Data Processing Agreement
Last updated: 19 August 2026
1. Definitions
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Passport Digital Limited (company number 17067449), trading as MyProductPassport ("Processor", "we", "us"), and the customer ("Controller", "you") and governs the processing of personal data in connection with our Digital Product Passport platform.
- Personal Data: Any information relating to an identified or identifiable natural person, as defined under UK GDPR.
- Processing: Any operation performed on personal data, including collection, storage, alteration, retrieval, use, disclosure, and erasure.
- Controller: The entity that determines the purposes and means of processing personal data (you, the customer).
- Processor: The entity that processes personal data on behalf of the Controller (Passport Digital Limited, trading as MyProductPassport).
- Data Subject: The individual to whom personal data relates.
2. Subject Matter & Duration
The Processor processes personal data on behalf of the Controller for the purpose of providing the MyProductPassport Digital Product Passport platform, including:
- User account management and authentication
- Product data management and Digital Product Passport generation
- Compliance reporting and audit logging
- Analytics and scan tracking
- Billing and subscription management (via Stripe)
This DPA is effective for the duration of your use of our services and continues until all personal data has been deleted or returned in accordance with Section 9.
Categories of data subjects: Controller's employees, end users, and supply chain contacts.
Types of personal data: Names, email addresses, company information, IP addresses, usage data, and product-related data entered by the Controller.
3. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, unless required by law
- Ensure that persons authorised to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures as described in Section 6
- Not engage another processor without prior written authorisation of the Controller (see Section 4)
- Assist the Controller in responding to data subject requests (see Section 5)
- Assist the Controller in ensuring compliance with obligations related to security, breach notification, impact assessments, and prior consultation
- Delete or return all personal data upon termination of services (see Section 9)
- Make available all information necessary to demonstrate compliance with this DPA
4. Sub-processors
The Controller authorises the Processor to engage the following sub-processors:
- Cloudways / DigitalOcean (EU/UK): Infrastructure hosting and server management
- Cloudflare (Global): CDN, DDoS protection, and web application firewall
- Stripe (US/EU): Payment processing and subscription management
- Brevo (EU): Transactional email delivery
The Processor shall notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.
5. Data Subject Rights
The Processor shall assist the Controller in fulfilling data subject requests under UK GDPR, including:
- Right of access: Users can export all personal data via the account settings page
- Right to rectification: Users can update their profile and company information at any time
- Right to erasure: Users can delete their account, which removes all personal data and associated records
- Right to data portability: GDPR data export provides a machine-readable JSON file of all personal data
- Right to restriction/objection: Contact [email protected] to exercise these rights
6. Security Measures
The Processor implements the following technical and organisational measures:
- Encryption in transit: All data transmitted via TLS 1.2+ (enforced via HSTS with preload)
- Encryption at rest: Sensitive fields (company numbers, VAT numbers, phone numbers) are encrypted at the application level
- Access control: Role-based access control (RBAC) with four levels: owner, admin, editor, viewer
- Authentication: Strong password requirements, optional two-factor authentication (TOTP), rate-limited login attempts
- Audit logging: All significant actions are recorded with timestamps, user identity, and IP addresses
- Infrastructure: Managed hosting with automated backups, firewall rules, and DDoS protection via Cloudflare
- Content Security Policy: Strict CSP headers with violation reporting
- Dependency scanning: Automated weekly security audits of all software dependencies
7. Breach Notification
In the event of a personal data breach, the Processor shall:
- Notify the Controller without undue delay and no later than <strong>24 hours</strong> after becoming aware of the breach
- Provide sufficient information to enable the Controller to notify the ICO within the statutory 72-hour window
- Cooperate with the Controller to investigate and remediate the breach
- Document all breaches, including their effects and the remedial action taken
Breach notifications should be sent to the Controller's registered email address and to [email protected].
8. Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct audits, including inspections, subject to:
- Reasonable prior written notice (minimum 30 days)
- Audits conducted during normal business hours
- The auditor being bound by confidentiality obligations
- A maximum of one audit per calendar year, unless a data breach or regulatory requirement necessitates an additional audit
9. Data Return & Deletion
Upon termination of services or upon request:
- The Controller may export all data using the platform's built-in GDPR data export feature
- The Processor shall delete all personal data within 30 days of account closure
- Backup copies shall be deleted within 90 days of account closure in accordance with automated backup rotation
- The Processor shall certify deletion upon the Controller's written request
10. Governing Law
This DPA is governed by and construed in accordance with the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales for any disputes arising under this DPA.
This DPA incorporates the UK GDPR and the Data Protection Act 2018. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of personal data.
For questions or concerns about this DPA, please contact [email protected].