice, recording, transcription and integrations apply only when included and separately enabled within the accepted scope by an authorised Customer user acting within delegated authority. Voice and separately chargeable functions default to off. Enabling calling does not authorise recording, transcription or additional analysis. Before each relevant use, the Customer shall establish lawful bases, participant notices and consent where required in all applicable jurisdictions. Ductio shall provide the agreed notice and recording controls, display usage and retention settings, and process only necessary data. Standard transcription does not authorise biometric identification, emotion recognition or inference of sensitive traits. The standard Voice service must not be relied on for emergency calling; statutory duties of Ductio and its provider remain unaffected.

12.4 Integrations shall use scoped permissions and protected tokens and may be disabled or revoked. Record association shall use verified identifiers where available, with review of uncertain matches; a name alone shall not be treated as conclusive identity. The Customer controls permitted recipients and remains responsible for lawful disclosures it initiates.

12.5 Trials have the same data protection safeguards as paid use. Unless the accepted trial Order states otherwise, they last seven days, cover one executive-search project and one AI run, with a second run only by express approval, and exclude voice and integrations. Expiry, return and deletion are governed by section 10; trial data shall not be retained for marketing or shared model development.

12.6 Each party shall meet applicable AI-law obligations for its actual role and intended use, including AI literacy, required documentation, transparency, risk assessment, oversight and incident cooperation to the extent applicable and in force. Recruitment, ranking, selection and workforce assessment require a documented classification assessment; describing a system as decision support or adding human review does not by itself remove a high-risk classification. Ductio shall provide relevant available intended-purpose, limitation and oversight information and discharge its own provider obligations where applicable. The Customer remains responsible for its deployment duties. No prohibited use is authorised, and a use needing unavailable safeguards must not be enabled until scope and safeguards are agreed and implemented. Material modification, repackaging or a change of intended purpose requires prior written assessment of resulting responsibilities.

12.7 Standard Services do not include formal background checks, regulated screening, security clearance, classified workloads or government mobilisation. Separately agreed public-sector or defence intelligence must have a lawful defined scope and appropriate controls. Ordinary lawful professional or aggregate organisational research is not prohibited solely because the client operates in that sector; targeting individuals for harm, coercion, unlawful surveillance or discriminatory profiling remains prohibited.

12.8 Protective action shall follow the accepted Acceptable Use Policy and Customer Terms, consistently with this Agreement. Ductio shall consider credible evidence, severity, urgency, affected people and available alternatives; unusual volume alone is insufficient to establish misuse. Normally give reasons, affected scope and a reasonable opportunity to correct, subject to lawful confidentiality restrictions. For an immediate security or legal risk it may promptly isolate content or temporarily restrict the narrowest affected function, then notify and review without undue delay. Offer a reasoned review by a person with authority to reconsider, accept relevant Customer evidence, and restore access when grounds cease. Termination and remedies follow the accepted commercial contract, without new penalties or liability caps. Suspension must not frustrate mandatory assistance, audit or return and deletion; where direct access is unsafe, provide a secure alternative where lawful.

13 Term liability and governing law

13.1 This Agreement continues for as long as Ductio processes Customer Personal Data. Commercial liability provisions in the Customer Terms apply between the parties only to the extent lawful and consistent with mandatory transfer clauses. They do not cap or exclude liability that mandatory clauses prohibit limiting, affect individuals' statutory compensation rights, or constrain regulator powers. Ductio's responsibility for subprocessors under section 6 remains intact.

13.2 Subject to mandatory transfer clauses and mandatory law, this Agreement is governed by the law of England and Wales and its courts have jurisdiction. If a provision is invalid, the remaining provisions continue and the parties shall replace it with a lawful equivalent preserving the required protection. Amendments shall be documented and agreed; website publication alone does not vary an existing signed or accepted DPA.

13.3 Notices shall be delivered to the contacts in Schedule 5 or subsequently verified replacements. The Customer shall keep them current. Privacy notices, public policy changes or a change of supplier branding do not replace contractual acceptance or necessary authorisation.

Schedule 1 Processing details and standing instructions

1 Subject matter and purpose. Processing necessary to provide enabled executive search, candidate assessment, succession, leadership, governance, organisational and investment-research intelligence assignments: secure hosting, private project analysis, controlled collaboration, support, authorised communications and return or deletion. Investment-research information is not regulated investment advice. The accepted Order identifies intended uses and enabled modules. No independent resale, advertising, general population surveillance or shared model training is instructed.

2 Nature and operations. Collection from Customer uploads and authorised integrations; validation, identity matching, organisation, storage, retrieval, extraction, indexing and embedding; customer-specific AI summarisation, comparison, scoring and explanation; authorised viewing, sharing and export; correction, restriction, support, backup, recovery and deletion. Voice processing includes transmission, recording and transcription only where enabled. The Customer instructs which projects and individuals to assess and which authorised recipients may access results.

3 Data subjects. Candidates, executives, directors, employees, applicants, referees, interviewers, assessors, client contacts, authorised users, meeting participants and other adults whose data the Customer lawfully supplies. Services are not directed at children and intentional processing of children's data is excluded without a separately agreed lawful scope.

4 Data categories. Names and identifiers; professional contact details and location; employment, education, qualifications and board history; CVs and biographies; compensation and objectives; interview and reference notes; assessment responses and customer opinions; role and project requirements; communications and attachments; customer-specific prompts, rankings, inferences, scores and explanations. Enabled voice may include telephone numbers, timestamps, audio, transcripts and summaries. Necessary authentication, access and processing metadata is included to the extent processed on instructions.

5 Sensitive data. Routine processing of Article 9 special category data, Article 10 criminal-offence data and biometric identification is excluded. Incidental appearance in a lawful document does not authorise evaluation of sensitive traits. The Customer shall redact unnecessary information. Any intentional sensitive-data processing requires written agreement identifying categories, purpose, lawful conditions, access restrictions, safeguards and retention before upload. Ductio shall restrict and notify the Customer of unexpected sensitive inputs where detected and seek instructions for lawful removal or handling.

6 Frequency and scale. Continuous or intermittent throughout enabled use, including batch uploads, repeated analysis and ongoing authorised integrations. Scope, approximate volumes and access groups follow the Order and Customer configuration and shall be documented in Schedule 5 where relevant to risk. No bulk harvesting or unrelated population profiling is instructed.

7 Duration. From the first authorised processing until return and deletion under section 10, including limited isolated backup and legally required retention. Subscription renewal does not extend a shorter data-specific retention setting.

8 Retention instructions. Customer-selected shorter periods apply. In the absence of a documented shorter setting, Customer content is retained during the relationship and subject to section 10 at its end; audio is retained no longer than 12 months from creation and transcripts no longer than 24 months from creation. Longer retention requires a documented necessary Customer purpose, lawful instruction and explicit period. Personal data in customer-specific operational logs is retained no longer than 12 months unless a documented incident or legal requirement justifies a defined extension. Backups shall follow section 10 and the verified service rotation in Schedule 5. Retention of independent controller records follows the separate Privacy Policy.

9 Customer instructions. Process only enabled services, approved users, verified recipients and authorised integration scopes; protect confidentiality; apply Customer corrections, restrictions and deletion; assist with rights and compliance; prohibit provider training and unrelated reuse. Customer-appointed providers and independent Ductio intelligence are separately identified under sections 1 and 6.

Schedule 2 Technical and organisational security measures

These are minimum contractual duties, rather than statements that a certification has been obtained. Ductio shall implement them before receiving production Customer Personal Data and maintain evidence proportionate to processing risks. Service-specific details and additional agreed measures may be recorded in Schedule 5.

1 Governance and personnel. Maintain documented security responsibilities, data classification, risk assessments, access and incident procedures; confidentiality commitments and relevant staff training; periodic review and escalation of significant risks to accountable management. Maintain an inventory of systems and recipients processing Customer Personal Data.

2 Identity and access. Enforce unique staff accounts, role-based least privilege, multifactor authentication for privileged and administrative access, controlled service accounts and periodic access reviews. Approve and log support access; revoke credentials promptly on departure or role change. Provide appropriate customer authentication and administrator controls and protect recovery workflows from unauthorised takeover.

3 Tenant and environment separation. Enforce tenant permissions on the server for files, records, queries, outputs, embeddings and exports. Separate production from development and testing. Do not use identifiable production data in development or test without a documented necessary instruction and equivalent protection. Prevent one customer's data being returned in another customer's prompts or results.

4 Encryption and secrets. Protect data in transit with modern supported TLS and at rest with industry-standard encryption, ordinarily AES-256 or equivalent platform protection. Restrict and manage encryption keys, tokens and secrets through controlled secret-management facilities; prohibit secrets in source code and unnecessary logs. Rotate or revoke compromised credentials and separate key access from ordinary application access where practicable.

5 Application and infrastructure security. Use secure development, peer review, managed configuration, dependency and vulnerability scanning, risk-prioritised patching and regular security testing, including after material changes. Validate uploads, reject or isolate malicious files and protect against common web attacks. Treat retrieved documents, uploads and embedded prompts as untrusted inputs: restrict tool permissions and external actions, test for prompt injection and cross-tenant disclosure, and enforce access checks at retrieval and export. Critical vulnerabilities shall be triaged promptly and mitigated without undue delay. Restrict network and administrative exposure.

6 Logging and monitoring. Record material authentication, privileged access, exports and security events; protect logs against unauthorised alteration, monitor significant suspicious activity and investigate alerts. Minimise personal data in logs and avoid full document, credential or prompt logging unless necessary and within instructions. Restrict log access and enforce retention periods.

7 Availability and recovery. Maintain encrypted, access-controlled backups and documented continuity and restoration procedures appropriate to risk. Test restoration periodically, protect availability and integrity, and reapply deletion and restriction records after recovery. Recovery time and recovery point commitments apply only if separately agreed in the Order; none is invented by this schedule.

8 Incident response. Maintain a response plan covering detection, containment, evidence preservation, investigation, notifications and recovery. Maintain an on-call or equivalent monitored escalation route sufficient to meet the 24-hour contractual notice maximum. Exercise and review the process periodically and following material incidents.

9 Suppliers and physical security. Assess suppliers, bind and monitor subprocessors under section 6, restrict remote access, verify transfer safeguards and maintain the recipient register. Use hosting facilities with appropriate physical access and environmental protection; apply suitable device security, screen access and remote-working controls to Ductio personnel.

10 Minimisation and privacy controls. Limit flows, model inputs and integration permissions to purpose; separate controller and processor datasets; support correction, restriction, export and erasure across files, outputs, indexes and derived stores. Preserve relevant provenance and dates; distinguish source facts, allegations, customer opinions and AI inferences. Assess identity-match and attribution errors and support meaningful human review of rankings and scores. Apply configured recording and transcription controls, proportionate retention and provider training restrictions. Disclosure and external actions shall respect the authorised recipient and project scope.

11 Assurance and change. Maintain evidence of control operation, review risk after material processing changes, test controls and track remediation. Provide available relevant assurance under section 9. Do not substitute an unverified certification claim for evidence or reduce overall protection without lawful prior agreement.

Schedule 3 Private subprocessor schedule

The authorised subprocessor register is supplied privately to the Customer and forms Schedule 3 when accepted with the Order. It identifies each relevant legal entity, service, processing scope and locations, retention and applicable transfer safeguards. The register and any required particulars must be completed and supplied before that provider receives Customer Personal Data. Section 6 governs authorisation, advance notice, objections and subsequent changes. The supplier list is not published on this website; confidentiality does not limit required Customer disclosures, authorisation, regulator access or mandatory transfer protections.

Schedule 4 International transfer provisions

1 Transfer mechanism and applicability

1.1 Before any Restricted Transfer, identify the exporter, importer, their actual roles, countries, processing and applicable law in the Schedule 5 transfer record. Use a valid adequacy decision or regulation where it covers the transfer; otherwise establish applicable approved safeguards and the necessary assessment and supplementary measures. Do not assume UK or EU adequacy or a supplier's certification remains valid. Exceptional derogations shall not be used as the routine basis for ongoing Services.

1.2 The arrangements below apply to Customer-to-Ductio transfers only where that transfer is restricted and the chosen clauses are legally applicable. They do not automatically execute an agreement with a third-party recipient. Ductio must enter into appropriate binding clauses with each onward recipient before an onward Restricted Transfer. For onward processor-to-subprocessor transfers, the corresponding Module Three arrangements and actual parties and annexes shall be completed in that separate instrument.

1.3 The 2021 EU transfer SCCs shall not be relied upon where their legal scope excludes the importer's processing, including where the relevant importer processing is already subject to EU GDPR Article 3 and the approved instrument is not applicable to that situation. The parties shall use an available applicable approved mechanism or other lawful safeguard. Until one is established the affected Restricted Transfer shall not occur. This schedule does not represent that every cross-border flow requires SCCs.

2 EU standard contractual clauses

2.1 Where applicable, the parties incorporate the unmodified standard contractual clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. All general provisions and only the selected module and options apply. Acceptance of this Agreement binds the parties to those clauses for the identified eligible transfer; the official text shall be supplied or made accessible at acceptance and retained with the accepted contract.

2.2 Module Two applies where the Customer exports as controller and Ductio imports as processor. Module Three applies where the Customer exports as processor and Ductio imports as subprocessor, with the underlying controller identified in Schedule 5. No controller-to-controller transfer is authorised through these module selections.

2.3 Clause 7 docking is included; additional parties join only by the required agreement and completed Annex I.A. Clause 9(a) Option 2 general written authorisation applies, with 30 calendar days' advance notice under section 6. The optional independent dispute-resolution wording in Clause 11 is not included. Clause 17 Option 1 specifies Irish law, permitting third-party beneficiary rights. Clause 18(b) specifies the courts of Ireland. These choices concern EU SCCs and do not change section 13 for the remaining Agreement.

2.4 Annex I.A parties: exporter is the Customer, at its legal address and with its contact in the Order or Schedule 5, in the role selected under paragraph 2.2; importer is DUCTIO LTD, company number 17303286, at its registered office and with the verified contact in Schedule 5. Activities are procurement and provision respectively of the enabled Services. Signature and date are the recorded acceptance or signatures for this Agreement and the identified transfer record.

2.5 Annex I.B description: Schedule 1 supplies subjects, categories, sensitive-data limitations, frequency, nature, purpose and retention. Schedules 3 and 5 supply actual countries, recipients and specific transfer details. For subprocessor transfers the subject matter, nature and duration are the identified provider's authorised service and period, without expansion beyond Schedule 1.

2.6 Annex I.C authority: identify the competent supervisory authority under Clause 13 and record it in Schedule 5. For an EEA-established exporter this is its competent authority; for a non-EEA exporter within Article 3(2), identify the authority determined by its representative or, where no representative is required, a relevant Member State where affected individuals are located, as Clause 13 provides. Do not select the Irish authority solely because Irish law governs the SCCs.

2.7 Annex II measures: Schedule 2 and any additional verified service-specific measures in Schedule 5. Annex III authorised subprocessors, where required: the actual accepted register in Schedule 3. Placeholder fields must be completed before reliance on the SCCs. The clauses' assessment, government-access, onward-transfer, suspension, termination, liability and third-party beneficiary protections remain unmodified.

3 UK International Data Transfer Addendum

3.1 For eligible UK Restricted Transfers using the EU SCCs with the UK Addendum, the parties incorporate the ICO-approved Addendum. Its Part 1 is completed by paragraphs 3.2 to 3.5 below and the identified Schedule 5 transfer record. The mandatory provisions are incorporated by the following express wording: Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

3.2 Table 1 parties: start date is the date the identified transfer arrangement is accepted. Exporter and importer, full legal names, addresses, registration details, key contacts and signatures are those in paragraph 2.4 and Schedule 5. Both parties accept the Addendum through recorded contract acceptance or signature.

3.3 Table 2 selected SCCs: the approved EU SCCs described in paragraph 2.1; Module Two or Three as selected for the actual roles under paragraph 2.2; Clause 7 included; Clause 9(a) Option 2 with 30 calendar days' notice; Clause 11 optional wording excluded. EU-only law, forum and authority choices are modified for UK transfers as Part 2 requires. No commercial provision overrides those modifications.

3.4 Table 3 appendix information: Annex I.A is paragraph 2.4 and the completed Schedule 5 parties record; Annex I.B is Schedule 1 and the actual transfer record; Annex II is Schedule 2 and service-specific measures; Annex III, where required, is the accepted Schedule 3 register. All required particulars shall be complete before the transfer.

3.5 Table 4 ending when the Approved Addendum changes: both the importer and exporter may end the Addendum as provided in Section 19 of its Mandatory Clauses. This is not an unrestricted termination right and does not permit processing without safeguards. Automatic revisions apply as provided by the Mandatory Clauses. Official text: https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf.

3.6 If the parties instead use the UK IDTA, they shall complete and execute its applicable tables and mandatory clauses separately before reliance; this Agreement does not purport to complete the IDTA through a reference to its name. Where another territory requires an approved mechanism or mandatory local adaptation, record and execute it before the relevant transfer.

4 Assessment supplementary measures and precedence

4.1 Ductio shall cooperate in the assessment required by applicable law, including relevant destination-country laws and practices, access risks and the recipient's ability to comply. Apply proportionate supplementary measures such as minimisation, encryption and key restrictions, scoped access, pseudonymisation where useful, transparency and challenge commitments. Encryption at rest alone does not remove risks where the recipient can access plaintext. Retain and review the assessment on material changes.

4.2 Mandatory transfer terms prevail over conflicting Orders, liability limits, audit restrictions and termination conditions. If their requirements cannot be met, suspend transfers and apply their return, deletion and termination provisions. Keep accepted clause text, elections, completed annexes and assessments available as evidence.

Schedule 5 Customer particulars and acceptance

Customer-specific particulars and acceptance are completed separately in the accepted Order or a confidential attachment forming Schedule 5. They identify the parties and their roles, relevant controller, accepted contract version, enabled services, monitored privacy and incident contacts, processing countries, retention selections, accepted Schedule 3 register and any applicable transfer records, annex details and additional safeguards. These particulars are supplied and agreed before the relevant processing or Restricted Transfer; they are not published on the website. Missing particulars do not authorise unidentified recipients, locations or sensitive-data processing. Recorded acceptance of an Order expressly incorporating this DPA and the completed applicable schedules, or separate valid signature, binds the parties. Publication alone does not constitute acceptance or amend an existing agreement.